Privacy Policy
Revision: September 2026
This Policy describes what data the Pingy Tasks service — the mobile app and the personal account area on the tasks.png.uz website — collects, why it is needed, who it is shared with and how long it is kept. The app and the website use the same account. We write here only what actually happens: every point matches the way the service is built.
The binding version of this document is the Russian one. If the two differ, the Russian version prevails.
Who processes the data
The personal data operator is PINGY LLC (PINGY MChJ), tax ID 312989123, Republic of Uzbekistan, Tashkent. Processing is carried out in accordance with the Law of the Republic of Uzbekistan “On Personal Data” No. ZRU-547.
Questions about data processing: info@png.uz and the support section in the app or in the personal account area on the tasks.png.uz website.
What we collect
When you register and use the app or the website:
- your mobile phone number — it is also how you sign in; the service has no passwords;
- your name, profile photo, interface language and a description of yourself — if you have given them;
- your email address — if you have given it; it is not required.
When tasks are posted and carried out:
- the text of the task, its category, budget and photos;
- the address and coordinates of the place of work; the contact phone number for that task;
- bids and their prices, the chat for the task together with any photos attached to it;
- the marks for starting and submitting the work, including the coordinates at those moments — they are needed to settle a dispute about whether the tasker actually came;
- reviews and ratings, the history of tasks and statuses.
During identity verification:
- the images of the document you upload for the check;
- the result of the biometric check through the state MyID service: the name and document details confirmed by the state, the expiry date of the document, the degree of facial match and a hash of the PINFL. The name and document details are stored encrypted;
- on the tasks.png.uz website the check runs through the web version of MyID (MyID Web SDK) using the browser's camera; the data involved is the same as in the app. To start the check, MyID receives the PINFL or passport details and the date of birth you enter, as well as the browser's IP address;
- the biometric data itself — the face image and the template — we neither receive nor store. MyID does the comparison on its own side and returns only the result to us.
For payments:
- the card mask (the first and last digits) and the payment token issued by the bank;
- the full card number — when you link a card, it is sent over an encrypted channel to our server and on to the acquirer, and it is stored only in encrypted form: it is needed for payouts to that card;
- the card number in a payout request — if it was not saved when the card was linked, you enter it with the request; in the request it is stored encrypted and is erased the moment the payout is sent;
- the history of operations: amounts, dates, purpose, and the acquirer's payment identifier.
Technical data:
- the push notification token, the app and build version, the time of last activity;
- the device language and the data needed for the map and location to work.
When you use the tasks.png.uz website:
- server access logs: IP address, browser information (user-agent), time and the page requested, as well as technical reports of page errors — without phone numbers, card numbers or codes. The logs are kept on the server in the Republic of Uzbekistan and are needed to protect against abuse and to investigate failures;
- a session cookie — a strictly necessary file that keeps you signed in. Page scripts cannot access it (httpOnly); it lasts up to 30 days and is removed when you sign out on the website;
- the browser's local storage (localStorage) — only the chosen interface language and theme; the text of a task started before signing in is kept temporarily in the browser tab (sessionStorage) until the tab is closed;
- there are no advertising or analytics cookies, counters or third-party scripts in the personal account area.
Why this is needed
- signing in to an account, confirming the number with a one-time code and keeping you signed in on the website;
- posting tasks, receiving bids, and contact between the client and the tasker;
- showing tasks near you and building a route;
- making payments, holding the task amount and paying the tasker;
- identity verification — it is required in order to post a task or place a bid, and it protects both sides of the deal;
- handling disputes and complaints, and user support;
- protection against fraud, fake ratings and multiple accounts;
- meeting the requirements of the law.
What other users see
Until a bid is accepted, the exact address of the task and the contact phone number are not disclosed: other users only see the approximate area, within a radius of about 500 metres. The exact address and phone number are opened up to the tasker once the client has accepted their bid.
A public profile shows the name, photo, rating and reviews and — for a tasker — a description of themselves, their skills, categories and examples of work. The phone number is not shown in the profile.
Who we share data with
We do not sell personal data and do not pass it on for anyone else's advertising. Data is shared only to the extent the service needs to work:
- the other party to the task — the name, phone number and address, once a bid is accepted;
- Octobank (octo.uz) — the data needed to link a card, take payment and make payouts, including the card number and expiry date when the card is linked;
- the payment organisation Payme — the same data, to link a card and take payment, if payment through Payme is switched on;
- MyID (uz) — the data for the biometric identity check; the check is carried out by the state service; when the check is done on the website, MyID also receives the browser's IP address;
- Eskiz — the phone number, to deliver the SMS with the one-time code;
- Apple — the device token, to deliver push notifications to iPhone;
- Google (Firebase Cloud Messaging) — the device token and the notification text, to deliver push notifications to Android;
- 2GIS — coordinates and the search query, for the map and address search; when the map loads, also the IP address of the device or browser;
- OpenFreeMap — the IP address of the device or browser, to load the base map when a map is shown;
- Telegram — only if you have linked the account yourself to receive codes and notifications. If Pingy push notifications are not switched on on any of your devices (for example, you only use the website), notifications arrive as messages from the Pingy bot @pingy_robot with a link to your personal account area;
- state authorities — in the cases directly provided for by law.
Where the data is stored
The data of citizens of the Republic of Uzbekistan is processed and stored on servers located inside the Republic of Uzbekistan. Transmission is protected by TLS encryption. Identity verification data and full bank card numbers are stored only in encrypted form; staff access is limited by role and is logged.
How long we keep it
- account data — for as long as the account exists;
- the full number of a linked card — for as long as the card is linked to the account; deleting the card deletes the number;
- the card number in a payout request — until the payout is sent, then it is erased;
- website access logs — for a limited time, after which they are deleted automatically (as a rule, no longer than 90 days);
- the website session cookie — up to 30 days, or until you sign out;
- chats, tasks and reviews — for as long as the account exists, because they are needed to settle any claims that may arise;
- the history of money operations — for the period the law sets for accounting documents, even after the account is deleted;
- once an account is deleted, the rest of the data is made anonymous: the phone number, name and contact details are replaced and cannot be restored.
Your rights
You have the right to ask for information about the processing of your data, to require it to be corrected, blocked or deleted, and to withdraw your consent. You can delete your account yourself in the app settings, or without the app in the way described at png.uz/en/delete-account. Requests are accepted at info@png.uz and through the support section.
Withdrawing consent or deleting part of the data makes the service unusable: without a confirmed number and identity verification you cannot post a task or place a bid. An account cannot be deleted while the settlements on your tasks are unfinished.
Age
The service is intended for persons aged 18 or over. We do not knowingly collect children's data.
Changes
We may update this Policy. The current revision is always available at png.uz/en/privacy and in the app. We notify you of material changes in the app, in the personal account area on the website, or by a message from the Pingy Telegram bot if it is connected. By continuing to use the service, you accept the updated revision.