BizHub LK
Privacy & Data Protection

Your Privacy,
Our Responsibility

We believe privacy is a right, not a privilege. This page explains exactly what data Bizhub.lk collects, why we need it, and how we protect it — in plain, honest language.

Effective: 1 May 2026
Updated: 1 May 2026
Sri Lanka
We Never Sell Your Data
Your personal information is never sold or rented to third parties
Bank-Grade Encryption
All data encrypted with AES-256 at rest and TLS 1.3 in transit
You're in Control
Access, correct, or delete your data any time from your dashboard
No Ad Tracking
We don't track you across other sites or share data with ad networks

This Privacy Policy explains how Bizhub.lk (Pvt) Ltd ("we," "our," "us") collects, uses, stores, shares, and protects your personal information when you use our e-commerce platform. We've written this in plain language — not legalese — because we believe you deserve to understand exactly how your data is handled.

This policy applies to all users of Bizhub.lk, including buyers, sellers, visitors, and anyone who interacts with our website, mobile app, or services. It covers all transactions made through our platform including purchases, payments via PayHere, Stripe, bank transfer, card payments, and cash on delivery.

If you have any questions after reading this, please reach out to our Privacy Team at privacy@bizhub.lk — we're always happy to help.

01

What We Collect

The personal information we gather and why we need it

We collect only what's necessary to operate our e-commerce marketplace and provide you with a great shopping and selling experience. Here's a full breakdown by category:

Account & Identity
  • ·Full name and display name
  • ·Email address and phone number
  • ·Date of birth (age verification)
  • ·Profile photo (optional)
  • ·Encrypted account password
Delivery & Address
  • ·Billing address
  • ·Shipping / delivery address
  • ·District and province
  • ·GPS location (optional, with consent)
Payment Information
  • ·Tokenized card reference (last 4 digits only)
  • ·PayHere transaction IDs
  • ·Stripe payment intent IDs
  • ·Bank transfer reference numbers
  • ·Order and refund history
Shopping Activity
  • ·Browsing and product view history
  • ·Wishlist and saved items
  • ·Cart contents and abandoned carts
  • ·Order history and status
  • ·Product reviews and ratings
Seller Information
  • ·NIC or passport number (verification)
  • ·Business registration number (if applicable)
  • ·Bank account details for payouts
  • ·Store name, logo and description
  • ·Product listings and inventory data
Technical & Usage Data
  • ·IP address and approximate location
  • ·Browser type and operating system
  • ·Pages visited and time on site
  • ·Referral source and UTM parameters
  • ·Device identifiers and session tokens
We never store full payment card numbers. All payment processing is handled by certified PCI-DSS compliant gateways — PayHere and Stripe. We only store a tokenised reference and the last 4 digits for your records. Cash on delivery and bank transfers are never linked to card data.

Seller-Specific Data: If you register as a seller on Bizhub.lk, we additionally collect your NIC or passport number for identity verification, your business registration details (if applicable), bank account information for payouts, and all product listings and inventory data you upload.

Voluntary Data: Some information — such as your profile bio, social media links, or store banner image — is entirely optional. Skipping this data will not affect your ability to buy or sell on the platform.

02

How We Use Your Data

The specific purposes for which we process your personal information

We process your personal data only for specific, legitimate purposes. We will never use your data in ways you wouldn't reasonably expect as a shopper or seller on Bizhub.lk. Here's a complete breakdown:

PurposeData UsedLegal BasisOpt-Out?
Order fulfillment & deliveryName, address, order details, contact infoContract performanceNo
Payment processingPayment tokens, order amounts, billing addressContract performanceNo
Account managementEmail, password hash, profile dataContract performanceNo
Seller verification & payoutsNIC/passport, bank details, business registrationLegal obligationNo
Customer supportOrder history, contact info, chat logsLegitimate interestsNo
Fraud prevention & securityIP address, device data, transaction patternsLegitimate interestsNo
Platform improvement & analyticsAnonymised usage data, page views, click eventsLegitimate interestsLimited
Product recommendationsBrowse history, purchase history, wishlistLegitimate interestsLimited
Promotional emails & offersEmail address, purchase historyConsentYes
SMS order notificationsPhone number, order statusConsentYes
Legal & compliance obligationsTransaction records, identity dataLegal obligationNo

Where we rely on consent as our legal basis, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal. Where we rely on legitimate interests, you have the right to object — contact us at privacy@bizhub.lk.

03

Who We Share Data With

Third parties that may receive your information and why

We do not sell, rent, or trade your personal information. We share data only when it is strictly necessary to operate our marketplace — such as processing your payment or delivering your order. All third-party processors are bound by data protection agreements.

CategoryExamplesPurposeShared?
Payment ProcessorsPayHere, Stripe, Visa/Mastercard networksSecurely process card and online paymentsShared
Logistics & DeliveryPickMe Flash, DHL, local courier partnersShip and deliver orders to customersShared
Cloud InfrastructureAWS (Singapore region), CloudflareHost platform, store data, deliver contentShared
Email & SMS ServicesSendGrid (email), Dialog / Mobitel (SMS)Send order confirmations and notificationsShared
Analytics (Anonymised)Google Analytics 4 (IP anonymised)Understand platform usage in aggregateIf Required
Government & RegulatorsICTA, Sri Lanka Customs, PoliceComply with lawful legal orders onlyIf Required
Advertisers & Ad NetworksFacebook, Google Ads, TikTok, etc.N/A — Bizhub.lk is an ad-free platformNever
Data Brokers / Third PartiesAny commercial data buyersN/A — we never sell customer dataNever
We never share your data with advertisers. Bizhub.lk operates on a marketplace commission model — not advertising. We have no commercial incentive to share your personal data with marketing companies or ad networks, and we never will. Our platform is 100% ad-tracking free.
04

Cookies & Tracking

How we use cookies and what we do and don't track

We use cookies and similar technologies to keep the platform running, remember your preferences, and understand how shoppers use Bizhub.lk. Below is a full list of every type of cookie we use — and one type we deliberately never use:

Cookie TypePurposeRequired?Duration
Essential / SessionKeep you logged in, maintain your cart, secure your session. These are required for the platform to work.RequiredSession / 30 days
PreferenceRemember your language, currency (LKR/USD), display preferences, and recently viewed filters.Required1 year
AnalyticsAnonymised page view and click data via Google Analytics 4 to help us understand how buyers use the platform.Optional2 years
SecurityCSRF tokens, bot-detection signals (Cloudflare Turnstile), and fraud-prevention fingerprints.RequiredSession
PaymentTokenisation cookies set by PayHere and Stripe to validate payment sessions — never used for tracking.RequiredSession
Advertising / RetargetingNot used. Bizhub.lk does not run ad campaigns or retarget users on external platforms.Never UsedN/A

You can manage your cookie preferences at any time through your Account Settings → Privacy. You can also use your browser settings to block or delete cookies, though this may affect your ability to stay logged in or complete purchases.

We do not use Facebook Pixel, Google Ads tags, TikTok Pixel, or any third-party advertising trackers. Bizhub.lk is a fully ad-free platform. We do not track you across other websites, and we do not share browsing data with social media companies.
05

Data Retention

How long we keep your information and why

We retain your data only as long as necessary to fulfil the purpose it was collected for, or as required by Sri Lankan law (including the Companies Act, VAT Act, and anti-money-laundering regulations). Here's our full retention schedule:

Active Account DataWhile account is active
Your profile, address book, and preferences are retained for as long as your account remains open and active on Bizhub.lk.
Order & Transaction Records7 years
Sri Lankan tax and commercial law requires us to retain invoices, payment records, and order history for a minimum of 7 years from the transaction date.
Seller Identity & Payout Records7 years
NIC/passport copies, bank account details, and payout history are retained for 7 years to meet anti-money laundering (AML) requirements under Sri Lankan law.
Customer Support Communications3 years
Chat logs, support tickets, and email correspondence are kept for 3 years to resolve disputes and improve our support quality.
Marketing Consent Records3 years after opt-out
When you unsubscribe from marketing, we retain a record of that preference for 3 years to ensure we honour your wishes.
Analytics & Usage Data26 months (anonymised)
Google Analytics 4 data is automatically anonymised and retained for up to 26 months. Raw server logs are purged after 90 days.
Deleted Account Data30 days, then purged
When you delete your account, your personal data is queued for permanent deletion within 30 days. Transaction records required by law are retained in anonymised form only.
06

Security Measures

How we protect your data from unauthorised access and threats

Security is not an afterthought at Bizhub.lk — it is built into every layer of our platform. Here are the specific measures we implement to protect your personal information:

  • Encryption in Transit: All data transmitted between your browser or app and our servers is encrypted using TLS 1.3. We enforce HTTPS sitewide and reject plain HTTP connections.
  • Encryption at Rest: All stored personal data — including order history, addresses, and seller identity records — is encrypted using AES-256, the same standard used by major banks.
  • Password Security: Passwords are never stored in plain text. We use bcrypt hashing with a high work factor, making brute-force attacks computationally impractical even in a breach scenario.
  • Two-Factor Authentication (2FA): We offer optional 2FA via SMS or authenticator app for all users. 2FA is mandatory for seller accounts processing high-value payouts.
  • Payment Security: We are PCI-DSS compliant through our payment partners PayHere and Stripe. Full card numbers never touch our servers — only tokenised references are stored.
  • Access Controls: Internal access to user data is restricted on a strict need-to-know basis. All employee access is logged, monitored, and reviewed monthly.
  • Fraud & Bot Detection: We use Cloudflare Turnstile for bot detection and monitor transaction patterns in real time to detect and block fraudulent activity on the platform.
  • Incident Response: In the unlikely event of a data breach affecting your personal information, we will notify affected users within 72 hours of discovery and provide clear guidance on steps to protect yourself.
No system is 100% secure. While we work very hard to protect your data, we cannot guarantee absolute security. If you suspect your account has been compromised, please contact security@bizhub.lk immediately and change your password. Enable 2FA to significantly reduce your risk.
07

Children's Privacy

Our commitment to protecting minors online

Bizhub.lk is an e-commerce platform intended for adults and is not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18 years of age.

