Effective Date: July 27, 2026
Last Updated: July 27, 2026
1. GENERAL PROVISIONS
1.1. This Privacy Policy (the "Policy") governs the procedure for processing information related to the use of the Movnex mobile application for the iOS and Android platforms (the "Application"), and also defines the approach of Movnex LLC to matters of privacy and the processing of personal and other data processed in connection with the functioning of the Application.
1.2. In its current version, Movnex is a digital service of the Destination led mobility platform class, comprising:
- route planning within the city of Tbilisi, display of information on urban mobility and public transport, and navigation;
- display of points of interest (POI) and a catalog of partner venues;
- the Movnex Rewards loyalty program: accrual of cashback in points for visits to partner venues and payment with points at partner venues;
- a user wallet with a points balance and transaction history;
- a personal user QR code for identification at partner venues.
1.3. The Application may be used in guest mode without creating an account: in this case, reference, navigation, and routing functions are available, and the Company does not request the user's name, phone number, email address, or other identifying data. Registration of an account is required to access the loyalty program, the wallet, and the personal QR code.
1.4. In the course of the operation of the Application, the Company may process technical, telemetry, routing, and geolocation data, and, for registered users, also account data, wallet and points transaction data, and data on visits to partner venues, to the extent necessary for the functioning of the Application, the provision of the declared functions, ensuring information security, diagnostics, and improvement of the quality of the Service.
1.5. By using the Application, the user confirms that they have read this Policy and understand the conditions set forth herein.
2. PERSONAL DATA CONTROLLER
2.1. The controller of personal data under this Policy is:
Movnex LLC
Registration number: B26354264
Registered address: Georgia, Tbilisi, Saburtalo district, Bakhtrioni str., N22, flat 75
Email for privacy-related requests: info@gpsolutions.tech
2.2. Movnex LLC is a subsidiary of GP Solutions DMCC (registration number DMCC135261, OAKS Liwa Heights 3504, Jumeirah Lakes Towers, Sheikh Zayed Road, Dubai, UAE). Within the group of companies, data may be transferred between Movnex LLC and GP Solutions DMCC in the manner described in Sections 14 and 15 of this Policy.
2.3. Person responsible for data protection matters:
Jamshid Gaybullaev
For issues related to the processing of personal data and other information under this Policy, the user may contact: info@gpsolutions.tech.
3. TERMS AND INTERPRETATION
Unless otherwise expressly follows from the text, the following terms shall have the following meanings:
"Data" means any information relating to an identified or identifiable natural person, directly or indirectly.
"User" means any natural person using the Application.
"Processing" means any action or set of actions performed with personal data or other information, including collection, recording, systematization, storage, use, transfer, anonymization, blocking, deletion, and other operations.
"Application" means the Movnex mobile application for the iOS and Android platforms.
"Service" means the informational and navigation functionality, the loyalty program functionality, and other related functionality available through the Application.
"Account" means the User's account created upon registration in the Application.
"Points" means the accounting units of the Movnex Rewards loyalty program, accrued and redeemed in accordance with the Terms of Use.
"Wallet" means the section of the Application displaying the User's Points balance and transaction history.
"Partner Venue" means a venue (restaurant, hotel, wellness facility, tourist site, or other) participating in the Movnex loyalty program on the basis of an agreement with the Company.
"Visit" means a confirmed visit by the User to a Partner Venue, recorded by scanning the User's personal QR code.
4. SCOPE OF APPLICATION OF THE POLICY
4.1. This Policy applies to the processing of information carried out in connection with:
- use of the routing, navigation, and transport-information functions of the Application;
- use of geolocation, if such function is activated by the user;
- registration and use of the Account;
- participation in the loyalty program: accrual of cashback, payment with Points, use of the Wallet and the personal QR code;
- interaction with Partner Venues in the course of Visits;
- the technical functioning of the Application, including security, diagnostics, logging, and stability analysis.
4.2. This Policy does not govern the processing of information carried out by third parties outside the Company's control, including device manufacturers, mobile operators, operating system providers, app stores, Partner Venues in respect of their own data processing (for example, when a bill is paid directly to the venue), as well as other external services, unless otherwise expressly stated in this Policy.
