SIREKEESSIREKEES

Privacy Policy

Effective August 12, 2026

This English text is a convenience translation. The legally binding version is the Russian original at sirekees.com/legal/privacy.

This Policy describes personal data processing when Sirekees is used, including the sirekees.com website, the business dashboard, public booking pages, the AI administrator, Telegram, Instagram and WhatsApp connections, and related features (the "Platform").

The Platform is provided by Individual Entrepreneur «SIREKEES» (TIN 040502550481, registered at 506 Seifullin Street, office 12, Almaty, Kazakhstan; below - "Sirekees", "we"). This Policy applies together with the Republic of Kazakhstan laws on personal data and its protection and on artificial intelligence, and other applicable law.

1. Who determines data processing

  1. Sirekees determines the purposes of processing account, Sirekees payment, security, support, and Platform usage data.
  2. The Business owner determines why and how its Clients' data is processed, including conversations, bookings, orders, payments for its goods and services, and loyalty data. The Business owner must provide required Client notices and establish a lawful ground or consent.
  3. Sirekees processes Client data to provide the Platform and follow the Business owner's settings. Sirekees may also process limited data for security, mandatory legal requirements, and the protection of rights.
  4. For account data questions, contact Sirekees at help@sirekees.com. A Business Client should normally contact the Business first because the Business determines the purposes of processing that Client's data.

2. Who this Policy covers

  • Business owners and team members - people who sign up, configure a Business, receive a team role, or request setup and support.
  • Business Clients - people who message through Telegram, Instagram, or WhatsApp, use a public page, place an order, book or pay for a Business service, or participate in its loyalty program.
  • Website visitors - people who open the website or a public page without signing up.

3. Data we process

3.1. Account and Business data

  • Email, account identifier, and login data. Firebase Authentication processes the password, and Sirekees does not receive it in readable form.
  • Name, phone number, and other owner and team member details, roles, and invitations.
  • Business name and description, address, contacts, links, services, products, prices, images, schedules, specialists, booking rules, and AI administrator instructions.
  • Connection identifiers and credentials: Telegram bot token and chat ID, Meta Instagram and official WhatsApp identifiers and tokens, Green API instance identifier and token, and the n8n address if the User enables forwarding.
  • Payment acceptance and loyalty settings, including connected FreedomPay and Google Wallet identifiers and secrets. Sirekees does not store full bank card details.
  • Invoices, amounts, currencies, payment statuses, access period, promotion code used, and other records of payment for the Sirekees plan.
  • Support messages, information the User provides for setup, and actions taken by authorized Sirekees personnel to fulfil that request.

3.2. Clients, conversations, and bookings

  • Name, phone number, delivery address, comment, and other details a Client provides to the Business.
  • Telegram, Instagram, and WhatsApp user identifiers and names, phone number, channel, and profile information needed to continue the conversation.
  • Message text, images and other attachments, timestamps, conversation status, AI administrator replies, and human handoff markers.
  • Bookings and orders: selected services or products, specialist, date and time, quantity, amount, status, change history, and notifications.
  • Client payment information: operation identifier, amount, currency, and status. If a Client sends a receipt image, the Platform and AI may also process that image.
  • Loyalty balance and transactions and the Google Wallet pass identifier and data if the Business enables that feature.

3.3. AI and analytics data

  • AI prompts and outputs, the current and recent conversation, owner instructions, Business details, services, prices, schedules, and specialists.
  • Limited booking and order details, including Client name and phone number, when needed for AI analytics or repeat-Client identification.
  • AI editing conversation history that may be stored locally in the User's browser.
  • Every automated reply in a connected Channel and the public chat carries a visible "AI administrator" label. Based on the conversation, AI may answer a question, offer a time, create a booking, or hand the conversation to the owner.

3.4. Technical data

  • IP address, request time, page address, browser and device type, language, errors, security logs, and information needed to limit abuse.
  • Cookies, browser local storage, and aggregated usage metrics, as described in section 10.

4. Why we use data

  • Sign-up, login, role management, and account security.
  • Business setup, public pages, conversations, orders, bookings, notifications, and analytics.
  • The AI administrator, AI assistants, AI analytics, and receipt image processing.
  • Telegram, Instagram, and WhatsApp connections and forwarding to a User-selected n8n endpoint if enabled.
  • Payment for Sirekees access, payment status checks, and mandatory financial records.
  • Client payments to the Business through connected FreedomPay and Google Wallet pass creation if enabled by the owner.
  • Support, initial setup at the User's request, troubleshooting, and responses to requests.
  • Security, request rate limits, fraud prevention, incident investigation, and protection of rights.
  • Compliance with law and valid requests from authorized authorities.
  • Aggregated analytics and Platform improvement. Marketing messages are sent only with any consent required by law and a way to opt out.

5. Grounds for processing

Depending on the person, country, and feature, data is processed to enter into or perform a contract, on the basis of consent, to comply with law, or for legitimate interests in security, abuse prevention, and protection of rights where that ground is available under applicable law.

