Privacy Policy
Effective date: 25 March 2026
1. Introduction
MASK ("we," "us," "our") operates the online presence platform at mask.pk. This Privacy Policy explains how we collect, use, store, share, and protect your data when you use our platform, visit our website, or interact with links, Bio Pages, QR codes, or other content created through our Service.
This policy should be read together with our Terms of Service and Cookies Policy.
2. What We Collect
Account data. Name, email address, password (stored as a cryptographic hash, never in plaintext), and organization name when you register. If you sign in via a third-party provider (e.g., Google), we receive your name, email, and provider account identifier. We never receive or store your third-party password.
Workspace data. Workspace names, member invitations, role assignments, branding preferences, and configuration settings.
Content data. Links, Bio Page content, QR code configurations, campaign details, custom domains, tags, templates, link rules (device-based, geographic, language-based, schedule-based routing), A/B test configurations, event configurations, and social preview metadata you create.
Subscriber data. Email addresses and metadata collected through your Bio Page subscribe forms, lead magnets, and newsletter sign-ups. If you use email campaigns, we store subscriber lists, campaign content, delivery status, and engagement metrics on your behalf. For all subscriber data you import, collect, or send through the Service, you are the data controller and MASK acts only as a processor on your behalf. You are solely responsible for the lawful collection of that data, for obtaining any required consent, and for compliance with applicable anti-spam and unsubscribe laws. Email broadcasts are sent using an SMTP server or email service provider (ESP) that you supply, configure, and own. That provider processes the send under its own terms, and message deliverability is not guaranteed.
Attendee data (Event Check-in). If you use Event Check-in, you may create events and generate or import an attendee guest list, including attendee names, email addresses, and ticket tiers, for which MASK issues unique QR tickets and records check-in scans (ticket code, status, and time). For all attendee data you import or collect through the Service, you are the data controller and MASK acts only as a processor on your behalf. You are solely responsible for the lawful collection of that data and for obtaining any consent required to store attendees' details and check them in.
Customer order data (Food Orders). If you enable Food Orders, customers can place orders from your published Bio Page. To fulfil those orders we store the details the customer submits at checkout, including their name, phone number, optional email address, delivery address (for delivery orders), a table number (for dine-in orders placed by scanning a table QR code), order items, and any notes, along with the order total, any discount or promo code applied, a requested time for scheduled orders, the chosen fulfilment method, and payment method. Where you run promotional codes with a per-customer usage limit, the customer's phone number is used to count that code's prior redemptions. Food Orders does not take payment online: orders are paid by cash or card on delivery or at pickup, and MASK does not process or store any card details for them. For all customer order data collected through the Service, you are the data controller and MASK acts only as a processor on your behalf. You are solely responsible for the lawful handling of that data and for any order confirmations or updates you send. Any such email notifications are sent using an SMTP server that you supply, configure, and own. If you additionally enable SMS order updates, status texts are sent through a Twilio account that you supply, configure, and own, and the customer's phone number and order status are shared with Twilio to deliver them, subject to Twilio's terms. MASK does not send order notifications from its own email or SMS identity on your behalf.
CV data (CV Maker). If you use CV Maker, you can build one or more CVs / résumés and publish each at its own link. The CV content you enter is stored on your behalf and can include personal details such as a full name, professional headline, email address, phone number, location, work history, education, skills, and links. You choose whether to publish a CV and whether to protect it with a password; a published CV that is not password-protected is viewable by anyone who has its link. When you set a CV password, it is stored only as a salted hash and never in plain text. For all CV content you create through the Service, you are the data controller and MASK acts only as a processor on your behalf, and you are responsible for the lawful basis and any consent required where a CV describes a person other than yourself. If you use Mask AI to draft a CV, the background text you enter is processed as described under “AI features data” below.
Billing data. Subscription plan selection and billing history. Payment card details are processed and stored exclusively by Stripe and are never stored on our servers.
Analytics data. When someone clicks a link, visits a Bio Page, or scans a QR code, we collect: a hashed (pseudonymized) IP address, approximate geographic location (country level on free plans, city level on paid plans), device type, operating system, browser type, referring URL, and timestamp. Visitor IP addresses are one-way hashed (SHA-256) before storage and are not retained in raw form for analytics.
Session and security data. IP address, device type, browser, session timestamps, login attempts, two-factor authentication status, and suspicious activity indicators for authenticated sessions.
Usage data. Feature usage patterns, session duration, API call volumes, webhook delivery logs, and error logs.
Audit log data. Administrative and security-relevant actions within Workspaces, including who performed the action, action type, affected resource, and timestamp.
