Privacy Policy

ANUBRIS (PRIVATE) LIMITED

Effective Date: March 2026

Last Updated: March 2026

ANUBRIS (PRIVATE) LIMITED
CUIN: 0326864 | NTN: I546208
Lahore, Pakistan

1. Introduction

Welcome to Agrixia. This privacy policy explains how ANUBRIS (PRIVATE) LIMITED ("we," "us," or "our") collects, uses, protects, and shares your information when you use the Agrixia mobile application and web platform ("Agrixia" or "the platform").

Agrixia is an agricultural marketplace and networking platform designed for farmers, dealers, harvester operators, agricultural workers, service providers, and traders across Pakistan. We are committed to protecting your privacy and being transparent about how we handle your data.

By creating an account or using Agrixia, you agree to this privacy policy. If you do not agree, please do not use the platform.

This policy applies to all Agrixia users, including those accessing the platform via the Android app, iOS app, or web application at agrixia.com.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Phone number — Required for account creation and OTP-based login. Your phone number is your primary identifier on Agrixia.
  • Name — Your display name shown to other users.
  • Username — A unique handle you choose for your profile.
  • City and province — Used to show you relevant local listings, jobs, and market prices.
  • User type — Whether you are a farmer, dealer, equipment owner, worker, service provider, or trader.
  • Profile photo and bio — Optional information you add to your profile.

2.2 Identity Verification

To build trust on the platform, you may choose to verify your identity:

  • CNIC (Computerized National Identity Card) — Your CNIC number is encrypted using AES-256-GCM encryption before storage. It is never stored in plaintext. Only authorized administrators can access CNIC data for verification and dispute resolution purposes.
  • Dealer license — If you are a registered equipment dealer, you may provide your dealer license for verified dealer status.

Providing your CNIC or dealer license is voluntary, but verified users receive a trust badge on their profile.

2.3 Content You Create

When you use Agrixia, you create content that we store on our servers:

  • Listings — Equipment, produce, or services you post for sale or rent, including titles, descriptions, prices, photos, and videos.
  • Job postings — Harvest jobs, labor requests, or service offerings you post.
  • Messages— Text messages, photos, and files you send through Agrixia's chat system.
  • Shorts — Short-form video content you upload to the Agrixia feed.
  • Statuses — Temporary updates you share with your followers (automatically deleted after 24 hours).
  • Reviews and ratings — Feedback you leave for other users after transactions.

2.4 Location Data

  • GPS coordinates— When you use the Zameen Naap (land measurement) feature, we access your device's GPS to measure land area. GPS access requires your explicit permission and is only active while you are using the feature.
  • City-based filtering — We use your selected city to show you relevant local content. This does not require GPS access.

2.5 Usage Data

We collect information about how you interact with the platform:

  • View counts — How many times your listings, shorts, and profile are viewed.
  • Interaction data — Which features you use, search queries, and general app navigation patterns.
  • Timestamps — When you last used the app (for online/offline status).

2.6 Device Information

  • FCM tokens— Firebase Cloud Messaging tokens used to deliver push notifications to your device. We do not collect your device's unique hardware identifiers.
  • Device type — Basic information about whether you are using a mobile app or web browser, used to optimize your experience.
  • Push notification subscriptions — Web push subscription details (VAPID-based) if you enable browser notifications.

2.7 Payment Information

  • Transaction records — When you purchase Connects (our virtual currency), we store a record of the transaction amount, date, and status.
  • Payment processing — Payments are processed through Safepay, which integrates with JazzCash and EasyPaisa. We do notstore your JazzCash/EasyPaisa account details, mobile wallet PINs, or any payment credentials. These are handled entirely by Safepay's secure payment infrastructure.

3. How We Use Your Information

We use the information we collect to:

3.1 Provide and Improve Services

  • Display your listings, jobs, and content to other users.
  • Show you relevant listings, market prices, and job opportunities based on your location and user type.
  • Operate the Zameen Naap land measurement tool.
  • Provide real-time mandi (market) prices and weather information for your area.
  • Improve the platform based on usage patterns and feedback.

