1. Introduction
GeoMine AI (“we”, “our”, “us”), a service operated by Ace Communication (registered office: 1st Floor, Khayam Chambers, PECHS Block 2, Karachi, Pakistan), is committed to protecting the privacy of every visitor and customer of geomines.org. This Privacy Policy explains what data we collect, why we collect it, how we use it, and the choices you have regarding your information. By using our website or services you consent to the practices described below.
2. Information We Collect
2.1 Information you provide
- Account information: name, email address, phone number, company name and password (stored as a salted hash) when you register.
- Profile information: profile photo, contact preferences and marketing preferences you choose to share.
- Analysis input: mine boundaries (KMZ/KML uploads or coordinates), target mineral type, project notes.
- Payment information: billing name, billing address and the last four digits and expiry of the card. Full card numbers are never stored on our servers — they are processed directly by our payment provider (PayFast / Stripe).
- Communications: messages you send via our contact forms, email, or WhatsApp.
2.2 Information we collect automatically
- Device and browser information (user-agent, screen size, language).
- IP address and approximate geographic location (city / country).
- Usage data — pages visited, features used, analyses generated, time spent.
- Cookies and similar technologies for authentication, session management and analytics.
2.3 Information from third parties
- If you sign in with Google or another OAuth provider, we receive your name, email address and avatar.
- Our payment processor (PayFast for PKR transactions, Stripe for international cards) shares limited transaction metadata back with us (status, amount, currency, last four digits).
3. How We Use Your Information
We use the information collected for the following purposes:
- To create and operate your account and authenticate you on the platform.
- To process payments, deliver paid analyses, and issue invoices and receipts.
- To run satellite imagery analyses on the geographic areas you specify and deliver PDF reports.
- To respond to enquiries, provide customer support, and resolve disputes.
- To improve our products — debug errors, study aggregated usage, and refine the AI models that generate reports.
- To send transactional emails (account verification, payment receipts, analysis-ready notifications) and, with your consent, occasional product updates.
- To detect, prevent, and investigate fraud, abuse, or security incidents.
- To comply with our legal obligations under Pakistani law (including AML/CFT, taxation, and SBP regulations as applied to our payment partners).
4. Legal Basis for Processing
Where applicable, we rely on the following legal bases: (a) performance of our contract with you, (b) your consent (which you can withdraw at any time), (c) compliance with a legal obligation, and (d) our legitimate interests in operating, securing and improving the service.
5. Sharing of Information
We do not sell your personal data. We share information only as follows:
- Service providers: cloud hosting (DigitalOcean), database (Supabase), email delivery (Resend), satellite imagery (Google Earth Engine, Planet Labs), AI report generation (Anthropic), and payment processing (PayFast, Stripe). Each is bound by appropriate data-processing terms.
- Payment partners: PayFast (Pakistan) and Stripe (international) receive the data necessary to authorise and settle your transactions.
- Legal & safety: if required by Pakistani law, court order, or to protect the rights, property, or safety of Ace Communication, our customers, or the public.
- Business transfers: in the event of a merger, acquisition, or asset sale, your data may be transferred under equivalent privacy protections.
6. Data Retention
We retain account and analysis data for as long as your account is active and for a reasonable period afterward to comply with legal, tax, accounting and dispute-resolution requirements (typically up to 7 years for financial records). You may request deletion of your account at any time (see Section 8).
7. Data Security
We protect your information using a combination of administrative, technical and physical safeguards:
- HTTPS / TLS 1.2+ encryption in transit for all traffic to and from geomines.org.
- Encryption at rest for the database, uploaded files and PDF reports.
- Salted password hashing — we never store passwords in plain text.
- Role-based access control; only authorised Ace Communication personnel can access production systems, on a need-to-know basis.
- Regular security patching, automated backups, and isolated production / staging environments.
No system is 100% secure. If we discover a personal-data breach affecting you, we will notify you and the relevant authorities within the timeframes required by applicable law.
8. Your Rights
You have the following rights with respect to your personal data:
- Access — request a copy of the data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Deletion — ask us to delete your account and associated data, subject to legal retention obligations.
- Restriction / Objection — ask us to restrict or stop certain processing.
- Portability — receive a machine-readable export of the data you provided to us.
- Withdraw consent — where processing is based on your consent.
To exercise any of these rights, email info@geomines.org from the address registered on your account or call us on +92 300 3644444. We will respond within 30 days.
9. Cookies
We use a small number of cookies that are strictly necessary to operate the site (authentication, session management, CSRF protection) and a privacy-respecting analytics cookie that helps us understand aggregate usage. You can disable cookies in your browser, but parts of the site — particularly the dashboard and payment flow — may stop working.
10. Children's Privacy
GeoMine AI is a B2B exploration tool intended for use by mining professionals, geologists and institutional researchers. The service is not directed at children under 18 and we do not knowingly collect personal information from minors.
11. International Data Transfers
Some of our service providers (e.g. Anthropic, Stripe, Google Earth Engine) are based outside Pakistan. Where data is transferred internationally, we rely on standard contractual clauses or equivalent legal mechanisms to ensure your data continues to receive an adequate level of protection.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will reflect the most recent changes. Material changes will be notified via email or an in-app banner at least 14 days before they take effect.
13. Contact
For any privacy-related questions or to exercise the rights described above, please contact us at the registered office shown below.