Privacy Policy

WhaShield — a service of WHASOLS (SMC-PRIVATE) Limited

Effective: 14th Aug, 2026  |  Last updated: 14th Aug, 2026

1. Introduction & Scope

WHASOLS (SMC-PRIVATE) Limited ("WHASOLS," "we," "us," "our") takes the protection of your personally identifiable information ("Personal Data") seriously. This Privacy Policy ("Notice") covers Personal Data we process in three distinct contexts:

  • Personal Data processed through our WhaShield application, plug-ins, JavaScript tag, API, or fraud-detection platform at https://www.whashield.com (collectively, the "Service");
  • Personal Data we collect when you contact us or visit our website at https://www.whashield.com (the "Website"); and
  • Personal Data we collect or store about current, prospective, and former customers of the Service.

Unless stated otherwise, this Notice applies to all three categories described above.

2. Who We Are

We collect order-related data and process it through WhaShield to assess the likelihood of e-commerce fraud. Our customers use this risk analysis to make better decisions about which orders and users to trust — for example, an online store using WhaShield to screen international orders and reduce chargebacks.

We work to ensure that the Personal Data we collect is appropriate and proportionate to the Service we provide. You can request that we delete, or refrain from selling, any Personal Data we hold about you at any time, using the process described below.

Across all three categories of Personal Data described above, WHASOLS determines the purposes and means of processing. As a result, we act as a "data controller" or "business" under applicable privacy laws, including the EU General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act ("CCPA") (together with other applicable laws, the "Applicable Laws").

3. Data We Collect

Data used in the Service. The Personal Data we collect for the Service is summarized in the table below. We collect only the order information needed to assess e-commerce transaction risk. Most of this data is supplied by our customers based on information gathered during checkout on their site; customers may also embed our JavaScript to observe visitor activity on their own site.

Data collected via the Website or from customers. When you visit our Website, contact us, or become a current, prospective, or former customer, we may collect:

  • Identifiers: first and last name, username, email address, payment card details, company name, phone number, IP address, and device fingerprint.
  • Special categories of Personal Data (as defined under CCPA): credit card numbers or other financial account information.
  • Commercial information: records of products or services purchased from, or considered with, us.
  • Internet or network activity: interaction with our website and advertising, proxy-server use, ISP and connection details, mobile carrier and usage type.
  • Geolocation data: billing and shipping address, country, region, city, ZIP/postal code, time zone, and related location data.
  • Other Personal Data: feedback you send us, or information you provide when exercising your data-subject rights, to the extent not already listed above.

This Notice does not cover Personal Data of our employees, job applicants, contractors, directors, officers, or other staff.

4. Lawful Bases for Processing

We rely on one or more of the following lawful grounds to process your Personal Data:

  • performance of our obligations to you where you have purchased the Service, or to assist you with a purchase at your request;
  • our legitimate interests, and those of our customers, in fulfilling their business needs — including detecting and preventing payment fraud and complying with export-control and sanctions requirements; and
  • any other legal basis required or permitted in the relevant context.

Where we receive Personal Data under a contract with you, that data is necessary to perform the contract — without it, we cannot provide the Service.

5. How We Process Personal Data

Data used in the Service: We process certain categories of Personal Data within WhaShield to calculate e-commerce order risk. Our customers decide how to use this output — typically for fraud screening and export-control compliance, including deciding whether to accept or decline an order, or to detect proxy-server use. See the table below for more detail on data sources and third parties.

Data collected via the Website or from customers: we also process Personal Data to:

  • respond to your inquiries and requests;
  • sell you our services, including processing payment;
  • pay commissions to affiliates;
  • understand how you interact with our Website;
  • improve our Website;
  • send you our newsletter; and
  • logging and statistical purposes.

We do not collect additional categories of Personal Data without informing you first.

6. Sharing With Third Parties

We use third-party vendors to perform certain functions on our behalf and may share your Personal Data with them solely to enable those services. We require these vendors to maintain data-protection standards at least equivalent to our own. We do not provide your Personal Data to parties unrelated to the Service.

Data collected via the Website or from customers may be shared with vendors providing:

  • infrastructure hosting services;
  • analytics services;
  • payment processing services;
  • service-desk and bug-tracking software; and
  • email delivery services.

Data used in the Service — see the table below for the categories of third parties who may receive this data.

7. Summary Table — Data Used in the Service

Personal Data How We Obtain It Business/Commercial Purpose Third Parties Who Receive It
Identifiers — name, username, email, company name, phone, IP address, device fingerprint Order form on our Website, or supplied through the Service by our customers Fraud-risk analysis for our customers; our and their legitimate interests as described above Our customers; infrastructure and software-management vendors (service desk, bug tracking, etc.)
Special categories — payment card information Same as above Same as above Same as above
Commercial information — order amount, currency, quantity Same as above Same as above Same as above
Internet/network activity — site interaction, proxy use, ISP, connection speed, carrier data Same as above Same as above Same as above
Geolocation — billing and shipping address Same as above Same as above Same as above

8. Cookies

A "cookie" is a small file stored on your device holding information about your session or settings. We use cookies for session management, targeted advertising, and web analytics. Most cookies on our Website are first-party cookies placed directly by us; other parties (such as Google) may set their own third-party cookies through our Website — refer to their policies to learn more.

You can configure your browser to reject some or all cookies, though this may limit access to certain Website features. Learn more at aboutcookies.org. You may also enable a Do Not Track (DNT) signal in your browser — learn more at allaboutdnt.com.

9. Other Disclosures

We may also disclose your Personal Data:

  • where required by law, or where we believe in good faith that disclosure is necessary to comply with an official investigation, subpoena, search warrant, or court order — note that once disclosed to government or law enforcement, we cannot guarantee how that data is subsequently handled;
  • in connection with a sale or transfer of all or part of our business, or a corporate restructuring; or
  • to our subsidiaries or affiliates, only where necessary for the business purposes described above.

We reserve the right to use, transfer, sell, or share aggregated, anonymized data that does not identify any individual, for any lawful business purpose, including trend analysis and identifying compatible advertisers, sponsors, or customers.

10. Data Security

We are committed to keeping your Personal Data safe. WHASOLS has implemented, and will maintain, technical, administrative, and physical safeguards reasonably designed to protect Personal Data against unauthorized access, exfiltration, theft, disclosure, alteration, or destruction.

11. Data Retention

Personal Data processed as part of the Service is retained indefinitely unless you request its deletion, subject to the limitations described in this Notice.

12. Privacy of Children

WhaShield and our other services are not directed at, or intended for use by, individuals under the age of 18. We have no actual knowledge that we sell the Personal Data of minors under the age of 16.

13. Your Privacy Rights

You have specific rights over the Personal Data we process about you. These rights apply only where WHASOLS acts as a "data controller" under the GDPR or a "business" under the CCPA — that is, where we (not our customers) decide why and how your Personal Data is processed. To exercise rights over data we process on behalf of one of our customers, please contact that customer directly and refer to their privacy policy.

Right to Be Informed

You have the right to know how we collect and use your Personal Data, how long we retain it, and with whom we share it. This Notice is how we keep you informed, and we will continue to do so as our practices evolve.

Right of Access

You may ask us to confirm whether we process your Personal Data and, if so, request a copy of it along with related details. For Service data, you can view what we collect at any time via our demo feature (see "Exercising Your Rights" below). Upon a verified request regarding Website or customer data, we will disclose: the categories of data collected; the sources; our purposes for processing; the retention period (or the criteria used to determine it); the categories of third parties we share it with; meaningful information about any automated decision-making or profiling under Article 22 GDPR; the specific data points we hold (a "portability" request); and, if applicable, details of any sale or business-purpose disclosure of your data, and the legitimate interests we rely on.

Under GDPR, we may decline an access request where you already have the information, where compliance would involve disproportionate effort or impair the purpose of processing, or where the data is subject to a statutory duty of confidentiality. Under CCPA, we will never disclose Social Security numbers, government ID numbers, financial account numbers, health/medical ID numbers, or account passwords/security answers in response to an access request.

Right to Rectification

You may ask us to correct inaccurate Personal Data or complete incomplete data. If your account settings don't allow a direct edit, contact us using the process below.

Right to Erasure ("Right to Be Forgotten")

You may ask us to delete your Personal Data. We will do so where we can — but the law permits us to decline in certain cases, including where the data is needed to: complete a transaction; fulfill a warranty or legally mandated product recall; provide a good or service you requested or perform a contract with you; detect security incidents or fraud and pursue those responsible; debug and repair functionality; exercise free-speech rights or another legal right; conduct public-interest research under proper consent and ethical safeguards; support internal uses consistent with your relationship with us; comply with a legal obligation; or make other lawful, compatible internal uses of the data.

