Privacy Policy of the Qayda app
Revision of 1 September 2026
1. Who processes the data
The personal data operator is Individual Entrepreneur Vendo (hereinafter — “we”). We develop and maintain the Qayda mobile app for iOS and Android (hereinafter — the “App”) and the qayda.vendo.kz website.
This Policy explains what data we receive from users of the App, why, who we share it with and how it can be managed. Processing is carried out in accordance with the Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V “On Personal Data and Its Protection”.
By using the App you confirm that you have read this Policy. If you do not agree with it, do not use the App.
2. What data we collect
We collect the minimum required for the App to work.
2.1. Account data
- mobile phone number — the only way to sign in: the one-time code is sent to it;
- name — if you have provided one yourself;
- city — determines which city’s venues are shown to you.
2.2. Device data
- device identifier — a random number that the App generates itself on first sign-in and stores in the device’s secure storage. It is not linked to advertising identifiers and does not allow you to be recognised in other apps; it is needed only so that you can tell your active sessions apart;
- device model and platform (for example, “iPhone 15 Pro”, “Android”) — so that a session is recognisable in the list;
- App version and operating system version — for error diagnostics.
2.3. Usage data
- history of activated discounts: venue, discount amount, date and time of activation;
- sign-in session details: time of sign-in, device.
2.4. Technical data
When the App contacts our servers, the logs automatically record the IP address, the date and time of the request, the request type and the response code. The logs are used to protect against abuse and to restore the service’s operation.
3. What data we do NOT collect
| Data | Explanation |
|---|---|
| Location | The App does not request access to your location and does not track your movements. You choose the city yourself |
| Photos and video | Camera access is used only to recognise the QR code at the moment of scanning. The image is processed on the device in real time; frames are not stored and are not transmitted anywhere. The App does not request access to your photo library |
| Payment data | No payments are made inside the App. We do not receive card or account details: you pay the venue directly at the table |
| Advertising identifiers | IDFA (iOS) and the Google advertising identifier are not used |
| Contacts, calendar, microphone, files | The App does not request access to them |
| Special categories of data | We do not collect information about health, origin, beliefs, or biometrics |
We do not track your activity in other apps and on websites and do not share data with ad networks and data brokers. No third-party analytics or advertising SDKs are used in the App. Should this ever change, we will update this Policy and request consent before such processing begins.
4. Why we process data
| Purpose | Which data | Legal basis |
|---|---|---|
| Signing in to the App and confirming that the number belongs to you | Phone number, one-time code | Performance of the contract with you (the terms of use) |
| Showing venues and discounts in your city | City | Performance of the contract |
| Activating a discount via QR code and confirming it to the venue | Activation history, venue identifier | Performance of the contract |
| Showing you the list of active sessions and letting you end them | Identifier, device model | Performance of the contract; your security |
| Protection against code guessing, QR reuse and other abuse | Technical logs, activation history | Legitimate interest — security of the service |
| Replying to your enquiries | The data you provided in the enquiry | Your request |
| Improving the App and fixing errors | De-identified technical crash information | Legitimate interest — operability of the service |
We do not take decisions concerning you that are based solely on automated processing and produce legal consequences.
5. Who we share data with
We do not sell personal data and do not share it with third parties for their own marketing purposes. Sharing is possible only to the extent necessary for the service to work:
- The message delivery provider. Your phone number is passed to the service that delivers the one-time code in WhatsApp. The provider processes the number only to deliver the message.
- The partner venue. At the moment a discount is activated, the venue receives confirmation of the activation and its parameters: venue, discount amount, date and time. Your phone number is not passed to the venue.
- Infrastructure providers. Server and database hosting. They act on our instructions, under contract, and may not use the data for their own purposes.
- Apple and Google. As the App’s distribution platforms they receive information about installations and, if you have enabled it in your device settings, de-identified crash reports. This data is processed under Apple’s and Google’s own policies.
- Government authorities — only upon a justified request, in the manner and to the extent provided for by the legislation of the Republic of Kazakhstan.
6. Where data is stored
Data is stored on the secure servers of our infrastructure providers, who act on our instructions and under contract. If, for the operation of individual services, data is transferred outside the Republic of Kazakhstan, such transfer is carried out only to countries that ensure the protection of personal data and in compliance with the requirements of Article 16 of Law No. 94-V.
7. How long we keep data
- Account data and activation history — for as long as your account exists.
- After an account deletion request — the data is deleted or de-identified within 30 calendar days. Only what we are required to keep by law (for example, records of settlements with partner venues) is retained longer — in a de-identified or minimally necessary form.
- Technical server logs — no more than 12 months.
- One-time confirmation codes — a few minutes, until they expire.
8. How we protect data
- All exchange between the App and the servers goes over the secure HTTPS/TLS protocol.
- Access tokens are stored on the device in the system secure storage: Keychain on iOS and Keystore on Android, not in ordinary app files.
- The session refresh token is single-use: on refresh it is replaced with a new one, and an attempt to reuse an old one is treated as a compromise and ends all sessions of the account.
- Employee access to data is restricted and granted only to the extent necessary to perform their duties.
No system is absolutely secure, but we take the legal, organisational and technical measures provided for by the legislation of the Republic of Kazakhstan.
9. Your rights
You have the right to:
- obtain information about what data of yours we process;
- demand that inaccurate data be corrected or supplemented;
- withdraw consent to processing;
- demand that data be blocked or deleted if it is processed in breach of the law or is excessive;
- delete your account together with the associated data;
- appeal our actions to the authorised personal data protection body of the Republic of Kazakhstan.
To exercise any of these rights, write to izzatilla.sapayev@gmail.com from the phone number or address associated with the account, or submit a request on the Account deletion page. We reply within no more than 30 calendar days. We may ask you to confirm that the request comes from the account owner — this protects you from your account being deleted by outsiders.
10. How to delete your account
You can delete your account and the data associated with it at any time:
- via the qayda.vendo.kz/en/account/delete page;
- or by writing to izzatilla.sapayev@gmail.com with the subject “Account deletion”.
After deletion it will be impossible to restore the history of activated discounts. Signing in again with the same number will create a new, empty account.
11. Children
The App is not intended for persons under 16, and we do not knowingly collect their data. If you become aware that a child has provided us with their data, write to izzatilla.sapayev@gmail.com — we will delete it.
12. The website
The pages of the qayda.vendo.kz website do not use cookies to track visitors, nor counters or advertising pixels. The web server keeps standard technical request logs (see clause 2.4).
13. Changes to the Policy
We may update this Policy: for example, when new App features appear. The current revision is always available at qayda.vendo.kz/privacy, and the revision date is stated at the beginning of the document. We will announce material changes in the App before they take effect. Continued use of the App after the changes take effect means agreement with the new revision.
14. Contacts
For any questions about the processing of personal data:
Individual Entrepreneur Vendo
Email: izzatilla.sapayev@gmail.com