Platform Investor splits Pricing Blog Questions and answers Open app Request a demo
Privacy

What we collect, and what we do not

Written to be read rather than to be survived. It describes what the software actually does, including the part most policies skip: what happens to the identity documents and buyer details your showroom puts into it.

This describes how the system works and how we operate it. It is not legal advice, and it is not a substitute for a lawyer if you need one. If you are entering into a contract where data handling matters to you, ask us and we will put the specifics in writing rather than pointing at this page.

The distinction that matters

There are two very different kinds of personal data here, and conflating them is how privacy policies become useless.

Data about you, the showroom owner or member of staff using Odometric. Your name, email, phone. We decide what to do with that, so it is on us.

Data about other people, put in by you: your buyers, their CNICs, your investors, their phone numbers, the previous owner named on an excise book. You decide what to collect and why. We only hold it because you asked us to, and we do not use it for anything of our own.

In data protection language you are the controller of the second kind and we are the processor. In plain language: your customers' details are yours, we are storing them on your behalf, and we do not read them, sell them, mine them or train anything on them.

The website

The website uses two analytics tools. Google Analytics runs on the public pages, and its cookies recognise the same browser when it comes back, for up to two years after its last visit. Cloudflare Web Analytics is added by Cloudflare to every page of the site, including the application's own pages. Between them they record which pages are opened and the page you came from, roughly how many visits there are, the browser and device, and an approximate location worked out from your IP address. Google Analytics also records that the demo request form was sent, and when a link that leaves the site is clicked, such as a WhatsApp button, but not what you typed. On the application's pages Cloudflare's tool sees the page address, which for a vehicle includes its registration number, but never the contents of a record. There are no advertising pixels, no session recording and no heatmaps.

Almost nothing on these pages loads from a third party. The typefaces used to come from Google's font servers, which meant your IP address reached Google on every page load. They are now served from this domain. The exceptions are the two analytics tools above, which load from Google and Cloudflare. Every request to this site also passes through Cloudflare on its way to our server.

Beyond those, the one exception is by your own action: some buttons open WhatsApp. Nothing is sent, and WhatsApp learns nothing, until you choose to click.

If you fill in the demo request form we receive your name, your showroom's name, your phone number, your city and roughly how many units you hold. It is emailed to our founder's Gmail inbox, so Google stores it, and we use it to contact you about a demo. Nothing else. It is not added to a mailing list, because there is no mailing list.

Your account

To use the application we hold your name, email address, showroom name, and a hash of your password.

Passwords are stored as a scrypt hash with a unique salt per account, which means we cannot read your password and could not tell you what it is if you asked. If you lose it, it gets replaced rather than recovered.

We also keep a session cookie while you are signed in, and we record IP addresses temporarily for rate limiting, which is what stops someone guessing passwords in bulk.

What you put into it

This is the substantial part, and it is entirely yours: vehicles, purchase prices, expenses, scanned documents, buyers, investors, capital, payments and payouts.

Some of it is unavoidably sensitive. A vehicle record can hold a scan of a buyer's CNIC, a passport, a vehicle smart card or an excise book, plus names and phone numbers of people who never signed up to anything with us.

How the scanning works, precisely

Worth stating exactly, because the detail is favourable and easy to overstate.

Recognition happens in your browser. The text is read out of the image on your own device, by code running in a background worker on your phone or computer. The image is not uploaded anywhere to be read, and no third-party OCR service is involved at any point.

The image is then stored with the record, if you save it, along with the extracted fields and the raw recognised text, which is kept so a mis-read can be audited later. So the picture does reside on our server as part of your vehicle's record, and it is included in the encrypted nightly backup described under Where it is stored. We are not going to tell you documents never leave your device, because the one you choose to save does.

Where it is stored

The live data is on a server in Frankfurt, Germany, operated by Hostinger. Not in Pakistan, and not on a hyperscaler's shared analytics platform. Encrypted copies are kept outside Frankfurt, as described below.

There is also a copy on each device you use. So that the app keeps working where the signal does not, the browser on your phone or computer holds a copy of your showroom's records: the cars, the ledgers and the document lists, though not the scans and photos themselves. It is replaced each time the app loads with a connection, it is what you are reading when the app says it is showing an offline copy, and it is removed when you sign out of that device. Anything entered while offline is held there too until it reaches the server. A device that other people use should be signed out, for the same reason a register is not left on the counter.

Each showroom's records are isolated from every other showroom's. Nothing crosses that boundary, and the only information visible outside your own account is a vehicle you explicitly publish to the marketplace, with only the details you choose to publish.

Data is backed up automatically every night and before every deployment. Those backups stay on the same server as the live data, which protects against a bad deployment or a data mistake. Every night a copy also leaves the server: it is encrypted on the server first and then emailed to a Gmail mailbox belonging to our founder, so the data survives even if the machine does not. The emails are kept, so that mailbox holds one encrypted copy for each night. To be accurate rather than reassuring about what that means: those copies are stored by Google, wherever Google keeps Gmail, which is not necessarily in Germany or the EU. Each holds every active showroom's records, including scanned documents, photos and staff accounts with their password hashes, and leaves out the public demo showroom and accounts that have been closed. If the photos and scans ever grow too large to email, that night's copy carries the records without them, and we are told. Google holds the files but cannot read them, and neither could anyone who got into the mailbox, because the key that opens them is not on the server and not in the mailbox: it is kept on our founder's own computer. A backup is only as fresh as the night it was taken, so anything entered since then could be lost if the server failed.

Who can see your data

  • You and the staff you invite. You control who has an account and what they can do.
  • Us, in three narrow cases. When you ask us for support and we need to look at something to answer, when we have to investigate a technical fault, and when we restore data from a backup or check that a backup can be restored. Administrative access to a customer account through the software is recorded in an audit log. Opening a backup happens outside the software, so it is not in that log.
  • Nobody else uses it. Three companies are involved in running the service, and none is given your records to use for anything of its own: Hostinger operates the server in Frankfurt, Cloudflare handles every request between your browser and that server, so your records pass through its systems in readable form on the way, although it does not store them, and Google stores the encrypted nightly backup without the key to open it. We do not sell data, we do not share it with advertisers, the website's analytics tools never receive the contents of your records, and we do not use your records to train machine learning models of any kind.

We would disclose data if legally compelled to. If that happens and we are permitted to tell you, we will.

How long we keep it

  • While your account is active, we keep your records so the software works.
  • If you close your account, ask us for an export first. We will provide your data in a machine-readable form. After that we remove the account's records from the live system. To be accurate: removal sets them aside on the server, photos and scans included, rather than destroying them. They also remain in the backups kept on the server, including any taken while they are set aside, until those backups are deleted, and in the encrypted copies emailed off the server before the closure, which are not deleted on a fixed schedule. Copies emailed after the closure leave the account out. If you want the records destroyed rather than set aside, say so, and we will destroy the set-aside records and tell you when it is done.
  • Demo enquiries are kept in that inbox while we are in contact with you and deleted when the conversation is clearly over.
  • Audit and security logs are kept longer than ordinary records on purpose, because their whole function is to be checkable after the fact.

What you can ask for

Email [email protected] and ask us to:

  • Export your data.
  • Correct anything wrong about you.
  • Delete your account and its records.
  • Tell you what we hold about you specifically.

We aim to answer within a few working days. We will not ask you why.

Your side of it

Because you are the one deciding to collect your buyers' identity documents, some of the responsibility genuinely sits with you rather than with us. Three things worth being deliberate about:

  • Collect what the transaction needs, not everything a person will hand over. A CNIC copy for a sale is defensible. A folder of documents from someone who did not buy anything is harder to justify.
  • Give staff the access their job requires. Every account you create is another person who can see your buyers' details.
  • Tell people what you are keeping when they hand you a document. Most will not mind. Being surprised later is what people mind.

Changes

If we change this in a way that affects what we do with your data, we will tell account holders by email rather than quietly updating the date at the top. The date at the top will change too.

Contact

Questions, requests, or something here that does not match your experience of the product: [email protected]. If you think we have got something wrong, we would genuinely like to know, because a privacy policy that does not describe the software is worse than not having one.

Still deciding?

The questions and answers cover data ownership, hosting and what happens if you leave, in less formal language.

Read the FAQ Request a demo