5. APPROACH TO DATA PROCESSING AT THE CURRENT STAGE
5.1. The Company proceeds from the principle of data minimization and does not request from the user personal data that is not necessary for the provision of the relevant function of the Service.
5.2. In particular:
- guest mode does not require the provision of any identifying data;
- only the name, phone number, and email address are requested for Account registration;
- the Company does not request or process the User's bank card data or other payment details and has no access to the User's bank card details;
- payment of bills at Partner Venues (less the redeemed Points) is made by the User directly to the venue outside the Application;
- date of birth, identity documents, and other similar data are not requested.
5.3. Certain data may be processed in a technical, functional, or legal context if, without such processing, the functioning of the Application, ensuring security, error handling, the operation of the geolocation logic, the operation of the loyalty program, or compliance with legal requirements would be impossible or substantially hindered.
6. WHAT INFORMATION MAY BE PROCESSED
6.1. Account data
Upon registration and use of the Account, the Company may process:
- the name specified by the User;
- phone number;
- email address;
- the confirmation status of the phone number and email, events of sending and verification of one-time passwords (OTP), without storing the content of the codes after their use;
- the User's internal identifier;
- the identifier of the User's personal QR code;
- session data: login device, session start and end time;
- interface language and Application settings.
6.2. Technical and operational information
Upon installation, launch, and use of the Application, the Company may automatically process limited technical and operational information, including:
- device ID and other technical device identifiers (Firebase);
- information on the version of the Application (Firebase);
- information on the version of the operating system (Firebase);
- technical parameters of the device and runtime environment (Firebase);
- crash logs (Firebase);
- diagnostic records (Firebase);
- technical events within the Application (Firebase);
- network and system parameters, including IP address, if this is necessary for security, diagnostics, and ensuring the operation of the Service (Firebase).
Such information is used exclusively to the extent necessary for the technical functioning of the Application, stability analysis, identification of malfunctions, ensuring security, prevention of abuse, and improvement of the quality of the Service.
6.3. Geolocation and routing information
If the user grants the relevant permission at the device level, the Company may process:
- precise geolocation in real time;
- routing events;
- data related to route planning and use of navigation logic;
- search queries for addresses and places and the selected search results.
- The specified information is used for: route planning, displaying relevant movement options, navigation, improving routing logic, analysis of service quality, and diagnostics and resolution of incidents, if necessary.
6.4. Loyalty program, Wallet, and Visit data
For registered Users using the loyalty program, the Company may process:
- the Points balance, available and reserved;
- the history of Points transactions: cashback accruals, redemptions when paying with Points, cancellation, expiration; for each transaction: date and time, transaction type, amount, name of the Partner Venue, transaction identifier;
- Visit data: the fact and time of scanning of the personal QR code, the identifier of the Partner Venue, the bill amount entered by the venue's staff member, the amount of cashback accrued, the amount paid with Points;
- service data confirming the Visit: the identifier of the Partner Venue staff member who performed the scan, the geoposition of the staff member's device at the moment of scanning (for the purposes of verifying the correctness of the Visit), the status and result of the operation;
- the User's requests regarding disputed accruals and the results of their review.
6.5. Analytics data
The Company uses product analytics tools (Amplitude) to analyze the use of the Application. For analytical purposes, events of interaction with the Application interface may be processed, including: opening of screens and sections, use of search and filters, actions in the venue catalog, actions in the Wallet, language selection, onboarding and registration events (without the content of OTP codes), and technical parameters of the device and session. Analytics data is used to improve the interface, routing logic, relevance of the displayed information, and product development.
6.6. Advertising identifiers and campaign effectiveness measurement
The Company may process the device advertising identifier to measure the effectiveness of marketing campaigns and to attribute installations of the Application. Such processing is carried out exclusively with the User's consent. The tool used for these purposes is Amplitude.
On the iOS platform, the processing of the device advertising identifier (IDFA) is carried out only after the User's permission has been obtained through the App Tracking Transparency mechanism. The User may withdraw such permission at any time in the device settings.
On the Android platform, the processing of the device advertising identifier (Google Advertising ID) is carried out only with the User's consent granted in the Application. The User may at any time reset the advertising identifier or delete it in the device settings; after the identifier is deleted, the Application and the connected tools cease to receive its value.
