Skip to content
Home

Privacy Policy

Last updated:

This Privacy Policy explains how GreenApps Private Limited ("GreenApps", "we", "us", "our"), the operator of the Dona marketplace and live-video shopping service ("Dona", the "Platform"), collects, uses, shares and protects your personal data when you use our website at https://dona.uz and our iOS and Android apps (application id im.dona.app). It applies to Buyers, Sellers and visitors. We provide it for transparency and to help you understand your choices. It does not override the mandatory rights you have under the personal-data and consumer-protection laws of the Republic of Uzbekistan, which continue to apply to users in Uzbekistan and prevail over anything inconsistent here. Please read it together with our sibling policies, in particular the Terms & Conditions, the Cookie Policy and the Payments & Refunds Policy.

1. Who we are and our role

GreenApps Private Limited is a company incorporated in Singapore, with its registered office at 20 Collyer Quay #09-01, Singapore 049319. We operate the Dona Platform.

For most of the personal data processed through Dona, GreenApps acts as the controller — meaning we decide why and how the data is processed (for example, account registration, operating the marketplace, safety and fraud prevention).

Dona is an intermediary marketplace. Independent third-party Sellers list products, broadcast live video and sell to Buyers. When a Seller receives your order and delivery details to fulfil a purchase, the Seller acts as a separate, independent controller of the data it uses to process and deliver your order, and is responsible for its own handling of that data.

Our licensed payment providers (Payme, Click, ATMOS, UzCard and Humo) process your payment data as separate controllers or processors under their own terms and privacy notices. Some of our service providers (for example cloud hosting and delivery partners) act as our processors, handling data on our instructions.

For any privacy question you can contact us at hello@dona.uz with a clear subject line, or by post at the Singapore address above.

2. The personal data we collect

We collect the following categories of personal data:

  • Account and identity data — your phone number (used to register and sign in via a one-time code / OTP), and any name, username, profile photo or other profile details you provide. Registration is by phone number with OTP.
  • Seller data — for Sellers, business or individual registration details, contact information, and information needed for payouts and compliance.
  • Order and delivery data — items ordered, delivery address, recipient name and contact number, order history and preferences.
  • Transaction data — the status and record of your payments, refunds, wallet balance, coins and reward vouchers, and the payment method type used. We do not collect or store full card numbers — full card details are handled by the licensed payment providers.
  • Device, usage and diagnostics data — device model and operating system, app version, language settings, IP address, identifiers, crash and performance logs, and how you interact with the Platform.
  • Device and app-installation identifier — a random identifier created on your device the first time you install our app or visit our website. It is not derived from your phone number, your account, or any hardware identifier issued by your device manufacturer, and on its own it does not identify you by name. We use it to recognise the same installation across sign-ins, which is what lets us see whether several accounts are being used from one device — see safety and fraud prevention below. On the website it is stored in a first-party cookie and in your browser's local storage (see the Cookie Policy); in the apps it is stored in the device's secure storage. Clearing your browser storage, or uninstalling and reinstalling the app on Android, creates a new identifier.
  • Advertising identifier and campaign data — in our mobile apps only, and only for the advertising measurement described below. On iOS this is Apple's advertising identifier (IDFA), which we can read only if you allow tracking when iOS asks; if you refuse, or never answer, we never read it. On Android it is Google's advertising ID, which you can reset or opt out of in your device settings. We also record which advertisement, ad set and campaign an app installation came from, taken from the referral information Google Play and Meta attach to that installation. This is separate from our own analytics, which uses neither identifier — see Advertising measurement below.
  • Approximate location — only where you grant permission, for example to help with address entry and delivery.
  • Sign-in history and account security — to help protect your account, we keep a record of the devices you have signed in from, together with a coarse, city/region-level location derived automatically from the IP address of each sign-in (never your exact address). We also keep a history of changes to your saved delivery addresses. This is separate from the location above, which is only ever collected with your permission.
  • Camera and microphone — accessed only during live streams and only with your permission (for Sellers broadcasting, and for interactive features you choose to use).
  • Communications and content — chat messages, reactions, reviews and other user-generated content (UGC) you post, and the messages you send us for support or complaints.

