PRIVACY POLICY
Version dated 20 August 2026.
1. GENERAL PROVISIONS
1.1. This Privacy Policy (hereinafter referred to as the "Policy") regulates the procedure for processing and protecting personal data of users collected during the use of the Meiman online booking service (hereinafter referred to as the "Service"), including the meiman.kg website and the Meiman mobile applications for Android and iOS.
1.2. The data controller is Meimo LLC, Kyrgyz Republic.
1.3. By using the Service, the user agrees to the terms of this Policy.
1.4. This Policy forms an integral part of the User Agreement published at meiman.kg/terms.
2. WHAT DATA DO WE COLLECT
2.1. Data provided by the user:
full name, phone number, email address;
profile photo and, for partners, photos and descriptions of the listed properties;
booking data (property, dates, number of guests, booking comments);
support requests and messages in the Service chat.
2.2. Payment data. Payments are processed on the side of payment providers. The Service does not store bank card numbers or payment credentials; we receive and store only the status, amount and parameters of a transaction as required to confirm bookings and process refunds.
2.3. Automatically collected data:
IP address, operating system type and version, device type, interface language, application version;
information about the user's actions on the website and in the mobile application: property views, search queries, completed bookings;
location data — only with the user's explicit permission, to search for properties on the map and near the user;
cookies and similar technologies on the website;
crash and error reports of the application, including the technical state of the device at the time of the failure.
2.4. Technical identifiers. In order to link the actions of a single user together and avoid counting one person as several, the Service assigns pseudonymous identifiers to the device and to the visitor. These are randomly generated values; on their own they contain no name, phone number, email address or other information that would directly identify a person:
the device identifier and the visitor identifier are persistent and are retained between sessions and application launches;
the session identifier is regenerated after 30 minutes of inactivity;
the visitor identifier may be shared between the website and the mobile application so that moving from the website to the application is not counted as a new visitor.
The Service does not collect or use the Android Advertising ID.
2.5. Referral and campaign data (marketing attribution). When a user arrives at the Service through a link, we store the parameters of that link in order to understand which channels bring users in and to correctly account for partner and referral traffic:
partner code — stored for up to 90 days from the first visit;
UTM parameters, click source and click identifier — stored for up to 30 days from the most recent visit.
For the mobile application, information about the install source is provided by the application store (Google Play).
3. PURPOSES OF DATA PROCESSING
3.1. We use the data for the following purposes:
providing booking services;
contacting the user regarding booking issues;
operating the Service: authentication, push notifications, chat between guest and partner;
analytics and improvement of the Service — understanding how users find and book accommodation;
marketing attribution — accounting for partner, referral and advertising traffic;
diagnosing failures and maintaining the stability of the application;
preventing fraud and ensuring the security of the Service;
complying with legal requirements;
sending marketing notifications with the user's consent. The user can opt out of receiving such notifications at any time.
3.2. The Service does not make decisions producing legal effects concerning the user solely on the basis of automated processing.
4. LEGAL BASIS FOR DATA PROCESSING
4.1. Personal data processing is carried out in accordance with the legislation of the Kyrgyz Republic and includes the following legal bases:
user consent;
necessity for the performance of a contract (including making a booking);
compliance with legal requirements;
ensuring the security of the Service and preventing abuse.
5. DATA STORAGE AND PROTECTION
5.1. Data is stored for 5 years or until the account is deleted.
5.2. Retention periods for technical identifiers and marketing parameters are set out in clauses 2.4 and 2.5 of this Policy. When an account is deleted, the information that identifies the user (first name, last name, phone number) is permanently removed from the database, the pseudonymous visitor identifiers are reset, and information about the user's actions, transactions and bookings is retained in de-identified form. The deletion procedure is described at meiman.kg/articles/service/account-deletion.
5.3. Data is transmitted between the application, the website and our servers over a secure connection (HTTPS/TLS).
5.4. We apply modern data protection methods to prevent leaks and unauthorized access.
6. USER RIGHTS
6.1. The user has the right to:
obtain information about their data;
correct, delete, or restrict the processing of data;
withdraw consent to process data;
file a complaint with the regulatory authority.
6.2. An account and the data associated with it can be deleted by the user in the mobile application, or by sending a request to customer support using the contacts below. The deletion procedure, together with the list of data that is deleted and the data that is retained in de-identified form, is described at meiman.kg/articles/service/account-deletion.
7. DISCLOSURE OF DATA TO THIRD PARTIES
7.1. We may disclose data to:
partners involved in providing services (hotels, property owners, payment systems);
government authorities upon request in accordance with the law.
7.2. We also engage technical service providers that process data on our behalf, in our interest and only to the extent required for the operation of the Service:
Google — application crash reports, push notification delivery, maps and address search, application install source data;
Branch — handling of invitation links and links into the application;
payment providers — processing payments and refunds;
hosting and analytics providers — storage and processing of de-identified information about user actions.
7.3. We do not sell personal data and do not disclose it to third parties for their own advertising purposes.
8. MOBILE APPLICATION AND DEVICE PERMISSIONS
8.1. The application requests device permissions only when they are needed and at the moment the corresponding feature is used:
location — searching for properties on the map and near the user;
camera and photo access — uploading property and profile photos;
notifications — booking status updates and new chat messages.
8.2. Declining a permission does not block the use of the Service, except for features that cannot work without that permission.
8.3. Information about the data collected by the mobile application is additionally published in the "Data safety" section of the application's Google Play listing and is consistent with this Policy.
9. CHANGES TO THE POLICY
9.1. We may update the Policy and notify users of significant changes.
9.2. The current version and its effective date are always available at meiman.kg/privacy.
CONTACT INFORMATION
For questions related to the operation of the Service, processing of personal data, or exercising user rights, you can contact us through the following channels:
Phone / WhatsApp: +996 550 993 993
Phone (calls): +996 503 993 993
Email: [email protected]