Privacy Policy
Last updated 29 August 2026
This explains what Comet does with information when a shop uses Comet Retail. It is written to be read, not to be survived. If anything here is unclear, write to support@comet.com.pk and a person will answer.
Two different kinds of information, and two different roles
This matters more than anything else on the page, so it comes first.
Information about the shop itself — the business name, the people who sign in, their email addresses and phone numbers, branch addresses, tax registration numbers, and what the shop pays us. We decide what happens to this, so for it we are what data protection law calls a controller.
Information the shop records about its own customers — names, phone numbers, addresses, purchase history, credit (khata) balances, loyalty points, and where Pakistani sales tax law requires it on a large invoice, a buyer's CNIC. This belongs to the shop. We hold it and process it on the shop's instructions and for no purpose of our own, which makes us a processor. We do not sell it, mine it, or use it to advertise anything.
If you are a customer of a shop that uses Comet and you want to know what that shop holds about you, ask the shop. They control it. We will help them answer, but the request has to go to them.
What we collect from a shop
- The business name, trading address, and tax numbers (NTN and STRN) that a receipt must carry.
- Names, email addresses and phone numbers of the people who sign in.
- Passwords, stored only as a one-way hash. We cannot read them.
- Till PINs, stored as a salted one-way verifier. We cannot read those either.
- Which plan the shop is on, and whether it is paid up.
- An activity log of significant actions — who changed a price, who refunded a sale, who set a PIN — so a shop can answer its own questions later.
What a till keeps on the counter
A till has to work when the internet does not. That is the point of the product, and it has a consequence worth stating plainly: the till keeps a copy of the shop's catalogue, prices, offers, customer list and stock levels in the browser on that machine, along with the sales it has rung up and not yet sent.
It also holds a salted verifier for each staff PIN, so a PIN can be checked with no connection. A verifier cannot be turned back into a PIN, but it is on the machine, which is why PINs are six digits rather than four and why a till should be a machine the shop controls.
That copy is removed when the till is signed out or the browser's data for the site is cleared. Signing a new machine onto a counter revokes the old one's access.
What we never store
- Card numbers. Card payments are taken on the shop's own card machine. We record the amount, the date and the settlement reference the bank gives — never a card number, expiry or CVV. Nothing in this system is a place a card number could be typed.
- Payment details for the subscription. Those are handled entirely by Creem, who take the payment. We are told whether an invoice was paid, and nothing else.
Where the data is kept
On servers operated by Hetzner Online GmbH in Helsinki, Finland. Shops using Comet are in Pakistan, so this is a transfer outside the country. It is disclosed here because it is true, not because a template said to include a paragraph like this.
Each shop's records are separated at the database level by row-level security, so one shop's queries cannot return another shop's rows even if the application asked them to.
Backups are taken every six hours, kept for fourteen days, checked by restoring them, and mirrored onto separate storage in the same facility.
An assistant a shop connects
A shop can connect an AI assistant to its own data using a token it creates and can revoke. When it does, that assistant can read what the token allows, and the shop chooses which tools it may use. We do not connect anything on a shop's behalf, and we do not use any shop's data to train anything.
How long we keep it
While the account is open, and afterwards for as long as the shop is likely to need it. When an account is closed we mark it removed rather than erasing it: a shop's invoices and tax records are documents it may be required to keep for years, and they are ours to hold rather than ours to destroy on a Friday afternoon. A shop can ask us to erase them permanently, and we will, once we have told them what will be lost.
Asking for a copy, a correction, or deletion
A shop can export its own data at any time from Settings, without asking us. For anything else — a copy of what we hold about the people who sign in, a correction, or deletion — write to support@comet.com.pk. We will reply within thirty days and usually much sooner.
Who else sees it
We share information with three kinds of party, and no others:
- Hetzner Online GmbH, who host the servers.
- Creem, who take subscription payments.
- Anyone we are legally required to tell, if we are lawfully compelled.
We do not sell information to anybody, and we do not share it with advertisers. There is no advertising in this product.
Security, honestly
Traffic is encrypted in transit. Passwords and PINs are stored one-way. Shops are separated at the database level. Access to production is limited and logged. No system is perfectly secure, and anybody who tells you otherwise is selling something — if we ever discover a breach affecting a shop's data, we will tell that shop what happened and what we know, promptly and in plain words.
Changes
If this changes materially we will say so on this page and date it. The date at the top is the version in force.
Contact
Comet,
Pakistan.
support@comet.com.pk