AruGo

Privacy policy

This document describes what the service actually does with data — from how the database and the code are built, not from a template found on the internet.

Edition of 19 September 2026 Version 1.0 In force from 19 September 2026

The binding text of this policy is the Russian one, published at arun.kz/privacy. This English version is a translation provided for convenience; if the two diverge, the Russian text prevails.

1. Who processes the data

The operator of personal data is the owner of the AruGo service — an app for calling a taxi in the villages of Kazakhstan and the site arun.kz. The operator can be reached on any question about this data at berkenov.post@gmail.com.

Processing begins at the moment you enter your phone number when signing in to the app. Before that moment the app sends nothing about you to the server.

2. What data we collect and why

The list is complete. Every line below corresponds to a specific place in our database — if something is not in this list, it is not in the database either.

For all users

Phone number

The only identifier of a person in the system. We ask passengers and drivers for no passwords, no email address, no forms and no documents — the account exists precisely as a number.

Why: signing in to the app, connecting driver and passenger for a particular trip, and handling complaints.

Kept while the account exists

The name you signed with

An optional field. It is there so that the driver at the gate knows who he is picking up, and the passenger sees who is at the wheel.

Kept while the account exists

Interface language

Russian, Kazakh or English. It determines the language of notifications and of the sign-in code message.

Kept while the account exists

The confirmation code used at sign-in

We do not store the code itself — the database holds only an irreversible hash of it, with a five-minute lifetime, an attempt counter and the IP address the code was requested from. The IP is there for exactly one purpose: to stop code guessing when somebody is trying to get into another person’s account.

The code — 5 minutes. The requesting IP address — 30 days

Device data for notifications

The push notification token, the platform (Android or iOS), the app version and the phone’s language settings. Without a token the phone cannot be woken when an order arrives.

One person may have several devices — a driver often has two phones, and both must ring.

Kept while the device is active

When an order is created

Location at the moment the order is created

The app takes your current point once — when you place the order. From it the nearest connected village is determined, the price is calculated from that village’s fare, and the driver knows where to come.

There is no background tracking of movement. The app does not record your route, does not collect coordinates between orders and keeps no history of your movements outside orders. The pickup point and the destination exist only as part of a particular order.

Kept together with the order

The landmark and the note in words

“Hospital”, “School No. 1”, and your own addition such as “the green gate” or “opposite the pharmacy”. This is how directions are actually given in a village, and it saves a phone call.

Kept together with the order

The order log

The order number, its status, the time of every step, the calculated price, the assigned driver, the fact of a cancellation and who made it. Separately, the offer log: which drivers the order was shown to, who accepted, who declined, who stayed silent.

Why: without this log it is impossible to resolve a dispute over “no order reached me” or “the driver did not come” — nothing would be left but two accounts contradicting each other.

3 years

Points where the service does not operate

If there is no connected village near you, we record the fact of the failed attempt so that we know which village to connect next. The coordinates are coarsened at the moment of writing to roughly a kilometre and are tied neither to your number nor to your account. An exact point never exists in that table at any stage.

90 days

Additionally for drivers

The car’s plate number

Stored in two forms: as you typed it, and in a normalised form — so that “123 АВС” in Cyrillic and “123 ABC” in Latin count as one car and not two.

Why: the passenger has to recognise the car at the gate. It is also the only thread to pull on when a complaint is examined.

Kept while the driver profile exists

The colour, make, model and year of the car

So that the driver card can be read at seven in the morning in winter.

Kept while the driver profile exists

A photo of the car

Optional — declining it restricts nothing. A photo of the driver, that is of the person, we neither ask for nor store at all.

An uploaded picture is re-compressed on the server, and in doing so the EXIF metadata is forcibly stripped. EXIF contains the GPS coordinates of where the photo was taken — as a rule, the driver’s own yard. We do not want a person’s home address travelling along with the picture.

Kept while the driver profile exists

Shift and queue

Whether the driver is on the line or not, when he went on, his place in the village queue, the time of the last connection signal, and counters of missed orders.

Why: the queue is the core of the product. Without these fields there is nobody to hand an order to in turn.

Kept while the driver profile exists

The history of profile changes

If a driver changed the plate number or the make of the car, the old value is kept. This protects the passenger: in the middle of a dispute the car cannot “become a different one”.

Kept while the driver profile exists

Complaints and technical telemetry

The text of a complaint

What you wrote, about whom and against which order. It is read only by the platform staff who handle enquiries.

3 years

Three technical events from the app

The app reports to us exactly three things the server cannot learn by itself: after how many milliseconds the order card actually appeared on the driver’s screen, which system permissions have been granted to the app (location, notifications, background work, battery saving) and the fact that an order form was abandoned before reaching confirmation.

Why: the first shows whether orders arrive within seconds or whether we are lying to ourselves. The second explains why a particular driver on the line is not getting orders. The third shows at which step people give up on a trip.

