delivering across bahria phase 1–8 · free delivery above rs. 2,500

legal

privacy policy

effective
30 July 2026

pending legal review. this text is complete and ready for a Pakistani lawyer to review and approve. requirements vary by province, city and cantonment — see /docs/legal-checklist-pakistan.md.

we collect what we need to sauce your bowl, get it to your door, and remember you if you ask us to — and very little else. analytics stay on our own servers and carry no names. no card details ever touch this service. today no payment processor, email provider or advertising platform is connected to it at all, so your data does not leave us except to the people who cook and deliver your food. you can export or delete what we hold from your account, and the rest of this page explains exactly what that means.

what we collect, and why

every item below exists because something in the service needs it. if a field is optional, we say so.

order details

whether you order as a guest or signed in: your name, phone number, an email address if you give one, and — for delivery — the address line, phase or area, and any instructions for the rider. with it we store the bowls you ordered and how they were customised (shape, heat, add-ons), cutlery preference, any note you left, the time you scheduled it for, and the money on the order (items, discount, delivery fee, tax, tip, gift card or points applied, total, payment method and payment status). the kitchen needs the food; the rider needs the address; the ledger needs the numbers. allergy notes are the closest thing to health information we handle — they exist for kitchen safety, and go to the people making that bowl and no one else.

account details

if you create an account: your email, your name, your password stored as a cryptographic hash we cannot reverse, an optional phone number, an optional birthday as day and month (never the year), your saved addresses with their labels and instructions, your favourites, your saved bowls, your order history, and whether you have said yes to marketing.

twirls

if you are in the loyalty programme: your points balance, your lifetime points, every points movement (earned, redeemed, reversed or expired) and the order that caused it, streak awards, and the reward codes issued to you. har daswan bowl free needs a count that adds up, so this is a running ledger rather than a single number.

plans and subscriptions

if you take a meal plan: your delivery days and time window, the address it goes to, your protein preference, any dietary notes you write, and any allergens you have asked us to keep out of your bowls — plus the schedule of meals delivered, skipped or cancelled.

catering and contact enquiries

a catering enquiry stores your company or family name, contact name, phone, email, event date and time, headcount, area, budget range if given, dietary requirements, and your notes — together with our internal notes and any quote we build for you. a contact-form message stores your name, email, phone if given, subject and message. both exist so a person can reply properly.

newsletter

nothing here exists unless you subscribe. if you do: your email address, the moment you consented, and which form you used. if you unsubscribe we keep a note of that too, so you are not signed up again by accident.

analytics

we measure what happens on the site — menu views, a bowl added to a cart, a build finished, an order placed — using our own analytics stored in our own database. an event records its name, the page it happened on, and a short list of typed values such as a menu slug, a quantity, or a rupee amount. events carry no account ID and no name, and today they carry no visitor identifier at all: they tell us what happened, not who did it. we use them to decide what stays on the menu and what to fix on the site.

technical and session data

when you sign in we create a session: a random token goes into a cookie in your browser, and our database keeps a hash of that token with an expiry date and your user ID. we also record sensitive actions on your account — a password change, for example — in an internal audit log, and staff actions on customer records the same way.

why we are allowed to hold it

in plain terms, four reasons cover everything above.

  • because you asked us to do something. taking your order, cooking it, delivering it, running your meal plan, keeping your twirls straight, answering your enquiry. without this data there is no order.
  • because you said yes. marketing email, the newsletter, and your optional birthday. consent, and nothing else, puts you on those lists — you can take it back at any time and we stop.
  • because we have a legitimate need to run the service safely. preventing fraud and abuse, keeping accounts secure, limiting how fast forms and sign-ins can be hammered, logging who touched what internally, and understanding in aggregate how the site is used.
  • because the law requires it. tax and accounting records, and lawful requests from authorities entitled to make them.

withdrawing consent switches off the consent-based items and nothing more. it does not delete the order records we are obliged to keep — see rights and retention below.

data we deliberately do not collect

some of these are choices we made in the code, not promises we hope to keep.