Integration data. If you connect third-party services (Slack, Zapier, Stripe), we receive authentication tokens and event data necessary for integration functionality. If you connect your Stripe account, we receive payment notifications including transaction amounts, currency, customer email (if provided by Stripe), and payment status.
Affiliate data. If you join the Affiliate Programme, we collect referral link usage, referred sign-ups, commission amounts, and payout method details (bank account, PayPal, or Wise).
Communication data. Information you provide when contacting support, submitting reports, or using our contact form.
Free tools data. Some tools (such as the link shortener, QR generator, UTM builder, WhatsApp link tool, and bio link creator) can be started without an account; creating a free account is required to generate and save results. Data you submit to these tools may be stored to operate the tool, to generate and temporarily hold results, and for analytics and anti-abuse purposes. Depending on the tool, this can include names, email addresses, phone or WhatsApp numbers, and URLs you enter. Temporary tool results are retained for a limited period (approximately 24 hours) and tool usage events are retained for approximately 90 days (see Data Retention below).
AI features data. When you use Mask AI to generate bio-page copy or to draft a CV in CV Maker, the text you enter (such as your description, background, and any links you provide) is sent to a third-party AI processing provider (US-based) to generate the requested content. This text is used only to produce your output and is not used to train the third-party provider's models. Do not submit sensitive personal information you do not want processed by an AI provider.
3. How We Use Your Data
We use collected data for the following purposes:
- Provide the Service. Operate link redirection, Bio Page hosting, QR code generation, analytics dashboards, campaign management, A/B testing, templates, subscriber collection, email delivery, and integrations.
- Authenticate and secure. Manage sessions, enforce access controls, role-based permissions, approval workflows, and two-factor authentication.
- Process billing. Handle payments, manage subscriptions and expansion packs, generate invoices, and calculate affiliate commissions.
- Prevent abuse. Detect and respond to fraud, spam, phishing, bot activity, suspicious clicks, and Terms violations.
- Maintain audit trails. Log administrative actions for compliance, governance, and troubleshooting.
- Improve the product. Analyze anonymized and aggregated usage data to develop and improve features.
- Communicate. Send service updates, security alerts, billing notifications, and, where you have opted in, marketing communications.
- Comply with law. Meet legal obligations and respond to lawful requests from authorities.
4. Public Data and Analytics Tracking
Bio Pages and links you create through the Service may be publicly accessible by design. When you publish a Bio Page or create a link, visitors can view the page content and follow the link.
Public pages and links include analytics tracking by default. When visitors interact with your content, data is collected automatically for performance measurement, security monitoring, and abuse detection. This includes hashed (pseudonymized) IP addresses, device information, geographic location, referral source, and timestamps. This data is made available to you through the analytics dashboard.
You are responsible for disclosing this data collection to your visitors under applicable privacy laws. If you create shareable reports or public analytics pages, that data is accessible to anyone with the URL. Password-protected reports require the configured password.
5. Cookies and Tracking
We use cookies to maintain your session, remember preferences, and understand how the platform is used. We do not use third-party advertising cookies or participate in cross-site tracking networks.
For full details on what cookies we use and how to manage them, see our Cookies Policy.
6. Third-Party Services and Subprocessors
We rely on a small set of third-party service providers (subprocessors) to operate the Service. We share data with them only as needed to provide the Service:
- Hosting and infrastructure. Cloud hosting, content delivery, and the database and file storage that run the Service.
- Payment processor. Stripe processes subscription payments and add-on (expansion pack) billing. It receives the billing information necessary to complete transactions. Your use of payment features is also subject to the payment provider's own privacy policy and terms. MASK does not store payment card details on its servers.
- Bot and abuse protection. When enabled, Google reCAPTCHA helps protect our public forms (sign-up, login, magic link, contact, enterprise contact, and founding-creators forms) from automated abuse. When reCAPTCHA runs, your IP address and interaction signals are sent to Google for scoring, subject to Google's privacy policy and terms.
- AI processing. When you use Mask AI, the text you enter is sent to a third-party AI processing provider (US-based) to generate copy. It is not used to train the provider's models.
- Email delivery. A third-party email provider delivers our transactional emails (such as account and security notifications). Email broadcasts you send to your own subscribers are delivered through the SMTP server or email service provider that you configure and control, under that provider's terms.
- Affiliate payouts. If you participate in the Affiliate Programme and request a payout, your chosen payout details are used to remit commissions. Payouts made by PayPal or Wise involve those providers; bank transfers are handled by the relevant financial institutions.
- Your integrations. When you configure API keys, webhooks, or integrations (Slack, Zapier), data flows to the systems you designate. You are responsible for those systems.
A current list of the subprocessors we use, with their purpose and region, is maintained on our Subprocessors page.
We do not sell, rent, or trade your personal data. We may disclose data if required by law, to protect our rights or safety, or in connection with a business transfer (merger, acquisition, or asset sale).
