1. Who processes the data
The operator of personal data is the owner of the AruGo service — an app for calling a taxi in the villages of Kazakhstan and the site arun.kz. The operator can be reached on any question about this data at berkenov.post@gmail.com.
Processing begins at the moment you enter your phone number when signing in to the app. Before that moment the app sends nothing about you to the server.
2. What data we collect and why
The list is complete. Every line below corresponds to a specific place in our database — if something is not in this list, it is not in the database either.
For all users
Phone number
The only identifier of a person in the system. We ask passengers and drivers for no passwords, no email address, no forms and no documents — the account exists precisely as a number.
Why: signing in to the app, connecting driver and passenger for a particular trip, and handling complaints.
The name you signed with
An optional field. It is there so that the driver at the gate knows who he is picking up, and the passenger sees who is at the wheel.
Interface language
Russian, Kazakh or English. It determines the language of notifications and of the sign-in code message.
The confirmation code used at sign-in
We do not store the code itself — the database holds only an irreversible hash of it, with a five-minute lifetime, an attempt counter and the IP address the code was requested from. The IP is there for exactly one purpose: to stop code guessing when somebody is trying to get into another person’s account.
Device data for notifications
The push notification token, the platform (Android or iOS), the app version and the phone’s language settings. Without a token the phone cannot be woken when an order arrives.
One person may have several devices — a driver often has two phones, and both must ring.
When an order is created
Location at the moment the order is created
The app takes your current point once — when you place the order. From it the nearest connected village is determined, the price is calculated from that village’s fare, and the driver knows where to come.
There is no background tracking of movement. The app does not record your route, does not collect coordinates between orders and keeps no history of your movements outside orders. The pickup point and the destination exist only as part of a particular order.
The landmark and the note in words
“Hospital”, “School No. 1”, and your own addition such as “the green gate” or “opposite the pharmacy”. This is how directions are actually given in a village, and it saves a phone call.
The order log
The order number, its status, the time of every step, the calculated price, the assigned driver, the fact of a cancellation and who made it. Separately, the offer log: which drivers the order was shown to, who accepted, who declined, who stayed silent.
Why: without this log it is impossible to resolve a dispute over “no order reached me” or “the driver did not come” — nothing would be left but two accounts contradicting each other.
Points where the service does not operate
If there is no connected village near you, we record the fact of the failed attempt so that we know which village to connect next. The coordinates are coarsened at the moment of writing to roughly a kilometre and are tied neither to your number nor to your account. An exact point never exists in that table at any stage.
Additionally for drivers
The car’s plate number
Stored in two forms: as you typed it, and in a normalised form — so that “123 АВС” in Cyrillic and “123 ABC” in Latin count as one car and not two.
Why: the passenger has to recognise the car at the gate. It is also the only thread to pull on when a complaint is examined.
The colour, make, model and year of the car
So that the driver card can be read at seven in the morning in winter.
A photo of the car
Optional — declining it restricts nothing. A photo of the driver, that is of the person, we neither ask for nor store at all.
An uploaded picture is re-compressed on the server, and in doing so the EXIF metadata is forcibly stripped. EXIF contains the GPS coordinates of where the photo was taken — as a rule, the driver’s own yard. We do not want a person’s home address travelling along with the picture.
Shift and queue
Whether the driver is on the line or not, when he went on, his place in the village queue, the time of the last connection signal, and counters of missed orders.
Why: the queue is the core of the product. Without these fields there is nobody to hand an order to in turn.
The history of profile changes
If a driver changed the plate number or the make of the car, the old value is kept. This protects the passenger: in the middle of a dispute the car cannot “become a different one”.
Complaints and technical telemetry
The text of a complaint
What you wrote, about whom and against which order. It is read only by the platform staff who handle enquiries.
Three technical events from the app
The app reports to us exactly three things the server cannot learn by itself: after how many milliseconds the order card actually appeared on the driver’s screen, which system permissions have been granted to the app (location, notifications, background work, battery saving) and the fact that an order form was abandoned before reaching confirmation.
Why: the first shows whether orders arrive within seconds or whether we are lying to ourselves. The second explains why a particular driver on the line is not getting orders. The third shows at which step people give up on a trip.
The platform event log
The technical stream from which the service metrics are calculated. By a rule built into the database schema itself, it contains no personal data — only internal identifiers (order number, user number, village number). Neither a phone number, nor a name, nor a plate, nor coordinates, nor the text of an address note ever reaches this log.
3. What we refuse to collect on principle
This list is every bit as binding as the previous one. We do not collect:
- Location outside an order. No background tracking, no movement history.
