Privacy Policy

The sBook app stores your business's financial records. This document explains clearly what data is collected, why it is needed, who can see it and how you can manage it.

1.General provisions

1.1 This Privacy Policy sets out how Users' personal data is processed within the sBook mobile app (package identifier uz.devares.sbook) and the related server services.

1.2 This document has been prepared in accordance with the Law of the Republic of Uzbekistan "On Personal Data" (ZRU-547, 02.07.2019) and other applicable regulations.

1.3 By registering in the app, you confirm that you have read the terms of this Policy and consent to your personal data being processed in the manner described here.

1.4 This Policy forms an integral part of the Public Offer and the Terms of Use.

2.Data operator

2.1 The operator processing personal data is the administration of the sBook project (hereinafter — "we").

2.2 For any privacy question, request or complaint you may contact us using the contact details in section 17.

3.What data is collected

3.1Data you provide at registration

DataRequiredPurpose
First nameYesPersonalising the Account, showing who entered what within the team
Last nameYesThe same purpose
Phone number (+998…)YesUnique identifier, sign-in by SMS, notifications
Profile picture (avatar)NoOnly if you wish — selected from the gallery and uploaded
Business logoNoOnly if you wish

The app does not use passwords. Each sign-in is confirmed with a 6-digit one-time SMS code sent to your phone number.

3.2Business data you enter into the app

  • Income and expense records — amount, currency (UZS or USD), category, description, date, and who added the record;
  • Debts — amount, currency, name of the debtor or creditor, description, due date, direction ("I Need to Pay the Debt" / "I Need to Collect the Debt"), status;
  • Warehouse — product name, quantity and stock-in/stock-out history;
  • Assignments and comments — title, description, status, comment text and author's name;
  • Notes — the text you write;
  • Categories — the names of the categories you create;
  • Business details — name, logo, list of Members.

3.3Technical data

  • Push notification identifier (FCM token) — used to send notifications to your device. Issued by the Google Firebase service;
  • App type marker — at sign-in the server records that the session was opened from the mobile app;
  • Interface settings — the selected language (Uzbek / Russian / English) and theme (light / dark);
  • Session tokens — access tokens stored on the device so that you do not have to enter a code every time.

3.4Data stored only on your device

The following is never sent to the server and remains solely on your phone:

  • The 4-digit PIN for App Lock;
  • Whether biometric protection is enabled (a "yes/no" flag only);
  • Excel export files — until you share them yourself;
  • The saved card record (only the last 4 digits, the expiry date and the cardholder's name);
  • The app's internal cache: the list of businesses, subscription status, a copy of the profile picture, the onboarding-seen flag and the list of join requests.

3.5Server logs

Like any internet service, our server keeps technical logs. These record the time of the request, the address requested, the response code, the approximate IP address and error details. These logs are used solely to detect faults, prevent attacks and maintain the stability of the service; they are not analysed for marketing purposes or to track user behaviour.

4.What is not collected

Apart from the items listed in section 3, the app does not collect the following data at all — this is confirmed by the app's technical design:

  • Geolocation — your location is never requested or read. The app declares no location permission;
  • Phone contacts — the address book is not accessed;
  • SMS and call history — not read;
  • Camera and microphone — not used. Images are selected from the gallery only;
  • Advertising identifier, IMEI, device "fingerprint" — not read;
  • Analytics and tracking systems — the app contains no third-party analytics, advertising or user-tracking SDK whatsoever (no Google Analytics, Facebook SDK, AppsFlyer, Amplitude or similar);
  • Biometric data — fingerprints and face images are neither read, stored nor transmitted by the app. Verification is performed by the operating system itself, and the app receives only a "confirmed / not confirmed" response;
  • Password — the app has no concept of a password, so none is stored either.
No advertising

sBook does not use your data for advertising purposes, does not sell it and does not transfer it to third parties for commercial purposes.

5.Why data is processed

  • To create your Account and sign you in;
  • To store and display the records you enter and synchronise them across devices;
  • To send notifications about debt due dates, assignments, join requests and payments;
  • To generate analytics and reports for the Business you have selected;
  • To determine subscription status and process payments;
  • To handle support enquiries;
  • To improve the service and resolve technical faults;
  • To comply with statutory requirements.

