1. Scope
This Privacy Policy describes how Together We Go (Pvt) Ltd ("TWG", "we") collects, uses and stores information through the client portal. It applies to registered company accounts, the individuals who use them, and the guarantors named on an application.
2. Information we collect
Account information: company name, registered user's name, work email, phone number, and a password (stored as a salted hash, never in plain text). Application information: vendor line items, approved amounts and repayment terms. Verification information: company registration and guarantor identity documents you upload, and the outcome of their review. Usage information: sign-in times, IP address for rate limiting and abuse prevention, and audit events tied to actions taken on your account (an append-only record of who did what and when, kept for accountability on financial transactions).
3. Why we collect it
To operate your account and process applications; to verify company and guarantor identity as required before approving an application; to detect fraud and enforce rate limits that protect every account, not only yours; to communicate about applications, invoices and repayments; and to meet TWG's own record-keeping and regulatory obligations.
4. Document retention
Verification documents and application records are retained for as long as your account is active and for a period after closure needed to satisfy audit, tax and regulatory requirements. Documents flagged as rejected during review remain part of the audit record even after a corrected document is accepted, so the review history stays complete. Specific retention periods are being finalised with TWG and will be stated here once settled.
5. Third parties we use
TWG uses a small number of processors to run the Service, each bound to use your data only to provide that service to TWG:
- Cloudflare R2 — stores uploaded verification documents in a private, tenant-scoped bucket. Documents are never publicly listable; access is through a short-lived signed link issued only when a reviewer opens a specific document.
- Resend — sends transactional email: verification codes, magic sign-in links, application and payment notifications. Resend processes the message content and recipient address needed to deliver each email.
TWG does not sell personal information, and does not share it with third parties for their own marketing purposes.
6. Data security
Passwords are hashed with argon2id and never stored in reverse- readable form. Sessions are hashed at rest and revoked on password reset or account deactivation. One-time codes are HMAC-keyed rather than stored as sent. Documents are held in a private bucket and reached only through time-limited signed links, each access recorded.
7. Your rights
You may ask TWG to correct inaccurate account information, and to tell you what personal information TWG holds about you. Because approved applications and their documents form part of a financial and audit record, some information cannot be deleted on request while your company has an open or recently closed application — the append-only audit log in particular is retained for accountability and cannot be edited or deleted by anyone, including TWG staff. Requests can be sent to the contact below.
8. Changes to this policy
TWG may update this policy from time to time. Material changes will be communicated directly rather than through this page alone.
9. Contact
Questions about this policy, or a request concerning your personal information, can be sent to your TWG relationship manager or to the company's registered contact address.