Privacy Policy
SP Tool Mobile Application
Effective Date: October 2, 2026
Registered address: Bishkek, Kyrgyz Republic
Email: support@smartpoint.kg
1. Introduction
This Privacy Policy explains how Smart Point Solutions LLC ("we", "us", "our") collects, uses, stores, and protects personal data when you use the Smart Point mobile application "SP Tool" (the "Application").
The Application is available on Google Play and the App Store and is intended for employees of cargo companies and sorting centers that partner with the Smart Point platform. In the Application, staff register and sort incoming items, accept returns, build and dispatch shipments, manage the warehouse and the customer base, hand orders over to customers and accept payment, chat with colleagues and partners in the in-app messenger, and confirm sign-ins to the SP Linker web app. The Application is not intended for end customers.
By installing or using the Application, you confirm that you have read and agreed to this Privacy Policy. If you do not agree, please uninstall the Application and discontinue its use.
2. Legal Basis for Data Processing
We process personal data on the following legal grounds:
- Performance of a contract — to provide logistics services to the cargo company, keep records of items, shipments and handovers, and manage the employee account.
- Processing on behalf of the cargo company — we process the data of the cargo company's customers (item recipients) on behalf of and in the interests of the cargo company, which is their data controller.
- User consent — for optional features (photos, voice messages, push notifications) and for the chosen one-time code (OTP) delivery channel. Consent may be withdrawn at any time.
- Legal obligation — to comply with financial, tax, and regulatory requirements of the Kyrgyz Republic.
- Legitimate interests — fraud prevention, account protection, security monitoring, and service improvement, balanced against user rights.
3. Information We Collect
We apply the principle of data minimization: we collect only data that is strictly necessary for the purposes described below.
3.1 Employee Data
- Full name and phone number
- Email address — if specified in the profile
- Role and groups (cargo company, sorting center) the employee works in
- Profile photo — if the user uploaded one
- Telegram chat identifier — only if the user linked the Smart Point Telegram bot to receive codes and notifications
- Activity log in the Application: who registered, accepted, dispatched, handed over an item or changed its status, and when. The log is needed for record-keeping and dispute resolution
3.2 Item, Shipment and Handover Data
- Tracking number, customer code, weight, dimensions, declared value, amount due, status, storage cell, box
- Shipment and return composition and statuses, destination pickup points
- Handovers: which items were handed over or returned, return reason, payment status
- Photo of the customer's signature — if the "Signature photo" module is enabled for your group: a picture the employee takes with the camera or selects from the gallery when handing over an order. The photo is stored on our servers and is available only to staff with access to that handover
3.3 Data of the Cargo Company's Customers
In the "Warehouse" and "Handover" sections, staff see the data of their cargo company's customers: name, phone number, customer code, selected pickup point, and whether Telegram is linked. This data is uploaded and maintained by the cargo company itself; the Application shows it only to that cargo company's staff, to the extent needed to work with orders. We do not use customer data for our own purposes.
3.4 Device and Technical Data Collected Automatically
Technical data is collected only while the Application is in use and does not include background surveillance.
a) FCM Token (Firebase Cloud Messaging)
A unique token generated by Firebase for a specific installation of the Application. Used exclusively to deliver push notifications: new arrivals and handovers, status changes, messenger messages, authorization codes. Stored on our server linked to the account. Deactivated on logout, account deletion, or when the device rotates the token.
b) Installation identifier (device_id)
A random identifier the Application creates on first launch. It is not tied to hardware and cannot be used to track the device across other apps; it is used only to link the sign-in session and FCM token to this installation. A new identifier is created after reinstalling the Application.
c) Platform, OS version and Application version
For example, "Android 14" or "iOS 18", and the SP Tool version number. Used for correct notification delivery and in the list of active sessions so you can recognize your device. The Application does not collect the device model or hardware serial numbers.
d) Sign-in sessions
For each active session we store the platform, Application version, IP address, and time of last activity. You see this list in "Active sessions" and can end any session.
e) Other technical data
- IP address and server request logs
- Crash reports and diagnostic data (Firebase Crashlytics)
- Online presence status — while the Application is open, it periodically tells the server you are online, and colleagues see you as "online" in the messenger. No status is sent from the background or outside the Application
3.5 Sign-in and One-Time Codes (OTP)
Sign-in is performed with a phone number and a one-time code (OTP), which is also a simple electronic signature within the meaning of the Law of the Kyrgyz Republic "On Electronic Signature".
The code is delivered through the channels the user chose in the SP Linker profile and that are available to them:
- Smart Point Telegram bot — via the Telegram Bot API to the user's Telegram account
- Push notification — to a device where the user is already signed in to a Smart Point app, or to the device that requested the code
- Email — to the verified email address in the profile
After sign-in the session is extended automatically: a short-lived access token is refreshed using a long-lived token kept in the device's secure storage (see Section 4.2).
3.6 Confirming Web Sign-in with a QR Code
In "Active sessions" you can scan the QR code on the SP Linker sign-in page and confirm the sign-in in the browser. Before you confirm, the Application shows the browser name, operating system, and IP address of the computer requesting access, so you can make sure it is your computer. This information is kept in your account's sign-in history.
3.7 In-App Messenger
The Application includes a corporate messenger for staff, partners, and Smart Point support. When you use it, we process:
- The text of messages you send and receive, reactions, forwards, and pinned messages
- Attachments you choose to send: photos, videos, voice messages, and files
- Metadata: sender, recipients or group, timestamps, delivery and read status
- Name, avatar, and membership of group conversations
- Messages and attachments are transmitted over an encrypted connection (HTTPS/TLS) and stored on our servers so they can be delivered and displayed to the participants of the conversation.
- Content is available only to the participants of the relevant conversation and is not used for advertising or profiling. Messenger content is not end-to-end encrypted: our authorized systems can store and process it to operate the service, ensure security, and comply with legal obligations.
- Voice messages are recorded only after you start a recording; the microphone is never used in the background (see Section 4.4).
4. Device Permissions
The Application requests only the following permissions, each used strictly for the stated purpose, in line with Google Play Developer Program Policies and Apple App Store Review Guidelines. Permissions are requested at the moment they are needed and can be revoked in the phone settings; their current status is shown in the Application under "App permissions".
4.1 Camera (CAMERA)
Used only on the employee's action:
- Scanning barcodes and QR codes of items, boxes, and shipments when registering arrivals, accepting, building a shipment, handing over, searching for an item, and viewing history by code
- Scanning the QR code on the SP Linker sign-in page to confirm a browser sign-in
- Taking a photo of the customer's signature when handing over an order (if the "Signature photo" module is enabled)
- Taking a photo to send in the messenger or to use as a group conversation avatar
4.2 Storage
The Application uses only its own private storage (Android sandbox / iOS app container):
- Access token, installation identifier, FCM token, selected group, and interface settings — in
AsyncStorage - The long-lived session refresh token — in the OS secure storage (iOS Keychain / Android Keystore)
- A cache of voice messages for replay and temporary copies of selected attachments (cleared by the system or after upload)
READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, or READ_MEDIA_* permissions and does not read or write the phone's shared storage on its own. A file leaves the Application only if you send it yourself through the system "Share" menu.
4.3 Notifications (POST_NOTIFICATIONS)
Used for push notifications about arrivals, handovers, shipments, returns, messenger messages, and authorization codes. You may revoke this permission at any time: Device Settings → Apps → SP Tool → Notifications.
4.4 Microphone (RECORD_AUDIO)
Requested only to record voice messages in the messenger, and only when you start a recording.
4.5 Photos, Media and Files
When you attach a photo, video, or document to a message or pick a signature photo from the gallery, the Application opens the system picker (Android Photo Picker / Storage Access Framework; iOS system picker). The Application receives only the items you select and only at that moment, without standing access to your gallery.
4.6 Vibration (VIBRATE) and Sound
Short vibration signals and sounds confirm scan results. When registering arrivals, the Application may announce the item's destination by voice: the device's built-in text-to-speech is used, and the text (the pickup point name) is processed on the device and not sent to us.
5. How We Use Collected Data
We use personal data exclusively for:
- Operating the core features: registering arrivals, sorting, accepting, shipments, warehouse, inventory, and handovers
- Keeping records of item operations and resolving disputes
- Accepting payment at handover and reconciling payment status
- Delivering push notifications and one-time codes
- Operating the in-app messenger and presence status
- Managing accounts and sessions and confirming web sign-ins
- Protecting accounts and detecting and preventing fraud
- Responding to support requests and fixing crashes
- Complying with applicable legal and regulatory obligations
We do not use automated decision-making that produces legal or similarly significant effects without human review.
We do NOT use personal data for advertising, profiling, or cross-app tracking.
We do NOT collect data beyond what is described in this Policy.
6. Data Sharing and Disclosure
We share personal data only when necessary, and only with:
- Messenger conversation participants — messages, attachments, and presence status you send
- Logistics chain partners — pickup points (PVZ) and marketplace partners receive the item and shipment details needed for delivery and handover (tracking number, status, shipment composition, customer code)
- Banks and payment services (Bakai Bank, Optima Bank, Finik) — when accepting payment at handover: the amount and payment identifier to generate the QR code and check the payment status. The payer's card and bank account details are processed by the bank or payment service; we do not receive or store them
- Telegram (Telegram FZ-LLC) — when the user receives codes or notifications through the Smart Point Telegram bot
- Email service providers — to deliver the code by email if the user chose that channel
- Firebase / Google LLC — push notification delivery (FCM) and crash reports (Crashlytics)
- Apple Inc. — push notification delivery on iOS via the Apple Push Notification service
- Cloud infrastructure and hosting providers — to run servers and store data
- Government authorities — only when required by law, court order, or official request
All third-party providers are bound by confidentiality and data security obligations and may use data only to perform the agreed services.
7. Third-Party Services
The Application integrates:
- Firebase Cloud Messaging (FCM) — push notification delivery; FCM tokens are processed per Google's privacy policy
- Firebase Crashlytics — crash reports: device model and OS version, Application version, stack trace. Reports do not contain message text, customer data, or item data
- Bakai QR and Optima QR — the server generates a payment QR code, the Application shows it to the customer, and the customer pays in their bank's app
- Finik — the Finik payment page opens in an in-app web view (
react-native-webview); payment details are entered and processed on Finik's side - Telegram Bot API — codes and notifications if the user linked the Telegram bot
- Google Play / App Store In-App Review — optional system rating dialog
- On-device components that do not share data with third parties: code scanner (
react-native-camera-kit), audio recording and playback (react-native-nitro-sound,react-native-sound), OS text-to-speech (react-native-tts), system photo and file pickers (react-native-image-picker,@react-native-documents/picker), secure storage (react-native-keychain), notification display (@notifee/react-native)
- Google Privacy Policy: https://policies.google.com/privacy
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
- Telegram Privacy Policy: https://telegram.org/privacy
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Employee account and profile | While the account is active + a reasonable period after closure |
| Sign-in sessions | Until logout, session termination, or expiry |
| FCM tokens | Until logout, token rotation, or account deletion |
| Items, shipments, handovers, payments, signature photos, and activity log | As required by financial and tax law and the contract with the cargo company |
| Messenger messages and attachments | While the conversation exists or until the message is deleted |
| Crash reports | Up to 90 days |
After expiration, data is securely deleted or irreversibly anonymized.
9. Data Security
We implement:
- HTTPS/TLS encryption for all data in transit
- Short-lived access tokens, with the refresh token kept in the OS secure storage (Keychain / Keystore)
- A list of active sessions where any session can be ended, including all sessions except the current one
- Web sign-in confirmation only from a phone where the user is already signed in
- Role-based access control: staff see data of their own group only
- Security monitoring and protected backups with restricted access
- Android cloud backup of Application data is disabled
No method of transmission over the internet is completely secure. We promptly investigate and remediate security incidents we become aware of.
10. User Rights
You have the right to:
- Access — request a copy of personal data we hold
- Rectification — request correction of inaccurate data
- Erasure — request deletion of personal data
- Restriction — request limitation of processing
- Withdraw consent — at any time
- Portability — receive your data in a machine-readable format
If you are a customer of a cargo company and your data is visible in the Application, contact your cargo company or us about its processing — we will forward the request to the cargo company and help fulfil it.
Response time: within 30 calendar days (extendable by 30 days with prior notice for complex requests).
11. Account and Data Deletion
Employee accounts are created and disabled by the manager of the cargo company. To delete your account and associated personal data, contact your manager or us directly:
- Email: support@smartpoint.kg
- Telegram: https://t.me/existent_dd (Smart Point support)
Please include the phone number you use to sign in to the Application.
On request we delete the profile, sessions, FCM tokens, and all non-essential records. Records of item operations and payments required by financial and tax law are retained for the mandated period, detached from the profile where possible, and then deleted. Requests are processed within 30 calendar days.