6.Legal basis and consent

6.1 Personal data is processed on the following grounds:

  • Your consent — given at the time of registration;
  • Performance of a contract — necessary to provide the services under the Public Offer;
  • Legal requirement — in the cases provided for by law.

6.2 You may withdraw your consent at any time. To do so, submit a request to delete your Account (section 11). Once consent is withdrawn, the service is discontinued.

6.3 You may turn off the app's push notifications at any time in your device settings — this does not affect your Account.

7.Payment data

7.1 To pay for a subscription you enter your card number, its expiry date and the phone number linked to the card. This data is transmitted to our server in order to process the payment and is forwarded from there to the Payme payment system; the payment is confirmed with an SMS code. The card number is not stored for longer than is necessary to complete the payment.

7.2 The full card number is not stored on your device. For convenience at your next payment, the app stores only the following:

  • the last 4 digits of the card number;
  • the expiry date (month/year);
  • the cardholder's name (if entered);
  • the card type — UZCARD or HUMO.

7.3 You may delete a saved card record at any time in the app's "Payment Methods" section.

7.4 Payment history (date, amount, plan) is stored on the server — this is necessary for accounting purposes and for handling refund requests.

8.Who data is shared with

We do not sell your data and do not share it for advertising purposes. Data is shared only in the following cases, where this is necessary for the service to operate:

RecipientWhat is sharedPurpose
Google (Firebase Cloud Messaging) The device's push identifier and the notification text Delivering push notifications
Apple (APNs) Push identifier on iOS devices Delivering notifications on iOS
Payme Card and transaction data for the payment Processing the payment
Mobile operator Phone number and SMS code Delivering the sign-in code
Hosting provider All data stored on the server (within the scope of technical storage) Providing the server infrastructure
Competent state authorities To the extent prescribed by law On the basis of a lawful request

8.1 The services listed above have their own privacy policies. Their data processing practices are outside our control.

8.2 If you follow a link in the app or on the website to an external service — to Telegram, Instagram, App Store or Google Play pages — that service operates under its own privacy rules and falls outside our control.

8.3 Cross-border transfer. The infrastructure of certain providers listed above (Google, Apple, the hosting provider) may be located outside the Republic of Uzbekistan. By using the app, you consent to your data being transferred in this way to the extent necessary to provide the service. Such transfers are made solely for the operation of the service and are not used for commercial purposes.

8.4 Website. These legal documents and information about the app are published on sbook.uz. The website does not use advertising cookies that track users.

9.Visibility of data within a team

Important: every Member who joins a Business sees everything

Data inside a Business is fully shared between Members. There are no per-Member restrictions.

9.1 A Member of a Business can view and edit the following: all income and expense records, debts, warehouse, assignments, comments, notes and categories.

9.2 Each record shows who added it (the name), and this is visible to other Members.

9.3 In the list of Members, the Business Owner sees each Member's name and phone number.

9.4 If you send a request to join a Business, the Owner of that Business sees your name and phone number before reviewing the request.

9.5 Only the Owner can delete a Business. When a Business is deleted, all data inside it is lost permanently and cannot be restored.

9.6 Do not give your Business identifier to anyone you do not know — they may send a join request.

10.Your rights

Under the Law "On Personal Data" you have the following rights:

RightHow it is exercised
Access to your data View it in the app or download it via Excel export
Rectification of data Change your name and phone number in settings; edit records in the app
Erasure of data Every record, debt, product, assignment and an entire business can be deleted in the app
Obtaining a copy (portability) Excel export — select a date range and download an .xlsx file
Deletion of the Account By request — see section 11
Withdrawal of consent Through a request to delete the Account
Filing a complaint First with us, then with the competent state authority

10.1 Requests are accepted through the contact details in section 17. To confirm that the person making the request is the Account holder, the request must be made from the registered phone number.

10.2 Requests are reviewed within 30 (thirty) days.

11.Deleting your Account and data

11.1 At present there is no option to delete the Account independently from within the app. Deletion is carried out upon request.

11.2 To submit a request, contact +998 90 000 75 01 from your registered phone number and state that you are requesting deletion of your Account.

