Privacy Policy - SecondBook

Effective Date: July 6, 2026
Last Updated: August 24, 2026
Version: 1.3
IMPORTANT: This Privacy Policy describes how we collect, use, store, and protect your personal data. By using SecondBook, you agree to the terms of this Policy.

1. General Provisions

1.1. Data Controller

The data controller is Ilnur Stybayev, an independent individual developer (not a legal entity) (hereinafter referred to as "Company", "Operator", "we", "us" — in all cases meaning this independent developer). 2ndBook is a non-commercial tool that lets users find and contact each other directly. The operator is not a party to any transaction between users, does not hold, transfer or retain funds, and charges no commission. Data protection contact: support@secondbook.kz.

1.2. Applicable Law

Personal data processing is carried out in accordance with:

1.3. Consent to Data Processing

By registering with SecondBook or using our service, you consent to the collection and processing of personal data under the terms set forth in this Policy. You may withdraw your consent at any time.

2. What Data We Collect

2.1. Data You Provide

Data Category Examples Purpose of Collection
Registration Data Name, email, phone number Account creation, identification
Profile Data Profile photo, city, description Personalization, display to other users
Transaction Data Handover address or meeting place, chosen settlement method ("cash", "directly to the seller") Arranging the handover of a book between users. We do not collect or store bank card details: the Service does not process payments — settlement happens directly between users
Date of Birth Day, month, year of birth Determining access to age-restricted content (16+/18+/21+); if not provided, access to such content is restricted by default
User Content Listings, book photos and covers, reviews, text messages, voice messages and video in chat, uploaded book files, podcast audio and video with their transcripts Service functionality
Reading Data Position in a book, time spent reading, books started and finished, reading-day streaks, bookmarks Syncing your progress across your own devices and showing your personal reading statistics
Verification Documents Only if you apply for bookshop-partner, author or legal-entity status: a passport or national ID card, a business/sole-proprietor registration certificate, articles of association and similar documents (the exact set depends on the form of registration). Full name, tax number or IIN, date of birth, address, country, date of issue and issuing authority are read automatically from the uploaded pages and stored Verifying the applicant's identity and their right to trade on the Platform. An ordinary user never needs these documents — not to register, and not to buy or sell a book

2.2. Data Collected Automatically

Data Category Examples Purpose of Collection
Technical Data IP address, device type, operating system, browser Technical support, security
Usage Data Pages viewed, search queries, time on site Service improvement, analytics
Location Data City, region (based on IP or with your consent) Showing relevant listings
On-device authorization token Session Bearer token (not a cookie) Authentication in the app and web app — see Section 7
Push notification data Firebase Cloud Messaging (Google) device token, platform (iOS / Android / web), device name Delivering notifications about messages, transactions and moderation. Notifications can be turned off in profile settings or in your device settings
Session data List of active sessions: device, sign-in time and last activity Account security and the ability to end another session

2.3. Data from Other Sources

We may receive data from the following sources:

3. Purposes of Personal Data Processing

We process your personal data for the following purposes:

3.1. Contract Performance

3.2. Legitimate Interests

3.3. With Your Consent

3.4. Legal Requirements

4. Sharing Data with Third Parties

4.1. Categories of Recipients

We may share your data with the following categories of recipients:

Recipient Purpose of Sharing Data Shared
Other Users Completing transactions, communication Name, city, rating, public content
Delivery Services Delivering goods Address, contact details
Cloud Providers Data storage All data (encrypted)
Google (Firebase Cloud Messaging, Firebase Crashlytics) Delivering push notifications and collecting app crash reports Device token, platform; on a crash — technical data about the device and the circumstances of the crash
Analytics Services Usage analysis Anonymized data
Government Authorities As required by law Upon request

4.2. Cross-Border Data Transfer

Your data may be transferred to and stored on servers outside the Republic of Kazakhstan. In such transfers, we ensure an adequate level of data protection in accordance with legal requirements.

4.3. We Do NOT Sell Your Data

We do not sell users' personal data to third parties for their marketing purposes.

5. Data Storage and Protection

5.1. Retention Periods

Data Category Retention Period
Account Data Entire period of service use; when you delete your account, personal data is permanently deleted (see 6.3), except records the law requires us to keep longer (e.g. transaction data, below)
Transaction Data 5 years (tax legislation requirements)
Chat Messages As long as the conversation is active or either participant's account still exists; if you delete your account, your messages are anonymized (sender name removed) but the text remains visible to the other participant
Deleted book listings 30 days in "Archive" status (restorable by the owner), then permanent automatic deletion
Verification Data 1 year after confirmation
Logs and Technical Data 1 year
Marketing Consents Until consent is withdrawn

5.2. Security Measures

We apply the following measures to protect your data:

5.3. Incident Notification

In the event of a data breach that may pose risks to your rights and freedoms, we will notify you and the relevant government authorities within 72 hours of discovering the incident.

6. Your Rights

You have the following rights regarding your personal data:

6.1. Right of Access

You have the right to obtain confirmation of whether we process your data, as well as to receive a copy of your personal data.

6.2. Right to Rectification

You have the right to request correction of inaccurate or incomplete data about you.

6.3. Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal data if:

6.4. Right to Restriction of Processing

You have the right to request restriction of processing of your data in certain cases.

6.5. Right to Data Portability

You have the right to request a copy of your personal data in a readable format. We prepare this manually on request via support; a self-service automated export (e.g. a "download my data" button in the app) is not yet implemented.

6.6. Right to Object

You have the right to object to the processing of your data for direct marketing purposes at any time.

6.7. Right to Withdraw Consent

If processing is based on your consent, you may withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.

6.8. Right to Lodge a Complaint

You have the right to lodge a complaint with the supervisory authority for personal data protection if you believe your rights have been violated.

6.9. How to Exercise Your Rights

To exercise your rights, you may:

We will respond to your request within 30 calendar days.

7. Cookies and Similar Technologies

SecondBook does not use cookies for tracking, analytics, or advertising. The web app and mobile apps use a device-stored authorization (Bearer) token, not cookies, to manage your session. Technical session cookies may only be set on internal administrative interfaces, not reachable by regular users. Because no non-essential cookies are used, no cookie consent banner is required or shown.

8. Children and Age-Restricted Content

SecondBook is not intended for children under 14 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us with their data, please contact us and we will delete this information.

Users aged 14 to 18 may use the service with the consent of parents or legal guardians.

8.1. How Age Restriction Works

Some books in the catalog carry an age rating (16+, 18+ or 21+). Access to such content (in the catalog, search, book detail, cover and images, gifting, exchange, lending, and the book card in chat) is determined by the date of birth the user has entered in their profile settings.

9. Changes to the Policy

9.1. Amendment Procedure

We may update this Policy. We will notify you of material changes at least 30 days before they take effect.

9.2. Version History

Previous versions of the Policy are available upon request.

10. Additional Information for EU Users (GDPR)

If you are located in the European Union, additional rights and guarantees under GDPR apply to you:

10.1. Legal Bases for Processing

10.2. EU Representative

If you have questions regarding data processing under GDPR, contact us at: support@secondbook.kz

11. Contact Information

SecondBook

Address: Republic of Kazakhstan, Almaty

Privacy Email: support@secondbook.kz

GDPR Requests Email: support@secondbook.kz

General Support: support@secondbook.kz

Website: secondbook.kz

© 2026 SecondBook. All rights reserved.