12. Children's Privacy
The Application is a work tool and is not intended for individuals under 18. We do not knowingly collect personal data from minors. If we become aware of such data, we will promptly delete it. Contact: support@smartpoint.kg.
13. Changes to This Privacy Policy
When material changes are made, we will:
- Update the Effective Date at the top of this Policy
- Display an in-app notice before the changes take effect
- Where required by law, seek renewed consent
Continued use of the Application after notification constitutes acceptance of the revised Policy.
14. Contact Information
Bishkek, Kyrgyz Republic
Support email: support@smartpoint.kg
General inquiries: general@smartpoint.kg
Telegram support: https://t.me/existent_dd
15. International Data Transfers
The Application uses services of Google LLC, Apple Inc., and Telegram FZ-LLC, whose servers may be located outside the Kyrgyz Republic. Such transfers are protected by technical and contractual safeguards, including these providers' standard data processing terms.
Google LLC, Apple Inc., and Telegram FZ-LLC act as independent data controllers that process data under their own privacy policies (links in Section 7).
We ensure that such transfers comply with applicable law and that personal data receives a level of protection no lower than required by the laws of the Kyrgyz Republic.
16. Appendix: Google Play Data Safety Reference
For internal use when completing the Data Safety section in Google Play Console and App Privacy in App Store Connect.
Data Collected and Shared
| Data Type | Collected | Shared With | Purpose |
|---|---|---|---|
| Employee name, phone, email | Yes | Not shared | Account, sign-in |
| Cargo customers' data (name, phone, code) | Yes (on behalf of the cargo company) | Not shared | Order handover and records |
| Telegram chat ID | Yes (if linked) | Telegram | Codes and notifications |
| Payment amount and status | Yes | Bank / payment service | Payment at handover |
| Photos (signature, attachments) | Yes (only taken or selected by the user) | Conversation participants | Handover confirmation, communication |
| Voice messages | Yes (only recorded by the user) | Conversation participants | In-app communication |
| Videos and files (attachments) | Yes (only selected by the user) | Conversation participants | In-app communication |
| Messenger messages | Yes | Conversation participants | In-app communication |
| In-app actions (operations log) | Yes | Not shared | App functionality, records |
| FCM token, installation identifier | Yes | Firebase / Google, Apple (APNs) | Push notifications, sessions |
| IP address, platform, and OS version | Yes | Not shared | Security, session list |
| Crashes and diagnostics | Yes | Firebase / Google | Stability |
Data Practices
- All data is encrypted in transit (HTTPS/TLS)
- Data deletion — on request at support@smartpoint.kg
- Data is NOT sold and NOT used for advertising or cross-app tracking
- No advertising SDKs, no advertising identifiers (GAID/IDFA), no Firebase Analytics
- No geolocation, contacts, SMS, or call history collected
- Camera, microphone, gallery, and files are used only on user action
- The in-app web view is used only for the Finik payment page and playing messenger videos
Permissions Declared
| Permission | Type | Purpose |
|---|---|---|
| INTERNET | Required | Server communication |
| CAMERA | On request (runtime) | Code scanning, signature photo, messenger photos, QR sign-in |
| POST_NOTIFICATIONS | On request (Android 13+) | Push notifications |
| RECORD_AUDIO | On request (runtime) | Voice messages in the messenger |
| VIBRATE | Required | Scan and notification signals |
The READ_MEDIA_IMAGES, READ_MEDIA_VIDEO, READ_EXTERNAL_STORAGE, and WRITE_EXTERNAL_STORAGE permissions are explicitly removed from the build.
Third-Party SDKs
| SDK | Provider | Purpose |
|---|---|---|
| Firebase Cloud Messaging | Google LLC | Push notifications |
| Firebase Crashlytics | Google LLC | Crash reports |
| react-native-webview | On-device | Finik payment page, messenger videos |
| react-native-in-app-review | Google / Apple | Optional rating dialog |
| react-native-camera-kit | On-device | Barcode and QR scanning |
| react-native-image-picker, @react-native-documents/picker | OS (system picker) | Signature photo and attachments chosen by the user |
| react-native-nitro-sound, react-native-sound | On-device | Audio recording and playback |
| react-native-tts | Device OS | Voice prompts when registering arrivals |
| react-native-keychain | Device OS | Secure storage of the session token |
| @notifee/react-native | On-device | Notification display |