The Business owner is responsible for choosing the ground for its Clients' data, its privacy notice, and permissions for connected Channels. By putting that data into the Platform, the owner confirms that it may instruct Sirekees to process the data.

6. Data recipients and international transfers

Depending on the enabled features, data may be received by these providers and external parties:

  • Google Firebase - authentication, account identifier, and login data.
  • Supabase - the main PostgreSQL database, Storage for files and images, and Realtime updates; account, Business, Client, conversation, booking, order, and connection data is stored there. As of this Policy date, the linked primary database project is hosted in an EU region.
  • Vercel - application hosting, web request processing, and technical logs.
  • xAI - AI prompts and outputs, Business and conversation context, necessary booking or order details, and receipt images for enabled AI features.
  • Telegram - identifiers, messages, attachments, bot commands, notifications, and receipts transmitted through the Telegram Bot API.
  • Meta - connection, profile, and message data for Instagram Direct and official WhatsApp.
  • Green API - connection data and messages for the alternative WhatsApp connection if selected by the User.
  • YooKassa and Interkassa - creation and confirmation of payments for Sirekees access. They receive payment details directly; Sirekees receives the operation identifier, amount, currency, and status.
  • FreedomPay - Client payments to the Business if the owner enables payment acceptance. FreedomPay receives transaction data and necessary payer details; Sirekees receives the payment identifier and status.
  • Google Wallet - pass and loyalty program data if the Business enables pass issuance.
  • User-selected n8n endpoint - Telegram updates are forwarded to the address entered by the User only when this feature is enabled. The owner is responsible for the address, recipient, and further processing on its side.
  • Authorized personnel, advisers, and authorities - only where access is needed for support, security, protection of rights, or compliance with a mandatory legal request.

These providers may store and process data outside the Republic of Kazakhstan, including in countries where their infrastructure is located. Using the corresponding feature involves an international data transfer. Disclosing the foreign location does not replace mandatory local-storage requirements or prove compliance with them. Before adding Client data, the Business owner must verify whether the selected setup is permitted, tell Clients about the transfer, and obtain separate consent where required. Sirekees is separately reviewing and planning primary-storage infrastructure in Kazakhstan.

7. Retention and deletion

  • Account and Business data is retained while the account or Business is active and the data is needed to provide the Platform.
  • Conversations, bookings, orders, and Client data are retained under the Business owner's settings until Business deletion, a specific request, or another need determined by the owner and applicable law.
  • Disconnecting Telegram, Instagram, or WhatsApp stops new data collection and removes or invalidates connection data held by Sirekees, but it does not automatically delete prior conversations, bookings, or orders.
  • Deleting a Business removes its active record and linked operational records from the main database under the Platform's current logic. Uploaded files, technical logs, backups, and copies held by external providers may remain for a limited period until deletion, overwrite, or the end of the provider's retention period.
  • Financial documents and security, dispute, or support information may be retained longer only to the extent and for the period needed under applicable law, to protect rights, or to secure the Platform.

Channel disconnection, Business deletion, and full requests are explained on the Data Deletion page.

8. Rights and requests

To the extent available under applicable law, a data subject may:

  • Ask whether their data is processed and request access or a copy.
  • Correct inaccurate data.
  • Request restriction or deletion.
  • Withdraw consent where processing relies on consent.
  • Obtain information about how automated processing works and its possible consequences.
  • Object to automated processing and ask for human review where that right is provided by law.
  • Complain to an authorized supervisory authority.

An account owner sends a request from the registered email address to help@sirekees.com. A Business Client should first contact the Business owner. If the request needs action within Sirekees, the owner passes it to us. We may request information to verify identity and respond within the period required by applicable law.

9. Security

We use HTTPS/TLS for data in transit, database access controls, Row Level Security for user access, server-side access for privileged operations, request rate limits on critical routes, and role separation. Connection credentials are held in a separate server-side table with restricted access and are not returned in public Business requests. This description does not mean that every value is additionally encrypted by the application. No internet service can guarantee absolute security.

10. Cookies and local storage

  • Cookies and session markers - support login, security, and language selection.
  • LocalStorage on the device - may hold the cart, favorites, recent items, Client name, phone, address and comment, booking details, and AI editing history.
  • Technical logs and metrics - help secure the Platform, find errors, and understand aggregate load.

Cookies and LocalStorage can be cleared in browser settings. After clearing, the person may need to sign in again, and locally saved form, cart, and history data may be lost.

11. Children

The Business owner dashboard is not intended for persons under 16. The Business owner is responsible for lawful processing of minor Clients' data. If you believe a minor's data is processed without the necessary ground, contact the relevant Business or help@sirekees.com.

12. Policy changes

The current Policy is published at sirekees.com/legal/privacy with the revision date. We will give notice of material changes by email or within the Platform where practicable and required by applicable law.

13. Contact

For personal data questions, email help@sirekees.com or write to: 506 Seifullin Street, office 12, Almaty, Kazakhstan.

Privacy Policy | Sirekees