Documents

Privacy policy

How roxy.kz collects, uses, stores and protects user data.

Effective from September 13, 2026

Personal data operator

Service operator
GOOSEBUMPS DIGITAL LLP
BIN
260640014519
Registered address
31 Utepova street, apt. 76, Bostandyk district, Almaty 050060, Kazakhstan
Phone
+7 771 799 96 68
Email
team@roxy.kz

General provisions

This policy describes how GOOSEBUMPS DIGITAL LLP collects, stores, uses and protects data when you use the roxy.kz website, the account, public pages, plans, support and platform modules.

This policy does not remove the obligation of store owners to prepare their own documents for their buyers if they collect and process buyer data through their own storefront, forms, delivery, payments or other channels.

Roles in data processing

With respect to users of the roxy.kz account, we act as the personal data operator. With respect to buyers, leads, employees, counterparties and other individuals whom the user enters into the service, the source and the legal basis of processing are determined by the user.

roxy.kz processes such data as a technology platform, to the extent necessary to perform the contract, operate the modules, protect the service, provide support, keep logs and comply with the law.

Categories of data

  • Account data: name, email, phone, interface language, password in protected form, role, access rights and authorization events.
  • Company data: name, BIN/IIN, address, tax regime, company details, employees, stores, warehouses, points of sale and plan settings.
  • Business data: products, categories, prices, stock, orders, customers, CRM deals, documents, expenses, analytics, and settings for delivery, payments, integrations and the public storefront.
  • Buyer and counterparty data, if the user enters it into the service: name, phone, email, delivery address, order history, order contents, payment and delivery method, correspondence and related documents.
  • Technical data: IP address, browser and device information, cookies, session identifiers, error logs, security events, API requests and technical metadata of integrations.

Sources of data

  • Data the user enters during registration, payment, store setup, and creation of employees, products, orders and documents.
  • Data received through the public storefront: forms, cart, checkout, the buyer account and consents.
  • Data from integrations: payment services, delivery services, marketplaces, messaging services and messengers including WhatsApp Business, 1C, fiscalization, electronic invoicing, email and SMS services, and other services connected by the user.
  • Correspondence with buyers in connected messengers: phone number and profile name of the other party, message text and attachments, timestamps, delivery and read statuses, channel and conversation identifiers.
  • Technical data generated automatically when using the website, the account, the API and the platform infrastructure.

Purposes of processing

  • User registration, authentication, role management, account security and access recovery.
  • Providing SaaS features: online store, catalog, CRM, orders, warehouse, documents, fiscalization, analytics, integrations, AI features and customer support.
  • Issuing invoices, accepting payment, and accounting for plans, limits, packages, enterprise requests and financial operations related to the service.
  • Processing orders, notifications, deliveries, payments, returns, reservations, documents and requests, if the user uses the corresponding modules.
  • Fraud prevention, incident investigation, security logging, compliance with the law, and protection of the rights of the operator and of users.
  • Improving service quality, diagnosing errors, developing functionality and sending service notifications about how the platform works.

Legal basis and consent

Processing is carried out on the basis of the consent of the data subject, performance of the contract, legal obligations, the need to protect rights, and ensuring the security of the service.

The data subject may withdraw consent if further processing is not required to perform the contract, retain documents, or meet tax, accounting, claim-related or other mandatory purposes.

Disclosure to third parties

Data may be transferred only to the extent necessary for the service to operate: to hosting providers, payment systems, delivery services, messaging services, marketplaces, email and SMS providers, analytics and technical contractors, legal and accounting advisers, and to state authorities where there is a lawful basis.

If the user connects an external service, data may be processed by that service under its own rules. The user must take into account the terms of the external service and obtain the necessary consents from buyers, employees and other individuals.

Providers chosen by the operator

These providers serve all users of the platform regardless of which integrations a particular user has connected. The list is kept up to date and changes together with the architecture of the service.