Right to Restrict Processing

You may ask us to limit how we use or store your Personal Data — for example, while we verify its accuracy or the lawfulness of processing it.

Right to Object

You may object to our processing of your Personal Data where we rely on a legitimate interest (ours or a third party's), and you always have the right to object to processing for direct-marketing purposes. We will stop processing unless we have compelling legitimate grounds that override your interests, or we need the data to establish, exercise, or defend a legal claim.

Right to Data Portability

You may request a copy of the Personal Data you provided to us, or that we generated through your use of the Service, in a structured, commonly used, machine-readable format, so you can move, copy, retain, or transfer it elsewhere.

Rights Related to Automated Decision-Making

We may use automated tools to analyze your Personal Data, including to understand how you use our Services. Where a decision that significantly affects you is made this way, you have the right not to be subject to it without explanation — we will always tell you when this occurs, why, and what effect it has.

Right to Non-Discrimination

We will not deny you goods or services, charge you different rates, or provide a different quality of service because you exercised a privacy right, except as permitted by law.

Right to Lodge a Complaint

If the GDPR applies to your Personal Data, you may lodge a complaint with the supervisory authority in the EU member state of your residence, workplace, or where the alleged violation occurred.

Right to Opt Out of Sale

You may ask us not to sell your Personal Data at any time. We do not sell the Personal Data we collect from our Website or from our customers. Once you opt out, we will wait at least twelve months before asking you to reauthorize any sale; you may opt back in at any time.

Right to Opt In to Sale

If you previously opted out, you may opt back in at any time. We do not knowingly sell the Personal Data of individuals under 18. Anyone who opts in may opt out again at any time.

14. Exercising Your Rights

You may exercise any of the rights described above, including the right to opt out of a sale, by emailing us at [email protected], or by writing to us at:

WHASOLS (SMC-PRIVATE) Limited
Attn: Data Protection Officer
[Street Address]
Rawalpindi, Punjab, Pakistan

For requests related to data processed within the Service, since we need to verify your email address, the fastest route is via our request form (see Section 19). We will confirm your identity using a verification code sent to that address.

15. Authorized Agents

You may appoint an authorized agent to submit a rights request on your behalf, via written authorization or a power of attorney valid under the applicable rules of your jurisdiction (e.g., California Probate Code §§4000–4465 for California residents). We will ask your agent for that written authorization and will still require you to independently verify your identity.

For requests concerning data processed in the Service, your authorized agent must also provide a certification or attestation of authority.

16. Identity Verification

To act on a privacy-rights request, we need to confirm it genuinely comes from you. We may ask for specific information, potentially including Personal Data, solely to verify your identity or your agent's authority. You may submit a request to know or a portability request up to twice within any 12-month period.

For Service data specifically, we verify your identity by matching the email address you provide against the one on file in the Service. If they don't match, we will require additional verification, likely a certification or attestation, and may ask for your name or email solely to follow up on the request — this information is deleted once the request is resolved.

17. Response Timing & Format

We will confirm receipt of your request within 10 days, including an explanation of our verification process (if needed) and an expected response date, unless we've already acted on the request.

We aim to respond within 30 days of receipt. If we need more time (up to 90 days total), we will notify you of the reason and extended timeline in writing. Responses are delivered to your account if you have one, or by mail or electronically, at your preference, if you don't. Disclosures cover only the 12-month period preceding the request.

Opt-out-of-sale requests are actioned within 15 days; we will notify any third parties to whom we previously sold your data and instruct them to stop, informing you of this within 90 days of your request.

If we can't fulfill a request, we will explain why. For portability requests, we provide data in a format that is readily usable and easily transferable. We do not charge a fee to process rights requests, except where a request is manifestly excessive or repetitive — in which case we'll explain our reasoning and provide a cost estimate first.

18. Changes to This Policy

If we make a material change to this Notice, we will post the revised version on this page and update the "Effective" date above accordingly.

19. Contact Us

Questions about this Notice or how we process your Personal Data can be sent to [email protected], or by post to:

WHASOLS (SMC-PRIVATE) Limited
Attn: Data Protection Officer
[Street Address]
Rawalpindi, Punjab, Pakistan

Please allow up to 30 days for a response.


Questions? Contact us at [email protected].