Privacy Policy
Playfood and Playfood Driver apps (kz.playfood.driver) — Effective May 14, 2026
Summary. We collect location data (including
background location — even when the app is closed or not in use),
name, phone, document photos and device information. This data is
used only to operate the Playfood food-delivery / taxi
service (order dispatching, navigation, payouts, safety). We do
NOT sell data to third parties and we do NOT use it for advertising.
Separately, and only with your explicit consent, the
Playfood app can match the phone numbers in your address book to find
friends (§4) and show your location to friends you have accepted while
the app is open (§5). Both features are optional, can be switched off at
any time, and the app works fully without them.
1. Who we are
Data controller: TOO «Playfood», a legal entity
registered in the Republic of Kazakhstan, Almaty.
2. Data we collect
| Category | Specifically | Source |
| Location | Precise (GPS) and approximate (network) coordinates, speed, heading, accuracy | Device sensors, while the courier is on an active shift |
| Personal | Full name, phone number, date of birth, IIN (Kazakhstan tax ID) | Sign-up / profile |
| Documents and photos | Driver licence photo, selfie, vehicle photo, medical certificate, shift photo-checks | Camera / Photo Picker |
| Contacts (Driver) | Local lookup of contact name when the customer's phone matches an entry on the device. Data NEVER leaves the device | On-device only |
| Contacts (Playfood, "Friends") | Phone numbers and names from your address book — only if you gave separate consent | Sent to the server to find friends; the numbers themselves are not stored (see §4) |
| Location for friends (Playfood) | Your coordinates while the app is open — only if you gave separate consent | Shown to friends you accepted (see §5) |
| Chat content | Message text, photos, voice messages, a shared location pin | You send them in chat (see §6) |
| Order data | Trip / delivery history, ratings, earnings, tips | Server-side history |
| Technical | Device model, Android/iOS version, FCM token, IP address, crash logs | Automatically on launch |
| Payment | Card details for earnings payouts (stored at PCI-DSS-compliant provider) | Via PCI-DSS provider |
3. Background location (ACCESS_BACKGROUND_LOCATION)
IMPORTANT. The Playfood Driver app collects
location data (GPS), including even when the app is closed
or not in use. This permission is requested separately, with
a dedicated in-app prominent disclosure dialog shown BEFORE the
Android system permission dialog.
3.1. Why we need background location
- Order dispatching. The server picks the closest available driver based on real-time GPS.
- ETA. Customers see how many minutes until the driver arrives.
- Customer transparency. The driver appears live on the customer-facing map, refreshed every 5–10 seconds.
- Pricing. Distance and duration are computed from the actual GPS track, not approximations.
- Safety. If anything happens to the driver, the dispatcher sees the last known location.
3.2. When collection starts and stops
- Collection starts only when the driver taps "Go on shift" inside the app.
- Collection fully stops when the driver taps "End shift", logs out, or uninstalls the app.
- While collecting, a permanent Android notification "Tracking active" is always visible — you always know GPS is running.
- You can revoke the permission at any time: Android Settings → Apps → Playfood Driver → Permissions → Location → Allow only while using / Deny.
3.3. Who we share location with
- Playfood servers (HTTPS/TLS 1.2+).
- Partner-company dispatcher who registered your shift.
- The customer who placed your active order — only while the order is in progress. Once delivered, location is no longer shown to that customer.
We do NOT share location with ad networks, data brokers, insurance companies, or any third party for marketing.
4. Finding friends from your address book (Playfood app)
This is a separate, optional feature. It is enabled only
after you explicitly tap "Allow" on an in-app screen that explains what
happens. The app works fully without it — you can add a friend manually by
typing their phone number.
4.1. What happens to the numbers
- Phone numbers from your address book are sent to the Playfood server over
an encrypted connection (HTTPS/TLS 1.2+).
- On the server they are matched in memory against
registered users and are never written to disk in the clear.
- We store only an irreversible cryptographic transformation of the number
(HMAC-SHA256 with a secret key that is held on the server and is not part
of the app), plus the name you saved the contact under, so you recognise
the person in the list.
- We state this plainly: such a transformation does not
make a phone number fully anonymous — the space of phone numbers is
small. The protection comes from the secret key, which is exactly why the
transformation happens on the server and not inside the app.
4.2. What we do NOT do
- We never show your phone number to other users.
- We do not let people who do not have your number find you by phone number
if you enabled "Hide my number" in your profile.
- We never message or invite your contacts on your behalf.
- We never share contacts with ad networks or data brokers.
4.3. The "your contact joined" notice
- When someone registers with Playfood we may notify people who already
have their number in an uploaded address book: "your contact is now on
Playfood".
- That notice is sent at most once, ever, and only to
people who uploaded the number themselves.
- It can be switched off in advance or at any time: Profile →
"Don't announce that I joined". The setting is checked
at send time.
- Invitations to people who are not on Playfood are sent by
you, through the system share sheet. We never message
your contacts on your behalf and never store their numbers.
4.4. How to delete
Friends → menu → "Delete my contacts". We erase the uploaded
address book and remove you from other users' match lists. Friends you already
added are kept; you can remove them separately.
