Privacy Policy
How Sairo obtains, uses, discloses, stores and deletes Personal Data across its website, Telegram Mini App, Android and iOS apps and related services.
The Sairo operator's registered legal name and address are awaiting owner confirmation. This revision is not ready for legal publication until they are added. Data enquiries: hello@sairo.uz.
1. Who we are
Sairo is a local-services discovery and booking service. This Policy covers sairo.uz, the Telegram Mini App, Android and iOS apps, the API and user-facing business-console features. Verified operator details will be added here before legal publication.
2. Scope
This Policy applies when you browse, create or link an account, book or pay, communicate, publish content, use family profiles, location, notifications or AI try-on. Third-party sites and apps have their own notices.
3. Data we collect
The data depends on the features you choose. Required data is limited to what that feature needs.
- Account: Telegram ID, name, surname, username, locale, Premium flag and avatar; phone number and password hash for phone sign-in.
- Bookings: business, branch, professional, services, date/time, comments, status, cancellation, attendance and history.
- Content: reviews, ratings, images, inspirations, appointment results, chats, support requests and saved styles.
- Family profiles: name, relationship, birth date, phone, avatar, notes, linked account and representative consent for a minor.
- Financial: payment/refund history, amount, status and provider ID/token; provider reference, brand, last four digits and expiry for a saved card. Sairo does not store full PAN or CVV in the production hosted flow.
- Technical: push token, platform, locale, internal identifiers, usage events, and IP/user-agent in server or audit logs.
- Business users: roles, permissions, applications, business, contract and settlement details, and console actions.
4. How we obtain Data
From you, a verified Telegram profile, your device after system permission, businesses/professionals fulfilling a booking, and payment, push and AI providers responding to an operation you initiate.
5. Why we process Data
For authentication and security; catalogue and booking; communication; payments/refunds; support; family profiles; reviews; notifications; recommendations; AI try-on; abuse prevention; audit; and legal obligations. First-party product analytics is not used for cross-service advertising tracking.
On sairo.uz, Google Tag Manager and analytics connected through it load only after separate consent. Analytics and ad storage remain denied before consent, and advertising categories stay disabled. The choice is stored in browser localStorage and can be changed from Analytics settings in the footer.
6. Legal grounds
Processing supports entering into and performing the service agreement, consent where required, legal obligations, and protecting Sairo and users. Camera, photos, location and notifications are optional permissions; the related optional feature will not work if denied.
7. Location
With device permission, Sairo receives precise coordinates to find nearby places and calculate distance. Coordinates are sent to the API as search parameters; Sairo does not build a movement-history profile. You can select a district manually and disable access later. Business coordinates are public place data.
8. Camera and AI try-on
Live overlays, landmarks, face/hand contours and segmentation masks are computed on-device. Raw landmarks and masks are not uploaded. After a separate confirmation, one selected frame is uploaded to Sairo and sent to Google Gemini for an HD result.
The backend stores the session, result, style and limited derived analysis: a face-geometry category or nail-area/pose measurements and confidence. It is linked to the account and may describe anatomical features, but is not used to identify a person. The source file is deleted after generation succeeds or fails; the result remains in history until the user or account deletes it.
The code does not use images to train Sairo models. The AI provider’s own handling must be confirmed contractually by the Sairo owner before production release. Individual sessions and files can be deleted from history.
9. Payments
In production, card entry occurs on GlobalPay’s hosted page. Sairo receives/stores payment ID/token, status, amount, refunds and safe saved-method metadata: provider reference, brand, last four digits, expiry and title. Sairo does not store full card numbers or CVV. The mock flow is only for non-production test numbers. OTP is verified by the provider or temporary test session and is not stored as a card credential.
10. Notifications
The API may store a device token, platform and locale and send them to Firebase Cloud Messaging or APNs. Push covers bookings, changes, messages and service notices. Promotional notifications can be muted separately and system permission revoked. Firebase SDK is disabled in the current Flutter build, while server-side FCM infrastructure exists.
11. Recipients and providers
We do not sell Personal Data. Only booking participants and providers needed for the chosen feature receive it.
- Telegram — sign-in, profile, Mini App and service messages.
- Google Gemini — the selected source frame and AI-generation instruction.
- Google Tag Manager/Google Analytics — only after consent: page URL, referrer, browser/device technical parameters and website usage events; advertising storage remains disabled.
- GlobalPay — hosted card flow, tokenisation, payment status and refunds.
- Firebase Cloud Messaging and APNs — device token and notification content when enabled.
- Eskiz — phone number and one-time code when SMS is configured.
- PostgreSQL/Redis hosting and local or S3-compatible object storage — service processing and storage.
- Apple App Store and Google Play — purchase validation and store-controlled data.
- Apple Maps, Google Maps or Yandex Maps — place coordinates when the user chooses to open that app.
12. International transfers
Telegram, Google, Apple and other providers may process Data outside Uzbekistan. Data not subject to mandatory localisation may be transferred only with safeguards required by law. Biometric Data must be stored in Uzbekistan. Production transfer of AI frames/analysis remains a compliance blocker until infrastructure location and contractual safeguards are confirmed.
13. Retention
Account, booking, messages, reviews, push tokens, payment methods and content remain while the account exists or the feature requires them. The code has no approved general retention schedule for historical bookings, transactions, chats, logs and reviews; the owner and counsel must approve one.
Abandoned temporary uploads expire after about 24 hours. AI source frames are deleted after processing; results on user/account deletion. An archived family profile is scheduled for deletion after 30 days. Appointment-result, review and inspiration media may currently have permanent retention until withdrawal/deletion and require an organisational limit.
14. Security
Sairo uses role-based access, server verification of Telegram initData and tokens, password hashing, rate limiting, action auditing, signed links for sensitive files and production HTTPS. No system is absolutely secure; access is limited to those who need it.
15. Your rights
You may learn whether and what Data is held, obtain processing information, correct Data, withdraw consent, and request processing to stop or Data to be deleted/anonymised where applicable. You may contact Uzbekistan’s authorised body or a court. Email hello@sairo.uz from an account/address that can be securely linked to you.
16. Withdrawing consent
Withdrawal does not invalidate earlier lawful processing or stop processing required for a contract or law. Camera, photos, location and push can be disabled at system level. Appointment-result publication and promotional push consent are withdrawn separately. AI-upload consent is stored on-device; backend versioning of general and AI consent remains required work.
17. Account deletion
Start in Profile → Settings → Privacy & Account or at sairo.uz/delete-account. A current authenticated session and confirmation are required. Active bookings, unfinished payments or AI jobs must first complete or be cancelled.
Profile, credentials, Telegram links, push tokens, favourites, reviews, chats, support requests, AI history/files, family profiles and saved payment methods are deleted. Historical bookings, payments, refunds and audit entries needed for finance, contracts, security or disputes remain without direct identifiers or under a restricted pseudonymous ID. An active business owner must first resolve contractual obligations.
18. Children's Data
Sairo is not designed for a young child to create an independent account. An account owner may create a family profile for a child and confirms that they are a parent/guardian authorised to give electronic written consent. Name, birth date, relationship, contact and notes should be limited to what a booking needs.
19. Changes
A version and static date appear at the top. Sairo will update the page and seek renewed consent where required for material changes. The backend must record the accepted version; general consent infrastructure remains a required audit action.
20. Contact
Data questions, rights and deletion: hello@sairo.uz. The operator’s registered name and address must be added before final publication. Uzbekistan Personal Data Databases State Register: pd.gov.uz.