UBASE Privacy Policy
Version: v1 Last updated: August 7, 2026
1. General provisions
1.1. This Policy explains what personal data UBASE LLC (hereinafter — the “Platform”, “UBASE”) processes in the UBASE app, why, and how we protect it.
1.2. Processing is carried out under the Law of the Republic of Uzbekistan “On Personal Data” (ZRU-547).
1.3. Consent to the processing of personal data is given separately from acceptance of the offer — as a separate mark at registration.
1.4. The terms “Customer”, “Master”, “Order”, “Checklist” are used with the same meaning as in the UBASE offers.
2. What data we collect
2.1. Customer data
| Data | Purpose | Basis |
|---|---|---|
| Phone number | Login (via a one-time code), communication | Offer agreement |
| Full name | Identification | Offer agreement |
| Email (if provided) | Communication | Consent |
| Date of birth | Age check (18+) | Legal requirement |
| Profile photo (if added) | Display | Consent |
| Order address (and details: entrance, floor, apartment, intercom, landmark) | Order fulfilment | Service performance |
| Location — when creating an order | Finding the nearest Masters | Consent |
| Order photos (if added) | Describing the problem | Consent |
| Order history | Service operation | Offer agreement |
| Ratings and reviews | Quality control | Offer agreement |
| Device technical identifier (for notifications) | Notifications | Consent |
The Customer does not enter payment details in the app — payment for the work is made directly to the Master (see the customer offer).
2.2. Master data
In addition to data similar to the Customer’s (phone, communication, profile photo, history, ratings):
| Data | Purpose | Basis |
|---|---|---|
| Full name, date of birth, PINFL, passport series and number, registration address — via MyID | Identification and identity verification | Legal requirement |
| Location — during the shift | Assigning the nearest orders; on an active order — tracking and arrival estimate, passed to the Customer | Offer agreement |
| Payment details (card token, last 4 digits) | Purchasing packages and refunding a package balance | Offer agreement |
| Package and operation data (purchases, deductions, balance) | Accounting for UBASE services | Offer agreement |
UBASE does not store biometrics. Face recognition and passport verification are performed by the state MyID system; we store only text data (full name, date of birth, passport, PINFL, address).
3. How we use the data
3.1. Service operation: finding the nearest Master, order statuses, the Checklist, tracking and arrival estimates, package purchases by the Master and refunds of the balance.
3.2. Security: identity verification via MyID, fraud protection, a registry of restrictions (blocks for fraud and persistent rule violations; no automatic cleanup period is currently implemented and a separate operational decision is required; inclusion can be appealed through support).
3.3. Service improvement: analysis of popular categories, optimization of order assignment.
3.4. Communication: in-app notifications, an SMS with a login code, in-app chat and calls between the Customer and the Master.
4. Location
4.1. Customer. Location is requested when creating an order — to determine the address and find the nearest Masters, and is passed to the assigned Master for the duration of the order. Outside placing an order, the Customer’s location is not tracked (not 24/7).
4.2. Master. In the “I’m on shift” mode, coordinates are updated to assign the nearest orders; on an active order, tracking speeds up for the arrival estimate and is passed to the Customer. Shift coordinates are stored for up to 90 days, then deleted. When the shift ends, coordinate updates stop. Outside a shift and orders, the Master’s location is not tracked (not 24/7).
5. Whom we share data with
5.1. Between the order parties
The Customer sees the Master’s name, photo, and rating, and the Master’s tracking during the order. The Master sees the Customer’s name and address — only during the order. The parties’ phone numbers are not shared with each other — they are masked, and communication goes through in-app chat and calls.
5.2. Third parties
| Recipient | Data | Purpose |
|---|---|---|
| MyID | Phone number and PINFL for the session; full name, PINFL, passport data, date of birth and address from the verification result | Identity confirmation |
| Uzum, Payme, Click | Checkout/payment identifiers, amount, order/cart and fiscal data; token and last four digits where returned | Package payments |
| Agora | Real-time call audio and channel/session technical data; UBASE does not record calls | In-app voice calls |
| Cloudflare | Photos and media files | Cloud storage |
| Eskiz, Playmobile | Phone number and the one-time SMS message text | SMS with a login code |
| Firebase (Google) | Device token; notification/call payload (name, ID/role, channel and Agora fields); analytics events with order/category IDs and role | Notifications, calls and analytics |
| Sentry | Errors, performance, device information and a pseudonymous user ID with role | Fault diagnostics |
| State bodies | Upon request of a court / law-enforcement bodies | Legal requirement |
5.3. We do not sell personal data to third parties.
5.4. The map and address suggestions run on our own servers in Uzbekistan — for this, geodata does not leave the country. MyID processes the face and document; the processing country and retention period are determined by MyID’s official terms and its agreement with UBASE.