3.2 Verify Identity and Build Trust

  • Verify CNIC submissions to award trust badges.
  • Display verification status on user profiles to help the community identify trustworthy users.
  • Investigate and resolve disputes between users.

3.3 Facilitate Transactions and Communication

  • Enable direct messaging between buyers and sellers.
  • Process Connects purchases and manage your Connects balance.
  • Facilitate voice and video calls between users (WebRTC-based, peer-to-peer).

3.4 Send Notifications

  • Send push notifications about new messages, listing inquiries, job applications, and other activity.
  • Send SMS for OTP verification during login.
  • Notify you of important account or platform updates.

You can control which notifications you receive through your notification preferences in the app.

3.5 Prevent Fraud and Enforce Policies

  • Detect and prevent spam, fake listings, and abusive behavior.
  • Enforce our community guidelines and terms of service.
  • Rate-limit actions to prevent automated abuse.
  • Respond to reports filed by other users.

4. How We Protect Your Information

We take the security of your data seriously and implement the following measures:

4.1 Encryption

  • CNIC data is encrypted using AES-256-GCM, an industry-standard encryption algorithm. CNIC numbers are never stored in plaintext in our database.
  • Data in transit is protected using HTTPS/TLS encryption for all communication between your device and our servers.

4.2 Authentication Security

  • JWT-based authentication with short-lived access tokens (15 minutes) and longer-lived refresh tokens (7 days).
  • OTP verification via SMS for every login — no passwords are used or stored.
  • httpOnly cookies for web sessions, preventing JavaScript-based token theft.
  • CSRF protection on all state-changing operations.

4.3 Infrastructure Security

  • Rate limiting on sensitive endpoints (login, messaging, listing creation) to prevent abuse.
  • Input validation on all user-submitted data using strict schemas.
  • Parameterized database queries to prevent SQL injection attacks.
  • File upload validation — all uploaded files are checked for allowed types and size limits.
  • Separate admin authentication — the admin panel uses an entirely separate authentication system.

4.4 Access Controls

  • CNIC data is accessible only to administrators with super_admin or admin roles.
  • Soft-deleted data is excluded from all public queries.
  • Users can only modify or delete their own content.
  • Blocked users cannot view each other's profiles or send messages.

5. Information Sharing

5.1 We Do NOT Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing or advertising purposes. We do not share your data with data brokers.

5.2 Publicly Visible Information

When you use Agrixia, certain information is visible to other users:

  • Your name, username, profile photo, bio, city, and user type.
  • Your listings, shorts, and reviews.
  • Your verification status and trust badges.
  • Your follower/following count.
  • Your online/offline status (if you have not set your profile to private).

You can set your profile to private to limit what other users see.

5.3 Payment Processors

When you purchase Connects, your payment is processed by Safepay, which may share transaction data with JazzCash or EasyPaisa as needed to complete the payment. These processors have their own privacy policies governing how they handle your payment information.

5.4 Service Providers

We use the following third-party services to operate the platform:

  • Firebase Cloud Messaging — for delivering push notifications to your device.
  • SMSGate — for sending OTP verification codes via SMS.

These services receive only the minimum data necessary to perform their function (e.g., your device token for push notifications, your phone number for SMS delivery).

5.5 Legal Requirements

We may disclose your information if required to do so by law, regulation, or legal process under the laws of Pakistan, including but not limited to:

  • Responding to a valid court order or government request.
  • Complying with applicable laws and regulations, including the Prevention of Electronic Crimes Act (PECA) 2016 and the Personal Data Protection Bill.
  • Protecting the rights, property, or safety of ANUBRIS, our users, or the public.

6. Your Rights and Choices

6.1 Access Your Data

You can view the personal information we hold about you through your profile page in the app. This includes your account details, listings, reviews, and activity history.