7. Data Retention
- Account data. Retained while your account is active and for thirty (30) days after deletion to allow data export.
- Analytics data. Retention varies by plan. Free plans retain thirty (30) days of data. Paid plans retain data according to plan entitlements. Enterprise customers may negotiate custom retention.
- Billing and transaction data. Retained for a minimum of seven (7) years for tax and financial reporting compliance.
- Audit logs. Thirty (30) days on Growth plans. Indefinite on Enterprise plans.
- Subscriber and campaign data. Retained while your Workspace is active. You may delete subscriber data at any time.
- Event and attendee data. Tickets and check-in records are retained while your Workspace is active. You may delete an event and its attendee data at any time.
- Food Orders data. Menus, branches, and customer orders are retained while your Workspace is active. You may delete orders and menu data at any time.
- CV Maker data. CVs you build are retained while your Workspace is active. You may unpublish or delete a CV at any time; deleting it removes its public link.
- Affiliate data. Commission and payout records retained for a minimum of seven (7) years after programme participation ends.
- Free tools data. Temporary results generated by no-login tools are retained for approximately twenty-four (24) hours before expiry. Tool usage events (used for analytics and anti-abuse) are retained for approximately ninety (90) days.
- Anonymized data. May be retained indefinitely as it cannot identify individuals.
You may request deletion of your data at any time. We will delete or anonymize your personal data within thirty (30) days of a verified request, except where retention is legally required.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access. Request a copy of the personal data we hold about you.
- Correction. Request correction of inaccurate or incomplete data.
- Deletion. Request deletion of your personal data, subject to legal retention requirements.
- Restriction. Request that we restrict processing of your data in certain circumstances.
- Portability. Receive your data in a structured, machine-readable format.
- Objection. Object to processing based on legitimate interests.
- Withdraw consent. Where processing is based on consent, withdraw it at any time.
- Complaint. Lodge a complaint with a supervisory authority in your jurisdiction.
To exercise these rights, contact privacy@mask.pk. We respond to verified requests within thirty (30) days.
9. Lawful Basis for Processing
We process personal data on the following bases under GDPR:
- Contract. Processing necessary to provide the Service, manage your account, and fulfill subscriptions.
- Legitimate interests. Platform security, fraud prevention, abuse detection, and service improvement, balanced against your rights.
- Legal obligation. Tax regulations, financial reporting, and lawful authority requests.
- Consent. Marketing communications and optional cookies. You may withdraw consent at any time.
10. Data Controller and Processor Roles
MASK as controller. We are the data controller for personal data collected from registered users (account information, billing, usage data).
MASK as processor. When we handle data on behalf of our users, analytics data (click data, page views from visitors), subscriber data you import, collect, or send through email broadcasts, attendee data you upload for Event Check-in, customer order data collected through Food Orders, and CV content you build in CV Maker, we act as a data processor. Workspace owners are the data controllers for such data and are responsible for ensuring appropriate legal bases, consent, and anti-spam and unsubscribe compliance.
11. International Transfers
The Service may be hosted across multiple jurisdictions. Where personal data is transferred to countries without an adequacy decision from the European Commission, we ensure appropriate safeguards including Standard Contractual Clauses, data processing agreements with sub-processors, and technical measures (TLS 1.2+ encryption in transit, encryption at rest).
Contact privacy@mask.pk for details on safeguards applied to specific transfers.
12. Security
We implement technical and organizational measures to protect your data:
- Encryption in transit (TLS) and at rest for sensitive data.
- Cryptographic hashing of passwords and API keys.
- Two-factor authentication available for all accounts.
- Role-based access control with granular permissions.
- Enterprise security policies (mandatory 2FA, session limits, SSO-only access).
- Regular security assessments and code reviews.
- One-way IP hashing (pseudonymization) for analytics data.
No system is completely secure. We cannot guarantee absolute security but will promptly address incidents in accordance with our response procedures and applicable breach notification laws. In the event of a breach likely to risk your rights, we will notify the relevant authority within seventy-two (72) hours and affected individuals without undue delay.
13. Children
The Service is not directed at individuals under eighteen (18). We do not knowingly collect personal data from anyone under 18. If we learn we have collected data from someone under 18, we will promptly delete it. Contact privacy@mask.pk if you believe a minor has provided us with personal data.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via email or in-app notification at least thirty (30) days before taking effect. Continued use after the effective date constitutes acknowledgment of the updated policy.
15. Contact
For questions about this Privacy Policy or your data:
- Privacy: privacy@mask.pk
- Security: security@mask.pk
- Legal: legal@mask.pk
- Support: support@mask.pk
We respond to all inquiries within thirty (30) days.