5.5. Some external services may process data outside the Republic of Uzbekistan: MyID, Firebase, Sentry, Cloudflare, Agora, payment and SMS providers. The specific country, recipient role, retention period and legal basis are determined by the current terms of the relevant service and its agreement with UBASE. Only the minimum needed for the function is transferred, over protected connections.
6. Storage and protection
6.1. Retention periods
| Data | Period |
|---|---|
| Incomplete registration (no account created) | 30 days from the last step |
| Account data | Until deletion is confirmed; anonymized after the 14-day cancellation window |
| Financial data and orders | At least 5 years (tax requirement); automatic deletion of archived orders is not currently implemented |
| Master shift coordinates | 90 days |
| Chat messages (after the order is archived) | 30 days |
| Support requests and support messages | While needed to handle the request and related obligations; no separate fixed cleanup period is currently implemented |
| Notifications | 6 months |
| Authentication and OTP logs | No fixed cleanup period is currently implemented; the period must be confirmed by operational evidence |
| Registry of restrictions | No fixed cleanup period is currently implemented; the period requires operational and legal confirmation |
If registration was not completed and no account was created, everything already entered — including the data received from MyID (full name, date of birth, PINFL, passport, address) — is deleted 30 days after the last registration step. Returning to an incomplete registration extends this period.
6.2. Protection measures
- Encryption of data in transit over the network.
- Payment data — only a protected card token via a certified provider; the Platform does not store the full card number.
- Masking of phones and personal data when shown to the other party and in technical logs.
- Separation of database access rights. Backups are provided for by internal procedures and scripts; activation and the latest successful restore test must be confirmed by a separate operational record, so this edition does not claim that restore has been verified.
- Core UBASE data is on servers in Uzbekistan; MyID and other external processing is governed by their current terms and the agreement with UBASE. UBASE does not store biometric materials in its own database.
7. User rights
7.1. The user is entitled to: obtain information about their data; correct inaccurate data; delete the account and data; withdraw consent to processing.
7.2. Account deletion. The request is confirmed by a code; it can be cancelled within 14 days. After that, personal data is anonymized (phone, full name, passport, and other personal data are deleted), while financial records are kept in an anonymized form for the period required by tax law.
7.3. Requests regarding data — through customer support (section 13) or the authorized state body.
8. Analytics
8.1. The app uses Firebase Analytics (Google) and Sentry to understand how the service works and to diagnose faults. Firebase Analytics receives screen and action events, including order/category IDs and the user’s role; Sentry receives technical data and a pseudonymous user ID with role. The exact address, coordinates, and phone number are not sent in these events. There are no third-party advertising trackers.
9. Children
9.1. Registration is only from 18 years of age; age is checked at registration. We do not knowingly collect data of minors.
10. Automated decisions
10.1. The Master’s rating and the measures based on it (a warning, a restriction of access) are formed automatically under the Platform’s rules. The Master can see their rating and the rules in the app, receives notifications, and is entitled to file an appeal — disputed cases are reviewed by moderation. The internal parameters of the calculation are not disclosed to the Master.
11. Changes to the Policy
11.1. The Platform is entitled to update the Policy, notifying users through the app. The current version is always available in the app.
12. Security incident notification
12.1. In an incident affecting personal data, the Platform takes remedial measures and notifies affected users and the authorized body in the manner provided by law.
13. Contacts
UBASE LLC
Republic of Uzbekistan, Tashkent
Email: support@ubase.uz
Phone: +998 55 501 02 02
14. Legal basis
- Law “On Personal Data” of 02.07.2019 No. ZRU-547 (as amended on 26.03.2026);
- Civil Code of the Republic of Uzbekistan;
- Tax Code of the Republic of Uzbekistan (retention periods for financial records).