Privacy Policy
Complete Rules for the Processing and Protection of Personal Data
| Last Updated | August 29, 2026 |
| Company | MivoApp LLC |
| Identification Number | 445831565 |
| Registered Address | No. 66 Khasan Khelimishi Street, Batumi, Georgia |
| Website | mivo.ge |
| support@mivo.ge |
I. General Provisions
Article 1. Purpose of the Policy
1.1. This Privacy Policy explains how MivoApp LLC collects, receives, uses, stores, shares, transfers and otherwise processes personal data in connection with the operation of the Mivo Platform and related services.
1.2. Mivo processes personal data in accordance with applicable Georgian law, including the Law of Georgia on Personal Data Protection.
Article 2. Data Controller
2.1. Where Mivo determines the purposes and means of processing personal data, the data controller is MivoApp LLC.
2.2. For matters relating to personal data, you may contact us at support@mivo.ge.
Article 3. Who This Policy Applies To
3.1. This Policy may apply to Mivo Users, account holders, senders and recipients of Orders and Parcels, representatives and authorised persons of Partner Merchants, Partner Couriers, persons involved in Support matters and other persons whose data is lawfully processed in the course of providing services.
3.2. Not every category of data described below applies to every person. The scope depends on the person’s role, the function used, device permissions and the nature of the particular service.
Article 4. Core Processing Principles
• lawfulness, fairness and transparency;
• a specific and lawful purpose;
• data minimisation;
• accuracy and updating;
• limitation of the retention period;
• confidentiality and security;
• restricting access to persons who need and are authorised to access the data.
Article 5. Required and Voluntary Data
5.1. Providing certain data is necessary to create an account, place an Order, send a Parcel, make a payment, establish or manage a partnership, ensure security or use another particular function.
5.2. If required data is not provided, the relevant function may be unavailable or restricted. Failure to provide voluntary data must not restrict a function for which that data is not necessary.
II. Categories of Personal Data
Article 6. Account and Identification Data
• first and last name;
• telephone number;
• email address;
• profile photo, if provided;
• unique account identifier;
• authentication and account-security information;
• language and region settings;
• relevant information lawfully received through a third-party authentication service where the User chooses to use that function.
Article 7. Telephone Number and Contacts
7.1. A telephone number may be processed for registration, account verification, Order-related contact, delivery coordination, Support and security.
7.2. Providing a telephone number does not mean that Mivo automatically obtains access to the full list of contacts stored on the device. Such access will be requested only where it is genuinely necessary for a particular function, has an appropriate lawful basis and is covered by the relevant device permission.
Article 8. Order and Service Data
• Order number, product, quantity and value;
• delivery fee, discount, promotion and Tip;
• Order date, time, status and participants;
• delivery or pickup address and instructions;
• acceptance, preparation, pickup and handover times;
• cancellation, refund, complaint and dispute information;
• ratings, reviews and Support-related information.
Article 9. Parcel Data
9.1. When the Parcel service is used, Mivo may process information about the sender, the recipient’s name and contact details, pickup and delivery addresses, necessary Parcel-related instructions and performance records.
Article 10. Personal Data of Another Person
10.1. If a User or Partner provides Mivo with another person’s personal data, that person confirms that there is an appropriate lawful basis or authority for providing the data.
10.2. Where required by law, the relevant person must be appropriately informed that their data is being provided to Mivo and used in connection with the relevant service.
Article 11. Payment and Transaction Data
• transaction number;
• transaction amount;
• payment status;
• payment date and time;
• refund status;
• information required for settlements and financial adjustments;
• limited technical or security information received from a payment service provider.
Article 12. Processing of Card Data
12.1. Full card data may be processed directly within the secure system of an authorised payment service provider.
12.2. Mivo does not claim to store full card data where such data is not actually stored in Mivo’s systems.
Article 13. Mivo Wallet Data
13.1. Where Mivo Wallet is active, Mivo may process Wallet balance, credit and spending history, related Orders, refunds, adjustments and security records.
