This Privacy Policy describes how A R Malik Seeds Pvt. Ltd. ("we," "our," or "the Company") collects, uses, stores, and protects personal information when you use the AR Malik Seeds mobile application (the "App" or "Service"), available on Google Play.
The App serves two distinct user groups:
By using the App, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the App. This policy is publicly accessible at a non-gated URL and is written in plain language as required by Google Play's Developer Programme Policies.
The table below is a quick-reference summary of every data type this App handles. It is designed to align with the Google Play Data Safety form declarations in our Play Console.
| Data Type | Collected? | Shared with Third Parties? | Encrypted in Transit? | User Can Delete? |
|---|---|---|---|---|
| Precise Location (GPS) Field staff only |
Yes | No | Yes (TLS) | Yes — on request |
| Phone Number Account identifier, OTP delivery |
Yes | No | Yes (TLS) | Yes — account deletion |
| Employee ID Field staff only |
Yes | No | Yes (TLS) | Yes — on request |
| SMS Content (OTP only) Processed in memory — never stored |
In memory only | Never | Not transmitted | N/A — not retained |
| Device ID / Device Info Model, OS version, battery, network |
Yes | Firebase (crash logs) | Yes (TLS) | Yes — account deletion |
| App Activity / Usage Data Session info, feature usage, error logs |
Yes | Firebase Analytics | Yes (TLS) | Yes — on request |
| Crash and Diagnostics Data | Yes | Firebase Crashlytics | Yes (TLS) | Yes — on request |
| Google Advertising ID (GAID) Via Firebase Analytics |
Yes | Google (Firebase) | Yes (TLS) | Yes — Android Ads Settings |
| FCM Push Token Notifications only |
Yes | Firebase FCM | Yes (TLS) | Yes — account deletion |
| Call Log Data | Not collected | N/A | N/A | N/A |
Before requesting any location permission, the App displays a clear in-app disclosure screen. You must acknowledge this disclosure before the Android OS permission prompt is shown. The disclosure states the following:
The App uses a One-Time Password (OTP) authentication system as its primary login method. Before requesting any SMS permission, the App displays a clear in-app disclosure screen. You must acknowledge this disclosure before the Android OS permission prompt is shown. The disclosure states the following:
With your permission, the App accesses a narrowly scoped subset of SMS data for the sole purpose of OTP-based authentication:
Important: No SMS message content is ever stored locally or on any server. SMS processing is entirely transient, in-memory, and non-aggregated.
Location data is collected in the foreground and, for field staff with background tracking enabled, continuously in the background. See Section 13.
A unique token issued by Firebase Cloud Messaging (FCM) is collected and stored to enable push notifications, including OTP delivery confirmations, operational alerts, and order or service updates.
Via Firebase Analytics, we collect anonymised usage signals including: app session durations, feature engagement, screen flow data, and error events. See Section 10 for full Firebase disclosure and opt-out options.
Via Firebase Crashlytics, we collect crash reports, stack traces, and device state at the time of a crash. This data does not include personally identifiable information and is used solely to diagnose and fix bugs.
| Purpose | Data Used | Who It Applies To |
|---|---|---|
| OTP Authentication — verify identity at login without a password | Phone number, SMS OTP content (transient) | All users |
| Location Tracking — attendance, route verification, duty monitoring | GPS coordinates, timestamps | Field staff only |
| Push Notifications — operational alerts, OTP confirmations, service updates | FCM token | All users |
| App Performance — diagnose crashes, fix bugs, improve stability | Crash logs, device info | All users |
| Analytics — understand feature usage, improve the App | Usage data, GAID (anonymised) | All users |
| Account Security — detect and prevent unauthorised access | Device ID, phone number, login metadata | All users |
| Business Operations — field force management, farmer support | Location history, employee ID | Field staff / assigned roles |
| Legal and Regulatory Compliance | Account data, location records | As required |
We do not use any of your data for advertising, profiling for sale, or any purpose not listed in the table above. We operate on a strict purpose limitation principle: data collected for one purpose is not reused for a different purpose without new consent or a clear legitimate basis.