  • Servercore (Kazakhstan, kz-1 region, Almaty) — computing capacity, database, object storage for files and media, backups and outgoing email. The main volume of user data is stored here.
  • GitHub and the ghcr.io image registry (USA) — source code and application images. User data is not transferred there.
  • Sentry (USA) — collection of technical errors of the website, storefront and account. User, company and store identifiers and technical request details are transmitted; cookies, request bodies, query strings and the values of fields containing passwords, tokens, card numbers, IIN, phone numbers and emails are masked.
  • OpenAI (USA) — generation and translation of catalog and store page texts: product names and descriptions, attributes, SEO texts, category names, page texts and store settings. Buyer data is not sent to the model.
  • PhotoRoom — processing of product photos if the user uses background removal. The product image itself is transmitted.
  • Google — sign-in with a Google account at the user choice (email and profile name are transmitted) and loading of fonts on website and storefront pages.
  • OpenStreetMap Nominatim — fallback address lookup by map point at checkout if the store has no map service configured.
  • Telegram — operator service notifications and moderation of payment onboarding applications, including documents attached to an application.
  • PS.kz and Servercore — domain registration and maintenance; the domain owner contact profile is transmitted: name, phone, email and address.

Providers chosen by the user

These services receive data only after the user connects the corresponding module and enters their own credentials. The scope of transmitted data is determined by the selected operation.

  • Messaging services: Wazzup24 — correspondence with buyers in WhatsApp, Instagram and Telegram, including phone number, profile name, message text and attachments. See the WhatsApp page for details.
  • Payment services: Plexy, Freedom Pay, CloudPayments, TipTop Pay, Kaspi Pay, Robokassa, Halyk ePay. The amount, order identifier and payer contacts are transmitted; bank card details are entered on the payment service side and are not stored on the platform.
  • Delivery services: CDEK, DPD Kazakhstan, Yandex Delivery, DHL Express, Kazpost. The recipient name, phone, email and address are transmitted.
  • Fiscalization and electronic document services, marketplaces, the national catalog and 1C exchange — to the extent required for the selected operation.
  • Map services from Yandex, Google or 2GIS — at the store owner choice, for the map and address hints on the storefront.

Cross-border transfer

When cloud infrastructure, external APIs, payment, communication, AI and other services are used, some data may be processed using infrastructure outside the Republic of Kazakhstan. In particular, this applies to Sentry, OpenAI, PhotoRoom, Google, GitHub and Telegram, which operate outside Kazakhstan.

Such transfer is allowed only where there is a legal basis and with protection measures appropriate to the nature of the data and the purposes of processing.

Data retention

Data is stored for the term of the account, the contract and the connected plan, and for the period necessary to achieve the purposes of processing. Some data may be stored longer where required for accounting, tax, claim-related or archival purposes, for information security, or to comply with the law.

  • Database backups — 14 days, after which they are overwritten automatically.
  • Service technical markers in the cache — 7 days.
  • Infrastructure load metrics — 14 days.
  • Aggregated platform sales overview — 400 days.
  • Account, store and business data — for the term of the account and until a deletion request has been completed; the procedure and deadlines are described on the data deletion page.

Data protection

  • Access separation by roles, stores, companies and technical rights.
  • Encryption of sensitive integration credentials and restriction of access to them on the backend.
  • Security logs, auditing of critical actions, backups and monitoring of technical events.
  • Transmission over secure channels where applicable, and minimization of employee and contractor access to user data.
  • Separation of platform user data so that one user cannot access another user data without a legal basis.

Rights of the data subject

The data subject may request information about processing, correction, blocking, deletion, withdrawal of consent or restriction of processing by sending a request to team@roxy.kz.

To protect the data, the operator may request confirmation of the identity or authority of the applicant. Requests are handled within the time limits set by the laws of the Republic of Kazakhstan; where applicable, initial handling of a request takes up to 3 business days.

The step-by-step procedure for deleting an account, a store, correspondence and buyer data is described on a separate page.

Cookies and technical identifiers

The website and the account may use cookies, local storage and similar technologies for authorization, saving settings, security, error analytics and correct operation of the interface.

Disabling cookies may break sign-in, the cart, the account, the site editor and other features.

Data of minors

The platform is intended for business use and is not designed for independent use by minors. If such data has been submitted without a proper basis, a legal representative may contact the operator for verification and deletion.

Changes to this policy

This policy may be updated when the law, the service architecture, the set of modules, the methods of data processing or external integrations change. The current version is published on this page.

Home