Withdrawal of consent, as well as resetting or deleting the advertising identifier, does not affect the availability of the Application's functions. The Company does not use the advertising identifier for purposes unrelated to measuring the effectiveness of marketing campaigns and attributing installations of the Application.
6.7. Derived, analytical, and statistical information
The Company shall have the right to generate derived, evaluative, analytical, and statistical information based on the data processed in connection with the use of the Application, if this is necessary for: improving routing scenarios, improving the interface, increasing the relevance of the displayed information, analysis of user scenarios, internal analytics, security and resilience of the Service, and development of the loyalty program. Such information shall, where possible, be used in aggregated, anonymized, or otherwise minimized form, if this is compatible with the purposes of processing.
6.8. Request data
The content of support requests and dispute requests, the WhatsApp communication channel, the contact details required for a response, and the history of correspondence regarding the request.
7. SOURCES OF INFORMATION
The Company may receive information:
- directly from the User (upon registration, changes to Account data, support requests, and submission of dispute requests);
- automatically when the Application is used;
- from its own technical, routing, and cartographic systems;
- from transport datasets and open sources, including GTFS and other similar data;
- from internal logs, monitoring systems, and diagnostic tools;
- from Partner Venues and their staff in the course of confirming Visits (the fact of QR code scanning, the bill amount, the confirmation status).
Open transport and cartographic sources by themselves, as a rule, do not provide the Company with user data, but may be used together with technical and geolocation data to ensure the operation of the Service.
8. PURPOSES OF PROCESSING
The Company processes information only to the extent necessary for one or more of the following purposes:
- provision of routing and navigation functionality;
- display of information on urban mobility and public transport;
- registration, authentication, and servicing of the Account, including the sending of OTP codes;
- functioning of the loyalty program: accrual of cashback, maintenance of the balance and transaction history, enabling payment with Points, display of the personal QR code;
- confirmation of Visits to Partner Venues and correct calculation of accruals;
- review of requests and disputes regarding accruals and redemptions;
- processing of User requests;
- processing of requests to the support service, including requests via WhatsApp;
- processing of partnership applications (Apply as a partner), including the applicant's contact details (governed separately by the Privacy Policy);
- sending of service notifications: SMS and email with verification codes, push notifications on Points transactions and Visit statuses (subject to permission for push notifications);
- diagnostics, correction of errors, and improvement of the stability of the Application;
- ensuring information security;
- prevention of abuse, bad-faith use, and technical attacks, including abuse of the loyalty program;
- analysis of use of the Service and product development;
- internal quality control and operational analytics;
- compliance with legal requirements, including the requirements of accounting legislation;
- protection of the rights and lawful interests of the Company.
9. LEGAL BASES FOR PROCESSING
The Company carries out information processing on one or more of the following legal bases:
- necessity of processing for the provision to the User of the service requested by them, including performance of the terms of the loyalty program;
- necessity of processing for performance of the Terms of Use of the Application;
- consent of the User, if and when such consent is required by applicable law (in particular: access to geolocation, push notifications, processing of the device advertising identifier on the iOS and Android platforms);
- necessity of compliance with a legal obligation imposed on the Company, including obligations to retain transaction records;
- the Company's legitimate interest, including the interest in ensuring security, stability, diagnostics, analytics, product development, prevention of abuse, and protection of the Company's rights, if such interest does not violate the rights and freedoms of the User.
If processing is based on consent, the User shall have the right to withdraw such consent in the manner provided for by applicable law; withdrawal of consent does not affect the lawfulness of the processing carried out before the withdrawal.
10. PERSONALIZATION, PROFILING, AND ANALYTICS
10.1. The Company shall have the right to use information on the User's interaction with the Application, routing scenarios, navigation actions, actions in the venue catalog, and use of individual functions for:
- personalization of the interface;
- improvement of display logic;
- forming more relevant recommendations, including recommendations of Partner Venues;
- improvement of routing logic;
- product analytics.
10.2. The Company does not make exclusively automated decisions producing legally significant consequences for the User without human participation, unless otherwise expressly disclosed separately. Automated checks within the framework of abuse prevention (Section 12) may result in transactions being flagged for subsequent manual review; decisions affecting the User's accruals are made with human participation.
