KZ RU EN

Privacy Policy

Last updated: March 8, 2026

1. General Provisions

1.1. This Privacy Policy (hereinafter referred to as the "Policy") defines the procedures for collecting, processing, storing, and protecting personal data of users of the VenueCall platform (hereinafter referred to as the "Platform").

1.2. The data controller is IE Abdrakhmanov, IIN 990331300094, Almaty, Republic of Kazakhstan (hereinafter referred to as the "Controller").

1.3. This Policy has been developed in accordance with the Law of the Republic of Kazakhstan "On Personal Data and Their Protection" dated May 21, 2013 No. 94-V (hereinafter referred to as the "Law").

1.4. By registering on or using the Platform, the user agrees to the terms of this Policy. If the user does not agree with the terms, they must discontinue use of the Platform.

1.5. The Platform is accessible at https://venuecall.app.

2. Definitions

Personal DataAny information relating to an identified or identifiable natural person (data subject)
Data SubjectA natural person whose personal data is being processed
ControllerThe entity that determines the purposes and means of processing personal data — IE Abdrakhmanov
ProcessingAny operation performed on personal data, including collection, recording, organization, storage, modification, use, distribution, depersonalization, blocking, and destruction
Venue OwnerAn entity that has registered a venue (restaurant, bar, cafe) on the Platform
Staff MemberAn employee added to the Platform by a Venue Owner
GuestAn individual who uses the Platform's guest interface via QR code or directly
CookiesSmall text files stored on a user's device

3. Personal Data Collected and Purposes

3.1. Venue Owner Data

DataPurposeLegal Basis
Email addressRegistration, authentication, notificationsContract performance
Full nameAccount identificationContract performance
Password (bcrypt hash)AuthenticationContract performance
Venue name and addressService delivery, guest-facing informationContract performance
Logo (image)Venue interface customizationConsent
3.2. Staff Member Data
DataPurposeLegal Basis
Email addressRegistration, authenticationContract performance
Full nameAccount identificationContract performance
Role (position)Access controlContract performance
3.3. Guest Data
DataPurposeLegal Basis
Phone numberOTP authentication via WhatsAppConsent
NameOrder and reservation identificationConsent
Order historyService delivery, analyticsContract performance
Loyalty program dataBonus and discount trackingConsent
Chat messagesCommunication with venueConsent
3.4. Technical Data
DataPurposeLegal Basis
IP addressError monitoring (Sentry)Legitimate interest
User AgentError monitoring (Sentry)Legitimate interest
Anonymous eventsProduct analytics (Amplitude)Legitimate interest

4. Methods of Data Collection

4.1. Direct collection — the user provides data voluntarily during registration or while using the Platform.

4.2. Automatic collection — technical data (IP address, User Agent, cookies) is collected automatically during interaction with the Platform.

4.3. Third-party collection — phone number verification is performed via WhatsApp during OTP authentication.

5. Data Processing and Storage

5.1. Personal data is processed electronically and stored on secure servers.

5.2. Database: PostgreSQL hosted on Fly.io (Netherlands, European Union).

5.3. Passwords are hashed using the bcrypt algorithm and cannot be recovered in plaintext.

5.4. Authentication is performed via JSON Web Tokens (JWT) with a validity period of 7 (seven) days.

5.5. All data transmission is encrypted via HTTPS (TLS 1.2+).

5.6. Data retention periods:

6. Third-Party Data Sharing

The Controller shares personal data with the following third parties solely for the purposes indicated:

Third PartyData SharedPurposeJurisdiction
TipTopPaymentsTransaction identifier (card data is NOT shared)Payment processingKazakhstan
WhatsApp (Meta Platforms)Phone numberOTP delivery, messagingUSA
AmplitudeAnonymous event dataProduct analyticsUSA
SentryIP address, User Agent, stack traceError monitoringUSA
ResendEmail addressEmail notificationsUSA
Telegram (Telegram FZ-LLC)Telegram user identifierBot notificationsUAE
Fly.ioAll server-side dataHosting infrastructureNetherlands (EU)
Upstash, Inc.Token blocklist, session cacheData caching and token blocklist (Redis)EU
6.1. The Controller does not collect or store payment card data. All payment transactions are processed by TipTopPayments in compliance with the PCI DSS standard.

6.2. The Controller does not sell, rent, or trade personal data to third parties.

6.3. Data may be disclosed to government authorities in cases provided for by the legislation of the Republic of Kazakhstan.

7. Cookies

The Platform uses the following cookies:

CookieTypePurposeExpiration
venue-tokenEssential (httpOnly, Secure)JWT authentication token7 days
venue-langEssentialInterface language preference (kz/ru/en)1 year
7.1. The Platform does not use marketing or tracking cookies.

7.2. Essential cookies are required for the Platform to function properly. Disabling them may result in limited functionality.

8. User Rights

In accordance with Article 15 of the Law, data subjects have the following rights:

8.1. Right of access — to obtain information about their personal data and the conditions of its processing.

8.2. Right to rectification — to request correction or supplementation of their personal data.

8.3. Right to erasure — to request deletion of their personal data (except where retention is required by law).

8.4. Right to withdraw consent — to withdraw consent to data processing at any time.

8.5. Right to data portability — to receive their data in a structured, machine-readable format.

8.6. To exercise these rights, please contact support@venuecall.app. Requests will be processed within 15 (fifteen) business days.

8.7. Users may submit an account deletion request through the Platform's "Settings" section or via email.

9. Data Security Measures

The Controller implements the following measures to protect personal data:

9.1. Organizational measures:

9.2. Technical measures:

10. Cross-Border Data Transfers

10.1. The primary database is located in the Netherlands (European Union) on the Fly.io platform.

10.2. Certain third-party services (Amplitude, Sentry, Resend, WhatsApp) may process data in the United States.

10.3. Cross-border data transfers are conducted in accordance with Article 16 of the Law, ensuring an adequate level of personal data protection in the recipient countries.

10.4. By registering on the Platform, the user consents to cross-border data transfers as described in this Policy.

11. Changes to This Policy

11.1. The Controller reserves the right to modify this Policy at any time at its sole discretion.

11.2. The updated version of the Policy shall take effect upon publication on the Platform.

11.3. Users will be notified of material changes via email or an in-Platform notification.

11.4. Continued use of the Platform following publication of changes constitutes acceptance of the updated Policy.

12. Contact Information

Controller: IE Abdrakhmanov
IIN: 990331300094
Address: Almaty, Republic of Kazakhstan
Email: support@venuecall.app
Website: https://venuecall.app

Complaints regarding personal data processing may be sent to support@venuecall.app. Complaints will be reviewed within 15 (fifteen) business days.

If you believe your rights have been violated, you may file a complaint with the Committee on Information Security of the Ministry of Digital Development, Innovations and Aerospace Industry of the Republic of Kazakhstan (https://www.gov.kz).