Skip to content
Privacy Policy

How we handle your data at KARCSHAM

This page explains how we handle account data, contact messages, service requests, and store operations in the central website.

Version 2.0
Effective from
Last edited
Scope The KARCSHAM Central website, accounts, service requests, store workflows, and connected-application sign-in flows.
Contact info@karcsham.com

This version describes what the site actually applies today. Material changes are published with a version number and an announced effective date, and earlier versions stay in the change log at the bottom of the page.

Who controls your data

The party responsible for your data on this site is KARCSHAM CO. FOR BUSINESS TECHNOLOGY & DIGITAL WORKS, registered in Sudan under BN: 12316, with its address at Sudan — North Darfur — El Fasher — Kutum. To reach us about your data: info@karcsham.com.

What data we receive

Account data: name, email, phone or WhatsApp number, and language and notification preferences. Transaction data: orders, service requests and their attachments, a shipping address when an order needs one, the payment proof or transaction reference you upload yourself, and refund requests with their reasons. The Starlink account details you give us to pay its invoice. Contact and support messages. And technical records needed for security: IP address and browser type in server logs and attempt limits, which are also kept with a payment authorization document when one is issued.

How we use it

To manage your account, process store orders and service requests, review and confirm payments, execute the service with the provider, send transactional notifications, answer your inquiries, protect the site from abuse, and keep a financial and operational record of orders. We do not sell your data or use it for third-party advertising.

Payment proofs and automatic reading

A payment proof is kept in private storage opened only to you and authorized KARCSHAM staff. To speed up the review, the proof file (image or PDF) is sent to the Anthropic service to be read automatically and extract: bank name, transaction number, amount, currency, payment date, sender account, recipient account, beneficiary name, transaction status, and its note. This reading is only an aid: the decision to accept or reject a payment is made by a staff member, and if the reading fails the proof is reviewed manually as usual. So do not include in a payment proof anything unrelated to the transaction, and never include passwords.

Starlink account details

If you share Starlink login details, the password is stored encrypted inside the order, read by the fulfilment team only when needed, and deleted automatically together with the login screenshot when the order is confirmed complete. The login screenshot — the one that may contain a password — is never sent to any automatic reading service or outside party. Screenshots of device or account details that the team uses to register your device in the device registry may be read automatically through Anthropic to extract the account number, name, email, phone, device identifiers and service address; the screenshot is not stored after reading, and a staff member reviews the fields before saving them.

Who receives data

Hostinger: the hosting provider. The database and uploaded files — payment proofs included — are kept on a server rented from it and administered by KARCSHAM, which also runs the site and the WhatsApp bridge. Cloudflare Turnstile: at account creation, to check that the request comes from a person; it receives the IP address and browser signals. WhatsApp: transactional notifications and support messages pass through a WhatsApp bridge that KARCSHAM runs on that same server and then through the WhatsApp network, which receives your number and the message text. Brevo: for sending email; it receives your email address and the message text. Anthropic: for reading payment proofs and device-registration screenshots as described in the two sections above, with nothing else from your account sent along. The provider you ask us to execute with (such as Starlink): only what is needed to carry out your order. The site does not process payment cards or store their details; bank transfers and Binance payments happen outside the site between you and the payment provider.

Cookies

The site uses necessary cookies only: the session cookie for sign-in, the request-forgery protection token (XSRF), and the kc_locale cookie that remembers your language for one year. The site uses no third-party analytics or advertising trackers.

Notifications

Order, payment and deadline notifications reach you on the transactional channel you prefer in your account; by default your verified WhatsApp, then email if delivery fails. The channel in use is shown on the order page and in settings. Marketing messages are a separate preference you can turn off at any time without affecting transactional notifications.

Connected-application sign-in

When you use KARCSHAM Central to start sign-in to KF or KWSM — both systems run by KARCSHAM — we process identity status, application access, and limited technical audit metadata needed to correlate the request with its outcome. Signing keys and session data are not displayed on this page.

Retention

We keep data as needed for service delivery, follow-up, and the financial and operational record of orders. What is applied automatically today: the Starlink password and login screenshot are deleted when the order completes, and device-registration screenshots are not stored after reading. This version does not announce fixed periods for other categories; any periods adopted later will be published in a new version of this policy before they apply.

Your rights

You can edit your profile and notification preferences directly from your account. To request a copy of your data, its correction or its deletion, write to info@karcsham.com from the email registered on your account. We may keep the necessary order, payment and financial-document records even after an account is deleted, and we will explain that in our reply.

Versions and updates

Every version of this policy has a number, a publication date and an effective date, and earlier versions stay available in the change log below. The policy version in force when an order is created is recorded with that order. Changes are published with an announced effective date before they apply.

For questions about this policy, you can contact us at:

info@karcsham.com

Change log

Every change to this document with its date and kind; editorial corrections are told apart from substantive changes.

  1. Substantive · v2.0

    Version 2.0 published, in force from 21 September 2026: names the hosting provider and the external processors actually used and what each receives, the automatic reading of payment proofs, the deletion of Starlink login details when an order completes and that their screenshots are never read automatically, the reading of device-registration screenshots, cookies, the notification channel, and rights requests.

  2. Editorial · v1.0

    Editorial corrections with no change of meaning.

  3. Published · v1.0

    First version at launch.

Previous versions