Legal

Privacy Policy

How Forma collects, uses, and protects your data and your customers' data.

Template — review with qualified legal counsel before launch.This page is placeholder boilerplate written for Forma's planned features. It has not been reviewed by a lawyer and must not be relied on as a binding legal document until reviewed and approved.Last updated 19 June 2026.

1. Who this policy covers

This policy describes how Forma Technologies ("Forma", "we") handles data for: (a) merchants who create an account and operate a store on Forma, and (b) customers who place orders on a Forma-powered storefront. Each merchant's store may also have its own customer-facing privacy policy describing how that merchant uses customer data — this policy covers Forma's handling of data as the platform provider.

2. Information we collect

Merchant account data

  • Name, business details, and phone number (used for one-time-passcode verification and magic-link sign-in via Better Auth).
  • Store configuration: products, inventory, theme choices, discount rules, and tax/GST settings.
  • Billing information processed by Stripe for the Starter subscription (Forma does not store full card numbers).
  • Files you upload — product images and other assets — stored via Cloudflare R2.
  • Payment gateway and shipping carrier credentials you provide for your store (e.g. JazzCash, EasyPaisa, TCS, Leopards, PostEx), encrypted at rest.

Customer data (storefront)

  • Order details: items purchased, delivery address, contact information, and payment method selected.
  • Optional customer account information, if a customer chooses to create one after checkout.

3. How we use this information

  • To provide, operate, and maintain the Forma platform.
  • To authenticate merchant accounts via phone OTP and magic link.
  • To process Starter subscription billing via Stripe.
  • To enable order fulfillment — e.g. passing order and address details to the payment gateways and shipping carriers a merchant has configured for their store.
  • To operate the Mira AI WhatsApp assistant — message content from merchants and their customers is transmitted to OpenAI's API to generate replies (see Section 4 and the Mira AI section below).
  • To provide customer support and respond to inquiries.
  • To maintain the security and integrity of the Service, including detecting abuse.

4. Third parties we share data with

We share data with the following categories of service providers, only as necessary to operate the Service:

  • Stripe— processes Forma's subscription billing.
  • Cloudflare R2 — stores uploaded product images and other assets.
  • SMS provider — delivers one-time passcodes for phone-based authentication.
  • Payment gateways & shipping carriers— each merchant's configured providers (JazzCash, EasyPaisa, TCS, Leopards, PostEx, etc.) receive order data necessary to process payments and deliveries for that merchant's orders.
  • OpenAI— powers the Mira AI WhatsApp assistant. When a merchant or their customers send messages to Mira, those messages are transmitted to OpenAI's API to generate replies. OpenAI processes this data under its own privacy policy. Do not send sensitive personal data (e.g. payment card numbers, passwords) to Mira.

We do not sell personal data to third parties.

5. Mira AI assistant

Forma includes Mira, an AI-powered WhatsApp assistant that merchants can enable for their stores. When Mira is active:

  • Messages sent to Mira (by merchants or their customers via WhatsApp) are transmitted to OpenAI to generate responses. This includes the text of those messages and, where necessary to fulfil a request, relevant order or store data.
  • Mira is a beta feature. It is still evolving and may occasionally produce inaccurate or incomplete responses.
  • Merchants are responsible for informing their own customers that messages may be processed by an AI service when Mira is enabled on their store.
  • OpenAI's use of data is governed by OpenAI's Privacy Policy. We do not sell Mira conversation data.

6. Cookies

Forma uses essential cookies to maintain merchant and customer sessions (via Better Auth) and to remember basic preferences. We do not currently use third-party advertising or tracking cookies.

7. Data retention

We retain account and order data for as long as your account or store is active, and for a reasonable period afterward to comply with tax, accounting, and legal obligations. If you close your account, we may retain certain records as required by Pakistani law.

8. Your rights

You may request access to, correction of, or deletion of your personal data by contacting us at hello@forma.pk. We will respond within a reasonable timeframe, subject to our legal and operational requirements (e.g. retaining transaction records for tax purposes).

9. Security

We use industry-standard measures to protect your data, including encryption of merchant payment/shipping credentials at rest and secure session management via Better Auth. No system is completely secure, and we cannot guarantee absolute security.

10. Children's privacy

Forma is intended for use by businesses and adults. We do not knowingly collect personal data from children under 18.

11. International data transfers

Some of our service providers (e.g. Stripe, Cloudflare) operate infrastructure outside Pakistan. Where data is transferred internationally, we rely on those providers' own safeguards and contractual protections.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated to active merchants via email or dashboard notice.

13. Contact

Questions about this Privacy Policy can be sent to hello@forma.pk.