For users in the European Union (and as a matter of global best practice), every data processing activity is grounded in one or more of the following legal bases under GDPR Article 6:
| Data Type | Legal Basis | Explanation |
|---|---|---|
| Phone number (account creation) | Contract (Art. 6(1)(b)) | Necessary to provide the Service and deliver OTP codes to your registered number. |
| SMS OTP content | Consent (Art. 6(1)(a)) | You grant SMS permission explicitly. You may revoke it at any time. |
| Location data (field staff) | Contract / Legitimate Interest (Art. 6(1)(b)(f)) | Necessary to fulfil the operational tracking obligations agreed in your employment terms. |
| Device information | Legitimate Interest (Art. 6(1)(f)) | Necessary for App security, account integrity, and technical diagnostics. Not overridden by user rights. |
| Analytics and usage data | Legitimate Interest (Art. 6(1)(f)) | Used to improve App performance and user experience. Anonymised where possible. |
| Crash and diagnostics data | Legitimate Interest (Art. 6(1)(f)) | Necessary to identify and fix software errors that affect service reliability. |
| Google Advertising ID (GAID) | Consent (Art. 6(1)(a)) | Collected by Firebase Analytics. Governed by Google's Terms. You may opt out via Android Ads Settings. |
| Data shared with authorities | Legal Obligation (Art. 6(1)(c)) | When required by law, court order, or regulatory demand. |
For users in Bangladesh, processing is conducted in accordance with the Bangladesh Cyber Security Act 2023 and applicable data protection norms.
The following data is stored locally on your device:
SMS content is never stored locally. OTP processing is entirely in-memory and leaves no trace on the device.
The following is stored on our secured servers:
No SMS content — including OTP messages — is ever stored on our servers.
| Data Type | Retention Period | Basis for Retention |
|---|---|---|
| SMS / OTP content | Not retained — discarded immediately after login | Data minimisation principle |
| Account data (phone, profile) | Duration of active account; deleted within 30 days of account deletion request | Contract |
| Location history | As required by operational needs; deleted on account deletion or request | Legitimate interest (field management) |
| Device and usage data | Up to 12 months; anonymised after 90 days | Legitimate interest (app improvement) |
| Crash logs (Crashlytics) | Up to 90 days per Firebase Crashlytics policy | Legitimate interest (bug fixing) |
| FCM push tokens | Active account lifetime; deleted on account deletion | Contract (notification delivery) |
We collect only the minimum data necessary for each stated purpose. Data that is no longer needed is deleted or anonymised promptly. SMS content is the clearest example of this principle: we read it, use it once, and discard it without any storage.
We do not sell, rent, or trade your personal data. We share limited data with the third-party services listed below solely to operate the App. SMS data is never shared with any third party under any circumstances.
| Service | Provider | Data Shared | Purpose | Privacy Policy |
|---|---|---|---|---|
| Firebase Analytics | Google LLC | App usage events, session data, device info, GAID | App usage analysis and improvement | policies.google.com/privacy |
| Firebase Crashlytics | Google LLC | Crash reports, stack traces, device state at crash time. No PII beyond device metadata. | Bug diagnosis and app stability | firebase.google.com/support/privacy |
| Firebase Cloud Messaging (FCM) | Google LLC | FCM device token only. No message content is accessed by Google. | Delivering push notifications to your device | policies.google.com/privacy |
| Google Play Services | Google LLC | Device identifiers, location services API | Location API infrastructure, device functions | policies.google.com/privacy |
Firebase Analytics collects the following automatically:
Firebase Analytics data is processed by Google LLC on servers that may be located outside Bangladesh. Google acts as a data processor under its Firebase Data Processing Terms.
Crashlytics collects the following when a crash occurs:
Crash data is retained by Firebase Crashlytics for up to 90 days.
FCM only receives your device's push token in order to deliver notifications to your specific device. Google does not have access to the content of notifications sent through FCM. We do not use FCM for advertising.
In the event of a merger, acquisition, or asset sale, your data may be transferred to the successor entity. You will be notified via in-app notice and/or email (if available) before your data becomes subject to a different privacy policy.
We may disclose your data if required by applicable law, court order, or a binding request from a government authority. We will notify you of such requests where legally permitted to do so.
The Google Advertising ID (GAID), also called the Android Advertising ID (AAID), is a resettable identifier assigned by Google to your Android device. The AR Malik Seeds App uses Firebase Analytics, which automatically reads the GAID to produce anonymised usage analytics and to attribute app installs and events across sessions.
The GAID is used solely by Firebase Analytics for aggregated, anonymised app usage reporting. We do not use it for behavioural advertising, retargeting, cross-app profiling, or any purpose beyond understanding how the App is used in aggregate.
You have full control over your Google Advertising ID:
To disable Firebase Analytics data collection entirely for this App, you may:
This section is a full and transparent disclosure of all SMS-related permissions declared in this App's Android manifest, provided in compliance with Google Play's Restricted Permissions policy and the Permissions Declaration Form requirements.
Under Google Play's SMS Permissions Policy, temporary exceptions for non-default SMS handlers are granted when:
The AR Malik Seeds App meets both conditions. The permitted use case is "SMS-based user verification / OTP authentication." The core functionality — user login — depends on this. Without SMS OTP, a significant proportion of our farmer user base (rural, low-literacy, infrequent users on basic devices without password managers) would be unable to access the service.