  • no card data. ever.today we take cash on delivery or at the counter. a clearly-labelled test payment method exists in development and moves no real money. there is no field anywhere in this service that stores a card number. if online card payment launches, the card details will go straight into a licensed processor’s own hosted form and never pass through our servers — and this policy will say so before that day, not after.
  • no personal details inside analytics. every event a browser can send is validated against a strict schema that lists its permitted fields. an extra field — a name, a phone number, an email, an address — fails the whole event instead of being quietly stored. menu slugs are checked against the live menu and area names against our own delivery zones, so free text typed into the site cannot end up in the analytics table.
  • no advertising pixel and no cross-site tracker. no Meta pixel, no TikTok pixel, no Google Ads tag, no third-party analytics script. nothing on this site follows you to another one.
  • no IP addresses in our database.rate limiting counts requests in the server’s memory and is keyed by a one-way hash where it needs to recognise an account. your IP address is not written to a table and not attached to your orders.
  • no device location. you tell us your phase; we never ask your browser or phone where you are.

we do not sell personal data. to anyone.

who sees your data

  • our kitchen and our team. staff see the orders and customer records they need to cook, dispatch, and sort out problems. access is limited by role and sensitive actions are logged.
  • riders. whoever brings your order sees the name, phone number, address and delivery instructions for that delivery. not your history, not your account.
  • nobody else, today — and this is worth stating plainly. no payment processor, no email, SMS or WhatsApp provider, no analytics vendor and no advertising platform is connected to this service. order confirmations are written to an internal outbox in our own database; nothing is dispatched to an outside sender yet. when we do connect a provider, we will name what it does here, it will be bound to use the data for that job and nothing else, and the change will be published before it goes live.
  • hosting. the site and its database run on infrastructure operated by a hosting provider, which can technically access what it stores for us. details in the next section.
  • the law. where disclosure is required — tax records, or a lawful request from an authority entitled to make it. we disclose what is asked for and no more.
  • a future owner. if the business is ever sold or restructured, customer records may transfer with it. we would tell you, and the buyer stays bound by this policy until it publishes its own.

where your data is stored

the website runs on Vercel and its database on Neon. both are hosted in Singapore, which means your name, phone number and delivery address are stored outside Pakistan.

we chose Singapore deliberately. a closer region was available, and we passed on it because where your personal information lives is not a decision that should be made purely on speed.

both providers process this data on our instructions alone, under their own security and confidentiality terms, and neither is permitted to use it for their own purposes. they keep technical request logs — the kind every web server keeps, which can include IP addresses — for [counsel to confirm: the provider’s current log-retention period].

cookies and similar technologies

one cookie, and it appears once you sign in and not before. it is called pastas_session (yes — the name still carries the platform this service was built on; renaming a session cookie signs everyone out, so it keeps its old name for now). it holds a random token and nothing else, it cannot be read by JavaScript, it travels to this site and to no other, it goes over HTTPS in production, and it expires after 30 days.

your cart is not a cookie. it lives in your own browser’s local storage and stays on your device until you place the order. we do not run third-party advertising cookies or cross-site trackers. the full list, with what each entry does and how to clear it, is on the cookies page.

how long we keep things

  • sign-in sessions: 30 days. signing out deletes the session immediately, and changing your password ends every session on every device.
  • order records: kept for as long as tax and accounting rules require — [counsel to confirm: the retention period Pakistani tax and accounting rules set for sales records] — then deleted or stripped of anything that identifies you.
  • account data: kept while your account is open. ask us to delete it and we remove your profile, addresses, favourites, saved bowls and twirls ledger, keeping what the order-record rule above obliges us to hold and nothing else.
  • catering and contact enquiries: kept while we are handling the enquiry and for a period afterwards so we can pick the conversation back up — [counsel to confirm: the retention period for enquiry and quote records].
  • newsletter: until you unsubscribe, plus a record that you unsubscribed so we do not add you again.
  • analytics events: kept while they are useful for menu and site decisions. they contain nothing that identifies you, which is why they do not expire with your account.
  • internal messages: queued order confirmations and similar notices contain your email or phone number and the message text, and are kept alongside the order they belong to.
  • audit log: a record of sensitive actions — a password change, a staff member editing a customer record — kept so we can investigate if something goes wrong.

your rights, and the buttons that action them

you can ask what we hold about you, get a copy, correct it, have it deleted, and take back marketing consent. none of it costs anything.

