Privacy Policy for Dostavix Courier App

Effective date: June 29, 2026
This Privacy Policy explains how Dostavix Limited Liability Company processes personal data in connection with the Dostavix courier mobile application (the App). The App is intended for couriers and delivery personnel who use Dostavix services to receive, manage, and complete delivery orders.
Operator: Limited Liability Company "Dostavix" (Dostavix LLC), taxpayer identification number (INN) 6320073390, address: room 3, building 14, 40 Let Pobedy street, Tolyatti, Samara Region, 445047, Russian Federation. Contact email: info@dostavix.com.
App name: Dostavix. Android package: pro.aeroapps.samuraicourierapp.

1. Data We Collect and Process

Depending on how the App is used, we may collect and process the following categories of data:
  • courier account and authentication data, including username, password submitted during login, authentication token, profile data, courier identifier, first name, phone number where available, department, city, roles, and account status;
  • precise and approximate location data, including latitude and longitude used to support courier delivery tracking;
  • order and delivery data, including order identifiers, order status, delivery stage, delivery address, department, delivery time, customer name and phone number visible to the courier for order performance, payment type, order totals, and delivery-related comments;
  • push notification data, including Firebase Cloud Messaging tokens and notification delivery metadata;
  • diagnostics and crash data, including app version, device and operating system information, crash traces, logs, and technical identifiers processed through Firebase Crashlytics and related diagnostic services;
  • device, network, and app metadata needed to operate the App, maintain security, check connectivity, provide updates, and prevent misuse.
The App may store authentication data, including an authentication token and login credentials, locally on the device to keep the courier signed in and to support App operation. Local data is protected by the mobile operating system application sandbox. Couriers should keep their devices secured and should not share their account credentials.
When a courier chooses to call a customer, operator, or office from the App, the App opens the device phone dialer with the relevant phone number. The App does not request access to call logs and does not record phone calls.

2. Background Location Use

The App collects location data to enable courier delivery tracking and operational order management. This includes collecting and sending precise location data while the courier is performing delivery work, including when the App is closed, running in the background, or not actively in use.
Background location is necessary so dispatchers and Dostavix systems can understand courier availability, monitor delivery progress, support timely delivery, and resolve operational incidents. The App requests location permission from the user. If the required location permission is denied, location-based courier functions may be unavailable.
Location data is transmitted to Dostavix backend systems using the courier account authentication token. The App does not collect location data for advertising, does not sell location data, and does not use location data to build advertising profiles.
Background location and background fetch services may run on the device to support location updates, restart tracking after device reboot where permitted by the operating system, and keep delivery operations available during active courier work. These background services are used for delivery operations only.

3. Purposes of Processing

We process data for the following purposes:
  • authenticating couriers and maintaining secure sessions;
  • assigning, displaying, accepting, updating, and completing delivery orders;
  • showing delivery addresses and enabling phone calls needed to complete orders;
  • supporting route and navigation actions opened by the courier;
  • tracking courier location for delivery operations and service quality;
  • sending operational push notifications about orders and account events;
  • providing technical support, troubleshooting, diagnostics, and crash analysis;
  • maintaining security, preventing misuse, and protecting Dostavix systems;
  • complying with legal, accounting, tax, employment, and contractual obligations.

4. Legal Basis

We process personal data where it is necessary to perform courier-related agreements and operational tasks, where processing is required by law, where processing is necessary for legitimate operational and security interests, or where the courier has provided consent, including through App permissions.

5. Sharing and Service Providers

We do not sell personal data. We may disclose or provide access to data only as needed for the purposes described in this Policy:
  • to Dostavix backend infrastructure and authorized Dostavix personnel who operate delivery, support, security, and administrative processes;
  • to Google Firebase services, including Firebase Cloud Messaging for push notifications and Firebase Crashlytics for crash diagnostics;
  • to map or navigation applications, such as Yandex Navigator, Google Maps, or 2GIS, only when the courier chooses to open a route or navigation link;
  • to hosting, infrastructure, analytics, security, and technical service providers acting under our instructions;
  • to government authorities, courts, or other parties where disclosure is required by applicable law or necessary to protect legal rights.

6. Data Retention

We retain personal data for as long as needed to provide the App, manage the courier account, perform delivery operations, resolve disputes, maintain security, and comply with legal obligations. Operational records may be kept for the duration of the courier relationship and for additional periods required by applicable law, accounting rules, tax rules, employment or contractor documentation requirements, and limitation periods.
  • account, authentication, and courier profile records are retained while the courier account or courier relationship remains active and then for the periods required to resolve disputes, prove service performance, maintain security, and comply with legal obligations;
  • location records are retained as operational delivery records for the period needed to manage deliveries, verify order performance, investigate incidents, support customer or courier claims, and satisfy legal or contractual duties;
  • order, address, customer contact, payment, and status data are retained as business records for delivery operations and for legally required accounting, tax, reporting, dispute, and limitation periods;
  • push notification tokens are retained until logout, token replacement, account deactivation, technical expiry, or until they are no longer needed to deliver operational notifications;
  • crash, diagnostic, and technical logs are retained for the period needed to troubleshoot incidents, improve stability, maintain security, and comply with service provider retention settings.
Push tokens are deleted or invalidated when they are no longer needed, such as after logout or token replacement. Diagnostic data is retained according to the retention settings of the relevant diagnostic service and our operational needs. Local App data can be removed by logging out where the App supports it, clearing App data, or uninstalling the App.

7. Security

We use organizational and technical measures designed to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction. These measures include access controls, authentication, role restrictions, infrastructure security practices, and encrypted transmission where supported by the relevant systems. No method of transmission or storage is completely secure, so we continuously review and improve our protection measures.

8. User Choices and Rights

Couriers can manage App permissions through device settings. Disabling location or notification permissions may limit or prevent use of courier features that depend on those permissions.
Subject to applicable law, users may request access to their personal data, correction of inaccurate data, restriction or termination of processing, deletion of data, information about processing, or withdrawal of consent where processing is based on consent. Requests can be sent to info@dostavix.com. We may need to verify the requester's identity before fulfilling a request.

9. Children

The App is intended only for couriers and delivery personnel authorized to work with Dostavix delivery operations. It is not intended for children and is not directed to users under the age required by applicable law to perform courier work.

10. International Processing

Data may be processed using infrastructure and service providers located in different jurisdictions. Where cross-border processing occurs, we take steps required by applicable law to protect personal data and to ensure that service providers process data only for authorized purposes.

11. Google Play Data Safety

This Policy is intended to be consistent with the Google Play Data safety disclosures for the App. The Data safety section in Google Play should reflect the same categories of collected, shared, and processed data, including location, account, app activity, diagnostics, device identifiers, and operational order data where applicable.

12. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will publish the updated version on this page and update the effective date where appropriate. Continued use of the App after publication of an updated Policy means that the updated Policy applies to further processing.

13. Contact

For privacy questions, data requests, deletion requests, or complaints, contact Dostavix LLC by email at info@dostavix.com or by mail at: room 3, building 14, 40 Let Pobedy street, Tolyatti, Samara Region, 445047, Russian Federation.