5. Location for friends (Playfood app)
Foreground only. The Playfood app does
not collect your location in the background for this
feature and does not request ACCESS_BACKGROUND_LOCATION. §3 of this policy
applies solely to the Playfood Driver app during a courier's shift.
- The feature is enabled only after separate consent and runs while the app
is on screen. Minimising or closing the app stops the sharing.
- If the app is force-closed or loses connectivity, your location stops
being shown to friends within 90 seconds at most.
- Only users whose friend request you accepted can see your
location. Nobody else — not other users, not drivers, not partners.
- Visibility has two independent switches: a global "Show me on the map"
toggle in your profile, and a per-friend "Hide my location". Hiding from
someone does not stop you seeing them.
- We keep no movement history for this feature — only the
latest point and a last-seen timestamp.
- Friends receive coordinates only. Speed, heading and positioning accuracy
are never shared.
6. Chat content
- Message text, photos, voice messages and shared location pins are stored
on Playfood servers so your conversation is available on your devices.
- Chats are not end-to-end encrypted. The connection is
encrypted (HTTPS/TLS), but Playfood staff technically can access content
— this is required to handle abuse reports and moderation.
- Files (photos and voice messages) are served from a link with a random,
unguessable name. The link is neither indexed nor published, but it is
not protected by additional authorisation — please do
not send documents or data whose disclosure would be unacceptable.
- Any user can be blocked or reported directly from the
conversation, from a pending friend request, and from their card on the
map.
7. Permissions and why we request them
| Android permission | Purpose |
| ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION | Driver GPS during shift |
| ACCESS_BACKGROUND_LOCATION | Tracking when screen is locked or driver uses a navigation app (see §3) |
| FOREGROUND_SERVICE / FOREGROUND_SERVICE_LOCATION | Persistent "Tracking active" notification during the shift |
| POST_NOTIFICATIONS | Push notifications about new orders |
| USE_FULL_SCREEN_INTENT | Full-screen incoming-order alert on the lock screen (similar to a phone call) |
| SYSTEM_ALERT_WINDOW | Floating "return to Playfood" bubble while you use a navigation app |
| CAMERA | Shift photo-checks and document upload |
| READ_CONTACTS (Playfood Driver) | On-device lookup of customer name in driver's address book. Data NEVER leaves the device |
| READ_CONTACTS (Playfood) | Finding friends from your address book. Requested only when you enable the feature; numbers are sent to the server but never stored in the clear (§4) |
| RECORD_AUDIO (Playfood) | Voice messages in chat, and calls to the driver or support |
| RECEIVE_BOOT_COMPLETED / WAKE_LOCK | Resume work after a phone reboot |
| REQUEST_IGNORE_BATTERY_OPTIMIZATIONS | Prevent Android from killing the foreground service |
8. Third-party services (data processors)
- Google Firebase Cloud Messaging — push delivery. Sends FCM device token. Privacy.
- Google Crashlytics — crash reports. Sends device model, stack trace, pseudonymous user ID.
- MapLibre / OpenStreetMap — map rendering. Tile requests carry the device IP only; no personal data.
- PCI-DSS L1 payment provider — stores and processes card details for earnings payouts.
9. Retention
- GPS coordinates — 90 days, then aggregated into anonymous distance statistics.
- Order history and finance — 5 years (Kazakhstan tax law).
- Documents (driver licence, selfie) — for the duration of the contract + 1 year.
- Crash logs — 30 days.
- Contacts ("Friends") — transformed numbers are kept while
the feature is on. Deleted immediately via "Delete my contacts", and
automatically when the account is deleted.
- Location for friends — no history is kept at all. The last
point expires within 90 seconds of closing the app; only a last-seen
timestamp remains.
- Conversations and attachments — for as long as the thread
exists. Listing chats are deleted automatically after 24 hours with no
messages; friend chats are kept until you delete your account.
- After account deletion, all non-mandatory data is removed within 30 days.
10. International data transfers
Playfood servers are physically located in the Republic of Kazakhstan.
Third-party processors (Firebase, MapLibre) may handle data on EU/US
servers. These providers comply with GDPR and/or EU SCCs.
11. Your rights
- Request a copy of your data (GDPR Art. 15).
- Correct inaccurate data (Art. 16).
- Delete your account and associated data (Art. 17 — right to be forgotten): playfood.kz/privacy/data-deletion.
- Revoke location consent at any time via Android settings.
- File a complaint with the Kazakhstan personal-data authority.
12. Security
- All data is transmitted over HTTPS/TLS 1.2+.
- Passwords stored as Argon2id hashes.
- Admin panel access requires 2FA + IP allow-list.
- Access logs retained and audited.
13. Children
Playfood Driver is restricted to users 18 years and older
(driver licence required). We do not knowingly collect data from minors.
14. Changes to this policy
Material changes will be announced in-app and by email. The effective
date is shown at the top of this document.
15. Contact us
- Email: support@playfood.kz
- Subject line: "Privacy / GDPR"
- Response time: up to 30 calendar days