Privacy policy
Maroom is an app for independent masters — people who work for themselves and keep their own clients. This page explains what data Maroom keeps, why it is needed, who else handles it, and how to delete it.
Who is responsible
Maroom — the app, its Telegram bot and this website — is run by Maroom. Below, "we" means Maroom, "you" means a master with a Maroom account, and "clients" means the people who come to you.
Our contact details will appear on this page shortly.
What we keep about you
When you sign up and use the app, we keep:
- your name and phone number (the number is your login);
- your password — only as a hash, from which the password itself cannot be recovered;
- your specialty, address and profile photo;
- your working hours, days off, the app's settings and the language you chose;
- your services and prices, your promotions, and the broadcasts you send to clients, with their pictures;
- your shop orders: the items, your name and number, the delivery address and your note to the order;
- your own Telegram chat, if you link it to receive notifications;
- your phone's notification token — to send a sound notification about a new booking request (deleted when you sign out);
- the details of your Payme or Click cashbox, if online payment is connected for you;
- when the app was last used.
We also keep a record of the payments you make to us for the service: the sum, the dates and how it was paid.
What the app keeps about your clients
What you enter about your clients, and what they tell the Telegram bot themselves:
- name, phone number, birthday and your notes;
- bookings and visits: services, prices, what was paid, paid in advance or is still owed;
- the client's tier (how reliable the client is) and missed visits;
- for clients who use the bot: their Telegram account (chat id, name and username), the phone number they shared as their own contact, the language they chose, and the reviews they wrote;
- shop orders a client places on your page in the bot: the items, name, number and delivery address.
You decide what to record about a client. For this data we act on your behalf: we store and process it only so that the service works for you, and use it for nothing else. Enter only what your work needs, and let your clients know that their details are kept in Maroom.
What your clients see
Clients who open your link in the bot see your name, specialty, photo, address, phone number, working hours, services and prices, free times, and published reviews with your replies. Your name, specialty, number and address are also signed under the messages the bot sends them on your behalf.
The same card appears in the bot's catalogue of masters, where anyone using the bot can find it. To leave the catalogue, turn off "Show in the catalogue" on Profile — your own link keeps working.
A published review shows only the first name of the client who wrote it. Reviews with words are read by us before they are published.
Why the data is used
- to run the service: the calendar, reminders, bookings through the bot, deposits and debts, finances, promotions and the shop;
- to sign you in and keep the account safe;
- to answer your questions, and to call you back about a sign-up or an order;
- to send the messages you ask for: reminders and broadcasts to your clients, notifications to your own Telegram;
- to show our news (short posts) in the app and, if your Telegram is linked, to send them there.
We show no ads, do not track you in other apps or on other websites, and never sell or rent out anyone's data. The app contains no third-party analytics or advertising code.
Who else handles the data
- Telegram — the bot and every message to you and your clients go through Telegram, and Telegram's own privacy policy applies there.
- Google Firebase Cloud Messaging — delivers notifications (push) to your phone: only the notification text and the phone token go there.
- Payme and Click — when a client pays a deposit or a debt online. The card is entered on the payment provider's own page: we never see card numbers, only the amount and whether the payment went through.
- The hosting provider whose servers store the data.
We give data to state bodies only when the law of the Republic of Uzbekistan requires it, and to no one else.
The data is stored on a server in the Republic of Uzbekistan.
On your phone
- The app keeps its sign-in token in the phone's secure storage (Keychain on iPhone, Keystore on Android).
- The language you chose, the server address and which posts you have already watched are kept in the app's settings on the phone.
- The camera is used only when you take a profile photo, and the photo library only when you pick a profile photo or a picture for a broadcast.
- The app does not read your contacts or your location.
This website
Maroom's web pages set only a technical session cookie they need to work; the client's page in Telegram keeps its shop basket in the browser. There are no advertising or analytics cookies.
How long the data is kept
- Everything is kept while your account exists.
- When you delete the account — in the app, or by asking us — it is deleted at once and for good. The account deletion page lists exactly what goes and what stays.
- The database is backed up every night and each copy is kept for about two weeks, so deleted data is gone from the backups within 16 days.
- To protect sign-in, the server counts attempts by IP address; these counters expire within an hour. A web page's session (the IP address and the browser's name) expires two hours after the last visit. Error logs are used only to find and fix faults.
Your rights
- See and correct your data in the app at any time: your profile, clients, services and everything else.
- Delete your account in the app: Profile → App → "Delete account".
- Ask us what data we keep about you, and ask us to correct it or delete it — write to the contacts above.
A client may ask their master to correct or delete their card, or write to us. A client can stop the bot's messages at any time by blocking the bot in Telegram.
Children
Maroom is made for adults who work for themselves. The app is not meant for anyone under 16.
Security
- Data travels only over an encrypted connection (HTTPS).
- Passwords are kept only as hashes.
- The app signs in with a personal token, which is erased when you sign out or delete the account.
- Every account sees only its own data: no master sees another master's clients.
- The database cannot be reached from the internet.
Changes to this policy
When this policy changes, the new version is published on this page with a new date at the bottom.