Who we are
Panora Virtual Tours (Private) Limited is a company registered in Pakistan, with its registered office in Lahore. We produce 360° virtual tours and AR/VR content, and we operate Panora Business Messaging, a service that lets businesses send transactional notifications to their own customers over the WhatsApp Business Platform.
In this policy, “we” and “us” mean Panora Virtual Tours (Private) Limited. This policy covers three groups: visitors to this website, clients of our virtual tour services, and businesses that connect a WhatsApp Business Account to Panora Business Messaging.
Website visitors
When you browse this site we collect basic technical information — pages viewed, approximate location derived from IP address, browser and device type, and referring site — to keep the site working and understand which pages are useful. If you submit an enquiry or request a demo, we collect the name, email address, phone number and message you give us, and use them to respond to you.
Virtual tour clients
For production work we hold the contact details of the people we deal with, the site addresses we photograph, and the imagery we capture. We publish captured imagery in our portfolio only where the client has agreed to it. We do not deliberately capture identifiable people in 360° imagery, and we will blur or remove any individual on request.
Panora Business Messaging
This section covers the data handled by our WhatsApp Business Platform service. The WhatsApp Business Account always belongs to the client business, never to us. We act on it only with permission the business grants, and only to provide the service.
| Category | What it includes | Why we hold it |
|---|---|---|
| Account identifiers | WhatsApp Business Account ID, business phone number ID, display name, and the access token issued when an account is connected | To send messages and manage templates on the client’s account |
| Client contact details | Name, business email and phone number of the person who sets up the connection | Support, billing and service notices |
| Message data | Message content, recipient phone numbers, template contents, and delivery and read statuses returned by WhatsApp | To deliver messages and report what happened to them |
| Attachments | Files sent through the service, such as invoice or receipt PDFs | To attach them to the messages the client asked us to send |
| Technical logs | Timestamps, API request and error logs, and the IP address used at connection | Security, fault diagnosis and abuse prevention |
We never see WhatsApp or Meta login credentials. Connecting an account happens inside Meta’s own sign-up window. Credentials are entered on Meta’s systems and are never visible to us.
How we use personal data
We use the data described above to provide and support our services, to respond to enquiries, to send the messages our clients instruct us to send, to meet our legal and tax obligations, and to keep our systems secure.
We do not sell personal data. We do not use client message content or recipient phone numbers for advertising, for our own marketing, or to build profiles, and we do not use them to train machine learning models.
Who we share it with
- Meta Platforms, Inc. — messages and template data pass through the WhatsApp Business Platform in order to reach recipients. Meta’s handling of that data is governed by Meta’s own terms and privacy policy.
- Hosting and infrastructure providers — who store and process data on our behalf under contract and may not use it for their own purposes.
- Authorities — where we are required to by law.
We do not share personal data with anyone else.
Where data is stored
Data is held on servers operated by our infrastructure providers, which may be located outside Pakistan. Message delivery necessarily involves Meta’s global infrastructure.
How long we keep it
- Message content and delivery logs — up to 12 months, then deleted.
- Attachments such as invoice PDFs — up to 90 days after sending.
- Account identifiers and access tokens — for as long as the account is connected, and deleted when it is disconnected.
- Enquiry and client records — up to 3 years after our last contact.
- Technical and security logs — up to 12 months.
We keep records longer only where the law requires it.
Security
Access tokens are stored encrypted. Data in transit is protected with TLS. Access to production systems is limited to staff who need it and is logged. No system is perfectly secure; if a breach affects your data we will tell you.
Your rights
You may ask us for a copy of the personal data we hold about you, ask us to correct anything inaccurate, or ask us to delete it. To make a request, see our User Data Deletion page or write to us using the details below.
A business using Panora Business Messaging can also revoke our access at any time in its own Meta Business Settings, under connected apps and business partners. That stops our access immediately.
Our clients’ customers
When a business sends messages through Panora Business Messaging, that business decides what is sent and to whom. It is the controller of its customers’ data and we process that data on its instructions. If you received a message from a business and want your data removed, contact that business first. If you cannot reach them, write to us and we will pass the request on.
Children
Our services are provided to businesses. They are not directed at children and we do not knowingly collect data from anyone under 18.
Changes to this policy
If we change this policy we will update the date at the top of this page, and tell connected businesses about anything significant.
Contact us
Panora Virtual Tours (Private) LimitedPlot No 5/6 Kalamkaar Road, 19km Ferozpur Road
Lahore, Punjab 54000, Pakistan
contact@panoraproperties.com
+92 339 1726672