  • if you have an account: go to /account/preferences. your name, phone, birthday and marketing choice are editable there. the same page has a button to request a full export of your data and a button to request deletion of your account. both go into a queue that a person on our team works through — we act within 30 days and confirm by email.
  • if you ordered as a guest: there is no account to log into, so email contact@pastas.pk with the order number and the phone number you used. we will check you are the person on the order before we send or delete anything — protecting your data means not handing it to someone who simply knows your name.
  • marketing: untick the marketing box in your preferences, or tell us at contact@pastas.pk. it takes effect straight away.

what deletion cannot reach. an order that has been placed, taxed and accounted for is a financial record, and we are not allowed to erase it on request. when we process a deletion we remove your account and everything attached to it, keep the order records the law obliges us to keep, and tell you plainly which records stayed and why. those retained records are used for accounting and nothing else — you will not be marketed to from them.

marketing, and switching it off

there are exactly two places you can say yes: the marketing checkbox when you create an account, and the newsletter form. placing an order does not opt you in — checkout has no marketing box at all.

messages about something you asked for — an order confirmation, a delivery update, a reply to your enquiry — are not marketing, and you get those whenever you order. marketing is separate, it is optional, and it stops the moment you switch it off in /account/preferences or email contact@pastas.pk. once an email provider is connected, every marketing email will also carry its own unsubscribe link.

children

this service is not directed at children under 13, and we do not knowingly collect their personal data. accounts and orders are for adults, or for someone old enough to place an order responsibly. if you believe a child has given us personal data, write to contact@pastas.pk and we will delete it.

how we protect it

no claims of impenetrability — here is what is actually in place.

  • passwords are stored as scrypt hashes with a random salt per account. we never see or store the password itself, and the check at sign-in is written to avoid leaking information through timing.
  • sessions live in our database, not in a token you could tamper with. a hash of your session token is stored, never the token itself; sessions expire after 30 days, signing out deletes one, and a password change revokes them all.
  • the session cookie is HTTP-only, restricted to this site, and marked secure in production so it is not sent over plain HTTP.
  • staff access is role-based. customer, staff, manager and admin are distinct levels, and admin tools are gated on them rather than on knowing a URL.
  • sensitive actions are logged with who did what, to which record, and when.
  • sign-ins and public forms are rate-limited, per account as well as per origin, so a password cannot be ground down by repetition.
  • there is no card data to lose. the safest way to protect a card number is not to have one.

no system is perfectly secure and we will not pretend otherwise. if a breach affects your data, we will tell the customers affected and the relevant authorities as promptly as the law requires, explain what happened in plain language, and tell you what to do about it.

when this policy changes

if we change this policy, the effective date at the top of the page changes with it, and anything material — a new processor, a new category of data, a new purpose — is flagged on the site rather than slipped in quietly. we will not start using data we already hold for a materially different purpose without telling you before it happens. ask us at contact@pastas.pk for a copy of an earlier version and we will send it.

complaints

if something here has gone wrong, write to contact@pastas.pkwith “privacy complaint” in the subject, or use the contact form. a person reads it and replies within 30 days — you will get an answer, not a template. if you are not satisfied with that answer, you can escalate to [counsel to confirm: the authority or forum for privacy complaints in Pakistan, once counsel confirms the applicable regime]. this policy is governed by the laws of Pakistan, whose data-protection framework is still developing; when it changes in a way that affects you, this page changes too.

who you are dealing with

pastas is a sole proprietorship operating in Pakistan, operating a fresh pasta kitchen in Bahria Town Phase 4, Rawalpindi, and the ordering service at pastas.pk. the contracting party is pastas [legal name to be confirmed].

address for notices:
[counsel to confirm: registered address]
legal and privacy contact:
contact@pastas.pk — one inbox, read by a person. put “legal” or “privacy” in the subject and it reaches the right hands.