Zarnuma Staff App — Staff Privacy Notice
STATUS: FINAL — Version 1.0, approved by the Owner, 6 September 2026. Shown to every staff member in the App alongside the Terms of Use.
The short version
- The App records the work you do in it — orders, money, stock, approvals — with your name, the time, and your signature. Those records are permanent.
- We hold your CNIC photos and bank details only to employ and pay you. Only you, Finance, and the Owner can see them.
- We never receive your fingerprint or face. Passkey sign-in keeps them on your own device; we store only a cryptographic key.
- We do not track your phone. No GPS, no reading of your messages, photos, or contacts. The App only knows what you do inside the App.
- Nothing is sold or shared with advertisers. There are no trackers.
1. Who we are, and who this notice covers
This notice explains what personal data the Zarnuma Staff App at staff.zarnuma.com (the "App") holds, why, and who can see it. The App is run by M/S FAWAD FLOUR AND GENERAL MILLS, 1-KM Nankana Road, Warburton, Tehsil & District Nankana Sahib (the "Company"). Zarnuma is one of the brand names the Company uses on its products, and the one this App carries. Questions go to the Owner, or through the in-app Report a problem.
It covers:
- every staff member with an App login; and
- employees without a login whose details Finance keeps in the App for payroll (their sections 2, 3, 5, 6, 8 and 9 apply the same way).
Customers' (shops') data is addressed in Section 10.
2. What we collect
Identity and employment
- Your name, login email, and role(s).
- CNIC photos (front and back), reviewed and authenticated by Finance.
- Bank details for salary transfer: account title, bank, branch, account number, IBAN.
- Date of joining; company assets assigned to you (official phone, number, email, rickshaw).
- A profile photo, if you add one.
Pay
- Salary, salary advances and their recovery, absence deductions, commission accruals and monthly slices, payslips.
Your work in the App
- Every record you create or approve — orders, collections, cash custody and hand-overs, loads, deliveries, dispatches, expenses, returns — each stamped with your identity, the time, and (where signed) the signature method used (password or fingerprint).
- Photos you upload as evidence: deposit slips, transfer screenshots, loaded vehicles, delivery drop-offs, expense receipts.
- Problem reports you file (including which screen you were on and your device's browser description, sent to help diagnose the issue).
Security
- A one-way encrypted form of your password. Nobody — including the Owner — can read your password.
- If you enroll fingerprint / Face ID: a passkey public key for each device, and the record of when it was used. Never your fingerprint or face — those stay on your device and cannot be reconstructed from what we hold.
- Sign-in times and session records, used to enforce automatic sign-out (24 hours idle, 7 days maximum) and to show the Owner each account's last sign-in.
- Standard security logs such as rate-limit counters (kept briefly).
Notifications
- If you enable push notifications on a device: that device's push subscription address, used only to send you work notifications.
What we do NOT collect
- Your fingerprint or face (see above).
- Your location. The App does not use GPS today. (Shops' map locations are the shops' data, picked on the map — not tracking of you.) See Section 11 for planned delivery tracking.
- Anything else on your phone: contacts, messages, photos you did not yourself attach, other apps.
3. Why we hold it
- To run the business: orders, stock, deliveries, and money need records of who did what, when.
- To employ and pay you: payroll needs your CNIC (identity) and bank details; commission needs your sales and recovery figures.
- Accountability and protection against fraud: the signature and audit trail exists so that money and stock movements can never be silently altered or denied — this protects honest staff first. It is the App's core purpose, agreed in the Terms of Use.
- Security: session limits, sign-in records, and rate limits protect everyone's accounts.
- Legal obligations: keeping business and payroll records the law requires.
We collect nothing for advertising or resale, and we run no analytics trackers.
4. Where it comes from
From you (what you enter and upload), from management (account creation, roles, pay, targets), and from the records your work creates.