10.3. The Company does not currently use Users' data for direct marketing. If marketing communications are introduced, such processing will be carried out on the basis of the User's separate explicit consent. The User will be able to withdraw consent at any time by the same means through which the communication is carried out, or by any other available means; processing for direct marketing purposes shall cease no later than 7 working days after receipt of the withdrawal.
11. GEOLOCATION
11.1. The use of geolocation is an essential part of the operation of Movnex. The Company may process the User's precise geolocation for:
- route planning;
- navigation;
- determination of relevant transport scenarios;
- display of the nearest Partner Venues;
- improvement of the quality of routing logic;
- analysis of the quality of operation of the Service;
- processing of incidents and requests, if necessary.
11.2. Background geolocation may be used only after the User grants the corresponding permission at the device level.
11.3. If the User does not grant permission to use geolocation, certain functions of the Application may be unavailable, limited, or operate with reduced accuracy. Participation in the loyalty program does not require the User to grant access to geolocation.
11.4. When a Visit is confirmed, the geoposition of the device of the Partner Venue's staff member at the moment of scanning the QR code may be processed; this data relates to the control of the correctness of Visits and does not constitute tracking of the User's location.
12. ANTI-ABUSE MEASURES
12.1. To protect Users, Partner Venues, and the Company from fraud and bad-faith use of the loyalty program, the Company may:
- maintain a log (audit log) of all scans of personal QR codes, including the time, the User identifier, the venue identifier, the transaction type, the bill amount, the geoposition of the staff member's device, and the staff member identifier;
- apply automatic rate limiting of transactions;
- verify that the geoposition at the moment of scanning corresponds to the location of the venue;
- automatically flag transactions with signs of anomalies for manual review;
- carry out manual review of transactions in the course of dispute resolution.
12.2. Data processed for these purposes is used exclusively to ensure the correctness of transactions, resolve disputes, prevent abuse, and protect the Company's rights, and is not used for other purposes.
13. MINORS
13.1. Use of the Application in guest mode (reference, routing, and navigation functions) has no special age restriction.
13.2. Registration of an Account and participation in the loyalty program are available to persons who have reached the age of 16. By registering an Account, the User confirms that they have reached the specified age.
13.3. In accordance with the Law of Georgia on Personal Data Protection, consent to the processing of the personal data of a minor under the age of 16 is given by their parent or other legal representative. When processing data relating to minors, the Company proceeds from the need to protect the best interests of the minor and to apply measures proportionate to the user's age, the nature of the Service, and the risks of processing.
13.4. If the Company becomes aware that certain processing of a minor's personal data is carried out in violation of applicable law, the Company shall have the right to restrict the relevant functionality, suspend processing, delete data, or otherwise bring such processing into compliance with the law.
13.5. A parent or other legal representative may contact the Company at info@gpsolutions.tech, attaching confirmation of their authority.
14. TRANSFER AND DISCLOSURE OF INFORMATION
14.1. The Company shall have the right to transfer information only to the extent necessary to achieve the purposes specified in this Policy to the following categories of recipients:
- Partner Venues in the course of confirming a Visit: when the personal QR code is scanned, the venue's staff member is shown the User's name and the data necessary for carrying out the operation, including the bill amount and the result of the operation; the venue's manager has access to summary information on the operations at their venue;
- GP Solutions DMCC as the parent company of the group: for the purposes of development, technical support, provision of infrastructure, and functioning of the Application; data may be transferred between Movnex LLC and GP Solutions DMCC under intra-group data processing agreements;
- service and technical contractors (providers of infrastructure, analytics, and SMS, email, and push notification delivery), listed in Section 21;
- consultants, auditors, lawyers, and other professional advisers to the extent necessary;
- competent state authorities, courts, law enforcement authorities, regulators, and other authorized entities where there is a legal basis or mandatory requirement;
- other persons, if such transfer is necessary for the protection of the rights of the Company, users, or third parties.
14.2. The Company does not sell user data and does not disclose it to third parties for such persons' independent direct marketing.
14.3. Partner Venues receive access to the User's data exclusively to the extent necessary for confirming the Visit and carrying out loyalty program operations, and are obliged to use such data only for these purposes.
14.4. The Company transfers data to service providers, contractors, and group companies (including GP Solutions DMCC) only on the basis of agreements obliging such recipients to ensure a level of data protection no lower than that provided for by this Policy and applicable law, to process data exclusively on the documented instructions of the Company, and not to use it for their own purposes.
15. INTERNATIONAL TRANSFER
15.1. Users' data is stored on the servers of the infrastructure provider Hetzner in Finland (Helsinki), within the European Union.
15.2. Certain service providers specified in Section 21 (in particular Google Firebase, Amplitude, SMSService.ge, Bird, Meta) may process data in other jurisdictions, including the USA. Such transfer is carried out in accordance with the requirements of the Law of Georgia on Personal Data Protection: to states and organizations ensuring appropriate data protection guarantees according to the lists determined by the supervisory authority, or on the basis of an agreement with the recipient ensuring appropriate guarantees of data protection and of the User's rights.
15.3. Intra-group transfer of data to GP Solutions DMCC (UAE) is carried out to the extent necessary for the purposes specified in Section 14, on the basis of an intra-group data processing and protection agreement ensuring appropriate guarantees.
16. RETENTION PERIODS
16.1. The Company retains information no longer than necessary to achieve the purposes of processing, unless a longer period is required or permitted by law, or is necessary for dispute resolution, ensuring security, compliance with a legal obligation, or protection of the Company's rights.
16.2. Unless otherwise required by law or by the circumstances of a particular case, the Company proceeds from the following indicative retention periods:
- Account data: for the duration of the existence of the Account and for 12 months after its deletion (Section 17);
- Wallet and Points transaction records: at least 6 years in accordance with the requirements of the tax and accounting legislation of Georgia;
- Audit log of QR code scans and Visit data: at least 2 years;
- Geolocation events and derived routing records: as a rule, up to 12 months, unless a longer period is required in connection with an incident, investigation, security, a dispute, or compliance with law;
- Routing and other related service records: as a rule, up to 5 years, if this is necessary for analytics, legal protection, incident review, and improvement of the Service;
- User requests and related correspondence, including accrual disputes: as a rule, up to 3 years from completion of the processing of the request, unless longer retention is required for legal or operational reasons;
- Crash logs, diagnostic, and technical records: as a rule, up to 12 months;
- Access and security logs: as a rule, up to 12 months, unless longer retention is required for reasons of investigation, security, abuse, technical incident, or legal requirement;
- Event-based analytics data: as a rule, up to 24 months; aggregated and anonymized statistics may be retained without limitation of period.
16.3. Upon expiry of the applicable retention period, data shall be deleted, anonymized, or otherwise removed from active processing, except where further retention is required by law or necessary for the establishment, exercise, or defense of legal claims.
17. ACCOUNT DELETION
17.1. The User may delete the Account at any time: in the Application (My Account, Delete My Account) or by submitting a request via the web page or by email to info@gpsolutions.tech. Deletion requests submitted via the web page or by email are, as a rule, processed within 3 days of receipt.
17.2. Upon deletion of the Account:
- the Account is deleted: access to the Account, the Wallet, and the personal QR code is terminated, and the Account is removed from active systems and cannot be restored;
- accumulated Points are cancelled without monetary or other compensation;
- Account data is retained for 12 months from the date of deletion for the purposes of resolving possible disputes, preventing abuse, and complying with legal requirements (limited retention on the specified legal grounds does not constitute continued use of the Account), after which it is deleted or anonymized;
- records of Points transactions are retained for the periods provided for in clause 16.2, to the extent necessary to comply with accounting requirements, including in anonymized form;
- the historical data of a deleted Account is not transferred to a new Account upon re-registration with the same phone number or email address.
18.SECURITY
18.1. The Company applies technical and organizational measures to protect information from unauthorized access, unlawful processing, destruction, loss, alteration, disclosure, and other unlawful impact. Such measures may include:
- encryption in transit and at rest;
- segregation of access rights;
- logging and monitoring;
- backup;
- internal incident response procedures;
- assessment of supplier reliability.
18.2. Access of Partner Venue staff to transaction data is restricted by a role model: a staff member has access only to the data necessary for carrying out the current operation; extended data is available only to the venue's manager and the Company's administrators.
18.3. Despite the application of security measures, no system of transmission, processing, or storage of information can guarantee absolute protection.
18.4. In the event of a data security incident that may cause substantial harm or create a substantial threat to the rights and freedoms of natural persons, the Company shall notify the supervisory authority no later than 72 hours from the moment the incident is identified, in the manner provided for by law, and shall also maintain an internal register of incidents, their consequences, and the measures taken.
18.5. If an incident creates a substantial threat to the User's rights, the Company shall immediately inform the User of the incident, its possible consequences, and the measures being taken, except in cases provided for by law.
19. USER RIGHTS
19.1. To the extent provided by applicable law, the User shall have the right to:
- receive information about the processing of their personal data;
- request access to their personal data;
- require correction, updating, or clarification of inaccurate or incomplete data;
- require deletion of personal data in the absence of legal grounds for further processing;
- withdraw consent, if processing is based on consent;
- require restriction of processing in cases provided for by law;
- object to processing in cases provided for by law;
- require data portability in applicable cases;
- lodge a complaint with the supervisory authority of Georgia for personal data protection (as of the date of publication of this Policy, its functions are exercised by the State Audit Office of Georgia) or with a court.
19.2. Requests may be sent to: info@gpsolutions.tech in the following languages:
- English;
- Georgian;
- Arabic;
- Russian;
- Turkish;
- Uzbek.
19.3. In the event of any contradiction, discrepancy, difference in interpretation, or inconsistency between the language versions of this Policy, the English version shall prevail.
20. REVIEW OF REQUESTS
20.1. The Company reviews data subjects' requests within the time limits established by the Law of Georgia on Personal Data Protection: as a rule, no later than 10 working days from receipt of the request. In special cases, where duly justified, this period may be extended by no more than 10 working days, of which the applicant shall be notified immediately. The internal target period for an initial response is up to 2 working days; such target period does not replace the time limits established by law.
20.2. The Company shall have the right to request additional information necessary to confirm the identity of the applicant and verify their authority.
21. EXTERNAL SERVICES AND PLATFORMS
21.1. The Application may use external technical infrastructure and platform dependencies necessary for its operation, including:
- Hetzner (Finland): hosting and server infrastructure;
- Firebase (Google): technical telemetry, crash logs, push notification delivery;
- Amplitude: product analytics;
- Bird and SMSService.ge: delivery of SMS with verification codes;
- SMSService.ge: delivery of email messages with verification codes;
- Telegram: a tool for confirmation of Visits by Partner Venue staff (Telegram Mini App); the User does not interact with Telegram directly within the Application;
- WhatsApp (Meta): a channel for contacting the support service; when contacting support via WhatsApp, the User's phone number and the content of the correspondence with support are processed;
- Google Maps: mapping services;
- Amplitude: measurement of the effectiveness of marketing campaigns and attribution of installations (only with the User's consent obtained in the manner described in clause 6.6).
21.2. The Apple App Store and Google Play may act as channels for distribution of the Application; however, they are not controllers of the user's personal data within the framework of the relations governed by this Policy, unless otherwise expressly provided by their own documents.
21.3. Device manufacturers, operating system providers, mobile operators, and other external technical participants may process data on the basis of their own rules and policies, which are outside the Company's control.
22. TRANSPORT AND OPEN DATA
22.1. Movnex uses its own GTFS resources, transport datasets, and open sources to display information on public transport, stops, routes, schedules, and navigation.
22.2. Such sources are used for routing and informational functionality and, by themselves, as a rule, do not transfer the user's personal data to the Company.
23. AMENDMENT OF THE POLICY
23.1. The Company shall have the right at any time to amend, supplement, and update this Policy.
23.2. The current version of the Policy is published in the Application interface or otherwise brought to the user's attention. If the changes are material in nature, the Company shall have the right additionally to notify users through the Application or in another appropriate manner.
23.3. Continued use of the Application after the entry into force of an updated version of the Policy shall mean the user's acceptance of such version to the extent permitted by applicable law.
24. CONTACT INFORMATION
For all questions related to this Policy and the processing of information, the user may contact:
Movnex LLC
Email: info@gpsolutions.tech
Telephone: +971 (4) 5808147
Address: Georgia, Tbilisi, Saburtalo district, Bakhtrioni str., N22, flat 75
For data protection matters: Jamshid Gaybullaev, info@gpsolutions.tech