Privacy Policy
A Bangla version of this policy is available. The Bangla text is a faithful translation; if the two versions differ, this English version prevails.
1. Who we are
AmarKarigor ("আমার কারিগর", "we", "us", "the App") is a mobile application that helps people in Bangladesh find independent repair technicians (for air conditioners, refrigerators, washing machines, electrical and plumbing work, electronics, and similar), talk to them, and coordinate a repair.
The App is operated by AmarKarigor, Bangladesh (the "Operator").
Contact for privacy questions: support@rimonlabs.com. For help with the App you can also message us on WhatsApp.
2. Scope
This policy explains what personal data the App collects, why, how long we keep it, who can see it, and what choices you have. It applies to everyone who uses the App, whether as a customer (someone looking for a repair) or as a technician (someone offering repair services), and to the small admin team that reviews verifications and reports.
By using the App you agree to this policy. If you do not agree, please do not use the App.
3. What we collect and why
We only collect what the App needs to work. The tables below are the complete list of personal data the App stores.
3.1 Account data (all users)
| Data | Why we collect it | Required? |
|---|---|---|
| Email address | To create your account and log you in — either through Google or with a one-time code we email to you; to send you that sign-in code; to recognise you if you contact support | Required |
| Google account ID, name, and email | Only if you choose "Continue with Google": to link your Google login to your AmarKarigor account and fill in your name | Automatic when Google is used |
| Full name | Entered by you, or filled in from your Google account (you can change it); shown to the people you talk to | Required |
| Mobile phone number (+880) | Entered by you, so that a customer and a technician can call each other about a request. The number is not verified (we send no SMS) — please enter your own number | Required |
| Profile photo | To help the other party recognise you | Optional |
| Chosen language (Bangla / English) | To show the App in your language | Required (defaults to Bangla) |
| Role (customer or technician) | To show you the right screens | Required |
| Last-active time | To keep search results fresh and to detect inactive accounts | Automatic |
How you sign in. There are no passwords in the App. You can log in in either of two ways:
- Continue with Google. Google shares your name, email address, and a link to your Google profile photo with us. Our login system (Supabase Auth) keeps these details as part of your login record. The App uses your name to fill in your profile; it does not show or copy your Google profile photo — your AmarKarigor profile photo is only a photo you upload yourself. We never see or store your Google password.
- Email with a one-time code. You type your email address, we email you a 6-digit code (valid for a short time, currently 10 minutes), and you type the code into the App. The email is sent through our transactional email provider (see section 7). Our login system keeps your email address and the time it was confirmed.
If you use Google and the email code with the same email address, both lead to the same AmarKarigor account. We do not use SMS or phone-number login, and we never send you SMS messages.
We do not collect your date of birth, gender, or any payment-card information.
3.2 Location data
| Data | Why we collect it | Required? |
|---|---|---|
| Your approximate current location (when you grant the location permission) | To show technicians near you and the distance to each one; to attach a location to a service request so the technician knows where to go | Optional — you can search by area name instead |
| Saved addresses (label, address line, area, district, optional map point) | So you do not have to type your address every time you request a service | Optional (customers) |
| Technician base location, service area names, and service radius | So customers can find technicians who cover their area | Required for technicians (to be listed) |
The App requests location only while you are using it (foreground). It never tracks your location in the background, and background-location permission is explicitly blocked in the App's build configuration.
3.3 Technician professional profile (technicians only)
Headline, short bio, years of experience, areas of expertise, service mode (home visit / workshop / both), inspection fee, work photos and captions, availability, and optional WhatsApp opt-in. This information is public: it is shown to anyone using the App (including before they log in) so that customers can compare technicians.
3.4 Identity verification documents (technicians only, optional)
To earn a "verified" badge a technician may submit: full name as on the National ID (NID), NID number, photos of the front and back of the NID, a selfie, and a current address.
- These documents are stored in a private storage bucket. They are never public.
- They can be viewed only by the technician who submitted them and by AmarKarigor admins who review the verification. No customer or other technician can ever see them.
