Privacy Policy – AR Malik Seeds

Version: 2.0 Effective Date: June 11, 2026 Last Updated: June 11, 2026

1. Introduction and App Identification

This Privacy Policy describes how A R Malik Seeds Pvt. Ltd. ("we," "our," or "the Company") collects, uses, stores, and protects personal information when you use the AR Malik Seeds mobile application (the "App" or "Service"), available on Google Play.

App Details:
App Name: AR Malik Seeds
Developer / Publisher: A R Malik Seeds Pvt. Ltd.
Contact: it@malikseedsbd.com

The App serves two distinct user groups:

By using the App, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the App. This policy is publicly accessible at a non-gated URL and is written in plain language as required by Google Play's Developer Programme Policies.

2. Data at a Glance

The table below is a quick-reference summary of every data type this App handles. It is designed to align with the Google Play Data Safety form declarations in our Play Console.

Data Type Collected? Shared with Third Parties? Encrypted in Transit? User Can Delete?
Precise Location (GPS)
Field staff only
Yes No Yes (TLS) Yes — on request
Phone Number
Account identifier, OTP delivery
Yes No Yes (TLS) Yes — account deletion
Employee ID
Field staff only
Yes No Yes (TLS) Yes — on request
SMS Content (OTP only)
Processed in memory — never stored
In memory only Never Not transmitted N/A — not retained
Device ID / Device Info
Model, OS version, battery, network
Yes Firebase (crash logs) Yes (TLS) Yes — account deletion
App Activity / Usage Data
Session info, feature usage, error logs
Yes Firebase Analytics Yes (TLS) Yes — on request
Crash and Diagnostics Data Yes Firebase Crashlytics Yes (TLS) Yes — on request
Google Advertising ID (GAID)
Via Firebase Analytics
Yes Google (Firebase) Yes (TLS) Yes — Android Ads Settings
FCM Push Token
Notifications only
Yes Firebase FCM Yes (TLS) Yes — account deletion
Call Log Data Not collected N/A N/A N/A

3. Prominent Disclosure: Location Data Collection

Before requesting any location permission, the App displays a clear in-app disclosure screen. You must acknowledge this disclosure before the Android OS permission prompt is shown. The disclosure states the following:

Your control: You may revoke location permission at any time via Device Settings → Apps → AR Malik Seeds → Permissions → Location. Revoking permission will prevent the attendance and route-tracking features from functioning.

4. Prominent Disclosure: SMS Access and OTP Authentication

The App uses a One-Time Password (OTP) authentication system as its primary login method. Before requesting any SMS permission, the App displays a clear in-app disclosure screen. You must acknowledge this disclosure before the Android OS permission prompt is shown. The disclosure states the following:

Your choice: SMS permission is optional. If you deny or revoke it, the OTP code will still be delivered to your phone number by SMS and you can enter it manually. The App will never block login solely because SMS permission is not granted.

5. Information We Collect

5.1 Account and Identity Information

5.2 SMS Data — OTP Authentication Only

With your permission, the App accesses a narrowly scoped subset of SMS data for the sole purpose of OTP-based authentication:

Important: No SMS message content is ever stored locally or on any server. SMS processing is entirely transient, in-memory, and non-aggregated.

5.3 Location Data (Field Staff)

Location data is collected in the foreground and, for field staff with background tracking enabled, continuously in the background. See Section 13.

5.4 Device and Technical Information

5.5 Firebase Push Token (FCM)

A unique token issued by Firebase Cloud Messaging (FCM) is collected and stored to enable push notifications, including OTP delivery confirmations, operational alerts, and order or service updates.

5.6 Analytics and Usage Data

Via Firebase Analytics, we collect anonymised usage signals including: app session durations, feature engagement, screen flow data, and error events. See Section 10 for full Firebase disclosure and opt-out options.

5.7 Crash and Diagnostics Data

Via Firebase Crashlytics, we collect crash reports, stack traces, and device state at the time of a crash. This data does not include personally identifiable information and is used solely to diagnose and fix bugs.

6. How We Use Your Information

Purpose Data Used Who It Applies To
OTP Authentication — verify identity at login without a password Phone number, SMS OTP content (transient) All users
Location Tracking — attendance, route verification, duty monitoring GPS coordinates, timestamps Field staff only
Push Notifications — operational alerts, OTP confirmations, service updates FCM token All users
App Performance — diagnose crashes, fix bugs, improve stability Crash logs, device info All users
Analytics — understand feature usage, improve the App Usage data, GAID (anonymised) All users
Account Security — detect and prevent unauthorised access Device ID, phone number, login metadata All users
Business Operations — field force management, farmer support Location history, employee ID Field staff / assigned roles
Legal and Regulatory Compliance Account data, location records As required

We do not use any of your data for advertising, profiling for sale, or any purpose not listed in the table above. We operate on a strict purpose limitation principle: data collected for one purpose is not reused for a different purpose without new consent or a clear legitimate basis.