3. How we use your data and our legal bases

We use personal data for the purposes below, relying on the legal bases indicated:

  • To provide the Platform and your account — registration, sign-in, operating the marketplace, live shopping, the wallet, coins and reward vouchers. Legal basis: performance of a contract with you and taking steps at your request.
  • To process orders and payments — sharing what is necessary with the relevant Seller, payment provider and delivery partner. Legal basis: contract and, for records, legal obligation.
  • To enable live commerce and content features — showing streams, chat, reactions and reviews. Legal basis: contract and, for camera/microphone/location, your consent.
  • For safety, moderation and fraud prevention — detecting abuse, protecting users and the Platform, and enforcing our policies. This can include comparing data such as sign-in IP address, delivery address, or the device and app-installation identifier described above across accounts, to detect patterns associated with fraud or abuse — for example several accounts placing orders from the same address, or a large number of accounts being created and used from a single device, in a way that suggests abuse of a promotion or of our coins, reward vouchers and live-shopping games. Where a device shows such a pattern we may refuse new sign-ins and new registrations from that device. Blocking a device does not by itself close, suspend or restrict any account: action against an account is taken separately, on its own grounds, and under the Account Management & Deletion Policy. We will tell you the reason on request, and you can ask us to review the decision — see Your rights. Legal basis: our legitimate interests and legal obligation.
  • For support and communications — responding to enquiries and complaints, sending service messages. Legal basis: contract and legitimate interests.
  • To improve and secure the Platform — analytics, diagnostics and security. Legal basis: legitimate interests.
  • For advertising measurement — finding out which of our advertisements actually bring people to Dona and lead to an order, so that we stop paying for advertising that does not work. This is the one purpose for which data about you is shared with a company outside Dona — Meta Platforms — and it is set out in full under Advertising measurement below. Legal basis: your consent, given through Apple's tracking prompt on iOS and through Settings → Ad measurement in the app on both platforms, and — where the applicable law does not require consent for this — our legitimate interests in measuring our own advertising. Refusing costs you nothing: every part of Dona keeps working, and what refusing does and does not reach is set out in full below.
  • For legal, tax and accounting compliance — keeping records required by law. Legal basis: legal obligation.
  • For optional marketing — only where permitted and, where required, with your consent, which you can withdraw at any time.

Where we rely on consent, you may withdraw it at any time (for example in your device settings for camera, microphone and location, or by contacting us); withdrawing consent does not affect processing already carried out.

4. How we share your data

We share personal data only as needed:

  • With Sellers — the order and delivery information a Seller needs to fulfil and deliver your purchase. The Seller is a separate controller for that data.
  • With service providers (our processors) — cloud hosting, delivery/courier partners, communications and analytics providers, acting on our instructions.
  • With licensed payment providers — Payme, Click, ATMOS, UzCard and Humo, to process payments and refunds. They handle full card data separately under their own terms.
  • With Meta Platforms, for advertising measurement — where you have not refused it, we send Meta the events set out under Advertising measurement below, together with your advertising identifier, your device and app-installation identifier, and an irreversibly hashed form of your email address, phone number and Dona account number. The readable email address and phone number are never sent. Meta is a separate, independent controller for what it does with that data afterwards, under its own privacy policy. This is the only entry on this list that serves our advertising rather than your order, and the only one you have a choice about — Advertising measurement below sets out exactly what that choice reaches.
  • For legal and safety reasons — where required by law, a valid legal request, or to protect the rights, safety and property of users, the public or Dona.
  • In a business transfer — if GreenApps is involved in a merger, acquisition, reorganisation or sale of assets, data may be transferred as part of that transaction, subject to this Policy.

We do not sell your personal data. Sharing data with Meta for advertising measurement is not a sale — we pay Meta to advertise, Meta does not pay us for data — but it is a real disclosure to another company, so we describe it plainly and let you refuse it.

5. International transfers

Dona runs on cloud infrastructure that may be located outside Uzbekistan (for example, in the European Union). This means your personal data may be transferred to, and processed on, servers outside Uzbekistan, and payment providers may process payment data on their own systems.

Where personal data is transferred internationally, we apply appropriate security safeguards and take reasonable steps to ensure it is protected to a standard consistent with this Policy and applicable law. Please see the section on Uzbek personal-data law below, which explains how the data-localisation requirement affects this and how we are addressing it honestly.

Advertising measurement is a further international transfer, and a different one in kind: it goes to Meta Platforms, Inc. and its group companies, which process it on their own infrastructure outside Uzbekistan — including in the United States and Ireland — under their own privacy policy rather than on our instructions. Refusing advertising measurement stops the app's half of that transfer entirely, and stops any advertising identifier being read or sent. Refusing stops both halves of that transfer: the app's, and the server-side record of a paid order described under Advertising measurement below.

6. Uzbekistan personal-data law and data localisation

The processing of personal data of citizens of the Republic of Uzbekistan is governed by the Law of the Republic of Uzbekistan "On Personal Data". Among other things, that law requires operators to process the personal data of Uzbek citizens using databases physically located in Uzbekistan (data localisation), and to register in the State Register of personal-data bases.

We are committed to describing our actual processing honestly. Because Dona currently uses cloud infrastructure that may be located outside Uzbekistan, we treat such processing as an international transfer with security safeguards, as described above, and we are working towards the localisation and registration requirements under Uzbek law. We will not claim a compliance status that is not in place. As our arrangements evolve, we will update this Policy and notify users of material changes.

If you have questions about how Uzbek personal-data law applies to you, contact us at hello@dona.uz.

7. How long we keep your data

We keep personal data only for as long as it is needed for the purposes described in this Policy — for example, while you have an account and to operate the Platform — and thereafter for as long as necessary to meet legal, tax, accounting, dispute-resolution and record-keeping obligations, or to establish, exercise or defend legal claims.

When data is no longer needed, we delete it or anonymise it. Some records (for example transaction and tax records) may be retained for the period required by applicable law even after you close your account. See the Account Management & Deletion Policy for how deletion requests are handled.

Sign-in history, device records, the device and app-installation identifier, the record of which accounts have signed in from a given installation, and the history of changes to your saved delivery addresses are kept for the life of your account, since they are what lets us detect and investigate suspicious activity. They are handled the same way as your other account data if you delete your account.

Advertising-attribution records — which campaign an app installation came from — and the record of whether you allowed advertising measurement are kept for the life of your account and are removed with it. Events already sent to Meta are thereafter held by Meta under its own retention rules, which we do not control; that is a reason to refuse before rather than after, if you would rather they were not sent.

8. How we protect your data

We use technical and organisational security measures designed to protect personal data against loss, misuse, and unauthorised access, disclosure or alteration — including encryption in transit, access controls and monitoring. Full card details are never stored by Dona; they are handled by the licensed payment providers.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please help protect your account by keeping your device and phone number secure and by not sharing your one-time codes with anyone.

9. Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you and obtain information about how we process it.
  • Correct data that is inaccurate or incomplete (you can also update much of your profile in the app).
  • Delete your data, subject to legal retention obligations.
  • Object to or restrict certain processing, including where we rely on legitimate interests.
  • Withdraw consent at any time where processing is based on consent (for example camera, microphone, location or marketing).
  • Data portability — receive certain data in a commonly used format, where applicable.
  • Complain to the relevant authority (see below).

To exercise any right, contact us at hello@dona.uz with a clear subject line. We may need to verify your identity. We will respond within the period required by applicable law.

10. Children and minors

Dona is not intended for children below the minimum age required by applicable law. Users must meet that minimum age to register and use the Platform. We do not knowingly collect personal data from children below that age. If you believe a minor has provided us with personal data without appropriate consent, contact us at hello@dona.uz and we will take appropriate steps, including deletion where required.

11. Analytics we run ourselves — website and apps

We measure how our website and our mobile apps are used with our own first-party analytics, hosted on our own infrastructure. For that we do not use Google Analytics or any third-party analytics service, and this data is never sold, shared for advertising, or sent to another company — it stays on our servers.

This section is only about that first-party system. Our mobile apps also run a separate advertising-measurement system that does send data to Meta; it has its own section, Advertising measurement, below, and you can refuse it without losing anything on Dona. The two are deliberately kept apart, and nothing described in this section is shared with Meta.

On our website

What we record — the page path you visited (never the query string), the website that referred you (domain only), any campaign tags in the link you followed, your approximate country, region and city (resolved at the moment of your visit from your IP address using a geolocation lookup — the address itself is never stored, only a city-centroid map coordinate for the resulting location, never your exact position), and a coarse description of your device, operating system and browser. To tell one visit from another we store a random identifier in your browser's local storage, together with a session identifier.

