Legal
Privacy Policy
Last updated: September 12, 2026
1. Introduction
QistLock ("we", "us", "our") is a financed-device management platform operated in Pakistan. This Privacy Policy explains how we collect, use, store and protect information when you use our website, application and related services (collectively, the "Service").
By using QistLock, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
We collect the following types of information:
- Account information: Business name, owner name, email address, phone number and shop details provided during registration.
- Customer records: Customer names, CNIC numbers, phone numbers and contact details that you enter into QistLock as part of your financing operations.
- Device information: IMEI numbers, device model, brand and device status that you record against sales and financing plans.
- Payment records: Installment schedules, payment amounts, due dates and collection history that you log in the system.
- Usage data: Login timestamps, actions performed within the application and interaction data used for system operation and support.
- Device telemetry (when restriction is active): Location data, device status and connectivity information from financed devices that have the QistLock agent installed and restriction enabled.
3. How We Use Your Information
We use the collected information for the following purposes:
- To operate and maintain the QistLock platform.
- To process and record your financing transactions, payments and device actions.
- To enable device restriction, restoration and recovery workflows as configured by you.
- To provide customer support and respond to your enquiries.
- To send service-related notifications, including payment reminders and device status alerts.
- To improve the Service and develop new features.
- To comply with legal obligations and enforce our terms.
4. Data Ownership
You retain full ownership of all business data, customer records, payment information and device data you enter into QistLock. We do not sell, share or distribute your data to third parties for marketing or commercial purposes.
We act as a data processor on your behalf. The data you enter belongs to your business and is used solely to provide the Service to you.
5. Data Storage and Security
Your data is stored on secure servers with industry-standard encryption and access controls. We implement the following measures:
- Encrypted data transmission (TLS/SSL).
- Encrypted data storage at rest.
- Role-based access controls within your account.
- Regular security audits and monitoring.
- Automatic session management and login tracking.
While we take reasonable measures to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Data Sharing
We do not share your personal or business data with third parties except:
- With your explicit consent.
- To comply with a legal obligation, court order or government request.
- To enforce our Terms and Conditions.
- With service providers who assist in operating the Service (e.g. hosting, email delivery), bound by confidentiality obligations.
- In connection with a merger, acquisition or sale of assets, with prior notice to you.
7. Device Telemetry and Location Data
When you enable device restriction on a financed device, QistLock may collect:
- Device location (last known coordinates).
- Device connectivity and sync status.
- Device model and operating system information.
This data is collected solely for the purpose of device recovery and financing compliance. It is accessible only to the account administrator and authorised users. We do not track device location when restriction is not active.
8. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. If you delete your account, we will remove your data within a reasonable period, except where required by law.
9. Your Rights
You have the right to:
- Access the data stored in your QistLock account.
- Correct or update inaccurate data.
- Export your data in a portable format.
- Request deletion of your account and associated data.
To exercise these rights, contact us at privacy@qistlock.com.
10. Limitation of Liability — Device Integrity
QistLock provides software-based device management and restriction capabilities. QistLock is not responsible for:
- Hardware-level tampering, hijacking or physical modification of any device.
- Use of advanced technology, tools or techniques by any party to bypass, disable or interfere with device firmware, operating system or QistLock agent functionality.
- Damage to device firmware, software or hardware resulting from unauthorised third-party interference.
- Bypassing of device restriction through hardware exploits, custom recovery partitions, JTAG, chip-level access or similar methods beyond standard software controls.
- Any loss, damage or claim arising from hardware hijacking, firmware tampering or use of advanced circumvention techniques by any person.
QistLock's restriction and control features operate at the software level. Physical or hardware-level interference with a device is beyond the scope of our service and our liability.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us:
- Email: privacy@qistlock.com
- Contact page: qistlock.com/contact
Questions about your data?
Contact us and we will clarify how your information is handled.