During registration, we collect date of birth for age verification purposes. If we become aware that we have inadvertently collected personal data from a child under 18, we will take immediate steps to delete that information from our systems and cancel the associated account.

If you are a parent or guardian and believe your child has created an account on Bizhub.lk without your consent, please contact us at privacy@bizhub.lk and we will resolve it promptly — typically within 24 hours.

Individuals aged 16–17 may use the platform only with documented parental or guardian consent. The consenting adult assumes full responsibility for that minor's purchases and activity on Bizhub.lk.

08

International Data Transfers

When and how your data may cross borders

Bizhub.lk is headquartered in Sri Lanka and our primary data infrastructure is hosted on AWS servers in Singapore. This means some of your data is processed and stored outside Sri Lanka, specifically in Singapore.

Additionally, our payment processors (PayHere and Stripe), email delivery service (SendGrid), and CDN provider (Cloudflare) may process certain limited data in other countries. When this occurs, we ensure appropriate safeguards are in place:

  • Contractual data processing agreements that bind all processors to equivalent data protection standards
  • Data transfer impact assessments for cross-border flows involving sensitive personal data such as identity documents
  • Hosting our primary infrastructure in Singapore (AWS ap-southeast-1) — a jurisdiction with strong data protection frameworks
  • Contractual obligations for all international processors to notify us within 48 hours of any security incident
For users in the European Economic Area (EEA) or United Kingdom, we apply GDPR-equivalent protections as a matter of best practice, even where not legally required under Sri Lankan law. Your data rights described in Section 09 apply regardless of your location.
09

Your Rights & Choices

How to control your personal data on Bizhub.lk

You have meaningful, practical control over your personal data. Here's exactly how to exercise each right:

  • Right to Access: Request a full export of all personal data we hold about you. Available instantly via Account Settings → Privacy → Download My Data.
  • Right to Correct: Update inaccurate information directly in your Account Settings. For data you cannot edit yourself (e.g. verified identity documents), email us and we will correct it within 14 days.
  • Right to Erasure: Request deletion of your account and personal data. We will process this within 30 days, subject to legal retention obligations (e.g. 7-year transaction records).
  • Right to Object: Object to data processing based on legitimate interests — such as product recommendations or analytics. Email privacy@bizhub.lk and we will stop that processing.
  • Right to Portability: Receive your data in a machine-readable format (JSON or CSV) to transfer to another service. Request via your Account Settings or by emailing us.
  • Right to Restrict Processing: Ask us to pause processing of your data while a dispute or correction is pending. We will restrict processing within 48 hours of your request.
  • Right to Withdraw Consent: Where we process data based on your consent (e.g. marketing emails), you can withdraw that consent at any time via the unsubscribe link in emails or Account Settings.
Most requests are instant.You can download your data, update your details, manage marketing preferences, and request account deletion directly from your Account Settings dashboard. For requests that require our team's involvement, we respond within 48 hours and resolve within 30 days. We never charge a fee.
10

Policy Updates

How we communicate changes to this privacy policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, or applicable Sri Lankan law. Here is how we handle updates transparently:

  • We update the "Last Updated" date at the top of this page whenever any change is made.
  • For material changes — those that significantly affect your rights or how your data is used — we will send an email notification to all registered users at least 14 days before the changes take effect.
  • For minor updates such as typographical corrections, formatting improvements, or added clarity, we will update the policy without a separate email notification.
  • Your continued use of Bizhub.lk after the effective date of any change constitutes your acceptance of the updated policy.
  • If you disagree with a material change, you have the right to close your account before it takes effect. We will process your deletion request promptly and honour it fully.

Previous versions of this policy are archived and available upon request — simply email privacy@bizhub.lkwith the subject line "Previous Policy Version" and we will send the relevant archived version within 5 business days.

11

Contact Our Privacy Team

We're here to help with any privacy questions or concerns

If you have any questions, concerns, or requests related to this Privacy Policy or how we handle your data, our Privacy Team is ready to help. We believe in human responses — not automated replies.

We aim to acknowledge all privacy enquiries within 48 hours and resolve them within 30 calendar days. If you are dissatisfied with our response, you have the right to escalate your complaint to the Information and Communication Technology Agency of Sri Lanka (ICTA) or the relevant regulatory authority in your country.

Your Privacy Is Safe With Us

Questions About Your Data?

Our Privacy Team is happy to answer any questions. We believe transparency builds trust — and trust builds a better marketplace.

Policy v1.0 · Effective 1 January 2025 ·