What we deliberately do not do — on this website we do not store your IP address anywhere, we do not use cookies for analytics, and we do not fingerprint your device or attempt to identify you across other websites. There is no advertising pixel on dona.uz: the advertising measurement described below runs in our mobile apps, not here. The random identifier is not linked to your account unless you are signed in, and clearing your browser storage removes it entirely and makes you a new visitor.

Your controls — if your browser sends a "Do Not Track" signal, we send nothing at all. You can also clear your site data at any time to reset the identifier.

In our iOS and Android apps

The same first-party system runs inside the Dona app. It records which screens you open (the screen name only, never the content you are looking at), when the app is first installed on your device, when a session starts and when you open the app, your app version, your device model and operating-system version, your platform (iOS or Android), the language you use the app in, and your approximate country, region and city (resolved the same way as on our website — never your exact position).

To count devices without identifying you, the app stores two random identifiers in the app's own storage on your device: a device identifier, and a session identifier that groups the screens you open in one sitting and starts afresh after 30 minutes of inactivity. Neither of these two is an advertising identifier, and neither is ever sent to Meta or to anyone else: the analytics system described here does not read or use Apple's IDFA or Google's advertising ID. It also does not read your device name, device build fingerprint, contacts or precise location.

The app does read an advertising identifier — but only for the separate advertising-measurement purpose, never for the analytics described here, and only on the terms set out under Advertising measurement below: on iOS only if you allow tracking when iOS asks you, and on Android unless you turn Settings → Ad measurement off in the app or opt out in your device settings. As part of advertising measurement a coarse technical description of your handset — its model, operating-system and app version, screen size and density, language, time zone, mobile operator, processor cores and total storage — is sent to Meta; that is described in the same section.

Your account — while you are signed in, the app sends these records with your normal Dona login, so they are linked to your account. While you are signed out they carry only the two random identifiers above and no account. This is the same rule as on our website.

Your controls — you can switch this off at any time in the app under Settings → Usage analytics. Turning it off stops all collection by this analytics system and deletes both identifiers from your device. Deleting the app also removes them, and reinstalling starts new ones, unconnected to the old. Advertising measurement is a separate purpose with its own switch, Settings → Ad measurement; turning one off does not turn off the other, and each can be refused on its own. One exception, once: if you had already turned usage analytics off before advertising measurement existed, that refusal was carried across to it the first time, so that an app update could not read an old no as a new yes. After that the two are independent.

Both surfaces

How long we keep it — detailed visit records are kept for up to 13 months; after that only aggregated counts remain, which cannot be traced back to an individual visitor. We run an automated job that deletes the detailed records once they pass that age.

Legal basis: our legitimate interests in understanding and improving our service, using the least intrusive method we could design.

12. Advertising measurement — a separate purpose you can refuse

We advertise Dona on Facebook and Instagram. To know whether that advertising works — whether an advertisement actually led to an installation, a sign-up or an order, rather than being paid for and ignored — our mobile apps share a limited set of events with Meta Platforms, Inc. and its group companies ("Meta"). This is a separate purpose from the analytics described above; it is set out separately here because it behaves differently, and it is the one purpose for which data about you leaves our infrastructure and reaches another company. You can refuse it and keep every feature of Dona.

This section applies to our iOS and Android apps. There is no advertising pixel on dona.uz.

What it does

  • In the app. Our app includes Meta's software development kit (SDK). Where you have not refused advertising measurement, it reports a small number of events to Meta — that the app was installed and opened, that an account was created, that a product was viewed, searched for or added to the cart, and that an order was paid, with the order's value and currency.
  • Where you came from. When you install the app, Google Play and Meta pass on the referral information attached to the advertisement you tapped. We decrypt it on our own servers so that our own records show which campaign, ad set and advertisement brought that installation. On Android this information is real; on iOS Apple does not provide it, so there we only ever see aggregated results.
  • From our servers. An app can be closed, lose signal, or have its network requests blocked, so the record of a completed order is also sent to Meta from our servers, through Meta's Conversions API — making our own payment records the source of truth rather than the phone. Each event carries an identifier that lets Meta discard the duplicate when the app has already reported the same purchase.