7. Legal Basis for Processing Your Data

For users in the European Union (and as a matter of global best practice), every data processing activity is grounded in one or more of the following legal bases under GDPR Article 6:

Data Type Legal Basis Explanation
Phone number (account creation) Contract (Art. 6(1)(b)) Necessary to provide the Service and deliver OTP codes to your registered number.
SMS OTP content Consent (Art. 6(1)(a)) You grant SMS permission explicitly. You may revoke it at any time.
Location data (field staff) Contract / Legitimate Interest (Art. 6(1)(b)(f)) Necessary to fulfil the operational tracking obligations agreed in your employment terms.
Device information Legitimate Interest (Art. 6(1)(f)) Necessary for App security, account integrity, and technical diagnostics. Not overridden by user rights.
Analytics and usage data Legitimate Interest (Art. 6(1)(f)) Used to improve App performance and user experience. Anonymised where possible.
Crash and diagnostics data Legitimate Interest (Art. 6(1)(f)) Necessary to identify and fix software errors that affect service reliability.
Google Advertising ID (GAID) Consent (Art. 6(1)(a)) Collected by Firebase Analytics. Governed by Google's Terms. You may opt out via Android Ads Settings.
Data shared with authorities Legal Obligation (Art. 6(1)(c)) When required by law, court order, or regulatory demand.

For users in Bangladesh, processing is conducted in accordance with the Bangladesh Cyber Security Act 2023 and applicable data protection norms.

8. Data Storage, Retention, and Deletion

8.1 Local (On-Device) Storage

The following data is stored locally on your device:

SMS content is never stored locally. OTP processing is entirely in-memory and leaves no trace on the device.

8.2 Server Storage

The following is stored on our secured servers:

No SMS content — including OTP messages — is ever stored on our servers.

8.3 Retention Periods

Data Type Retention Period Basis for Retention
SMS / OTP content Not retained — discarded immediately after login Data minimisation principle
Account data (phone, profile) Duration of active account; deleted within 30 days of account deletion request Contract
Location history As required by operational needs; deleted on account deletion or request Legitimate interest (field management)
Device and usage data Up to 12 months; anonymised after 90 days Legitimate interest (app improvement)
Crash logs (Crashlytics) Up to 90 days per Firebase Crashlytics policy Legitimate interest (bug fixing)
FCM push tokens Active account lifetime; deleted on account deletion Contract (notification delivery)

8.4 Data Minimisation

We collect only the minimum data necessary for each stated purpose. Data that is no longer needed is deleted or anonymised promptly. SMS content is the clearest example of this principle: we read it, use it once, and discard it without any storage.

9. Data Sharing and Third-Party Service Providers

9.1 What We Share and With Whom

We do not sell, rent, or trade your personal data. We share limited data with the third-party services listed below solely to operate the App. SMS data is never shared with any third party under any circumstances.

Service Provider Data Shared Purpose Privacy Policy
Firebase Analytics Google LLC App usage events, session data, device info, GAID App usage analysis and improvement policies.google.com/privacy
Firebase Crashlytics Google LLC Crash reports, stack traces, device state at crash time. No PII beyond device metadata. Bug diagnosis and app stability firebase.google.com/support/privacy
Firebase Cloud Messaging (FCM) Google LLC FCM device token only. No message content is accessed by Google. Delivering push notifications to your device policies.google.com/privacy
Google Play Services Google LLC Device identifiers, location services API Location API infrastructure, device functions policies.google.com/privacy

9.2 Firebase SDK Data Practices — Detailed Breakdown

Firebase Analytics

Firebase Analytics collects the following automatically:

Firebase Analytics data is processed by Google LLC on servers that may be located outside Bangladesh. Google acts as a data processor under its Firebase Data Processing Terms.

Firebase Crashlytics

Crashlytics collects the following when a crash occurs:

Crash data is retained by Firebase Crashlytics for up to 90 days.

Firebase Cloud Messaging (FCM)

FCM only receives your device's push token in order to deliver notifications to your specific device. Google does not have access to the content of notifications sent through FCM. We do not use FCM for advertising.

9.3 Business Transfers

In the event of a merger, acquisition, or asset sale, your data may be transferred to the successor entity. You will be notified via in-app notice and/or email (if available) before your data becomes subject to a different privacy policy.

9.4 Legal Disclosure

We may disclose your data if required by applicable law, court order, or a binding request from a government authority. We will notify you of such requests where legally permitted to do so.

10. Google Advertising Identifier (GAID) and Analytics Opt-Out

10.1 What Is the Google Advertising ID?

The Google Advertising ID (GAID), also called the Android Advertising ID (AAID), is a resettable identifier assigned by Google to your Android device. The AR Malik Seeds App uses Firebase Analytics, which automatically reads the GAID to produce anonymised usage analytics and to attribute app installs and events across sessions.

10.2 How We Use It

The GAID is used solely by Firebase Analytics for aggregated, anonymised app usage reporting. We do not use it for behavioural advertising, retargeting, cross-app profiling, or any purpose beyond understanding how the App is used in aggregate.

We do not run paid advertising campaigns using the GAID collected through this App. The GAID is used purely for first-party analytics to improve the App experience.

10.3 How to Opt Out or Reset Your Advertising ID

You have full control over your Google Advertising ID:

10.4 Firebase Analytics Opt-Out

To disable Firebase Analytics data collection entirely for this App, you may:

11. SMS and Call Log Permissions: Complete Google Play Declaration

This section is a full and transparent disclosure of all SMS-related permissions declared in this App's Android manifest, provided in compliance with Google Play's Restricted Permissions policy and the Permissions Declaration Form requirements.

This App is NOT a default SMS handler.
The AR Malik Seeds App does not request, and has never requested, to be set as the user's default SMS or messaging application. It does not intercept, display, manage, or replace the user's standard SMS inbox. The App's use of SMS permissions is strictly limited to OTP-based user authentication as described below, which is a recognised permitted exception under Google Play's SMS Permissions Policy.

11.1 Permitted Exception Basis

Under Google Play's SMS Permissions Policy, temporary exceptions for non-default SMS handlers are granted when:

  1. The use of the permission enables a core app functionality listed in Google Play's permitted uses table, and
  2. There is currently no alternative method to provide that core functionality.

The AR Malik Seeds App meets both conditions. The permitted use case is "SMS-based user verification / OTP authentication." The core functionality — user login — depends on this. Without SMS OTP, a significant proportion of our farmer user base (rural, low-literacy, infrequent users on basic devices without password managers) would be unable to access the service.

11.2 Why Full SMS Permissions Are Required (SMS Retriever API Considered)

Google recommends the SMS Retriever API as a less invasive alternative for OTP autofill. We evaluated this approach. The SMS Retriever API requires a stable, app-specific SHA-256 hash embedded in every OTP message sent by our SMS gateway. This approach creates operational constraints across our user base, which includes:

Given that our primary farmer users cannot fall back to password login (no password exists for farmer accounts), a failed autofill combined with an unclear error message creates a complete access failure. We are committed to migrating to SMS Retriever API as our user base and infrastructure matures, and we will update this policy and our Play Console declaration when that migration is complete.

11.3 SMS Permissions: Detailed Declaration Table

Permission Specific Technical Purpose Data Accessed Retained?
android.permission.
RECEIVE_SMS
Registers a BroadcastReceiver for the SMS_RECEIVED intent. When a new SMS arrives, the App checks whether its sender address matches our OTP system. If it does, the OTP extraction flow is triggered. If it does not match, the message is ignored entirely. Sender address of each incoming SMS. Message body is accessed only when sender matches our known OTP originator. No
Discarded immediately after OTP is extracted and submitted.
android.permission.
READ_SMS
Reads the body of the matched OTP SMS message to extract the numeric verification code. The extracted code is held in memory and auto-filled into the login field. This eliminates manual entry for users who may have difficulty reading or typing a numeric code on a small screen under field conditions. Body of the single OTP SMS from our sender only. No other messages in the inbox are read or examined. No
Only the numeric OTP value is used transiently. No message text is stored in any form.
android.permission.
SEND_SMS
Used for two purposes: (1) to programmatically trigger an OTP resend request when the user taps "Resend OTP," which initiates a new OTP delivery cycle via our authentication backend; and (2) to support user-initiated SMS communication features within the App where a user can directly contact their assigned agricultural support representative via SMS from within the App interface. Outgoing SMS composed by the App on the user's behalf, only when the user explicitly triggers the action. No third-party inbox content is accessed. Partial
OTP resend triggers: no retention. User-initiated support messages: reference logs retained for support traceability. Users are informed before any outgoing SMS is sent.

11.4 Explicit Scope Limitations for SMS Permissions

We confirm, unconditionally, that SMS permissions are NOT used for:

11.5 Call Log Permissions — Explicitly Not Used

The AR Malik Seeds App does not declare, request, or use any call log permissions. The following are absent from the App manifest and not used in any build version:

The App does not collect, process, or store any telephone call metadata or call log data from users' devices. If any past build version inadvertently included call log permissions through a third-party SDK dependency, they have been identified and fully removed. All current and future builds are confirmed free of call log permissions.

11.6 User Controls for SMS Permissions

12. App Permissions Summary

Permission Purpose Applies To Required?
ACCESS_FINE_LOCATION (foreground) Field attendance, route and duty verification Field staff Required for tracking features
ACCESS_BACKGROUND_LOCATION Continuous tracking when App is in background Field staff (explicit consent required) Required for background tracking
RECEIVE_SMS Detect incoming OTP SMS for autofill All users Optional — manual entry always available
READ_SMS Read OTP code from verified OTP SMS All users Optional — manual entry always available
SEND_SMS OTP resend requests; user-initiated support messages All users Optional — requires explicit user action
INTERNET Transmitting data to servers, receiving notifications All users Required for all features
ACCESS_NETWORK_STATE Check internet connectivity before data transmission All users Required
POST_NOTIFICATIONS Displaying push notifications and alerts All users Required for notifications
CAMERA Photo capture for field reporting workflows Field staff (specific features) Optional — feature-specific
READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGE Read or save files in App workflows Field staff (specific features) Optional — feature-specific
READ_CONTACTS Contact lookup for in-app communication features Selected features only Optional — feature-specific
RECORD_AUDIO Audio capture for specific field workflows Selected features only Optional — feature-specific
RECEIVE_BOOT_COMPLETED Restart background location service after device reboot Field staff with background tracking Required for background tracking
FOREGROUND_SERVICE Keep location tracking service running in foreground Field staff Required for tracking features

You may revoke any permission at any time via Device Settings → Apps → AR Malik Seeds → Permissions. Revoking a permission will disable the feature that depends on it, as described in Sections 3, 4, and 11.

13. Background Data Collection

For field force staff with location tracking enabled, the App collects location and device status data in the background, including when the App is closed. This is necessary for real-time operational tracking. Background data collection includes:

SMS data is never collected in the background. SMS permission is only active during the active login session when the user is on the OTP entry screen. No background SMS monitoring, inbox scanning, or passive message reading occurs under any circumstance.

Background location tracking can be disabled via Device Settings → Apps → AR Malik Seeds → Permissions → Location → Allow only while using the App. Note: this will affect field attendance and route tracking functionality.

14. Account Management and Data Deletion

As required by Google Play's Account Deletion Policy (effective 2024), all users with an account in this App have the right to delete their account and associated data.

14.1 In-App Account Deletion Path

You can initiate account deletion directly within the App:

  1. Open the App and log in
  2. Go to Settings (accessible from the main menu)
  3. Tap Account
  4. Tap Delete My Account
  5. Confirm your intent by entering your OTP when prompted
  6. Your deletion request is submitted and you will receive a confirmation

14.2 External Account Deletion Request

You may also submit a data deletion request by emailing us directly:

Email: it@malikseedsbd.com
Subject line: Data Deletion Request – AR Malik Seeds App
Include: Your registered phone number and a brief description of what you want deleted (full account or specific data types).

A dedicated account deletion web page is available at:
https://malikseedsbd.com/delete-account

14.3 Deletion Processing and Timelines

14.4 Data We May Retain After Deletion

In certain limited circumstances, we may need to retain some data after an account deletion request, as permitted under Google Play's Account Deletion Policy:

We will inform you of any retention at the time of your deletion request and specify the reason, category of data retained, and retention duration.

15. Data Security and Breach Notification

15.1 Security Measures

We implement the following technical and organisational measures to protect your data:

15.2 Data Breach Notification

In the event of a confirmed data security breach that affects your personal data, we will:

No method of transmission or storage is 100% secure. While we apply commercially reasonable standards, we cannot guarantee absolute security. We encourage you to contact us immediately at it@malikseedsbd.com if you suspect unauthorised access to your account.

16. Field Staff Monitoring Disclosure

This section applies exclusively to field force employees and staff who use the App's GPS tracking and attendance features.

16.1 Nature and Scope of Monitoring

As a condition of using the App in your employment capacity, the Company uses this App to collect your device's GPS location and operational status during working hours and, if background tracking is enabled, continuously when the App is running in the background.

The following employer activities are conducted through the App:

16.2 Legal Basis for Employment Monitoring

This monitoring is conducted on the legal basis of your employment contract and the Company's legitimate business interests in operational management, field force accountability, and accurate attendance records. By accepting your employment terms and installing this App on a company-issued or registered device, you consent to this monitoring during your assigned duty hours.

16.3 Access to Your Monitoring Data

16.4 Personal Use and Off-Hours Tracking

If the App is installed on a personal device, background location tracking should be disabled outside of working hours to protect your personal privacy. You may do this via: Device Settings → Apps → AR Malik Seeds → Permissions → Location → Allow only while using the App. The Company is not responsible for location data collected outside duty hours on a personally owned device if background permission remains enabled.

17. Your Rights and How to Exercise Them

17.1 Your Rights

Subject to applicable law, you have the following rights in relation to your personal data:

Right What It Means How to Exercise
Access Receive a copy of the personal data we hold about you Email it@malikseedsbd.com — Subject: Data Access Request
Correction Have inaccurate data corrected Email with specific correction details
Deletion Have your data and account deleted (see Section 14) In-App (Section 14.1) or email (Section 14.2)
Portability Receive your data in a structured, machine-readable format Email request — we will provide in CSV or JSON format
Restriction Request that we limit processing of your data in certain circumstances Email with specific restriction request
Objection Object to processing based on legitimate interest Email with specific objection
Withdraw Consent Revoke consent for any consent-based processing at any time Revoke in Device Settings (Location, SMS); or email

17.2 Response Timelines

We will acknowledge your request within 5 business days and respond fully within 30 calendar days of receiving a verified request. If we require more time for complex requests, we will inform you within the initial 30-day period.

17.3 Identity Verification

To protect your data, we may ask you to verify your identity before processing certain requests (e.g., data access, portability, or deletion). Verification is typically performed by confirming your registered phone number via OTP.

17.4 Right to Complain to a Supervisory Authority

If you are not satisfied with our response to a data request, or if you believe we are processing your data unlawfully, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction. For users in the European Union, this is your national Data Protection Authority (DPA). For users in Bangladesh, you may contact the Bangladesh Telecommunication Regulatory Commission (BTRC) or relevant authorities under the Cyber Security Act 2023.

18. Children's Privacy

The AR Malik Seeds App is intended for use by adults only. It is not directed at, and we do not knowingly collect personal data from, children under the age of 13 (or the applicable minimum age in your country). If you are a parent or guardian and believe your child has created an account or provided personal data through the App, please contact us immediately at it@malikseedsbd.com. We will delete such data promptly upon verification.

19. International Data Transfers

Your data may be processed or stored on servers outside Bangladesh, including in the United States and the European Economic Area, due to our use of Firebase (Google LLC) and related infrastructure. These transfers are conducted under appropriate data transfer safeguards:

By using the App, you acknowledge that your data may be transferred to and processed in countries with different data protection laws than your home jurisdiction. We ensure that any such transfers are protected by appropriate safeguards.

20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time as the App evolves or as legal requirements change. When we make material changes, we will:

We recommend reviewing this policy each time the App is updated. Your continued use of the App after the effective date of any changes constitutes your acceptance of the revised policy.

Policy version history:
v1.0 — Initial policy
v2.0 — June 11, 2026: Full SMS/Call Log declaration, GAID disclosure, account deletion, legal basis, breach notification, field staff monitoring notice added to comply with Google Play Developer Programme Policies.

21. Your Consent

By installing and using the AR Malik Seeds App, you acknowledge that you have read and understood this Privacy Policy and consent to:

Consent for SMS and location permissions is obtained through in-app prominent disclosure screens before the Android OS permission dialogs are shown. You may withdraw consent at any time by revoking permissions in Device Settings or by contacting us as described in Section 22.

22. Contact Us

For any questions, requests, or concerns about this Privacy Policy or our data practices, please contact us:

Company A R Malik Seeds Pvt. Ltd.
Email it@malikseedsbd.com
Website malikseedsbd.com
App Portal dashboard.malikseedsbd.com

We will acknowledge your contact within 5 business days and respond fully within 30 calendar days.

23. Regulatory Compliance

This Privacy Policy has been drafted to comply with: