Legal

Privacy Policy

Last updated: July 2026  ·  Parr, Lahore, Pakistan

Parr ("we", "our", "us") is a business tool for home businesses in Pakistan. This policy explains what information we collect, how we use it, and what choices you have. We keep it short and in plain language.


1. What we collect

Account information. When you sign up, we collect your email address and the password you create (stored as a secure hash, we never see it).

Business data you enter. Everything you add to the Parr Ledger, client names, phone numbers, measurements, orders, payments, recipes, bookings, vendor details, and follow-ups, is stored so you can access it across devices. This data belongs to you.

Business profile. Your business name, type, and display preferences (accent colour, shortcuts) are stored as part of your account.

Contact form submissions. If you fill out a demo request or interest form on our site, we receive your name, email, city, and business type.

Technical data. Basic usage data (device type, browser) may be logged by our hosting provider (Netlify) and database provider (Supabase) for security and reliability. We do not use third-party analytics trackers.


2. How we use your information

We do not sell your data. We do not use your data for advertising. We do not share it with third parties except the infrastructure providers listed below.


3. Infrastructure providers

Your data is stored and processed using:

Both providers are bound by confidentiality obligations and do not use your data for their own purposes.


4. Data retention

Your account data is kept for as long as your account is active. If you delete your account, all your data (clients, orders, measurements, etc.) is permanently deleted from our database. This cannot be undone.

Contact form submissions are retained in Netlify for up to 12 months, then deleted.


5. Your rights


6. Security

All data is transmitted over HTTPS. Passwords are hashed and never stored in plain text. Database access is protected by row-level security, each user can only access their own records. We review our security practices regularly.


7. Children

Parr is intended for adults running home businesses. We do not knowingly collect data from anyone under 18.


8. Changes to this policy

If we make material changes, we will notify active subscribers by email before the changes take effect. The "Last updated" date at the top of this page will always reflect the current version.


9. AI document import (beta)

Some accounts have access to an invite-only beta feature that lets you photograph or upload a business document (a supplier price list, a client list, a notebook of orders, and similar) and turns it into an editable draft you can review before anything is saved. Access to this beta is granted individually by us to specific accounts and is separate from your subscription plan, having it does not depend on which plan you are on.

You choose when this happens. Nothing is scanned, uploaded, or processed automatically. An image is only sent for processing when you deliberately take a photo or pick a file inside the import screen.

What is sent, and to whom. The single image you select is sent, together with your business type and the type of document you told us you're importing, to our server (Supabase Edge Functions) and from there to Google's Gemini API, which reads the image and returns structured text back to our server. Google acts as an AI processing provider for this one feature, the same way Supabase and Netlify act as infrastructure providers elsewhere in this policy. We do not use Google Search grounding or any feature that would let Gemini query the open web with your data.

We do not keep your photo. The image is processed in memory by our server and discarded immediately after Gemini responds, it is never written to our file storage and never saved anywhere by Parr. Google's own retention for API requests is governed by our project-level settings with Google; before this beta is made available to any account, we configure those settings to disable request logging for this feature.

The draft, not the photo, is what you see. What comes back, names, prices, quantities, phone numbers, and similar fields Gemini was able to read, is held only in your browser, in a storage area scoped to that browser tab, for up to 30 minutes. It is never written to our database. Closing the import screen, cancelling, or letting the 30 minutes lapse without confirming all discard the draft immediately.

Nothing reaches your real business data without your confirmation. You review every extracted field, correct anything wrong, resolve any possible duplicates, and explicitly confirm before a single client, order, price, or any other record is created or updated in your account.

Original script is preserved exactly. Names written in Urdu script, Roman Urdu, or English are never automatically translated or transliterated by this feature.

What we keep about each import attempt. Separately from the draft, we keep a small operational record of each import attempt: a timestamp, which business/document type you selected, whether it succeeded, and technical details like which AI model responded. This record never contains the image, the extracted text, or any business data, and is used only for reliability and to enforce a daily limit on how many imports an account can run.


10. Contact

Questions about this policy or your data? Reach us at: