Privacy Policy
1. Introduction
This Privacy Policy describes how Safa (referred to as "we", "us", or "our"), operated by IE Mamazhanov Abdutair, collects, uses, stores, and protects your personal information when you use our mobile application (Bundle ID: kg.genesis.safa.app) and associated services.
Safa is a specialized mobile logistics and delivery platform designed for wholesale marketplaces (such as the Dordoi Bazaar in Bishkek) and city-wide deliveries in the Kyrgyz Republic. It connects customers requesting cargo transportation with independent verified couriers and cart specialists («Тачкисты»).
By installing, registering for, or using the Safa application, you acknowledge that you have read and understand this Privacy Policy. If you do not agree with our practices, please do not use the application.
2. Information We Collect
We only collect information that is strictly necessary to provide our delivery services, verify identities, process payments, and ensure safety. The information collected depends on your role as a Client or a Specialist (Carrier):
A. Account & Registration Information
- Phone Number: We collect your mobile phone number in the Kyrgyz format (
+996XXXXXXXXX). Your phone number is your primary account identifier and is used for authentication via WhatsApp one-time password (OTP) codes. - First Name: Displayed to matched couriers or clients during an active delivery to coordinate handovers.
- Account Role: Whether you register as a "Client" or "Specialist" (and specialist sub-type: "Cart Specialist" or "Courier").
- Profile Avatar: If you choose to upload a profile photo, it is stored on our media server and displayed within your profile.
- City / Region: Optional geographic preference (e.g., Bishkek).
B. Specialist Verification Data (KYC)
Applicable only to users registering as Specialists (Couriers and Cart Specialists):
- National Identity Card: High-resolution photos of the front and back of your official national identity card (passport).
- Verification Selfie: A selfie photograph of you holding your ID card next to your face (
selfie_id_card) to verify authentic identity ownership. - Verification Status: Records of moderation review, approval timestamps, and administrative comments.
C. Delivery and Shipment Details
- Package Details: Title, cargo description, service type ("delivery", "cars" / «тачки», or "amanat"), and optional return trips.
- Route Waypoints: Sequence of pickup and drop-off stops, street addresses, or specific marketplace coordinates including Bazaar name, passage number, and container number.
- Order Financials: Distance in kilometers, estimated fare, final agreed fare (in Kyrgyzstani Som - KGS), and payment status.
- Order Ratings & Reviews: 1-to-5 star ratings and written feedback provided upon order completion.
D. Amanat Charitable Donations
When you contribute to social assistance campaigns in the Amanat module, we record the selected campaign, donation amount in KGS, timestamp, and payment verification status.
3. Location Information
Location data is fundamental to the operation of Safa. We collect location data differently depending on your role and permissions:
1. Client Location (Foreground Only)
When you open the map or place an order, we request access to your device's current location (NSLocationWhenInUseUsageDescription on iOS;ACCESS_FINE_LOCATION on Android). We use this data only to center the interactive map on your position, suggest nearby pickup points, and locate nearby wholesale market containers. We do not track clients in the background.
2. Specialist Location (Foreground & Background During Active Delivery)
For registered specialists, real-time GPS coordinates are required to:
- Match available delivery orders within a 2,500-meter operating radius.
- Provide live location streaming to the customer waiting for the cargo.
- Calculate real-time ETA and display dynamic route progress on the map.
Specialist devices transmit location coordinates (latitude and longitude) via POST /api/delivery/position/ and live WebSocket streams. Because deliveries occur while the phone screen may be turned off or the app minimized, specialists must grant background location access (UIBackgroundModes: location on iOS; ACCESS_BACKGROUND_LOCATION and foreground services on Android). Background tracking stops when no delivery is in progress.
3. Geocoding & Address Resolution
Coordinates are converted to human-readable street names and container identifiers using Yandex Geocoder API, 2GIS API, and OpenStreetMap.
4. Device and Technical Information
When you interact with the Safa application, our servers automatically collect standard technical telemetry necessary to maintain service reliability:
- Platform & OS Version: Operating system (iOS or Android) and application build version to ensure feature compatibility.
- Network & Connection: IP address, connection status (via
connectivity_plus), and standard HTTP request headers in server access logs. - Encrypted Local Storage: JWT authentication tokens (access token and refresh token) and KYC session tokens are stored securely on your device using
flutter_secure_storage, utilizing the iOS Keychain and Android Keystore. Non-sensitive app preferences are stored viaSharedPreferences. - No Third-Party Advertising Trackers: Safa does not integrate third-party ad networks, advertising IDs (such as IDFA or Google Advertising ID), or behavioral profiling tools.
5. Firebase & Push Notifications
We use Google Firebase Cloud Messaging (FCM) to send operational push notifications. When you permit notifications, your device registers a unique FCM token sent to our backend (/api/fcm/register/).
Push notifications are categorized into two specific channels:
Delivery Updates
Order acceptance, arrival at pickup/destination, route advancement, and payment confirmations.
Account & KYC Alerts
Specialist identity approval or rejection notices and critical service announcements.
You can modify or revoke push notification permissions at any time through your device operating system settings.
6. Third-Party Services
Safa integrates only with third-party service providers that are strictly required for technical operations, maps, payments, and SMS/WhatsApp OTP delivery. Below is the complete, factual list of integrated providers:
Purpose: Push notification routing to iOS and Android devices.
Data Shared: Device push token, event identifier, notification title and body.
Purpose: Interactive MapKit rendering, address autocomplete, reverse geocoding of coordinates, and route line drawing.
Data Shared: Geographic coordinates (lat/lon), map tile requests, search queries.
Purpose: Precise lookup of market passages, container numbers, and retail points in Bishkek (e.g., Dordoi market).
Data Shared: Address search terms and market container queries.