5. Who can see what
Access in the App is enforced in the database itself by role — not just hidden in the screens. The key points:
| Data | Who can see it |
|---|---|
| Your CNIC photos, bank details, date of joining | You, Finance, and the Owner. Nobody else. (Owners' own details are visible only to Owners.) |
| Your payslips | You, Finance, and the Owner. Colleagues never see your pay. |
| Salaries, advances, absence deductions | Finance and the Owner. |
| Your commission earnings and target progress | You; the Sales Manager and Owner (who manage targets and the pool); Finance (who pays it). |
| Your password | Nobody, ever. (Stored one-way encrypted.) |
| Your enrolled fingerprint devices | You (listed in My Profile). The system knows a device is enrolled, never the biometric itself. |
| Your sign-in times / last sign-in | The Owner (on the Team page). |
| Problem reports you file | You and the Owners. |
| Work records (orders, collections, custody, loads, deliveries, expenses) | The roles that need them to do their jobs — for example: a salesman sees his own shops and orders; managers see their team's work to approve it; Finance and the Owner see money records across the office; the Warehouse Keeper sees stock movements; a Driver sees his own runs; the Recovery Agent sees a deliberately limited worklist (no shop phone numbers, no statements). |
Nothing in the App is visible to the public or to anyone without a login.
6. Where it is stored, and who processes it
- Database, authentication, and photo storage: Supabase — the Company's database runs on Supabase's cloud infrastructure, currently on Amazon Web Services servers located in Tokyo, Japan.
- App hosting: Netlify serves the App itself.
- Push notifications: delivered through your device's own push service (Google, Apple, Mozilla, or Microsoft, depending on your phone/browser). These services carry the notification; message content is encrypted to your device.
- Backups: the database is backed up daily by the hosting provider, and evidence photos are additionally mirrored, append-only, to a Company computer.
No advertising networks, no analytics services, no data brokers. The Company does not sell or rent personal data — ever. Data is disclosed outside the Company only if the law requires it (for example a lawful order of a court or authority), or to professional advisers under confidentiality.
7. How it is protected
In plain words:
- Everything travels encrypted (HTTPS, enforced).
- The database itself enforces role-based access on every row — the limits in Section 5 hold even if a screen has a bug.
- Photos live in a private store; they are viewable only through short-lived signed links given to authorized roles.
- Every sensitive action requires a fresh signature (password or fingerprint), and the signature trail is append-only.
- Sessions expire automatically; sign-in attempts are rate-limited.
- Automated security checks run on every release to catch permission regressions before they ship.
No system is perfectly secure, but access is deliberately narrow and every access path is checked.
8. How long we keep it
- Business and financial records, signatures, and evidence photos: permanently. They are the Company's books and its proof of money and goods. It is the Owner's standing policy that transaction proof photos are never deleted.
- Employment documents (CNIC, bank details): for your employment and as long afterwards as employment, tax, and audit law requires.
- Passkeys: until you remove them or your account is disabled.
- Push subscriptions: until you disable notifications or the device stops accepting them (dead devices are pruned automatically).
- Security counters (rate limits): about a day.
9. Your choices and rights
- See your own data: My Profile shows your documents, bank details, and enrolled devices; Payroll shows your own payslips; Commissions shows your own earnings.
- Correct it: tell Finance or the Owner about any error in your details; corrections to signed business records are made as new signed entries.
- Optional things stay optional: push notifications and fingerprint enrollment are off until you turn them on, per device, and you can turn them off again.
- What cannot be deleted on request: business records of actions you took are the Company's books and evidence — they name you and remain, as agreed in the Terms of Use.
- Complaints: to the Owner, or through Report a problem.
10. Customers' (shops') data
The App also holds business data about the shops the Company serves: shop and owner names, addresses, phone numbers, map locations, credit limits, balances, and transaction ledgers. This is held to run the business and collect what is owed. Staff duties of confidentiality towards customer data are in the Terms of Use, Section 10 — use it only for your job, and never share it outside the Company.
11. If the App changes what it collects
If the App starts collecting a new kind of personal data — for example, live driver location during delivery runs is a planned future feature — staff will be told before it starts, this notice will be updated with a new version number, and re-acceptance will be asked for where the change is significant.
12. Changes and contact
This notice may be updated; the current version and date always appear at the bottom, and the App shows you material changes. It is governed by the laws of Pakistan.
Contact: the Owner, or the in-app Report a problem.
Zarnuma Staff App — Staff Privacy Notice, Version 1.0, 6 September 2026.