Revision of · 20.09.2026
1Who controls the data
Personal data in the tezfin app and on tezfin.uz is controlled by tezfin LLC, Tashkent, Republic of Uzbekistan. Processing follows Law of the Republic of Uzbekistan No. ZRU-547 "On personal data".
tezfin is a personal finance tracking and financial-passport app. Loans are issued by microfinance organisations under their own contracts; tezfin is not a lender and does not take deposits.
2What this covers
The tezfin mobile app, the tezfin.uz website, and the forms you use to send us applications and enquiries.
The microfinance and merchant cabinets are separate products for the staff of those organisations. Data handling there is governed by the contracts with those organisations, not by this document.
3What we collect
The list is exactly this and nothing more:
- Account details: email address, phone number, the name you entered yourself, and date of birth. The date of birth is self-declared and not confirmed against a document — the product has no document-verification step.
- Financial-passport questionnaire answers: income source and amount, income currency, employment sector, social status, housing type, rent amount, household size and number of dependants. Sector and status are stored as dictionary codes, not free text.
- Ledger entries: income and expenses with amounts and dates, categories, recurring plans, cost centres, goals and your own notes on them.
- Loan details: the ones you entered yourself (lender name, amounts, schedule) and the ones sent in by the microfinance organisation your account is linked to.
- A credit-bureau summary — bureau score, longest overdue period, number of open disputes. Those three numbers reach the account by upload; the app itself does not query KATM/KIAC.
- The financial-passport score on the 300–850 scale and the components computed from everything above.
- Technical data: the device push-notification token, the platform (Android or iOS), the interface language and app version, and an irreversible fingerprint of the installation used for Telegram-bot sign-in.
We do NOT collect passport number, PINFL (JSHSHIR), bank card number, home address or employer name: the data schema has no field for any of them. Of your location only the country is stored, as a two-letter code.
4Consents and purposes
There are exactly six consents in the app, each its own switch:
- "Processing of personal data" — mandatory: the account does not work without it. It cannot be withdrawn on its own; you can delete the account instead.
- "Credit history request (KATM/KIAC)" — optional, withdrawable. Withdrawal deletes the bureau summary from your account immediately.
- "Building and sharing the scoring result with partners" — optional, withdrawable.
- "Cross-border processing of anonymised analytics" — optional, withdrawable.
- "Marketing and notifications" — optional, withdrawable. Withdrawal deletes your devices’ push tokens immediately.
- "Shared household budgeting" — optional, withdrawable.
No consent is pre-ticked. Every acceptance and every withdrawal is recorded together with the purpose, the revision of the text, the date, the interface language and the app version. The consent log cannot be rewritten after the fact — that is enforced by the database itself.
5Who we share with
Data leaves tezfin only in these cases:
- Apple and Google — if you take part in the closed test of the app: your email address goes to TestFlight or Firebase App Distribution so an install invitation can be issued.
- Google Firebase Cloud Messaging — push delivery: your device token and the notification text. The notification carries none of your data: the text is fixed and the event type is a short code.
- Delivery services — Resend for email, and Eskiz or Play Mobile for SMS. They receive the address or number and the message text, including the one-time code.
- Telegram — only if you use tezfin bot sign-in. You hand your phone number to Telegram yourself, by pressing its "share contact" button.
- Microfinance organisations and partners — the score, under the "Building and sharing the scoring result with partners" consent. The link between your account and an organisation is stored as a pointer, without your phone number: the organisation sees its own record of you, not an export from tezfin.
- Our support team — when you send an application for a partner product yourself: the enquiry carries what you wrote in it, including the contact detail you gave there.
Cross-border transfer is a separate consent, and today no live scenario performs one. Other members of a shared household budget see your entries only under the "Shared household budgeting" consent; withdrawing it closes the access.
6What we never do
These statements rest on how the system is built, not on a promise:
- Passport number, PINFL and card number can be neither stored nor shared: there is no field for them.
- One-time codes and link tokens are never stored as such — only as an irreversible fingerprint with a secret pepper. A code cannot be reconstructed from the database.
- You are absent from logs and counters: phone numbers and addresses pass through masking, and counter labels are the route, the outcome and the response code — never your identifier.
- We do not sell personal data and do not pass it to ad networks. The product carries no third-party analytics or crash-reporting SDK. The merchant you buy from in instalments never sees you — a dedicated build check enforces that.
7The tezfin.uz website
The site works without a login and without tracking:
- The `locale` cookie remembers the language you chose. One more cookie is set only in the invite-based registration flow, so a single invitation cannot be spent twice.
- The server counts page requests: route, method and response code. Who made the request is not recorded in those counters.
- The visitor IP address is passed to the gateway to rate-limit requests and stop automated form abuse.
The site carries no web-analytics counters, ad pixels or third-party scripts: the content security policy forbids the browser from loading foreign code.
8How long we keep it
The periods that actually apply:
- While the account exists, the account data is kept. A questionnaire answer you withdraw is deleted straight away.
- After the account is deleted, what cannot lawfully be erased is retained for 5 years — 1825 days from the day of deletion. That is the consent log, the score history, the ledger edit history, the links to microfinance organisations and the sign-in log.
- A one-time code lives for 5 minutes, is spent by the first correct entry and allows no more than five attempts.
- Service records of Telegram-bot sign-in clear themselves: challenges after one day, service marks after two.
Withdrawing a consent starts erasure of the related data at whoever holds it, within 30 days. Locally the withdrawal acts at once: "Credit history request" deletes the bureau summary, "Marketing and notifications" deletes the push tokens.
9How we protect it
Measures that are always on:
- Traffic to the app and the site runs over TLS only, through a gateway that rate-limits requests.
- Sign-in is confirmed by a one-time code; codes, invite tokens and device fingerprints are stored only as an irreversible fingerprint with a secret pepper.
- The consent log, the score history, the ledger edit history and the deletion journal are protected from rewriting by the database itself.
- Operator-initiated account deletion is off by default. When it is switched on it requires a stated reason and lands in a separate immutable journal.
10Your rights
Under ZRU-547 you may:
- learn what data of yours we hold and receive a copy of it;
- correct inaccurate data — account details, questionnaire answers and ledger entries are editable right in the app;
- withdraw any consent except the mandatory one, in the app, in the consent section;
- delete the account, from the app; the procedure is described on a separate page.
The mandatory consent to personal-data processing cannot be withdrawn on its own: the account does not work without it. The only way to stop the processing is to delete the account.
11Age
A tezfin account can be opened only from the age of 18: registration requires a date of birth, and the full 18 years are counted against the civil date in Tashkent. There are no accounts for children or teenagers in the product.
12Changes to this document
A new revision is published on this same page, with the revision date at the top. If the wording of a consent changes, the app asks you to confirm it again: every consent is recorded together with the revision of the text it was given under.
13How to reach us
Requests are answered by tezfin LLC. If you disagree with how we handled your request, you may approach the authorised state body for personal-data protection of the Republic of Uzbekistan.
Personal-data requests, questions about these documents and account-deletion requests are handled by tezfin LLC at compliance@tezfin.uz. Include the email address or phone number the account was opened with — otherwise we cannot identify you.