Privacy Policy for the iOS Application

This policy describes how the AstraCRM iOS app handles data, and follows App Store requirements and iOS privacy rules.

Last updated: July 2026

1. Introduction

This document explains what the AstraCRM iOS app collects and what happens to it. By using the app you accept the handling described here. The app is built for field technicians at service companies: orders, client information, photo reports, and staying in touch with the office.

2. What We Collect

The app collects: • Account data: name, email, phone, and other contact details you provide at registration • Device data: model, iOS version, and connection type, so the app runs reliably • Sign-in data: session tokens for secure access • Photos: the shots you take with the camera or pick from the library to attach to an order or set as an avatar • Usage data: which screens you open and which features you use • Push tokens: the device identifier used to deliver notifications, only if you granted permission • Crash reports: technical error data through our own self-hosted Sentry

3. Why We Use It

The data is there so that: • The app does its job: orders, clients, schedule, contact with the office • Sign-in is secure and nobody reaches data they should not see • Notifications about new and changed orders reach you • Photos land on the right order and are visible back at the office • We can find and fix bugs • Support can make sense of your request

4. Who We Share Data With

We do not sell data and do not hand it to third parties for their own purposes. Data leaves the app in three cases only. Inside your organization. Orders, photos, and messages are visible to colleagues according to their permissions. Contractors the app cannot run without: • Selectel: servers and object storage for photos and attachments. The data centers are in Russia • Timeweb Cloud: the content delivery network that serves images through temporary signed links • Expo: push notification delivery When the law requires it: if a court, an investigator, or another government body requests data within its authority. Error monitoring runs on our own self-hosted Sentry, so crash reports never leave it.

5. How We Protect Data

What is actually in place: • All traffic between the app and the server runs over TLS • Photos and files live in private storage with no public bucket access, and links are temporary and signed • Sign-in uses session tokens, with two-factor authentication and Face ID or Touch ID via passkeys • Data access is limited by roles inside your organization • Security updates on a regular cadence No system is perfectly secure, and we do not claim otherwise.

6. Your Rights

Regarding your own data you can: • Find out what we hold about you • Correct inaccuracies in the app settings • Request deletion of your account and the data attached to it • Manage push notifications in iOS Settings or in the app • Delete or replace photos you uploaded • Export your data in a machine-readable format Write to privacy@astracrm.pro or use the app settings.

7. Privacy on iOS

The app follows the platform rules: • Camera: permission is requested only when you take a photo for an order. iOS Settings, Privacy & Security, Camera • Photo library: permission is requested only when you attach an existing photo. iOS Settings, Privacy & Security, Photos • Push notifications: iOS Settings, Notifications, AstraCRM Mobile • No location tracking: the app does not request location access and does not track where staff are • No cross-app tracking: we use no advertising identifiers and show no App Tracking Transparency prompt • Background activity: receiving notifications and syncing your orders, nothing else • Over-the-air updates (Expo OTA): the app can pull new code and assets from our servers. No personal data is transmitted during that

8. Third-Party Services

The app works with these services: • Selectel: servers and storage for photos and files • Timeweb Cloud: the content delivery network for fast image delivery • Expo Push Notifications: delivering order notifications • Apple App Store: app distribution and updates Each has its own privacy policy, worth reading. We pass along only the minimum a given feature cannot work without. Error monitoring is not outsourced: Sentry runs on our own servers.

9. How Long We Keep Data

Retention works out as: • Account: while the account is active • Orders and photos: while your organization uses them • Technical logs: up to 30 days • Crash reports: up to 90 days After deletion, data disappears from our systems within 30 days.

10. Children

The app is built for work and is not intended for anyone under 17. We do not knowingly collect their data. If you are a parent or guardian and believe your child's data reached us, write to privacy@astracrm.pro.

11. Changes to This Policy

The policy is updated from time to time. We announce material changes by: • Publishing the new version in the app and on the website • Updating the date at the top of this document • Showing an in-app notice when the change matters It is worth checking back now and then.

12. Contact Us

For questions about your data: Privacy email: privacy@astracrm.pro Support: support@astracrm.pro Website: https://astracrm.pro Postal address: 164500, Severodvinsk, Karla Marksa St., 46, office 12 For App Store matters you can also reach us through App Store Connect or at the email above.

This policy describes how the AstraCRM iOS app handles data, and follows App Store requirements and iOS privacy rules.