Google recommends the SMS Retriever API as a less invasive alternative for OTP autofill. We evaluated this approach. The SMS Retriever API requires a stable, app-specific SHA-256 hash embedded in every OTP message sent by our SMS gateway. This approach creates operational constraints across our user base, which includes:
Given that our primary farmer users cannot fall back to password login (no password exists for farmer accounts), a failed autofill combined with an unclear error message creates a complete access failure. We are committed to migrating to SMS Retriever API as our user base and infrastructure matures, and we will update this policy and our Play Console declaration when that migration is complete.
| Permission | Specific Technical Purpose | Data Accessed | Retained? |
|---|---|---|---|
android.permission. |
Registers a BroadcastReceiver for the
SMS_RECEIVED intent. When a new SMS arrives,
the App checks whether its sender address matches our
OTP system. If it does, the OTP extraction flow is triggered.
If it does not match, the message is ignored entirely.
|
Sender address of each incoming SMS. Message body is accessed only when sender matches our known OTP originator. |
No Discarded immediately after OTP is extracted and submitted. |
android.permission. |
Reads the body of the matched OTP SMS message to extract the numeric verification code. The extracted code is held in memory and auto-filled into the login field. This eliminates manual entry for users who may have difficulty reading or typing a numeric code on a small screen under field conditions. | Body of the single OTP SMS from our sender only. No other messages in the inbox are read or examined. |
No Only the numeric OTP value is used transiently. No message text is stored in any form. |
android.permission. |
Used for two purposes: (1) to programmatically trigger an OTP resend request when the user taps "Resend OTP," which initiates a new OTP delivery cycle via our authentication backend; and (2) to support user-initiated SMS communication features within the App where a user can directly contact their assigned agricultural support representative via SMS from within the App interface. | Outgoing SMS composed by the App on the user's behalf, only when the user explicitly triggers the action. No third-party inbox content is accessed. |
Partial OTP resend triggers: no retention. User-initiated support messages: reference logs retained for support traceability. Users are informed before any outgoing SMS is sent. |
We confirm, unconditionally, that SMS permissions are NOT used for:
The AR Malik Seeds App does not declare, request, or use any call log permissions. The following are absent from the App manifest and not used in any build version:
android.permission.READ_CALL_LOG — NOT declaredandroid.permission.WRITE_CALL_LOG — NOT declaredandroid.permission.PROCESS_OUTGOING_CALLS — NOT declaredThe App does not collect, process, or store any telephone call metadata or call log data from users' devices. If any past build version inadvertently included call log permissions through a third-party SDK dependency, they have been identified and fully removed. All current and future builds are confirmed free of call log permissions.
| Permission | Purpose | Applies To | Required? |
|---|---|---|---|
| ACCESS_FINE_LOCATION (foreground) | Field attendance, route and duty verification | Field staff | Required for tracking features |
| ACCESS_BACKGROUND_LOCATION | Continuous tracking when App is in background | Field staff (explicit consent required) | Required for background tracking |
RECEIVE_SMS |
Detect incoming OTP SMS for autofill | All users | Optional — manual entry always available |
READ_SMS |
Read OTP code from verified OTP SMS | All users | Optional — manual entry always available |
SEND_SMS |
OTP resend requests; user-initiated support messages | All users | Optional — requires explicit user action |
| INTERNET | Transmitting data to servers, receiving notifications | All users | Required for all features |
| ACCESS_NETWORK_STATE | Check internet connectivity before data transmission | All users | Required |
| POST_NOTIFICATIONS | Displaying push notifications and alerts | All users | Required for notifications |
| CAMERA | Photo capture for field reporting workflows | Field staff (specific features) | Optional — feature-specific |
| READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGE | Read or save files in App workflows | Field staff (specific features) | Optional — feature-specific |
| READ_CONTACTS | Contact lookup for in-app communication features | Selected features only | Optional — feature-specific |
| RECORD_AUDIO | Audio capture for specific field workflows | Selected features only | Optional — feature-specific |
| RECEIVE_BOOT_COMPLETED | Restart background location service after device reboot | Field staff with background tracking | Required for background tracking |
| FOREGROUND_SERVICE | Keep location tracking service running in foreground | Field staff | Required for tracking features |
You may revoke any permission at any time via Device Settings → Apps → AR Malik Seeds → Permissions. Revoking a permission will disable the feature that depends on it, as described in Sections 3, 4, and 11.
For field force staff with location tracking enabled, the App collects location and device status data in the background, including when the App is closed. This is necessary for real-time operational tracking. Background data collection includes:
Background location tracking can be disabled via Device Settings → Apps → AR Malik Seeds → Permissions → Location → Allow only while using the App. Note: this will affect field attendance and route tracking functionality.
As required by Google Play's Account Deletion Policy (effective 2024), all users with an account in this App have the right to delete their account and associated data.
You can initiate account deletion directly within the App:
You may also submit a data deletion request by emailing us directly:
A dedicated account deletion web page is available at:
https://malikseedsbd.com/delete-account
In certain limited circumstances, we may need to retain some data after an account deletion request, as permitted under Google Play's Account Deletion Policy:
We will inform you of any retention at the time of your deletion request and specify the reason, category of data retained, and retention duration.
We implement the following technical and organisational measures to protect your data:
In the event of a confirmed data security breach that affects your personal data, we will:
No method of transmission or storage is 100% secure. While we apply commercially reasonable standards, we cannot guarantee absolute security. We encourage you to contact us immediately at it@malikseedsbd.com if you suspect unauthorised access to your account.
This section applies exclusively to field force employees and staff who use the App's GPS tracking and attendance features.
As a condition of using the App in your employment capacity, the Company uses this App to collect your device's GPS location and operational status during working hours and, if background tracking is enabled, continuously when the App is running in the background.
The following employer activities are conducted through the App:
This monitoring is conducted on the legal basis of your employment contract and the Company's legitimate business interests in operational management, field force accountability, and accurate attendance records. By accepting your employment terms and installing this App on a company-issued or registered device, you consent to this monitoring during your assigned duty hours.
If the App is installed on a personal device, background location tracking should be disabled outside of working hours to protect your personal privacy. You may do this via: Device Settings → Apps → AR Malik Seeds → Permissions → Location → Allow only while using the App. The Company is not responsible for location data collected outside duty hours on a personally owned device if background permission remains enabled.
Subject to applicable law, you have the following rights in relation to your personal data:
| Right | What It Means | How to Exercise |
|---|---|---|
| Access | Receive a copy of the personal data we hold about you | Email it@malikseedsbd.com — Subject: Data Access Request |
| Correction | Have inaccurate data corrected | Email with specific correction details |
| Deletion | Have your data and account deleted (see Section 14) | In-App (Section 14.1) or email (Section 14.2) |
| Portability | Receive your data in a structured, machine-readable format | Email request — we will provide in CSV or JSON format |
| Restriction | Request that we limit processing of your data in certain circumstances | Email with specific restriction request |
| Objection | Object to processing based on legitimate interest | Email with specific objection |
| Withdraw Consent | Revoke consent for any consent-based processing at any time | Revoke in Device Settings (Location, SMS); or email |
We will acknowledge your request within 5 business days and respond fully within 30 calendar days of receiving a verified request. If we require more time for complex requests, we will inform you within the initial 30-day period.
To protect your data, we may ask you to verify your identity before processing certain requests (e.g., data access, portability, or deletion). Verification is typically performed by confirming your registered phone number via OTP.
If you are not satisfied with our response to a data request, or if you believe we are processing your data unlawfully, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction. For users in the European Union, this is your national Data Protection Authority (DPA). For users in Bangladesh, you may contact the Bangladesh Telecommunication Regulatory Commission (BTRC) or relevant authorities under the Cyber Security Act 2023.
The AR Malik Seeds App is intended for use by adults only. It is not directed at, and we do not knowingly collect personal data from, children under the age of 13 (or the applicable minimum age in your country). If you are a parent or guardian and believe your child has created an account or provided personal data through the App, please contact us immediately at it@malikseedsbd.com. We will delete such data promptly upon verification.
Your data may be processed or stored on servers outside Bangladesh, including in the United States and the European Economic Area, due to our use of Firebase (Google LLC) and related infrastructure. These transfers are conducted under appropriate data transfer safeguards:
By using the App, you acknowledge that your data may be transferred to and processed in countries with different data protection laws than your home jurisdiction. We ensure that any such transfers are protected by appropriate safeguards.
We may update this Privacy Policy from time to time as the App evolves or as legal requirements change. When we make material changes, we will:
We recommend reviewing this policy each time the App is updated. Your continued use of the App after the effective date of any changes constitutes your acceptance of the revised policy.
Policy version history:
v1.0 — Initial policy
v2.0 — June 11, 2026: Full SMS/Call Log declaration, GAID disclosure,
account deletion, legal basis, breach notification, field staff monitoring
notice added to comply with Google Play Developer Programme Policies.
By installing and using the AR Malik Seeds App, you acknowledge that you have read and understood this Privacy Policy and consent to:
Consent for SMS and location permissions is obtained through in-app prominent disclosure screens before the Android OS permission dialogs are shown. You may withdraw consent at any time by revoking permissions in Device Settings or by contacting us as described in Section 22.
For any questions, requests, or concerns about this Privacy Policy or our data practices, please contact us:
| Company | A R Malik Seeds Pvt. Ltd. |
| it@malikseedsbd.com | |
| Website | malikseedsbd.com |
| App Portal | dashboard.malikseedsbd.com |
We will acknowledge your contact within 5 business days and respond fully within 30 calendar days.
This Privacy Policy has been drafted to comply with: