Back

Platform Documents

Privacy Policy

SP Tool Mobile Application

Effective Date: October 2, 2026

Operator: Smart Point Solutions LLC (OsOO «Smart Point Solutions»)
Registered address: Bishkek, Kyrgyz Republic
Email: support@smartpoint.kg

1. Introduction

This Privacy Policy explains how Smart Point Solutions LLC ("we", "us", "our") collects, uses, stores, and protects personal data when you use the Smart Point mobile application "SP Tool" (the "Application").

The Application is available on Google Play and the App Store and is intended for employees of cargo companies and sorting centers that partner with the Smart Point platform. In the Application, staff register and sort incoming items, accept returns, build and dispatch shipments, manage the warehouse and the customer base, hand orders over to customers and accept payment, chat with colleagues and partners in the in-app messenger, and confirm sign-ins to the SP Linker web app. The Application is not intended for end customers.

By installing or using the Application, you confirm that you have read and agreed to this Privacy Policy. If you do not agree, please uninstall the Application and discontinue its use.

3. Information We Collect

We apply the principle of data minimization: we collect only data that is strictly necessary for the purposes described below.

3.1 Employee Data

  • Full name and phone number
  • Email address — if specified in the profile
  • Role and groups (cargo company, sorting center) the employee works in
  • Profile photo — if the user uploaded one
  • Telegram chat identifier — only if the user linked the Smart Point Telegram bot to receive codes and notifications
  • Activity log in the Application: who registered, accepted, dispatched, handed over an item or changed its status, and when. The log is needed for record-keeping and dispute resolution

3.2 Item, Shipment and Handover Data

  • Tracking number, customer code, weight, dimensions, declared value, amount due, status, storage cell, box
  • Shipment and return composition and statuses, destination pickup points
  • Handovers: which items were handed over or returned, return reason, payment status
  • Photo of the customer's signature — if the "Signature photo" module is enabled for your group: a picture the employee takes with the camera or selects from the gallery when handing over an order. The photo is stored on our servers and is available only to staff with access to that handover

3.3 Data of the Cargo Company's Customers

In the "Warehouse" and "Handover" sections, staff see the data of their cargo company's customers: name, phone number, customer code, selected pickup point, and whether Telegram is linked. This data is uploaded and maintained by the cargo company itself; the Application shows it only to that cargo company's staff, to the extent needed to work with orders. We do not use customer data for our own purposes.

3.4 Device and Technical Data Collected Automatically

Technical data is collected only while the Application is in use and does not include background surveillance.

a) FCM Token (Firebase Cloud Messaging)

A unique token generated by Firebase for a specific installation of the Application. Used exclusively to deliver push notifications: new arrivals and handovers, status changes, messenger messages, authorization codes. Stored on our server linked to the account. Deactivated on logout, account deletion, or when the device rotates the token.

b) Installation identifier (device_id)

A random identifier the Application creates on first launch. It is not tied to hardware and cannot be used to track the device across other apps; it is used only to link the sign-in session and FCM token to this installation. A new identifier is created after reinstalling the Application.

c) Platform, OS version and Application version

For example, "Android 14" or "iOS 18", and the SP Tool version number. Used for correct notification delivery and in the list of active sessions so you can recognize your device. The Application does not collect the device model or hardware serial numbers.

d) Sign-in sessions

For each active session we store the platform, Application version, IP address, and time of last activity. You see this list in "Active sessions" and can end any session.

e) Other technical data

  • IP address and server request logs
  • Crash reports and diagnostic data (Firebase Crashlytics)
  • Online presence status — while the Application is open, it periodically tells the server you are online, and colleagues see you as "online" in the messenger. No status is sent from the background or outside the Application
We do NOT collect: geolocation, phone contacts, SMS content, call history, advertising identifiers (GAID/IDFA), or information about other installed apps. We do not scan your gallery or device files — photos, videos and documents leave the device only when you select or take them yourself and send them. Firebase Analytics and other advertising or behavioral analytics systems are not used in the Application.

3.5 Sign-in and One-Time Codes (OTP)

Sign-in is performed with a phone number and a one-time code (OTP), which is also a simple electronic signature within the meaning of the Law of the Kyrgyz Republic "On Electronic Signature".

The code is delivered through the channels the user chose in the SP Linker profile and that are available to them:

  • Smart Point Telegram bot — via the Telegram Bot API to the user's Telegram account
  • Push notification — to a device where the user is already signed in to a Smart Point app, or to the device that requested the code
  • Email — to the verified email address in the profile

After sign-in the session is extended automatically: a short-lived access token is refreshed using a long-lived token kept in the device's secure storage (see Section 4.2).

3.6 Confirming Web Sign-in with a QR Code

In "Active sessions" you can scan the QR code on the SP Linker sign-in page and confirm the sign-in in the browser. Before you confirm, the Application shows the browser name, operating system, and IP address of the computer requesting access, so you can make sure it is your computer. This information is kept in your account's sign-in history.

3.7 In-App Messenger

The Application includes a corporate messenger for staff, partners, and Smart Point support. When you use it, we process:

  • The text of messages you send and receive, reactions, forwards, and pinned messages
  • Attachments you choose to send: photos, videos, voice messages, and files
  • Metadata: sender, recipients or group, timestamps, delivery and read status
  • Name, avatar, and membership of group conversations
  • Messages and attachments are transmitted over an encrypted connection (HTTPS/TLS) and stored on our servers so they can be delivered and displayed to the participants of the conversation.
  • Content is available only to the participants of the relevant conversation and is not used for advertising or profiling. Messenger content is not end-to-end encrypted: our authorized systems can store and process it to operate the service, ensure security, and comply with legal obligations.
  • Voice messages are recorded only after you start a recording; the microphone is never used in the background (see Section 4.4).

4. Device Permissions

The Application requests only the following permissions, each used strictly for the stated purpose, in line with Google Play Developer Program Policies and Apple App Store Review Guidelines. Permissions are requested at the moment they are needed and can be revoked in the phone settings; their current status is shown in the Application under "App permissions".

4.1 Camera (CAMERA)

Used only on the employee's action:

  • Scanning barcodes and QR codes of items, boxes, and shipments when registering arrivals, accepting, building a shipment, handing over, searching for an item, and viewing history by code
  • Scanning the QR code on the SP Linker sign-in page to confirm a browser sign-in
  • Taking a photo of the customer's signature when handing over an order (if the "Signature photo" module is enabled)
  • Taking a photo to send in the messenger or to use as a group conversation avatar
The camera does not run in the background. When scanning, the image is processed on the device and only the decoded code is sent to the server. A photo is uploaded only after you take it and confirm sending. The Application does not save pictures to the phone's gallery.

4.2 Storage

The Application uses only its own private storage (Android sandbox / iOS app container):

  • Access token, installation identifier, FCM token, selected group, and interface settings — in AsyncStorage
  • The long-lived session refresh token — in the OS secure storage (iOS Keychain / Android Keystore)
  • A cache of voice messages for replay and temporary copies of selected attachments (cleared by the system or after upload)
The Application does not request READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, or READ_MEDIA_* permissions and does not read or write the phone's shared storage on its own. A file leaves the Application only if you send it yourself through the system "Share" menu.

4.3 Notifications (POST_NOTIFICATIONS)

Used for push notifications about arrivals, handovers, shipments, returns, messenger messages, and authorization codes. You may revoke this permission at any time: Device Settings → Apps → SP Tool → Notifications.

4.4 Microphone (RECORD_AUDIO)

Requested only to record voice messages in the messenger, and only when you start a recording.

The microphone is never used in the background or without your action. The Application does not perform passive listening, call recording, or ambient audio capture. Declining the permission only disables voice messages.

4.5 Photos, Media and Files

When you attach a photo, video, or document to a message or pick a signature photo from the gallery, the Application opens the system picker (Android Photo Picker / Storage Access Framework; iOS system picker). The Application receives only the items you select and only at that moment, without standing access to your gallery.

4.6 Vibration (VIBRATE) and Sound

Short vibration signals and sounds confirm scan results. When registering arrivals, the Application may announce the item's destination by voice: the device's built-in text-to-speech is used, and the text (the pickup point name) is processed on the device and not sent to us.

5. How We Use Collected Data

We use personal data exclusively for:

  • Operating the core features: registering arrivals, sorting, accepting, shipments, warehouse, inventory, and handovers
  • Keeping records of item operations and resolving disputes
  • Accepting payment at handover and reconciling payment status
  • Delivering push notifications and one-time codes
  • Operating the in-app messenger and presence status
  • Managing accounts and sessions and confirming web sign-ins
  • Protecting accounts and detecting and preventing fraud
  • Responding to support requests and fixing crashes
  • Complying with applicable legal and regulatory obligations

We do not use automated decision-making that produces legal or similarly significant effects without human review.

We do NOT sell personal data to third parties.
We do NOT use personal data for advertising, profiling, or cross-app tracking.
We do NOT collect data beyond what is described in this Policy.

6. Data Sharing and Disclosure

We share personal data only when necessary, and only with:

  • Messenger conversation participants — messages, attachments, and presence status you send
  • Logistics chain partners — pickup points (PVZ) and marketplace partners receive the item and shipment details needed for delivery and handover (tracking number, status, shipment composition, customer code)
  • Banks and payment services (Bakai Bank, Optima Bank, Finik) — when accepting payment at handover: the amount and payment identifier to generate the QR code and check the payment status. The payer's card and bank account details are processed by the bank or payment service; we do not receive or store them
  • Telegram (Telegram FZ-LLC) — when the user receives codes or notifications through the Smart Point Telegram bot
  • Email service providers — to deliver the code by email if the user chose that channel
  • Firebase / Google LLC — push notification delivery (FCM) and crash reports (Crashlytics)
  • Apple Inc. — push notification delivery on iOS via the Apple Push Notification service
  • Cloud infrastructure and hosting providers — to run servers and store data
  • Government authorities — only when required by law, court order, or official request

All third-party providers are bound by confidentiality and data security obligations and may use data only to perform the agreed services.

7. Third-Party Services

The Application integrates:

  • Firebase Cloud Messaging (FCM) — push notification delivery; FCM tokens are processed per Google's privacy policy
  • Firebase Crashlytics — crash reports: device model and OS version, Application version, stack trace. Reports do not contain message text, customer data, or item data
  • Bakai QR and Optima QR — the server generates a payment QR code, the Application shows it to the customer, and the customer pays in their bank's app
  • Finik — the Finik payment page opens in an in-app web view (react-native-webview); payment details are entered and processed on Finik's side
  • Telegram Bot API — codes and notifications if the user linked the Telegram bot
  • Google Play / App Store In-App Review — optional system rating dialog
  • On-device components that do not share data with third parties: code scanner (react-native-camera-kit), audio recording and playback (react-native-nitro-sound, react-native-sound), OS text-to-speech (react-native-tts), system photo and file pickers (react-native-image-picker, @react-native-documents/picker), secure storage (react-native-keychain), notification display (@notifee/react-native)

8. Data Retention

Data TypeRetention Period
Employee account and profileWhile the account is active + a reasonable period after closure
Sign-in sessionsUntil logout, session termination, or expiry
FCM tokensUntil logout, token rotation, or account deletion
Items, shipments, handovers, payments, signature photos, and activity logAs required by financial and tax law and the contract with the cargo company
Messenger messages and attachmentsWhile the conversation exists or until the message is deleted
Crash reportsUp to 90 days

After expiration, data is securely deleted or irreversibly anonymized.

9. Data Security

We implement:

  • HTTPS/TLS encryption for all data in transit
  • Short-lived access tokens, with the refresh token kept in the OS secure storage (Keychain / Keystore)
  • A list of active sessions where any session can be ended, including all sessions except the current one
  • Web sign-in confirmation only from a phone where the user is already signed in
  • Role-based access control: staff see data of their own group only
  • Security monitoring and protected backups with restricted access
  • Android cloud backup of Application data is disabled

No method of transmission over the internet is completely secure. We promptly investigate and remediate security incidents we become aware of.

10. User Rights

You have the right to:

  • Access — request a copy of personal data we hold
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of personal data
  • Restriction — request limitation of processing
  • Withdraw consent — at any time
  • Portability — receive your data in a machine-readable format

If you are a customer of a cargo company and your data is visible in the Application, contact your cargo company or us about its processing — we will forward the request to the cargo company and help fulfil it.

Contact: support@smartpoint.kg
Response time: within 30 calendar days (extendable by 30 days with prior notice for complex requests).

11. Account and Data Deletion

Employee accounts are created and disabled by the manager of the cargo company. To delete your account and associated personal data, contact your manager or us directly:

Please include the phone number you use to sign in to the Application.

On request we delete the profile, sessions, FCM tokens, and all non-essential records. Records of item operations and payments required by financial and tax law are retained for the mandated period, detached from the profile where possible, and then deleted. Requests are processed within 30 calendar days.

12. Children's Privacy

The Application is a work tool and is not intended for individuals under 18. We do not knowingly collect personal data from minors. If we become aware of such data, we will promptly delete it. Contact: support@smartpoint.kg.

13. Changes to This Privacy Policy

When material changes are made, we will:

  • Update the Effective Date at the top of this Policy
  • Display an in-app notice before the changes take effect
  • Where required by law, seek renewed consent

Continued use of the Application after notification constitutes acceptance of the revised Policy.

14. Contact Information

Smart Point Solutions LLC
Bishkek, Kyrgyz Republic
Support email: support@smartpoint.kg
General inquiries: general@smartpoint.kg
Telegram support: https://t.me/existent_dd

15. International Data Transfers

The Application uses services of Google LLC, Apple Inc., and Telegram FZ-LLC, whose servers may be located outside the Kyrgyz Republic. Such transfers are protected by technical and contractual safeguards, including these providers' standard data processing terms.

Google LLC, Apple Inc., and Telegram FZ-LLC act as independent data controllers that process data under their own privacy policies (links in Section 7).

We ensure that such transfers comply with applicable law and that personal data receives a level of protection no lower than required by the laws of the Kyrgyz Republic.

16. Appendix: Google Play Data Safety Reference

For internal use when completing the Data Safety section in Google Play Console and App Privacy in App Store Connect.

Data Collected and Shared

Data TypeCollectedShared WithPurpose
Employee name, phone, emailYesNot sharedAccount, sign-in
Cargo customers' data (name, phone, code)Yes (on behalf of the cargo company)Not sharedOrder handover and records
Telegram chat IDYes (if linked)TelegramCodes and notifications
Payment amount and statusYesBank / payment servicePayment at handover
Photos (signature, attachments)Yes (only taken or selected by the user)Conversation participantsHandover confirmation, communication
Voice messagesYes (only recorded by the user)Conversation participantsIn-app communication
Videos and files (attachments)Yes (only selected by the user)Conversation participantsIn-app communication
Messenger messagesYesConversation participantsIn-app communication
In-app actions (operations log)YesNot sharedApp functionality, records
FCM token, installation identifierYesFirebase / Google, Apple (APNs)Push notifications, sessions
IP address, platform, and OS versionYesNot sharedSecurity, session list
Crashes and diagnosticsYesFirebase / GoogleStability

Data Practices

  • All data is encrypted in transit (HTTPS/TLS)
  • Data deletion — on request at support@smartpoint.kg
  • Data is NOT sold and NOT used for advertising or cross-app tracking
  • No advertising SDKs, no advertising identifiers (GAID/IDFA), no Firebase Analytics
  • No geolocation, contacts, SMS, or call history collected
  • Camera, microphone, gallery, and files are used only on user action
  • The in-app web view is used only for the Finik payment page and playing messenger videos

Permissions Declared

PermissionTypePurpose
INTERNETRequiredServer communication
CAMERAOn request (runtime)Code scanning, signature photo, messenger photos, QR sign-in
POST_NOTIFICATIONSOn request (Android 13+)Push notifications
RECORD_AUDIOOn request (runtime)Voice messages in the messenger
VIBRATERequiredScan and notification signals

The READ_MEDIA_IMAGES, READ_MEDIA_VIDEO, READ_EXTERNAL_STORAGE, and WRITE_EXTERNAL_STORAGE permissions are explicitly removed from the build.

Third-Party SDKs

SDKProviderPurpose
Firebase Cloud MessagingGoogle LLCPush notifications
Firebase CrashlyticsGoogle LLCCrash reports
react-native-webviewOn-deviceFinik payment page, messenger videos
react-native-in-app-reviewGoogle / AppleOptional rating dialog
react-native-camera-kitOn-deviceBarcode and QR scanning
react-native-image-picker, @react-native-documents/pickerOS (system picker)Signature photo and attachments chosen by the user
react-native-nitro-sound, react-native-soundOn-deviceAudio recording and playback
react-native-ttsDevice OSVoice prompts when registering arrivals
react-native-keychainDevice OSSecure storage of the session token
@notifee/react-nativeOn-deviceNotification display