- The advertising identifier, the phone model, the mobile operator. Personal data without a single question that it would answer.
- Screen views, button taps, scrolls, time spent in the app. These are not product metrics but surveillance of behaviour.
- The contact list, the photo gallery, the microphone, the calendar. The app does not request these permissions.
- Payment data. No cards, no saved cards, no accounts: payment goes straight to the driver, bypassing the platform (see the Terms of use). We simply have no means to charge you.
- Drivers’ documents — licence, registration certificate, insurance. We do not check them and do not store them; an “upload later” field would create the false impression of a check.
- A photograph of a driver’s or a passenger’s face.
- Registered address, individual identification number, date of birth, marital status and other questionnaire data.
We do not sell data, do not pass it to ad networks, data brokers or credit bureaux, and do not use it for profiling or targeting.
4. Where the data is stored
The database is on a server within the territory of the Republic of Kazakhstan. This is a requirement of Article 12 of the Law of the Republic of Kazakhstan “On Personal Data and Its Protection”: the personal data of citizens of Kazakhstan must be stored in a database physically located in the Republic.
Database backups are the same personal data, so they too remain within the territory of Kazakhstan and are not exported to external clouds outside the country.
For the same reason the service does not use external cloud analytics platforms (Google Analytics, Amplitude, Mixpanel and the like): all of them take data outside Kazakhstan. Our analytics are our own and sit in the same database as the orders.
5. Who the data is passed to
There are exactly four third parties, and each receives a strictly defined minimum. Below we state not only what goes out but also what does not.
Google Firebase Cloud Messaging — delivering notifications
Goes out: your device’s push token, the short text of the notification (“New order”, “A car has been found”, “The driver is here”) and service fields — the internal order number, the event name and the deadline until which the offer is valid.
Does not go out: phone number, name, pickup address, destination address, coordinates, trip price, car plate number.
This is deliberate: the job of a push is to wake the app, not to deliver the contents of the order. The app fetches the contents itself from our server in Kazakhstan in a separate request. That is why the internal order number sent to Firebase means nothing outside our database.
The WhatsApp gateway — delivering the sign-in code
Goes out: your phone number and the text of one message — “AruGo: confirmation code 1234. Do not tell it to anyone”.
Does not go out: your name, your orders, your location, your trip history — nothing but the number and the code. The gateway is used only for sending and reads none of your data from us.
The message itself is delivered by WhatsApp’s infrastructure, like any other message in that messenger. We chose WhatsApp over SMS because everyone in the village has it and sending does not cost money per registration.
OpenStreetMap — the map picture
When you look at the map in the app, map tiles are loaded by your phone directly from the servers of the OpenStreetMap project. That server becomes aware of your phone’s IP address and roughly which part of the map you opened.
Your order point is not sent there — the map does not know where you placed the pin or where you are heading. Our server takes no part in that exchange at all.
External navigators — at the driver’s tap
We have no navigator of our own. When a driver taps “Build the route”, the address is handed to whichever maps app he chose himself — 2GIS, Yandex Navigator or the phone’s system maps. From there the privacy policy of that app applies, not ours.
The fourth party is the Kazakhstani hosting provider whose hardware our server runs on. It supplies the machine and has no access to the contents of the database in the course of ordinary operation. The data does not leave the territory of Kazakhstan.
Apart from the above, data may be passed to state authorities of the Republic of Kazakhstan upon an official request made in accordance with the law. There are no other recipients.
6. What the passenger and the driver see about each other
The point of the product is that the whole village does not learn about your trip. The visibility line is therefore drawn firmly:
- While the order is looking for a car, drivers see the route and the amount. Your contact details are not shown to them.
- Once a driver has accepted the order, you see his name, phone number, plate number, and the colour and model of the car. That is needed in order to recognise the car at the gate and to call if he cannot find the right house.
- The driver sees the pickup point, your note about the address and the destination — the things without which he cannot arrive.
- The other villagers see nothing at all. Your trip is not visible to drivers who did not take it: the order simply disappears from their screen.
- There is no chat inside the app — which means there is no correspondence for us to store or read.
It is important not to overstate the privacy: this is not anonymity. The driver will recognise you anyway — the village is small. The value is that the trip stops being a public announcement to three hundred people in a group chat.
7. Quiet two-way blocks
After a trip both the passenger and the driver may mark: “do not deal with this person again”. The system stops bringing that pair together in orders.