13.2. Wallet data is used only to manage the relevant function, display the balance to the User, maintain financial records, review disputes and ensure security.
Article 14. Partner Merchant Data
14.1. In the case of a Partner Merchant or its representative, Mivo may process relevant registration, identity, contact, banking, tax, business-authorisation, settlement, contractual-performance and security information.
Article 15. Partner Courier Data
15.1. In the case of a Partner Courier, Mivo may process first and last name, identity and contact data, photograph, banking information, relevant vehicle information, settlement data, delivery history, statuses, location, and Support and security records.
Article 16. Technical and Device Data
• IP address;
• relevant device and operating-system identifiers;
• application version;
• session, login and error logs;
• technical network and connection information;
• technical signals required for security and fraud prevention;
• cookie or local-storage records where the relevant technology is used.
Article 17. Support and Communication Data
17.1. Mivo may process text, photos, videos, documents, records relating to calls or other communications sent to Support, Order references and responses from relevant participants.
17.2. Such data is used to resolve issues, maintain quality and security, manage disputes and protect legitimate interests.
III. Location and Device Permissions
Article 18. User Location Data
18.1. Depending on the relevant function and device permission granted, Mivo may process a delivery address, a location selected on the map, approximate or precise location, and pickup and handover coordinates.
18.2. User location may be used to select an address, determine the service area, show nearby Partner Merchants, calculate distance and fees, and fulfil an Order.
Article 19. Partner Courier GPS Location
19.1. When a Partner Courier is active or performing a delivery, the Mivo courier application may process precise GPS-based location to make delivery offers available, coordinate and route deliveries, display relevant movement information to the User, ensure security, review disputes and assess service quality.
Article 20. Background Location Access
20.1. Where appropriate, a Partner Courier’s location may also be processed in the background where this is genuinely necessary for active-status or current-delivery functionality and the corresponding device permission has been granted.
20.2. Background location must not be used for a hidden purpose unrelated to the relevant service.
Article 21. Camera
21.1. Camera access may be required for a profile photo, product material, delivery evidence, damage evidence, a document or another function selected by the User.
21.2. The camera is not used secretly for a purpose that was not disclosed to the User or Partner in connection with the relevant permission.
Article 22. Photos, Videos and Files
22.1. Access to photos and files is used to upload material selected by the User or Partner. Mivo does not request access to the device’s entire storage unless this is necessary for a particular function.
22.2. Partner Merchant photos and videos may be processed for product listings and promotional activity permitted by the partnership agreement.
Article 23. Notifications
23.1. The application may request permission to send notifications about Order status, security, partnership matters, Support and other service-related information.
23.2. Marketing notifications are subject to a separate lawful basis and an appropriate opt-out mechanism.
Article 24. Other Device Permissions
24.1. Access to any other device function must correspond to actual functionality, be purpose-related, comply with the data-minimisation principle and not be used for a hidden or unrelated purpose.
IV. Processing Purposes and Lawful Bases
Article 25. Provision of Services
• creating and managing accounts;
• creating, accepting, preparing, picking up and handing over Orders and Parcels;
• administering payments and settlements;
• refunds and financial adjustments;
• communication with Partners;
• User Support.
Article 26. Security and Fraud Prevention
26.1. Mivo may process relevant account, Order, transaction, location, technical-record and communication data to detect and prevent unauthorised access, use of a stolen payment instrument, fake accounts, suspicious Orders, misuse, disputed card transactions or other fraud.
Article 27. Disputed Transactions and Financial Security
27.1. When reviewing a transaction disputed by a bank, payment service provider or card scheme, Mivo may process relevant evidence concerning Order fulfilment, handover, authorisation, the transaction, communications and other relevant circumstances.