- They are used solely to decide whether to grant the verified badge and to investigate fraud reports.
3.5 Service requests and jobs
When a customer requests a service we store: the problem description, category, preferred time, service mode, the address or location for the visit, optional photos of the problem (up to 4), and the technician chosen. As the job progresses we store the job status history, the technician's diagnosis, estimate, the final price breakdown (parts, labour, visit, other), the payment method the parties say they used (cash, bKash, Nagad, other), and whether the amount was marked as paid.
We do not process payments. The App only records what the customer and technician tell us about a payment that happened between them directly. No money passes through the App.
3.6 Chat messages
Text messages and optional images that you send to another user through the App. Messages are visible to the two participants of the conversation and to admins when a message is reported or when investigating abuse.
3.7 Reviews
After a completed job the customer may leave a star rating (overall, quality, price, punctuality, behaviour) and an optional written comment. Reviews are public and are shown on the technician's profile with the reviewer's first name and last initial only (for example "Rahim K."), never the full name or phone number.
3.8 Price statistics
When a job is completed with a final price, we keep an anonymised price record (category, district/area, and the amount breakdown). These records are used only to compute aggregated statistics such as "AC repair in Gazipur usually costs ৳800–৳1,500". Statistics are shown only when at least 5 completed jobs exist for that category and area, and the App never shows who paid what, or which technician charged what, to anyone other than the parties of that job.
3.9 Reports and blocks
If you report a user, review, message, or job, we store your report (reason, description) and the target. If you block a user we store the block so that neither of you can message or request each other.
3.10 Device and technical data
| Data | Why | Notes |
|---|---|---|
| Push notification token (Expo push token) and platform | To send you notifications about requests, job updates, messages, and reviews | Deleted when you log out of that device or delete your account |
| App version | To diagnose problems specific to a release | |
| In-app notification inbox | To show you your notification history inside the App | |
| Basic product analytics events (for example "app opened", "search performed", "request created", "job completed") | To understand which features are used and improve the App | Stored in our own database only; no third-party analytics SDK (no Google Analytics, Firebase Analytics, Facebook SDK or similar) is included in the App |
| Error logs | To find and fix crashes | By default errors are logged only on the device in development builds. If we later enable a crash-reporting service, this policy will be updated first. |
We do not use advertising identifiers and the App contains no advertising.
4. Permissions the App asks for (Android)
| Permission | Used for | Optional? |
|---|---|---|
| Location (coarse and fine, while in use) | Nearby technicians, distances, request location | Yes — you can decline and search by area name |
| Camera | Taking profile, work, problem, or verification photos | Yes — you can pick from the gallery instead |
| Photos / media (images only) | Choosing photos to upload | Yes |
| Notifications | Request, job, message, and review alerts | Yes |
| SMS | Not requested. The App does not use SMS at all (sign-in codes arrive by email) and never reads your SMS inbox | — |
| Background location, microphone, video | Never requested (explicitly blocked in the build) | — |
5. How we use your data
We use the data above to:
- Create your account and log you in.
- Show customers nearby technicians and let them compare profiles, ratings, and typical prices.
- Let customers and technicians communicate (in-app chat, phone call, optional WhatsApp link) and coordinate a repair.
- Keep a record of each job so both parties can see what was agreed.
- Show reviews and compute a technician's rating.
- Compute anonymised price statistics.
- Send notifications about your requests, jobs, messages, and reviews.
- Verify technicians who request the verified badge.
- Handle reports, blocks, and abuse, and enforce our Terms of Service.
- Understand feature usage and fix errors.
- Comply with legal obligations.
We do not sell your data, and we do not use it for advertising.
6. Who can see your data
| Data | Visible to |
|---|---|
| Your name and profile photo | Users you interact with; for technicians, everyone (public profile) |
| Your phone number | The other party of a service request or conversation (so you can call each other); admins. Technician phone numbers are exposed for calling from the technician profile. |
| Technician professional profile, work photos, ratings, reviews | Everyone, including visitors who have not logged in |
| Your current location / saved addresses | Only you, and — for a specific service request — the technician you requested |
| Verification documents (NID, selfie, address) | Only you and admins |
| Job details, diagnosis, price | The customer and technician of that job, and admins |
| Chat messages | The two participants, and admins when investigating a report |
| Price records | Nobody individually; only aggregated statistics are shown |
| Reports, audit logs, analytics events | Admins only |
We enforce these rules in the database itself (row-level security), not only in the App's screens.
7. Service providers (data processors)
- Supabase — hosts our database, file storage, authentication, and serverless functions. Your data is stored on Supabase's infrastructure in a data centre outside Bangladesh. Supabase acts on our instructions and does not use your data for its own purposes. Data is encrypted in transit (HTTPS/TLS) and at rest on Supabase's storage.
- Google (sign-in) — only if you choose "Continue with Google". Google confirms who you are and shares your name, email address, and profile-photo link with us; it does not receive your AmarKarigor activity from us. Google's own privacy policy applies to your Google account.
- Transactional email provider — delivers the one-time sign-in code to your email address on our behalf. It receives your email address and the content of that email (the code); it does not receive anything else about you.
- Expo push notification service / Google Firebase Cloud Messaging — deliver push notifications to your device. They receive a device token and the notification text.
- Google Play — distributes the App and may collect its own installation and crash data under Google's privacy policy.
- WhatsApp — only if you choose to message our support number on WhatsApp. WhatsApp handles those messages under its own terms and privacy policy; we see your WhatsApp number, profile name, and what you send, and use them only to answer you.
We do not share your personal data with any other third party except as required by law or to protect the safety of our users.
8. Data transfers outside Bangladesh
Because our hosting providers operate data centres outside Bangladesh, your data may be stored and processed outside the country.
9. How long we keep data (retention)
| Data | Retention |
|---|---|
| Account data (including your email address and login record) | Until you delete your account |
| One-time sign-in codes | Expire after a short time (currently 10 minutes) and stop working once used; the email provider may keep a delivery log for a limited period under its own terms |
| Verification documents | While your account exists; deleted when the account is deleted |
| Location and saved addresses | Until you remove them or delete your account |
| Chat messages | Until you delete your account (your message bodies are then replaced with "[deleted]" for the other participant) |
| Push tokens, notifications | Deleted on log-out / account deletion |
| Jobs, reviews, price records | Retained in anonymised form after account deletion: your name and phone are removed and the record is linked to a "Deleted user" placeholder, so the other party keeps their job history and public price statistics stay correct |
| Reports and audit logs | Retained for safety and legal-compliance purposes even after account deletion |
| Analytics events | Retained without a link to your identity after deletion |
10. Your choices and rights
- Access and correction — you can see and edit your name, phone number, photo, language, addresses, and (for technicians) your professional profile inside the App at any time.
- Location — you can revoke the location permission in Android settings; the App keeps working with area-name search.
- Notifications — you can turn off notifications in Android settings.
- Blocking — you can block any user from their profile or the chat screen.
- Delete your account — in the App: Settings → Delete Account, or by emailing support@rimonlabs.com from the email address you use to log in. See Delete your account for exactly what is deleted and what is kept. Deletion is immediate and cannot be undone.
- Complaints — contact support@rimonlabs.com.
11. Security
All traffic between the App and our servers uses HTTPS (TLS). Access rules are enforced in the database per row and per user. Verification documents and chat images live in private storage that requires an authenticated, authorised request. Your session token is kept in the App's private storage on your device, which other apps cannot read; it is not additionally encrypted on the device. Admin actions (verification decisions, suspensions, review moderation, report resolution) are recorded in an audit log.
No system is perfectly secure. If we learn of a breach affecting your data we will notify affected users through the App or by email as soon as reasonably possible.
12. Children
The App is intended for adults (18+). We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the App evolves. The "Last updated" date at the top will change, and for material changes we will show a notice in the App. Continued use after a change means you accept the updated policy.
14. Contact
See also: Terms of Service · Delete your account · Support