UBASE Privacy Policy
Version: v1 Last updated: July 28, 2026
1. General provisions
1.1. This Policy explains what personal data UBASE LLC (hereinafter — the “Platform”, “UBASE”) processes in the UBASE app, why, and how we protect it.
1.2. Processing is carried out under the Law of the Republic of Uzbekistan “On Personal Data” (ZRU-547).
1.3. Consent to the processing of personal data is given separately from acceptance of the offer — as a separate mark at registration.
1.4. The terms “Customer”, “Master”, “Order”, “Checklist” are used with the same meaning as in the UBASE offers.
2. What data we collect
2.1. Customer data
| Data | Purpose | Basis | |---|---|---| | Phone number | Login (via a one-time code), communication | Offer agreement | | Full name | Identification | Offer agreement | | Email (if provided) | Communication | Consent | | Date of birth | Age check (18+) | Legal requirement | | Profile photo (if added) | Display | Consent | | Order address (and details: entrance, floor, apartment, intercom, landmark) | Order fulfilment | Service performance | | Location — when creating an order | Finding the nearest Masters | Consent | | Order photos (if added) | Describing the problem | Consent | | Order history | Service operation | Offer agreement | | Ratings and reviews | Quality control | Offer agreement | | Device technical identifier (for notifications) | Notifications | Consent |
The Customer does not enter payment details in the app — payment for the work is made directly to the Master (see the customer offer).
2.2. Master data
In addition to data similar to the Customer’s (phone, communication, profile photo, history, ratings):
| Data | Purpose | Basis | |---|---|---| | Full name, date of birth, PINFL, passport series and number, registration address — via MyID | Identification and identity verification | Legal requirement | | Location — during the shift | Assigning the nearest orders; on an active order — tracking and arrival estimate, passed to the Customer | Offer agreement | | Payment details (card token, last 4 digits) | Purchasing packages and refunding a package balance | Offer agreement | | Package and operation data (purchases, deductions, balance) | Accounting for UBASE services | Offer agreement | | TIN (if the Master is an individual entrepreneur, at their discretion) | Tax accounting | Consent |
UBASE does not store biometrics. Face recognition and passport verification are performed by the state MyID system; we store only text data (full name, passport, PINFL, address).
3. How we use the data
3.1. Service operation: finding the nearest Master, order statuses, the Checklist, tracking and arrival estimates, package purchases by the Master and refunds of the balance.
3.2. Security: identity verification via MyID, fraud protection, a registry of restrictions (blocks for fraud and persistent rule violations; registry data is kept for 3 years; inclusion can be appealed through support).
3.3. Service improvement: analysis of popular categories, optimization of order assignment.
3.4. Communication: in-app notifications, an SMS with a login code, in-app chat and calls between the Customer and the Master.
4. Location
4.1. Customer. Location is requested when creating an order — to determine the address and find the nearest Masters, and is passed to the assigned Master for the duration of the order. Outside placing an order, the Customer’s location is not tracked (not 24/7).
4.2. Master. In the “I’m on shift” mode, coordinates are updated to assign the nearest orders; on an active order, tracking speeds up for the arrival estimate and is passed to the Customer. Shift coordinates are stored for up to 90 days, then deleted. When the shift ends, coordinate updates stop. Outside a shift and orders, the Master’s location is not tracked (not 24/7).
5. Whom we share data with
5.1. Between the order parties
The Customer sees the Master’s name, photo, and rating, and the Master’s tracking during the order. The Master sees the Customer’s name and address — only during the order. The parties’ phone numbers are not shared with each other — they are masked, and communication goes through in-app chat and calls.
5.2. Third parties
| Recipient | Data | Purpose | |---|---|---| | MyID | The Master’s passport data | Identity confirmation | | Uzum, Payme, Click | Card token, amount (Master) | Package payments | | Agora | Communication session identifier | In-app voice calls | | Cloudflare | Photos and media files | Cloud storage | | Eskiz, Playmobile | Phone number | SMS with a login code | | Firebase (Google) | Device technical identifier, anonymized events | Notifications and analytics (section 8) | | Sentry | Anonymized technical error data | Fault diagnostics | | State bodies | Upon request of a court / law-enforcement bodies | Legal requirement |
5.3. We do not sell personal data to third parties.
5.4. The map and address suggestions run on our own servers in Uzbekistan — for this, geodata does not leave the country. Face-recognition data (identity verification) is not transferred outside Uzbekistan.
5.5. Some technical services are located outside the Republic of Uzbekistan: Firebase (Google, USA) — notifications and anonymized analytics; Cloudflare (USA) — file storage; Agora (Singapore) — voice calls. Such transfer is permitted by law: confidentiality agreements are in place with the services, only the necessary minimum is transferred, and the data is protected in transit.
6. Storage and protection
6.1. Retention periods
| Data | Period | |---|---| | Incomplete registration (no account created) | 30 days from the last step | | Account data | While the account exists (+ 1 year) | | Financial data and orders | At least 5 years (tax requirement) | | Master shift coordinates | 90 days | | Chat messages (after the order is archived) | 30 days | | Notifications | 6 months | | Login logs | 6 months | | Registry of restrictions | 3 years |
If registration was not completed and no account was created, everything already entered — including the data received from MyID (full name, date of birth, PINFL, passport, address) — is deleted 30 days after the last registration step. Returning to an incomplete registration extends this period.
6.2. Protection measures
- Encryption of data in transit over the network.
- Payment data — only a protected card token via a certified provider; the Platform does not store the full card number.
- Masking of phones and personal data when shown to the other party and in technical logs.
- Separation of database access rights, backups.
- Core data — on servers in Uzbekistan; face-recognition data is not transferred outside the country and is not stored.
7. User rights
7.1. The user is entitled to: obtain information about their data; correct inaccurate data; delete the account and data; withdraw consent to processing.
7.2. Account deletion. The request is confirmed by a code; it can be cancelled within 14 days. After that, personal data is anonymized (phone, full name, passport, and other personal data are deleted), while financial records are kept in an anonymized form for the period required by tax law.
7.3. Requests regarding data — through customer support (section 13) or the authorized state body.
8. Analytics
8.1. The app uses Firebase Analytics (Google) and Sentry to understand how the service works and to diagnose faults. Anonymized events are collected: screen views, order-placement steps, in-app actions, the user’s role. The exact address, coordinates, and phone number are not sent to analytics. There are no third-party advertising trackers.
9. Children
9.1. Registration is only from 18 years of age; age is checked at registration. We do not knowingly collect data of minors.
10. Automated decisions
10.1. The Master’s rating and the measures based on it (a warning, a restriction of access) are formed automatically under the Platform’s rules. The Master can see their rating and the rules in the app, receives notifications, and is entitled to file an appeal — disputed cases are reviewed by moderation. The internal parameters of the calculation are not disclosed to the Master.
11. Changes to the Policy
11.1. The Platform is entitled to update the Policy, notifying users through the app. The current version is always available in the app.
12. Security incident notification
12.1. In an incident affecting personal data, the Platform takes remedial measures and notifies affected users and the authorized body in the manner provided by law.
13. Contacts
UBASE LLC
Republic of Uzbekistan, Tashkent
Email: [email protected]
Phone: +998 55 501 02 02
14. Legal basis
- Law “On Personal Data” of 02.07.2019 No. ZRU-547 (as amended on 26.03.2026);
- Civil Code of the Republic of Uzbekistan;
- Tax Code of the Republic of Uzbekistan (retention periods for financial records).