12 months

The platform event log

The technical stream from which the service metrics are calculated. By a rule built into the database schema itself, it contains no personal data — only internal identifiers (order number, user number, village number). Neither a phone number, nor a name, nor a plate, nor coordinates, nor the text of an address note ever reaches this log.

3 years for the order log, 12 months for telemetry

3. What we refuse to collect on principle

This list is every bit as binding as the previous one. We do not collect:

  • Location outside an order. No background tracking, no movement history.
  • The advertising identifier, the phone model, the mobile operator. Personal data without a single question that it would answer.
  • Screen views, button taps, scrolls, time spent in the app. These are not product metrics but surveillance of behaviour.
  • The contact list, the photo gallery, the microphone, the calendar. The app does not request these permissions.
  • Payment data. No cards, no saved cards, no accounts: payment goes straight to the driver, bypassing the platform (see the Terms of use). We simply have no means to charge you.
  • Drivers’ documents — licence, registration certificate, insurance. We do not check them and do not store them; an “upload later” field would create the false impression of a check.
  • A photograph of a driver’s or a passenger’s face.
  • Registered address, individual identification number, date of birth, marital status and other questionnaire data.

We do not sell data, do not pass it to ad networks, data brokers or credit bureaux, and do not use it for profiling or targeting.

4. Where the data is stored

The database is on a server within the territory of the Republic of Kazakhstan. This is a requirement of Article 12 of the Law of the Republic of Kazakhstan “On Personal Data and Its Protection”: the personal data of citizens of Kazakhstan must be stored in a database physically located in the Republic.

Database backups are the same personal data, so they too remain within the territory of Kazakhstan and are not exported to external clouds outside the country.

For the same reason the service does not use external cloud analytics platforms (Google Analytics, Amplitude, Mixpanel and the like): all of them take data outside Kazakhstan. Our analytics are our own and sit in the same database as the orders.

5. Who the data is passed to

There are exactly four third parties, and each receives a strictly defined minimum. Below we state not only what goes out but also what does not.

Google Firebase Cloud Messaging — delivering notifications

Goes out: your device’s push token, the short text of the notification (“New order”, “A car has been found”, “The driver is here”) and service fields — the internal order number, the event name and the deadline until which the offer is valid.

Does not go out: phone number, name, pickup address, destination address, coordinates, trip price, car plate number.

This is deliberate: the job of a push is to wake the app, not to deliver the contents of the order. The app fetches the contents itself from our server in Kazakhstan in a separate request. That is why the internal order number sent to Firebase means nothing outside our database.

Google servers, outside Kazakhstan

The WhatsApp gateway — delivering the sign-in code

Goes out: your phone number and the text of one message — “AruGo: confirmation code 1234. Do not tell it to anyone”.

Does not go out: your name, your orders, your location, your trip history — nothing but the number and the code. The gateway is used only for sending and reads none of your data from us.

The message itself is delivered by WhatsApp’s infrastructure, like any other message in that messenger. We chose WhatsApp over SMS because everyone in the village has it and sending does not cost money per registration.

The phone number and the code only

OpenStreetMap — the map picture

When you look at the map in the app, map tiles are loaded by your phone directly from the servers of the OpenStreetMap project. That server becomes aware of your phone’s IP address and roughly which part of the map you opened.

Your order point is not sent there — the map does not know where you placed the pin or where you are heading. Our server takes no part in that exchange at all.

IP address and the map area

External navigators — at the driver’s tap

We have no navigator of our own. When a driver taps “Build the route”, the address is handed to whichever maps app he chose himself — 2GIS, Yandex Navigator or the phone’s system maps. From there the privacy policy of that app applies, not ours.

Only on an action by the driver

The fourth party is the Kazakhstani hosting provider whose hardware our server runs on. It supplies the machine and has no access to the contents of the database in the course of ordinary operation. The data does not leave the territory of Kazakhstan.

Apart from the above, data may be passed to state authorities of the Republic of Kazakhstan upon an official request made in accordance with the law. There are no other recipients.

6. What the passenger and the driver see about each other

The point of the product is that the whole village does not learn about your trip. The visibility line is therefore drawn firmly:

  • While the order is looking for a car, drivers see the route and the amount. Your contact details are not shown to them.
  • Once a driver has accepted the order, you see his name, phone number, plate number, and the colour and model of the car. That is needed in order to recognise the car at the gate and to call if he cannot find the right house.
  • The driver sees the pickup point, your note about the address and the destination — the things without which he cannot arrive.
  • The other villagers see nothing at all. Your trip is not visible to drivers who did not take it: the order simply disappears from their screen.
  • There is no chat inside the app — which means there is no correspondence for us to store or read.

It is important not to overstate the privacy: this is not anonymity. The driver will recognise you anyway — the village is small. The value is that the trip stops being a public announcement to three hundred people in a group chat.

7. Quiet two-way blocks

After a trip both the passenger and the driver may mark: “do not deal with this person again”. The system stops bringing that pair together in orders.

The other side never finds out. No notification reaches them, they do not see it in the app, they are given no reason for the absence of orders, and they can learn neither the fact of the block nor who placed it. The information is shown on no screen of the app — neither to the passenger nor to the driver.

This is deliberate: in a village a conflict made public costs more than the conflict itself. We do not even ask for the reason for a block — it is a one-tap action, not a form with an explanation.

What we do with this information internally: blocks are visible to platform staff in de-identified form, as a counter. If many passengers stop riding with one driver, that raises a flag for a human to check. There is no automatic removal from the line based on that counter — the decision is taken by a person. The list of who blocked whom is not exported, not published and not disclosed to any user.

8. How long data is kept

Periods after which data is deleted automatically
WhatPeriod
Profile, phone number, driver profilewhile the account exists
Orders and the log of how they were carried out3 years
Complaints and the outcome of handling them3 years
Technical telemetry from the app12 months
IP address of a sign-in code request30 days
Confirmation code (hash)5 minutes
Points outside the service area90 days
De-identified aggregates by village and dayindefinitely

The three-year period for orders and complaints is not arbitrary: it follows the general limitation period, during which a trip log may be needed as evidence in a dispute.

De-identified aggregates are totals such as “in such-and-such village on such-and-such day there were this many orders”. By construction they contain no personal data, so they are not deleted.

9. Your rights, including account deletion

Access

You have the right to know what data of yours we hold. Some of it is visible right in the app: your profile, the list of your orders with prices and dates, and a driver’s car profile. A full export can be requested by mail — we will answer within 15 calendar days.

Correction

The name, the interface language and the car data are changed in the app by you, at any time. Changing the phone number means a new sign-in — write to us if the history needs to be carried over.

Deleting the account

The account can be deleted right in the app — in settings, with no letter, no phone call and no explanation of the reason. No separate permission from us is required.

If the app is unavailable for some reason, write from the number linked to the account to berkenov.post@gmail.com — we will delete the account within 30 days and confirm it by reply.

What happens on deletion, honestly:

  • Deleted irreversibly: phone number, name, linked devices and push tokens, a driver’s car data and car photo, and your quiet blocks.
  • Remains in de-identified form: the records of completed orders and the log of how they were carried out. There is no longer a person behind them — the reference points to an identifier that has neither a number nor a name. This is necessary because a trip has a second party: the driver has the right to keep proof of work done, and the platform the ability to handle a complaint about that same trip. Once the retention period ends these records are deleted along with all the others.
  • A deleted account cannot be brought back. A new sign-in with the same number creates a new, empty account with no history.

Withdrawal of consent

You give consent to the processing of your data by ticking the box before you request the code — before we send you the first message. It can be withdrawn at any time — withdrawing consent is equivalent to deleting the account, because without a phone number the service technically cannot work.

Objection and complaint

If you believe your data has been processed incorrectly, write to us first — almost everything is settled by a reply within a day. If our answer does not satisfy you, you have the right to apply to the authorised body for the protection of personal data of the Republic of Kazakhstan, or to a court.

10. How the data is protected

  • All traffic between the app and the server goes over HTTPS with an automatically renewed certificate.
  • The confirmation code is not stored in the clear — only an irreversible hash that lives for five minutes.
  • The number of sign-in attempts is limited both by number and by IP address: guessing the code runs into the limit.
  • In service logs the phone number is written masked, not in full.
  • EXIF metadata is stripped from every uploaded car photo on the server — even if the app has already removed it.
  • In the platform staff panel the passenger’s number is shown masked; the full number is available only where an enquiry cannot be handled without it.
  • Every action by a member of platform staff — a block, a change of fare, the handling of a complaint — is written to a log that is not deleted.
  • Backups are made daily and are kept within the territory of Kazakhstan.

Absolute protection does not exist, and promising it would be dishonest. If a leak occurs that affects your data, we will inform users and the authorised body.

11. The age of users

The app is not addressed to children and contains nothing intended for them. We do not verify age: the only identifier is a phone number, and we ask for no documents.

If it turns out that an account is used by a child under 16 without the consent of a legal representative, write to us — we will delete the account and the data associated with it.

12. Changes to this policy

The service changes, and the policy will change with it. We will not amend it retroactively and pretend it was always so: every edition has a date and a version number, shown at the start of the document.

If a change affects the set of data collected or the range of those it is passed to, we will say so in the app before the change takes effect.

13. Contacts and complaints

On any question about this data — access, correction, deletion, a complaint:

berkenov.post@gmail.com

We answer within 1–2 working days. For deletion and data export requests — no later than 15 calendar days.

Related documents: Terms of use and Support.