27.2. Such data is used only for resolving the relevant dispute and preventing fraud, to the extent permitted by law.
Article 28. Legal, Tax and Accounting Purposes
28.1. Relevant data may be processed to comply with tax and accounting obligations, respond to judicial or legal requests, protect rights, manage disputes, cooperate with regulatory authorities and pursue other purposes provided by law.
Article 29. Service Improvement and Analytics
29.1. Mivo may use Order, usage, technical and statistical data to analyse Platform performance, use of functions, quality, demand and security.
29.2. Where a purpose can be achieved using aggregated data or data that does not directly identify a person, Mivo seeks to use that less-identifying form.
Article 30. Communications
30.1. Necessary service-related communications may be sent on the basis of performance of a contract, security, legitimate interests or another appropriate lawful basis.
30.2. A necessary communication is not considered direct marketing merely because it is sent through an electronic channel.
Article 31. Direct Marketing
31.1. Direct marketing is carried out only on a lawful basis permitted by applicable law.
31.2. Users will have a simple and accessible way to stop direct marketing where required by law.
Article 32. Lawful Bases
32.1. Depending on the particular processing, the lawful basis may be performance of a contract or steps requested before entering into a contract, compliance with a legal obligation, a legitimate interest of Mivo or a third party, consent, or another basis provided by Georgian law.
32.2. Where processing is based on consent, the person may withdraw consent to the extent provided by law. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
V. Data Sharing and Recipients
Article 33. Partner Merchant
33.1. To fulfil an Order, a Partner Merchant may receive the User’s name, Order details, relevant notes, necessary contact information and other minimum data required for sale of the product and fulfilment of the User’s statutory requests.
33.2. A Partner Merchant must not use data received for personal purposes, unrelated advertising or another unlawful purpose.
Article 34. Partner Courier
34.1. To perform a delivery, a Partner Courier may receive the User’s or recipient’s name, delivery address, telephone number, delivery instructions and other minimum necessary information.
34.2. The Partner Courier uses the data only for the particular delivery, security, Support or another related lawful purpose.
Article 35. Payment Service Providers
35.1. Mivo may share necessary data with an authorised payment service provider, bank or card scheme to authorise and process payments, issue refunds, perform settlements and comply with related legal obligations.
35.2. Full card data may be processed directly by such a service provider, while Mivo may receive only limited transaction information.
Article 36. Fraud-Prevention and Payment-Security Service Providers
36.1. Mivo may share data with a specialised service provider to the relevant and necessary extent where this is required to detect and prevent a suspicious transaction, unauthorised access, use of a stolen payment instrument, a fake account or other fraud.
36.2. Such sharing is limited to data necessary for the relevant security purpose.
Article 37. Technical Service Providers
37.1. Mivo may use providers of cloud infrastructure, data storage, mapping, notifications, communications, analytics, Support, security, backups or other technical services.
37.2. Such a provider receives only the data necessary to provide the relevant service and is subject to appropriate confidentiality and security requirements.
Article 38. Professional Advisers
38.1. Mivo may share relevant data, to the extent necessary, with lawyers, accountants, auditors, tax advisers or other professional advisers where required for Mivo’s lawful operations, protection of rights or compliance with obligations.
38.2. Such recipients must be subject to appropriate professional or contractual confidentiality obligations.
Article 39. Public Authorities
39.1. Where required by law, a court decision, a legal obligation or another proper basis, Mivo may provide information to a court, tax authority, law-enforcement authority, the State Audit Office of Georgia, another regulator or authorised public authority to the relevant and necessary extent.
Article 40. Reorganisation and Business Transfer
40.1. In the event of a merger, division, reorganisation, transfer of assets or a relevant part of the business, investment, acquisition or succession, personal data may lawfully be transferred to the relevant potential or final recipient to the extent necessary for that process.
40.2. Mivo will take reasonable steps to ensure that data is protected in such a process in accordance with confidentiality requirements and applicable law.
Article 41. Publicly Available Data
41.1. If a User or Partner publishes information in a public area of the Platform or an area accessible to other Users, that information may be displayed within the relevant function.
