Privacy Policy
SP Trader Mobile Application
Effective Date: August 9, 2026
Registered address: Bishkek, Kyrgyz Republic
Email: support@smartpoint.kg
1. Introduction
This Privacy Policy explains how Smart Point Solutions LLC ("we", "us", "our") collects, uses, stores and protects personal data when you use the "SP Trader" mobile application (the "App").
SP Trader is an application for retail outlets and entrepreneurs: product and stock management, sales and cash register, supplies and suppliers, customer settlements, reporting, and management of outlets and sellers. The App is intended for business use rather than personal consumer use.
By installing or using the App you confirm that you have read and agree to this Privacy Policy. If you do not agree, please uninstall the App and stop using it.
2. Legal Basis for Processing
We process personal data on the following legal grounds:
- Performance of a contract — providing accounting, sales, settlement and reporting features and maintaining your account.
- Consent — access to the camera and photo library, and push notifications. Consent can be withdrawn at any time in your device settings.
- Legal obligation — compliance with financial, tax and regulatory requirements of the Kyrgyz Republic.
- Legitimate interests — fraud prevention, account protection and service reliability, balanced against user rights.
3. Information We Collect
We apply data minimisation: we collect only what is strictly necessary for the purposes described below.
3.1 Account data
When registering and using the App you provide:
- Phone number — it is also your login and receives the one-time sign-in code
- User name
- Name of the retail outlet or shop
- Role within the outlet (owner, seller) and the staff members you add yourself
Sign-in uses a phone number and a one-time code (OTP). No password is used, so we neither store nor recover passwords.
3.2 Your business data
The App stores the operational data you enter: products and their attributes, product photos, barcodes, purchase and sale prices, stock levels per outlet, sales and receipts, cash operations, supplies and supplier details, debts and settlements, and reports.
This data belongs to you as the business owner. We process it to operate the App and do not use it for our own commercial purposes.
3.3 Technical device data
Technical data is collected only while you use the App; there is no background monitoring.
- Device identifier — a random UUID the App generates itself on first launch and stores locally. It is not a hardware identifier: it is unrelated to IMEI, serial number or advertising IDs, and it is reset when the App is reinstalled. It links a session to a device and lets you see your active sign-ins.
- Device name and platform (for example, "iPhone 15",
ios/android) — so you can recognise your devices in the session list and so notifications are delivered correctly. - App version — for diagnostics and compatibility.
- FCM token (Firebase Cloud Messaging) — the delivery address for push notifications. It is stored linked to your account, deactivated on sign-out and deleted when the account is deleted. If push is not configured in the build or you did not allow it, no token is created and the App works without it.
- IP address and session logs — account security and incident investigation.
4. Data About Your Customers and Counterparties
The App lets you keep customer and counterparty records: name, phone number, type, debt limit, note, and the history of sales and settlements. You enter this information yourself.
You are responsible for the lawfulness of entering such data: you must have a basis for processing your customers' personal data and, where the law requires it, obtain their consent and inform them about the processing.
On your request we will delete or export your counterparties' data — see sections 12 and 13.
5. Device Permissions
The App requests permissions at the moment you actually need the related feature and explains why. Declining any permission does not block the App as a whole — only the related feature becomes unavailable.
5.1 Camera
Used to scan product barcodes and take product photos. The video stream is processed on the device while scanning and is never transmitted; only the photos you deliberately take are saved. There is no continuous or background capture.
5.2 Photo library
Used to add a product or variation photo from your library. The App opens the system file picker and receives only the images you selected. The App does not enumerate or scan your library and does not request broad storage permissions.
5.3 Notifications
Used to deliver operational push notifications: sales, stock, supplies and outlet events. On Android 13+ this is the separate POST_NOTIFICATIONS permission; on iOS it is the standard system prompt.
5.4 Biometrics (Face ID / fingerprint)
Used only to unlock the App locally if you enabled this protection. Verification is performed by the operating system on the device itself; the App only receives a "verified" result. Your biometric samples are not accessible to the App or our servers and never leave the device.
5.5 Internet
Required to exchange data with our server. All communication uses a secure HTTPS/TLS connection.
6. What Stays on Your Device Only
Some data never leaves your phone and is kept in secure system storage (Keychain on iOS, Keystore on Android) or in the App's private storage, inaccessible to other apps:
- Access and refresh session tokens — the refresh token is stored in Keychain/Keystore.
- App lock PIN — we store not the code itself but its salted cryptographic hash (salted SHA-256). The PIN cannot be recovered from it, including by us.
- Biometric unlock flag — an entry in secure storage readable only after the system verifies you.
- Interface settings — theme, selected outlet, local preferences.
- Temporary copies of selected photos and generated PDF documents — removed after sending or closing.
PIN and biometric checks run locally: the server takes no part in them.
7. How We Use the Data
- Creating an account and signing in with a one-time code
- Operating accounting features: products, stock, sales, cash, supplies, settlements, reports
- Synchronising data across devices and staff of the same outlet
- Delivering operational push notifications
- Generating documents and reports that you export or share yourself
- Technical support in response to your request
- Account protection: detecting suspicious sign-ins, limiting attempts, investigating incidents
- Complying with the legislation of the Kyrgyz Republic
8. Data Sharing with Third Parties
We disclose data to a limited set of recipients and only to the extent required to provide the service:
- Google LLC (Firebase Cloud Messaging) — technical delivery of push notifications to your device. The device token and the notification text are transmitted.
- One-time code delivery provider — the channel identifier (phone number or other delivery address) required to send the sign-in code.
- Infrastructure provider — hosting of our servers and databases.
- Government authorities — only upon a lawful and properly issued request under the legislation of the Kyrgyz Republic.
Other App users can see your data only within your retail outlet and only to the extent defined by the staff roles you grant.
9. Third-Party Services
| Service | Provider | Purpose | Data |
|---|---|---|---|
| Firebase Cloud Messaging | Google LLC | Push notifications | Device token, notification text |
| Notifee | On device | Displaying notifications | Data does not leave the device |
| System photo picker | Apple / Google (OS) | Selecting product images | Only the files you select |
| Keychain / Keystore | Apple / Google (OS) | Storing tokens and lock secrets | Data does not leave the device |
| System share sheet | Apple / Google (OS) | Sending reports and documents | Only the file and recipient you choose |
The App uses no advertising networks, behavioural analytics, crash-reporting services or cross-app tracking.
10. Data Retention
- Account and business data — while the account is active and for the periods required by law for accounting and tax records.
- FCM token — until sign-out, disabling notifications or account deletion.
- Session and security logs — normally up to 12 months, then deleted or anonymised.
- On-device data — until sign-out or App removal; uninstalling the App erases local storage including tokens and lock settings.
11. Data Security
- All transmission over a secure HTTPS/TLS connection
- Short-lived access token and a separate refresh token in secure device storage
- Optional local sign-in protection with a PIN or biometrics
- The PIN is stored as a salted hash — the original code cannot be recovered
- Role-based access control within the retail outlet
- Sign-in attempt limits and suspicious activity monitoring
- Backups and access control for server infrastructure
No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we apply measures proportionate to the risks.
12. Your Rights
You have the right to:
- learn which of your data is being processed;
- request correction of inaccurate data;
- request deletion of your data and account;
- receive a copy of your data in a machine-readable format;
- withdraw consent, including device permissions;
- object to processing based on legitimate interests;
- lodge a complaint with the competent data protection authority of the Kyrgyz Republic.
Send requests to support@smartpoint.kg. We respond within the periods required by law.
13. Account and Data Deletion
You can request account deletion from within the App or by writing to support@smartpoint.kg from the phone number registered to the account.
Once the request is confirmed, we delete the account's personal data and deactivate notification tokens. Some records may be kept longer where accounting and tax legislation requires it; such records are stored separately and are not used in service operations.
Removing the App from your device does not by itself delete the server-side account — send a request if you need full deletion.
14. Children's Privacy
The App is intended for entrepreneurs and retail staff and is not directed at persons under 18. We do not knowingly collect children's data. If you believe a child has provided us with data, contact us and we will delete it.
15. Changes to This Privacy Policy
We may update this Policy when App functionality or legal requirements change. The current version is always available on this page, and the effective date is shown at the top. We announce material changes in the App or via your account contacts.
16. Contact Information
Bishkek, Kyrgyz Republic
Email: support@smartpoint.kg
Website: smartpoint.kg
17. International Data Transfers
Our server infrastructure and some of our providers' services may be located outside the Kyrgyz Republic. For any such transfer we ensure compliance with applicable data protection law and a level of protection equivalent to the requirements of the legislation of the Kyrgyz Republic.
18. Appendix: Google Play Data Safety Reference
For internal use when completing the Data Safety section in Google Play Console.
Data collected and shared
| Data type | Collected | Shared | Purpose |
|---|---|---|---|
| Name, phone number | Yes | Not shared | Account, code sign-in |
| Retail outlet name | Yes | Not shared | Workspace setup |
| Customer data entered by the user | Yes | Not shared | Sales and settlement records |
| Business financial data (prices, sales, cash, debts) | Yes | Not shared | Accounting and reporting features |
| Product photos | Yes (only those selected by the user) | Not shared | Product card |
| Device identifier (app UUID) | Yes | Not shared | Session binding, sign-in list |
| Device name and platform | Yes | Not shared | Session list, notification delivery |
| FCM token | Yes | Firebase / Google | Push notifications |
| IP address and activity logs | Yes | Not shared | Security, support |
| Camera (scanning, product photos) | Yes | Not shared | Barcodes, product images |
| Location, contacts, SMS, advertising IDs | No | — | — |
Data handling principles
- All data is encrypted in transit (HTTPS/TLS)
- Users can request data deletion at support@smartpoint.kg
- FCM tokens are deactivated on sign-out and deleted when the account is deleted
- Data is NOT sold and NOT shared with advertising networks
- No advertising SDKs, behavioural analytics or trackers
- No background monitoring; technical data is collected only while the App is in use
- Location, contacts, SMS and advertising identifiers are not collected; the photo library is not scanned — access is limited to files the user selects
- The device identifier is a random app UUID, not a hardware identifier, and resets on reinstall
- Biometrics are verified by the operating system; biometric samples are not accessible to the App
- The PIN is stored only as a salted hash and cannot be recovered
- No automated decision-making with legal or similarly significant effects without human involvement
Declared permissions
| Permission | Type | Purpose |
|---|---|---|
| INTERNET | Required | Server communication |
| CAMERA | Optional (runtime) | Barcode scanning, product photos |
| POST_NOTIFICATIONS | Optional (Android 13+) | Push notification delivery |
| NSPhotoLibraryUsageDescription (iOS) | Optional | Selecting product photos from the library |
| NSFaceIDUsageDescription (iOS) | Optional | Local App unlock |
Declared third-party SDKs
| SDK | Provider | Purpose |
|---|---|---|
| Firebase Cloud Messaging | Google LLC | Push notifications |
| Notifee | On device (offline) | Displaying and styling notifications |
| react-native-vision-camera | On device (offline) | Barcode scanning, photo capture |
| react-native-image-picker | OS (system picker) | User-initiated selection of product photos |
| react-native-keychain | OS (Keychain / Keystore) | Storing the refresh token and lock secrets |
| react-native-share | OS (system share sheet) | User-initiated sharing of reports and documents |
| react-native-device-info | On device | Device name and App version |