The other side never finds out. No notification reaches them, they do not see it in the app, they are given no reason for the absence of orders, and they can learn neither the fact of the block nor who placed it. The information is shown on no screen of the app — neither to the passenger nor to the driver.
This is deliberate: in a village a conflict made public costs more than the conflict itself. We do not even ask for the reason for a block — it is a one-tap action, not a form with an explanation.
What we do with this information internally: blocks are visible to platform staff in de-identified form, as a counter. If many passengers stop riding with one driver, that raises a flag for a human to check. There is no automatic removal from the line based on that counter — the decision is taken by a person. The list of who blocked whom is not exported, not published and not disclosed to any user.
8. How long data is kept
| What | Period |
|---|---|
| Profile, phone number, driver profile | while the account exists |
| Orders and the log of how they were carried out | 3 years |
| Complaints and the outcome of handling them | 3 years |
| Technical telemetry from the app | 12 months |
| IP address of a sign-in code request | 30 days |
| Confirmation code (hash) | 5 minutes |
| Points outside the service area | 90 days |
| De-identified aggregates by village and day | indefinitely |
The three-year period for orders and complaints is not arbitrary: it follows the general limitation period, during which a trip log may be needed as evidence in a dispute.
De-identified aggregates are totals such as “in such-and-such village on such-and-such day there were this many orders”. By construction they contain no personal data, so they are not deleted.
9. Your rights, including account deletion
Access
You have the right to know what data of yours we hold. Some of it is visible right in the app: your profile, the list of your orders with prices and dates, and a driver’s car profile. A full export can be requested by mail — we will answer within 15 calendar days.
Correction
The name, the interface language and the car data are changed in the app by you, at any time. Changing the phone number means a new sign-in — write to us if the history needs to be carried over.
Deleting the account
The account can be deleted right in the app — in settings, with no letter, no phone call and no explanation of the reason. No separate permission from us is required.
If the app is unavailable for some reason, write from the number linked to the account to berkenov.post@gmail.com — we will delete the account within 30 days and confirm it by reply.
What happens on deletion, honestly:
- Deleted irreversibly: phone number, name, linked devices and push tokens, a driver’s car data and car photo, and your quiet blocks.
- Remains in de-identified form: the records of completed orders and the log of how they were carried out. There is no longer a person behind them — the reference points to an identifier that has neither a number nor a name. This is necessary because a trip has a second party: the driver has the right to keep proof of work done, and the platform the ability to handle a complaint about that same trip. Once the retention period ends these records are deleted along with all the others.
- A deleted account cannot be brought back. A new sign-in with the same number creates a new, empty account with no history.
Withdrawal of consent
You give consent to the processing of your data by ticking the box before you request the code — before we send you the first message. It can be withdrawn at any time — withdrawing consent is equivalent to deleting the account, because without a phone number the service technically cannot work.
Objection and complaint
If you believe your data has been processed incorrectly, write to us first — almost everything is settled by a reply within a day. If our answer does not satisfy you, you have the right to apply to the authorised body for the protection of personal data of the Republic of Kazakhstan, or to a court.
10. How the data is protected
- All traffic between the app and the server goes over HTTPS with an automatically renewed certificate.
- The confirmation code is not stored in the clear — only an irreversible hash that lives for five minutes.
- The number of sign-in attempts is limited both by number and by IP address: guessing the code runs into the limit.
- In service logs the phone number is written masked, not in full.
- EXIF metadata is stripped from every uploaded car photo on the server — even if the app has already removed it.
- In the platform staff panel the passenger’s number is shown masked; the full number is available only where an enquiry cannot be handled without it.
- Every action by a member of platform staff — a block, a change of fare, the handling of a complaint — is written to a log that is not deleted.
- Backups are made daily and are kept within the territory of Kazakhstan.
Absolute protection does not exist, and promising it would be dishonest. If a leak occurs that affects your data, we will inform users and the authorised body.
11. The age of users
The app is not addressed to children and contains nothing intended for them. We do not verify age: the only identifier is a phone number, and we ask for no documents.
If it turns out that an account is used by a child under 16 without the consent of a legal representative, write to us — we will delete the account and the data associated with it.
12. Changes to this policy
The service changes, and the policy will change with it. We will not amend it retroactively and pretend it was always so: every edition has a date and a version number, shown at the start of the document.
If a change affects the set of data collected or the range of those it is passed to, we will say so in the app before the change takes effect.
13. Contacts and complaints
On any question about this data — access, correction, deletion, a complaint:
berkenov.post@gmail.comWe answer within 1–2 working days. For deletion and data export requests — no later than 15 calendar days.
Related documents: Terms of use and Support.