Back

Platform Documents

Privacy Policy

SP Trader Mobile Application

Effective Date: August 9, 2026

Data controller: Smart Point Solutions LLC
Registered address: Bishkek, Kyrgyz Republic
Email: support@smartpoint.kg

1. Introduction

This Privacy Policy explains how Smart Point Solutions LLC ("we", "us", "our") collects, uses, stores and protects personal data when you use the "SP Trader" mobile application (the "App").

SP Trader is an application for retail outlets and entrepreneurs: product and stock management, sales and cash register, supplies and suppliers, customer settlements, reporting, and management of outlets and sellers. The App is intended for business use rather than personal consumer use.

By installing or using the App you confirm that you have read and agree to this Privacy Policy. If you do not agree, please uninstall the App and stop using it.

3. Information We Collect

We apply data minimisation: we collect only what is strictly necessary for the purposes described below.

3.1 Account data

When registering and using the App you provide:

  • Phone number — it is also your login and receives the one-time sign-in code
  • User name
  • Name of the retail outlet or shop
  • Role within the outlet (owner, seller) and the staff members you add yourself

Sign-in uses a phone number and a one-time code (OTP). No password is used, so we neither store nor recover passwords.

3.2 Your business data

The App stores the operational data you enter: products and their attributes, product photos, barcodes, purchase and sale prices, stock levels per outlet, sales and receipts, cash operations, supplies and supplier details, debts and settlements, and reports.

This data belongs to you as the business owner. We process it to operate the App and do not use it for our own commercial purposes.

3.3 Technical device data

Technical data is collected only while you use the App; there is no background monitoring.

  • Device identifier — a random UUID the App generates itself on first launch and stores locally. It is not a hardware identifier: it is unrelated to IMEI, serial number or advertising IDs, and it is reset when the App is reinstalled. It links a session to a device and lets you see your active sign-ins.
  • Device name and platform (for example, "iPhone 15", ios / android) — so you can recognise your devices in the session list and so notifications are delivered correctly.
  • App version — for diagnostics and compatibility.
  • FCM token (Firebase Cloud Messaging) — the delivery address for push notifications. It is stored linked to your account, deactivated on sign-out and deleted when the account is deleted. If push is not configured in the build or you did not allow it, no token is created and the App works without it.
  • IP address and session logs — account security and incident investigation.
We do NOT collect: location, contacts, SMS content, your entire photo library, advertising identifiers (GAID/IDFA), or the list of other installed apps. The App contains no advertising SDKs, behavioural analytics or trackers: the only Google service integrated is push notification delivery.

4. Data About Your Customers and Counterparties

The App lets you keep customer and counterparty records: name, phone number, type, debt limit, note, and the history of sales and settlements. You enter this information yourself.

For your customers' data you are the data owner, and we act on your instructions as the technical platform operator. We do not use this data for our own purposes, do not share it with other App users and do not send marketing to those contacts.

You are responsible for the lawfulness of entering such data: you must have a basis for processing your customers' personal data and, where the law requires it, obtain their consent and inform them about the processing.

On your request we will delete or export your counterparties' data — see sections 12 and 13.

5. Device Permissions

The App requests permissions at the moment you actually need the related feature and explains why. Declining any permission does not block the App as a whole — only the related feature becomes unavailable.

5.1 Camera

Used to scan product barcodes and take product photos. The video stream is processed on the device while scanning and is never transmitted; only the photos you deliberately take are saved. There is no continuous or background capture.

5.2 Photo library

Used to add a product or variation photo from your library. The App opens the system file picker and receives only the images you selected. The App does not enumerate or scan your library and does not request broad storage permissions.

5.3 Notifications

Used to deliver operational push notifications: sales, stock, supplies and outlet events. On Android 13+ this is the separate POST_NOTIFICATIONS permission; on iOS it is the standard system prompt.

5.4 Biometrics (Face ID / fingerprint)

Used only to unlock the App locally if you enabled this protection. Verification is performed by the operating system on the device itself; the App only receives a "verified" result. Your biometric samples are not accessible to the App or our servers and never leave the device.

5.5 Internet

Required to exchange data with our server. All communication uses a secure HTTPS/TLS connection.

6. What Stays on Your Device Only

Some data never leaves your phone and is kept in secure system storage (Keychain on iOS, Keystore on Android) or in the App's private storage, inaccessible to other apps:

  • Access and refresh session tokens — the refresh token is stored in Keychain/Keystore.
  • App lock PIN — we store not the code itself but its salted cryptographic hash (salted SHA-256). The PIN cannot be recovered from it, including by us.
  • Biometric unlock flag — an entry in secure storage readable only after the system verifies you.
  • Interface settings — theme, selected outlet, local preferences.
  • Temporary copies of selected photos and generated PDF documents — removed after sending or closing.

PIN and biometric checks run locally: the server takes no part in them.

7. How We Use the Data

  • Creating an account and signing in with a one-time code
  • Operating accounting features: products, stock, sales, cash, supplies, settlements, reports
  • Synchronising data across devices and staff of the same outlet
  • Delivering operational push notifications
  • Generating documents and reports that you export or share yourself
  • Technical support in response to your request
  • Account protection: detecting suspicious sign-ins, limiting attempts, investigating incidents
  • Complying with the legislation of the Kyrgyz Republic
We do not sell data, do not share it with ad networks or data brokers, and do not use your business records for profiling or targeting.

8. Data Sharing with Third Parties

We disclose data to a limited set of recipients and only to the extent required to provide the service:

  • Google LLC (Firebase Cloud Messaging) — technical delivery of push notifications to your device. The device token and the notification text are transmitted.
  • One-time code delivery provider — the channel identifier (phone number or other delivery address) required to send the sign-in code.
  • Infrastructure provider — hosting of our servers and databases.
  • Government authorities — only upon a lawful and properly issued request under the legislation of the Kyrgyz Republic.

Other App users can see your data only within your retail outlet and only to the extent defined by the staff roles you grant.

9. Third-Party Services

ServiceProviderPurposeData
Firebase Cloud MessagingGoogle LLCPush notificationsDevice token, notification text
NotifeeOn deviceDisplaying notificationsData does not leave the device
System photo pickerApple / Google (OS)Selecting product imagesOnly the files you select
Keychain / KeystoreApple / Google (OS)Storing tokens and lock secretsData does not leave the device
System share sheetApple / Google (OS)Sending reports and documentsOnly the file and recipient you choose

The App uses no advertising networks, behavioural analytics, crash-reporting services or cross-app tracking.

10. Data Retention

  • Account and business data — while the account is active and for the periods required by law for accounting and tax records.
  • FCM token — until sign-out, disabling notifications or account deletion.
  • Session and security logs — normally up to 12 months, then deleted or anonymised.
  • On-device data — until sign-out or App removal; uninstalling the App erases local storage including tokens and lock settings.

11. Data Security

  • All transmission over a secure HTTPS/TLS connection
  • Short-lived access token and a separate refresh token in secure device storage
  • Optional local sign-in protection with a PIN or biometrics
  • The PIN is stored as a salted hash — the original code cannot be recovered
  • Role-based access control within the retail outlet
  • Sign-in attempt limits and suspicious activity monitoring
  • Backups and access control for server infrastructure

No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we apply measures proportionate to the risks.

12. Your Rights

You have the right to:

  • learn which of your data is being processed;
  • request correction of inaccurate data;
  • request deletion of your data and account;
  • receive a copy of your data in a machine-readable format;
  • withdraw consent, including device permissions;
  • object to processing based on legitimate interests;
  • lodge a complaint with the competent data protection authority of the Kyrgyz Republic.

Send requests to support@smartpoint.kg. We respond within the periods required by law.

13. Account and Data Deletion

You can request account deletion from within the App or by writing to support@smartpoint.kg from the phone number registered to the account.

Once the request is confirmed, we delete the account's personal data and deactivate notification tokens. Some records may be kept longer where accounting and tax legislation requires it; such records are stored separately and are not used in service operations.

Removing the App from your device does not by itself delete the server-side account — send a request if you need full deletion.

14. Children's Privacy

The App is intended for entrepreneurs and retail staff and is not directed at persons under 18. We do not knowingly collect children's data. If you believe a child has provided us with data, contact us and we will delete it.

15. Changes to This Privacy Policy

We may update this Policy when App functionality or legal requirements change. The current version is always available on this page, and the effective date is shown at the top. We announce material changes in the App or via your account contacts.

16. Contact Information

Smart Point Solutions LLC
Bishkek, Kyrgyz Republic
Email: support@smartpoint.kg
Website: smartpoint.kg

17. International Data Transfers

Our server infrastructure and some of our providers' services may be located outside the Kyrgyz Republic. For any such transfer we ensure compliance with applicable data protection law and a level of protection equivalent to the requirements of the legislation of the Kyrgyz Republic.

18. Appendix: Google Play Data Safety Reference

For internal use when completing the Data Safety section in Google Play Console.

Data collected and shared

Data typeCollectedSharedPurpose
Name, phone numberYesNot sharedAccount, code sign-in
Retail outlet nameYesNot sharedWorkspace setup
Customer data entered by the userYesNot sharedSales and settlement records
Business financial data (prices, sales, cash, debts)YesNot sharedAccounting and reporting features
Product photosYes (only those selected by the user)Not sharedProduct card
Device identifier (app UUID)YesNot sharedSession binding, sign-in list
Device name and platformYesNot sharedSession list, notification delivery
FCM tokenYesFirebase / GooglePush notifications
IP address and activity logsYesNot sharedSecurity, support
Camera (scanning, product photos)YesNot sharedBarcodes, product images
Location, contacts, SMS, advertising IDsNo

Data handling principles

  • All data is encrypted in transit (HTTPS/TLS)
  • Users can request data deletion at support@smartpoint.kg
  • FCM tokens are deactivated on sign-out and deleted when the account is deleted
  • Data is NOT sold and NOT shared with advertising networks
  • No advertising SDKs, behavioural analytics or trackers
  • No background monitoring; technical data is collected only while the App is in use
  • Location, contacts, SMS and advertising identifiers are not collected; the photo library is not scanned — access is limited to files the user selects
  • The device identifier is a random app UUID, not a hardware identifier, and resets on reinstall
  • Biometrics are verified by the operating system; biometric samples are not accessible to the App
  • The PIN is stored only as a salted hash and cannot be recovered
  • No automated decision-making with legal or similarly significant effects without human involvement

Declared permissions

PermissionTypePurpose
INTERNETRequiredServer communication
CAMERAOptional (runtime)Barcode scanning, product photos
POST_NOTIFICATIONSOptional (Android 13+)Push notification delivery
NSPhotoLibraryUsageDescription (iOS)OptionalSelecting product photos from the library
NSFaceIDUsageDescription (iOS)OptionalLocal App unlock

Declared third-party SDKs

SDKProviderPurpose
Firebase Cloud MessagingGoogle LLCPush notifications
NotifeeOn device (offline)Displaying and styling notifications
react-native-vision-cameraOn device (offline)Barcode scanning, photo capture
react-native-image-pickerOS (system picker)User-initiated selection of product photos
react-native-keychainOS (Keychain / Keystore)Storing the refresh token and lock secrets
react-native-shareOS (system share sheet)User-initiated sharing of reports and documents
react-native-device-infoOn deviceDevice name and App version