Purpose: Processing mobile banking and bank card payments for delivery fees and Amanat donations.
Data Shared: Transaction amount, currency (KGS), unique order request ID. Payment credentials are handled exclusively by Finik.
Purpose: Secure transmission of one-time WhatsApp verification codes during registration and login.
Data Shared: Recipient phone number and generated 4–6 digit OTP code.
Purpose: Delivering native notifications to iOS devices.
Data Shared: Apple device token and notification payload.
Purpose: Calculating driving and walking distances between delivery stops.
Data Shared: Route coordinates (lat/lon).
7. Payments and Financial Data
Safa has adopted a strict security architecture for payments:
All payments are processed through Finik (finik_sdk). When an order is completed, the client selects their preferred payment channel within the secure Finik interface (such as MBank, Optima24, O!Dengi, Balance.kg, MegaPay, Bakai, DemirBank, or bank card).
Our backend receives and retains only verified transaction metadata:
- Payment identifier and unique Finik request ID.
- Finik transaction ID and GraphQL verification status.
- Total amount in Kyrgyzstani Som (KGS) and timestamp.
- Internal carrier settlement record (gross delivery fare, platform commission deduction, and net credited amount to the specialist's account).
8. How We Use Information
We process personal data only for lawful purposes directly connected to providing the service:
- Account & Authentication: Creating accounts, verifying ownership via WhatsApp OTP, and maintaining secure login sessions with JWT tokens.
- Fulfilling Delivery Services: Routing shipments, matching orders with nearby specialists within an operating radius, and coordinating package pickup and handoff.
- Real-Time Tracking & Navigation: Displaying live courier positions to clients and guiding couriers to designated containers.
- Identity Verification & Safety: Verifying courier ID cards and selfies to prevent fraud, theft, and unauthorized account use.
- Payment Processing: Verifying payment completion before an order is marked completed and calculating specialist commissions.
- Customer Support: Responding to inquiries, resolving order disputes, and reconciling transactions.
- Legal & Accounting Compliance: Complying with applicable laws, financial recording obligations, and law enforcement requests.
10. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Active Accounts: Profile and account data are retained while your account remains active.
- Specialist KYC Documents: ID photos and selfies are retained in secure server storage for the duration of the specialist's active service to maintain safety and accountability.
- Completed Deliveries & Invoices: Order history and transaction logs are kept in anonymized or pseudonymized form to comply with tax, accounting, and legal requirements.
- Real-Time Courier Coordinates: Live GPS position history is updated dynamically and stale coordinates are purged after order completion.
11. Data Security
We implement comprehensive technical and organizational safeguards to protect your personal data:
- Encryption in Transit: All communications between the mobile app, the backend servers, and third-party APIs are encrypted using modern TLS (HTTPS) and secure WebSockets (WSS).
- Secure Local Storage: Authentication tokens are stored in the device's hardware-backed Keychain (iOS) and Keystore (Android).
- JWT Token Rotation: Short-lived access tokens (3-hour lifetime) and refresh tokens with automated blacklisting on rotation.
- Access Controls & Database Isolation: Strict row-level permissions ensure couriers and clients can only access orders they participate in.
- Password Security: User passwords are never stored in plain text; they are hashed using standard cryptographic algorithms (PBKDF2/SHA256).
12. User Rights
Depending on applicable privacy legislation, you have significant rights regarding your personal data:
- Right to Access: You can inspect your active orders, personal profile, and history within the app at any time.
- Right to Rectification: You can edit your name, city, and avatar directly in the app.
- Right to Deletion: You have the absolute right to request the erasure of your personal account and associated data.
- Right to Withdraw Consent: You can revoke location access, camera access, or push notifications at any time via your device system settings.
- Right to Inquire / Complain: You can reach out to our team at
sattarzhanovdev@gmail.comwith any privacy question.
13. Account and Data Deletion Requests
Safa provides an automated, self-service account deletion process directly inside the application in compliance with Apple App Store guidelines:
How to delete your account in the app:
- Open the Safa mobile app.
- Go to the Profile tab.
- Select Settings or tap Delete Account.
- Confirm the deletion prompt.
What happens upon deletion:
- Your phone number is immediately scrubbed and replaced with an anonymized placeholder (
del<id>). - Your name is permanently replaced with "Deleted User".
- Your email, city, and OTP codes are permanently cleared.
- Your uploaded avatar image is physically deleted from server storage.
- Your specialist KYC verification images (if any) are deleted or purged from active records.
- Your account is marked inactive (
is_active = False) and all authentication tokens are revoked. - Historical financial records and completed delivery records are retained strictly in anonymized format to preserve database integrity and accounting compliance.
Manual Deletion Requests:
You may also request account deletion by emailing our support team at:
sattarzhanovdev@gmail.com
Please send the request from or include the registered phone number associated with your account. Requests are processed within 48 hours.
14. Children's Privacy
Our services are not intended for or targeted at children under the age of 16 (or the applicable age of legal capacity under local jurisdiction). We do not knowingly collect personal information from children.
If you become aware that a child has provided us with personal information without parental consent, please contact our support team at sattarzhanovdev@gmail.com so we can promptly take corrective measures and delete the information.
15. International Data Transfers
Our primary servers and operations are located in the Kyrgyz Republic and neighboring regional cloud infrastructure. Certain third-party services (such as Google Firebase and Apple APNs) maintain globally distributed server networks.
When your data is processed by these third-party infrastructure providers, it is transferred in encrypted format in compliance with standard contractual clauses and industry-leading security practices.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect modifications in our operational practices, technical features, or applicable statutory requirements.
When we make changes, we will update the "Last Updated" date at the top of this page. For significant modifications that alter your rights, we may provide additional notice within the mobile application or through push notifications.
17. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact us: