Jenix Labs (SMC-Private) Limited Last updated: 12 August 2026
1. Who we are
Jenix Labs (SMC-Private) Limited is a company registered in Pakistan with the Securities and Exchange Commission of Pakistan. Our registered office is at House No. 73, Midland Avenue, Model Town, T-Chowk, Multan, Punjab, Pakistan.
We make Faro POS, point-of-sale and workshop-management software sold to automotive workshops and oil-change shops.
Contact for any privacy question or request: privacy@jenixlabs.com
2. Two different kinds of people, and two different roles
This policy concerns two groups, and our responsibilities differ for each.
Workshops that buy our software. We hold their business details, their sign-in credentials and their subscription records. For this information we decide how it is used, so we are responsible for it directly.
The workshop's own customers — the people whose vehicles are serviced. We hold their names, phone numbers, vehicle details and billing history on the workshop's behalf and on the workshop's instructions. The workshop decides what is collected, why, and for how long; we process it in order to provide the software.
If you are a workshop's customer and you want your data corrected or removed, ask the workshop first — they control it, and they can act immediately. If they cannot help, write to us at the address above and we will assist them in doing so.
3. What we handle
From workshops
- Business name, address, phone number and email
- Owner and staff names, sign-in email addresses, and password hashes (never plaintext passwords)
- Subscription, plan and billing records
- Machine identifiers used to bind a licence to a counter
- Where a workshop signs in with Google, the verified email address on that account. We do not receive the Google password, and we do not access anything else in the account.
From a workshop's customers, on the workshop's behalf
- Name, phone number, and where the workshop records it, an address
- Vehicle registration, make, model and odometer readings
- Service history, invoices, amounts, and outstanding balances
- Whether the person has agreed to receive promotional messages, or has asked to stop
- A record of messages sent to them, including delivery status
We do not collect this information from a workshop's customers directly. It reaches us because a workshop entered it into the software.
Automatically
- Diagnostic and error logs, to find and fix faults
- Sync timestamps and device status, so a workshop can see whether its data is current
We do not collect browsing history, location, contacts from a phone, or any data unrelated to operating a workshop.
4. Where the data lives
On the workshop's own computer, first. Faro POS is offline-first. A workshop's records are stored locally on its own machine and the software works with no internet connection.
In our cloud, for the features that need it. Where a workshop uses cloud sync, backup, the owner portal, or WhatsApp messaging, data is transmitted to servers we operate. Those servers are hosted with DigitalOcean.
In encrypted backups. Backups are encrypted before they leave the workshop's machine and stored with DigitalOcean Spaces.
We must be plain about one thing: the encryption key for a backup is generated and held by our systems, so we are technically able to decrypt a workshop's backup. We do this only where it is necessary to restore a workshop's own data at its request, or where the law requires it. We do not read workshop data for any other purpose, and access is limited to the people who need it to run the service. We would rather say this clearly than claim a protection we do not have.
5. WhatsApp messaging
Where a workshop chooses to use WhatsApp, the software sends messages to that workshop's customers — bills, service reminders, payment receipts, and promotional messages.
The workshop is the sender. Its own WhatsApp Business account is used, its own business name is displayed, and its customers reply to the workshop, not to us. We provide the software that composes and dispatches the message.
The workshop pays WhatsApp directly. A workshop connects its own payment method to its own WhatsApp Business Account, and Meta charges that account for messages. We do not resell messages, we do not add a margin, and we never hold a workshop's message credit.
To send a message we transmit to Meta the recipient's phone number, the message content, and where a
bill is attached, the bill document. Meta processes this under its own terms; see Meta's privacy
policy at https://www.whatsapp.com/legal/business-data-transfer-addendum.
Consent. Promotional messages are sent only to customers a workshop has recorded as having agreed to receive them. Any customer can stop all promotional messages by replying STOP, which the software enforces automatically and permanently until they opt in again. Transactional messages about a customer's own job — a bill for work done, a receipt for a payment — are sent because the customer did business with the workshop.
What we keep about a message. We keep a record of what was sent, to which number, from which of the workshop's numbers, when, and whether it was delivered — so that a workshop has an honest record of what its customers received. We do not keep the attached bill on our servers: it is uploaded directly to Meta at the moment of sending, and we store no copy and no reference to it.
Delivery receipts. When Meta tells us a message was delivered or read, the identifier in that notification contains the recipient's phone number. We treat those identifiers as personal information: they are held only as long as needed to record delivery, are excluded from data that syncs to a workshop's other devices, and are removed automatically thereafter.
6. Who else sees the data
We do not sell personal information. We do not share it for advertising. We do not permit anyone to use it for their own purposes.
We use these providers to run the service:
| Provider | What they handle | Where |
|---|---|---|
| DigitalOcean | Server hosting and encrypted backup storage | Data centres outside Pakistan |
| Meta Platforms (WhatsApp) | Delivery of messages a workshop sends | Meta's infrastructure |
| Sign-in, where a workshop chooses it | Google's infrastructure |
We may disclose information where we are legally required to, or to establish or defend a legal claim. If we are ever compelled to hand over a workshop's data, we will tell that workshop unless the law forbids it.
Because our providers operate outside Pakistan, data is transferred internationally. We choose providers that maintain recognised security standards and contract with them accordingly.
7. How long we keep it
- Workshop account and subscription records — while the subscription is active, and for seven years afterwards, because tax and company law in Pakistan require it.
- Customer and billing records — for as long as the workshop keeps them. A workshop can delete a customer at any time, and the deletion reaches our servers on the next sync.
- Message history — up to 90 days on our servers. The workshop keeps its own longer record locally.
- Delivery identifiers containing a phone number — kept only until delivery is recorded, then removed automatically.
- Backups — for the retention period the workshop configures, one year by default.
- Diagnostic logs — 30 days.
When a workshop's subscription ends, we delete its operational data within 90 days unless it asks us to keep it, or the law requires us to.
8. Your rights
Whoever you are, you may ask us to:
- Tell you what we hold about you
- Correct anything wrong
- Delete what we hold, subject to what the law requires us to keep
- Give you a copy in a portable format
- Stop using it for a particular purpose
Write to privacy@jenixlabs.com. We will reply within 30 days. We do not charge for this.
If you are a workshop's customer, we will usually need to pass the request to that workshop, because the workshop controls its own records. We will tell you when we do this, and we will help them act on it.
9. Security
- Data in transit is encrypted with TLS.
- Backups are encrypted before leaving the workshop's machine.
- Sign-in passwords are stored only as cryptographic hashes and cannot be reversed.
- A workshop's WhatsApp credential is stored on that workshop's own computer, in the operating system's secure storage, encrypted so it cannot be moved to another machine. It is never stored on our servers.
- Access to production systems is limited to the people who need it.
No system is perfectly secure. If a breach affects a workshop's data, we will notify that workshop promptly and tell it what happened, what was affected, and what we are doing about it.
10. Children
The software is for businesses. We do not knowingly collect information about anyone under 18. If a workshop has entered a minor's details as a customer, that is the workshop's record and the workshop is responsible for it under the law that applies to it.
11. Changes
We will post any change here and update the date at the top. If a change materially affects how we handle personal information, we will tell workshops by email before it takes effect.
12. Contact
Jenix Labs (SMC-Private) Limited House No. 73, Midland Avenue, Model Town, T-Chowk, Multan, Punjab, Pakistan privacy@jenixlabs.com