What is sent

  • Your advertising identifier — Apple's IDFA on iOS, only if you allowed tracking when iOS asked; Google's advertising ID on Android, unless you have turned advertising measurement off in the app or opted out in your device settings. It is sent as it is, because it is what Meta matches on.
  • Your device and app-installation identifier — the random identifier described earlier in this Policy. Until now it was used only to keep you signed in and to detect fraud; it is now also sent to Meta for this purpose. It is sent as it is.
  • A hashed form of your contact details — your email address, phone number and Dona account number are converted, before they leave our servers, into an irreversible cryptographic hash (SHA-256). Meta can compare that hash against hashes it already holds, but cannot read the original values from it, and we never send the readable ones.
  • The order — its value, its currency and its order number.
  • A coarse technical description of your device — model, operating-system and app version, screen size and density, language, time zone, mobile operator, processor cores and total storage. This is what Meta's SDK requires. It is not your device name, and it does not include your contacts, your precise location or the content you look at.
  • Whether you allowed tracking. Every event carries the truthful answer, so that Meta applies the restrictions that answer requires. If you refused, we say you refused.

We do not send Meta what you wrote in chat, what you watched in a live stream, your delivery address, your saved cards, or the contents of your account.

Your controls — how to refuse

  • iOS — when the app first asks whether Dona may track your activity across other companies' apps and websites, choose Ask App Not to Track. You can change your mind at any time in iOS Settings → Privacy & Security → Tracking. If you refuse, no advertising identifier is read, and Meta is told that tracking was not allowed.
  • Android — open Android Settings → Google → Ads to delete your advertising ID or opt out of ad personalisation.
  • In the app, on both platformsSettings → Ad measurement. Turning it off takes effect straight away, not at the next restart: the app stops reporting to Meta, unbinds your account from Meta's SDK, and tells our servers that you have withdrawn, so no advertising identifier rides with any later event.
  • What refusing stops — all of it. It stops the app reporting to Meta, it stops your advertising identifier being read or sent, and it stops our servers reporting a paid order to Meta through the Conversions API. An order you place after refusing is not reported to Meta at all.
  • Your refusal follows you, not the handset. It applies if you refused on this device or on any device your Dona account has been seen on, so changing or adding a phone does not quietly restart the reporting.
  • What it cannot undo. Events already sent to Meta before you refused remain with Meta under its own rules, which we do not control — a reason to refuse early rather than late. You can also object to our past records under Your rights above.
  • Nothing is lost. Refusing advertising measurement does not restrict your account, your orders, your coins, your reward vouchers, or any part of the service. Nothing on Dona is priced, ranked or withheld according to that answer, and it is a choice separate from Settings → Usage analytics — you can refuse either one without the other.

Meta's role, transfers and retention

For what it does with this data once it has it, Meta acts as a separate, independent controller under its own privacy policy. Meta processes it on its own infrastructure outside Uzbekistan, including in the United States and Ireland — see International transfers above. Our own attribution records, and the record of what you allowed, are kept for the life of your account.

Legal basis: your consent, given through Apple's App Tracking Transparency prompt on iOS and through Settings → Ad measurement in the app on both platforms, and — where the applicable law does not require consent for this — our legitimate interests in measuring our own advertising, which is the basis the server-side order record described above currently rests on. Where we rely on consent you may withdraw it at any time using the controls above; withdrawal does not affect what was already shared.

13. Cookies and similar technologies

Our website and apps use cookies and similar technologies for functionality, security, preferences and analytics. For details of what we use and how to manage your choices, please see the Cookie Policy.

14. Changes to this Policy

We may update this Privacy Policy from time to time. The current version takes effect on the date shown above. If we make material changes, we will notify you by appropriate means — for example, an in-app notice or a message to your registered contact — before the changes take effect where required. Your continued use of the Platform after an update means you have read the updated Policy. We encourage you to review it periodically.

15. Contact us and how to complain

If you have questions, requests or complaints about privacy, contact us first so we can help:

  • Email: hello@dona.uz (please use a clear subject line, e.g. "Privacy request")
  • Post: GreenApps Private Limited, 20 Collyer Quay #09-01, Singapore 049319

If you are in Uzbekistan and are not satisfied with our response, you may also contact the competent Uzbek authority responsible for personal-data protection, or the relevant consumer-protection body or the courts, in accordance with the laws of the Republic of Uzbekistan. Mandatory rights under Uzbek law are not affected by this Policy. See also our Terms & Conditions.

The Dona platform is operated by GreenApps Private Limited (Singapore). · hello@dona.uz

This document is available in Uzbek, Russian and English.