6.2 Update or Correct Your Information

You can update your name, username, bio, profile photo, city, and other profile information at any time through the app's settings.

6.3 Delete Your Account

You can request account deletion from the app settings. When you delete your account:

  • Your account enters a 30-day soft-delete grace period. During this time, your profile and content are hidden from other users, but your data is retained in case you change your mind.
  • If you log back in within 30 days, your account is fully restored.
  • After 30 days, your account and associated data are permanently deleted from our systems.

6.4 Control Notification Preferences

You can choose which types of push notifications you receive through the notification settings in the app. You can also disable push notifications entirely through your device settings.

6.5 Control Profile Visibility

You can set your profile to public or private. Private profiles limit the information visible to users who do not follow you.

6.6 Block Users

You can block any user on the platform. Blocked users cannot view your profile, send you messages, or see your content.

6.7 Report Content

You can report listings, messages, shorts, or users that violate our community guidelines. Our moderation team reviews all reports.

7. Cookies and Web Technologies

When you use Agrixia through a web browser, we use the following cookies:

7.1 Authentication Cookies

  • access_token — An httpOnly, secure cookie containing your JWT access token. This cookie cannot be read by JavaScript, protecting it from cross-site scripting (XSS) attacks.
  • refresh_token — An httpOnly, secure cookie containing your JWT refresh token, used to obtain new access tokens without requiring re-login.

7.2 Security Cookies

  • csrf_token — A non-httpOnly cookie used for Cross-Site Request Forgery (CSRF) protection. This token must be included in the header of all state-changing requests.

7.3 No Third-Party Tracking

We do not use third-party tracking cookies, advertising cookies, or analytics cookies that track you across other websites. We do not participate in ad networks or cross-site tracking.

8. Data Retention

8.1 Active Account Data

Your account information, listings, reviews, and other content are retained for as long as your account is active.

8.2 Deleted Accounts

When you delete your account, your data is retained for 30 days (soft-delete grace period) and then permanently removed from our systems.

8.3 Chat Messages

Chat messages are stored on our servers for the duration of the conversation. Messages are retained as long as both participants' accounts are active.

8.4 Statuses

Statuses (story-like temporary updates) are automatically deleted from our servers 24 hours after they are posted.

8.5 Usage Logs

Server logs containing request metadata (IP addresses, timestamps, endpoints accessed) are retained for a limited period for security monitoring and debugging purposes.

8.6 Transaction Records

Records of Connects purchases and other financial transactions are retained as required by applicable tax and financial regulations in Pakistan.

9. Children's Privacy

Agrixia is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18.

If we become aware that a user is under 18, we will take steps to delete their account and associated data. If you believe a child under 18 is using Agrixia, please contact us at the email address listed below.

10. International Data

Agrixia is designed for users in Pakistan. Our servers and data storage are located to serve the Pakistani market. If you access Agrixia from outside Pakistan, please be aware that your information will be transferred to and processed in accordance with the laws of Pakistan, which may differ from the data protection laws of your country.

11. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make significant changes:

  • We will update the "Last Updated" date at the top of this policy.
  • We will notify you through an in-app notification or a notice on the platform.
  • Continued use of Agrixia after changes are posted constitutes your acceptance of the updated policy.

We encourage you to review this policy periodically.

12. Contact Us

If you have questions, concerns, or requests regarding this privacy policy or your personal data, please contact us:

  • Email: admin@agrixia.com
  • Company: ANUBRIS (PRIVATE) LIMITED
  • Address: Lahore, Pakistan
  • CUIN: 0326864
  • NTN: I546208

We will respond to your inquiry within a reasonable timeframe.

13. Governing Law

This privacy policy is governed by and construed in accordance with the laws of Pakistan. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts in Lahore, Pakistan.

This privacy policy is written in clear language to help you understand how your data is handled. If you have any questions, please do not hesitate to reach out to us.