11.3 The request is completed within 30 days. The following is then deleted permanently:

  • All Businesses belonging to you and all data within them (records, debts, categories, warehouse and its history, assignments, notes, membership records, join requests);
  • Notifications for your Account;
  • Subscription records;
  • Access tokens;
  • Your profile details: first name, last name, phone number, avatar.

11.4 Important exception. If you have entered records as a Member of a Business belonging to another User, those records will not be deleted — because they form part of that Business's cash records and accounts. In such records your name is removed and the record is attributed to the Business Owner. This is a necessary measure to keep a third party's financial records intact.

11.5 Where required by law (for example, the log of payment transactions), certain records may be retained for the prescribed period.

11.6 Once the Account is deleted, the data cannot be restored. Before submitting a request, save any data you need via Excel export.

Tip

You do not need to delete your Account in order to stop using the app temporarily — simply sign out. Your data will remain in place.

12.Place and period of storage

12.1 Data is stored in a secured database on servers under our control.

12.2 Data is retained for as long as the Account exists. Expiry of a subscription does not result in deletion of data — it is retained until the subscription is renewed.

12.3 Backup copies of the database are made on a regular basis. Once the Account is deleted, the data in backup copies is destroyed as their rotation cycle ends.

12.4 The data on your device (access tokens, the PIN, the saved card record, cached images) is deleted along with the app when you remove it from your phone.

If you intend to use a shared device

Signing out does not clear everything on the device: your name, phone number, App Lock setting and the saved card record (last 4 digits, expiry date, cardholder's name) may remain on the phone. The device may also remain linked to your Account for push notifications, so notifications intended for you may arrive on that phone. If you have used the app on a phone used by another person, signing out alone is not enough — uninstall the app from the device.

13.Security measures

The following measures are applied to protect your data:

  • Password-free sign-in — every sign-in is confirmed with a one-time SMS code sent to your phone number, meaning there is no permanent password that could be stolen;
  • Session tokens — every request is made with a personal, time-limited access token; when you sign out, the token is deleted from the device and a request is sent to revoke it on the server side;
  • App Lock — a 4-digit PIN and biometric protection (Face ID, fingerprint). The app locks automatically when it goes into the background;
  • Separation of access rights — Business data is available only to Members of that Business; removing a Member, renaming a Business and deleting it are the Owner's rights alone;
  • Backups — the database is backed up regularly;
  • Restricted staff access — technical support staff access data only within the scope of their duties.

13.1 At the same time, no data transmitted over the internet can be guaranteed to be 100% secure. We continuously raise our level of security, but cannot provide an absolute guarantee.

13.2 The security of your device is your responsibility: keep your phone locked, never disclose SMS codes to anyone, and enable App Lock.

13.3 If you suspect that your Account is being used without authorisation, report it immediately to +998 90 000 75 01.

14.Data about third parties

14.1 If you enter data about another person into the app, such as the name of a debtor, client or employee, you are the operator of that data — that is, you are responsible for the lawfulness of entering such data.

14.2 We store such data solely within the scope of providing the service to you and do not use it for any other purpose.

14.3 The app does not request or store a debtor's phone number — only the name you have entered is stored.

14.4 Before sending an Excel export file to a third party, check whether it contains data about other persons. Once the file has been sent, what happens to it is outside our control.

15.Age restriction

15.1 sBook is a business tool intended for persons aged 18 and over. We do not knowingly collect data about minors.

15.2 If it is established that data about a minor has been collected, it will be deleted. Please notify us of any such case.

16.Amendments to this Policy

16.1 This Policy may be updated from time to time. The current version is always published at sbook.uz.

16.2 Material changes (for example, the start of collecting a new type of data) will be announced in advance through an in-app notification.

16.3 Continuing to use the app after a new version has been published constitutes acceptance of the changes.

17.Contact

Enquiries about privacy, access to data or deletion of an Account:

sBook — privacy enquiries
Website
sbook.uz
Get the app
App Store and Google Play
Telegram
@sBookuz
Instagram
@sbookuz
Working hours
Monday–Saturday, 09:00–18:00 (Tashkent time, UTC+5)
Response time
Up to 30 days

This version takes effect on 10.09.2026.