Skip to content

Legal

Privacy Policy

Effective: · Version 1.0

This policy explains what personal data Cargo collects when you use the Cargo and Cargo Driver apps and the cargom.uz website, why it is needed, who can see it, how long it is kept and how you control it. Cargo processes personal data under the Law of the Republic of Uzbekistan “On Personal Data”.

O‘zbekcha

1.Who is responsible

Cargo (cargom.uz) operates the service and decides how your personal data is processed. You can reach us through support in the app, daily from 08:00 to 22:00 Tashkent time.

2.What we collect

  • Account: your name, mobile number, a one-way fingerprint of your Apple ID if you use Sign in with Apple, language and notification choices, and your signed-in sessions.
  • Requests: pickup and delivery points (region, city, street, house, landmark and map coordinates), time windows, the goods (items, count, dimensions, weight, photos and handling needs), access notes and the recipient’s first name.
  • Driver details: vehicle details (model, plate, dimensions, payload and photos you choose to publish), verification documents (identity, permission to drive, vehicle registration and cargo body photos), trips, standing routes, earnings and payouts.
  • Bookings and handover: offers and prices, status history, pickup, loading and delivery photos, item counts, handover code checks and recipient confirmations.
  • Location: if you allow it, your current location helps you place a point on the map; only the point you choose is saved. During an active journey Cargo Driver sends the driver’s latest positions so the sender can follow the delivery. When a driver arrives at a stop, Cargo records the time, accuracy and distance of the check, not a route history.
  • Payments: method, amounts, statuses and provider references. A saved card is kept as the payment provider’s token with the masked number and expiry; full card numbers are entered with the provider and never stored by Cargo. For cash, the driver’s declaration of what was collected.
  • Communication: messages between sender and driver, reports, blocks, reviews and ratings, and problem reports.
  • Technical: your device’s push notification token (stored encrypted) and your network address, used briefly to protect sign-in and public pages from abuse.
  • Website: no advertising or analytics cookies. One cookie remembers your language.

3.Why we use it

  • To provide Cargo: accounts, matching, offers, bookings, handover, payments and support. This is necessary to perform the agreement with you.
  • To keep people safe: driver verification, preventing fraud and abuse, moderating messages and reviews, and keeping an audit record of important actions.
  • To keep you informed: booking updates in the app and by push notification, and alerts about loads on your routes if you turn route alerts on.
  • To meet legal obligations, such as financial records and lawful requests from authorities.
  • To run the service: aggregated statistics for the operations team. Cargo does not build advertising profiles and does not sell personal data.

4.Who can see it

  • The other participant sees what the booking needs. Before a booking, drivers see the goods details with places at city level, and senders see the driver’s profile: verification status, rating and reviews. After confirmation, both see the exact pickup and delivery points and the agreed contact options. During the active journey, the sender sees the driver’s location.
  • Public listings and share cards show only cities and regions, the goods category and timing. A recipient link shows one delivery.
  • Cargo staff see data according to their role: operators, verifiers, finance and administrators. Read-only roles see shortened names and no phone numbers. Administrators and finance staff use two-factor sign-in, and staff actions are recorded.
  • Service providers that process data for Cargo: Supabase (database and private file storage), Render (API servers), Vercel (website hosting), Eskiz (SMS sign-in codes), Payme and inPAY (payments), Apple (Sign in with Apple, push notifications, and maps and address search in the iOS apps), and Resend (email for Cargo staff accounts).
  • Authorities, when the law requires it.

5.Where it is stored

Cargo’s database, private file storage and API servers are currently located in Singapore. The website is delivered through Vercel’s global network. Data is protected in transit and at rest as described below.

6.How long we keep it

  • Sign-in codes: 2 days. Expired sign-in sessions: 7 days after they end. Repeat-protection records for your actions: 7 days.
  • In-app notifications: 90 days.
  • Live journey positions: deleted when the trip ends, and any position not updated for 12 hours is deleted automatically.
  • Bookings, payments, problem reports, handover evidence and the audit record: kept after an account is deleted for as long as needed for accounting, safety and legal claims.
  • Driver verification documents: kept while the driver account is active, and afterwards only as long as needed to show that checks were made.

7.Your rights and choices

  • Access: download your data in the app (Profile, Privacy, Download my data). You receive one JSON file.
  • Correction: edit your profile in the app, or ask support to correct other records.
  • Deletion: request account deletion in the app. Once open bookings and payments are settled, Cargo removes your sign-in methods, device tokens, preferences, notifications and saved cards and replaces your name. Records the law or open obligations require are kept as described above.
  • Consent: turn route alerts and notifications off, or withdraw location permission, at any time.
  • Sessions: see your signed-in sessions and end any of them.
  • Complaints: contact us first. You can also contact the authorised state body for personal data in Uzbekistan.

8.Security

Connections are encrypted. Phone numbers, tokens and codes are stored encrypted or as one-way fingerprints. Photos and documents are kept in private storage with short-lived access, and their location metadata is removed on upload. Staff access is limited by role and recorded, and sign-in attempts are rate limited. No system is perfectly secure; tell us through support if you notice a problem.

9.Children

Cargo is not intended for anyone under 18.

10.Changes to this policy

When this policy changes, the new version is published here with its date, and material changes are announced in the app.

For questions, write to support in the app, daily 08:00–22:00.

The next trip is already planned

The app is coming to the App Store and Google Play. Posting cargo will take about three minutes.

Not in the stores yet.