41.2. Mivo does not consider public posting to eliminate all personal-data protection requirements; the processing must still correspond to the relevant purpose and lawful basis.
VI. Data-Protection Roles of Partners
Article 42. Independent Processing by a Partner Merchant
42.1. A Partner Merchant may act as an independent data controller in relation to data for which it independently determines the purposes and means of processing in order to carry out its own sales, fulfil statutory customer claims, or meet its own tax, accounting or other obligations.
42.2. The Partner Merchant is responsible for the lawfulness of its independent processing, information obligations, security and retention periods.
Article 43. Independent Processing by a Partner Courier
43.1. A Partner Courier may be independently responsible for limited processing for which the Partner Courier lawfully determines the purposes and means in order to meet the Partner Courier’s own legal or tax obligations.
43.2. Data received from Mivo for fulfilment of an Order must not be used for an unrelated personal purpose.
Article 44. Processing on Behalf of Mivo
44.1. Where, in a particular function, a Partner or other service provider processes personal data on behalf of Mivo and under Mivo’s documented instructions, it acts in accordance with the applicable processing terms, confidentiality obligations and security requirements.
44.2. In such a case, the scope and purpose of processing, data categories, retention, security, sub-processing and the fate of data upon termination are defined by contract as necessary.
VII. Retention, Security and International Transfers
Article 45. Retention Period
45.1. Personal data is retained only for as long as necessary for the relevant purpose or as required by a legal, tax, accounting, security, dispute-management, fraud-prevention or other lawful obligation.
45.2. The specific retention period may vary depending on the category of data and legal purpose.
Article 46. Account Deletion and Further Retention
46.1. Account deletion or termination of a partnership does not mean immediate deletion of all records where the relevant data remains subject to a valid legal, tax, accounting, security or dispute-related basis.
46.2. When no such basis remains, the data will be deleted, destroyed or converted, within relevant technical capabilities, into a form that can no longer be linked to a particular person.
Article 47. Security Measures
47.1. Mivo applies risk-appropriate technical and organisational measures, including access controls, authorisation restrictions, system logs, backup and recovery processes, security updates, and appropriate network and account-protection measures.
47.2. No digital system can guarantee absolute security, but Mivo takes reasonable steps to reduce risks.
Article 48. Personal Data Security Incident
48.1. In the event of a personal data breach, Mivo assesses the incident and, where required by law, notifies the State Audit Office of Georgia and the relevant data subject within the prescribed period.
48.2. A Partner or processor acting on behalf of Mivo that becomes aware of a possible breach involving personal data connected with Mivo must notify Mivo immediately and without undue delay so that applicable statutory deadlines can be met.
Article 49. International Transfers
49.1. Where use of a technical or other service provider results in the transfer of personal data outside Georgia, Mivo ensures use of the lawful basis and appropriate safeguard required by Georgian law.
49.2. Where necessary, Mivo takes into account the list of countries recognised by the State Audit Office of Georgia as providing appropriate safeguards, a relevant authorisation or another lawful mechanism.
VIII. Rights of Data Subjects
Article 50. Right to Information and Access
50.1. To the extent provided by law, a data subject may obtain information about the processing of their data and request access to the data and an appropriate copy.
50.2. Mivo may request information reasonably necessary to verify a person’s identity so that another person’s data is not disclosed without authorisation.
Article 51. Rectification, Erasure and Restriction
51.1. On grounds provided by law, a data subject may request correction or updating of inaccurate data, deletion or destruction of data, or suspension or restriction of processing.
51.2. These rights may be subject to exceptions provided by law, including where Mivo is required to retain a particular record.
Article 52. Withdrawal of Consent, Objection and Automated Processing
52.1. Where processing is based on consent, the person may withdraw that consent to the extent provided by law.
52.2. A person may exercise statutory rights relating to objection to processing and automated decision-making where the relevant conditions are met in the particular case.
52.3. Mivo may use automated security or fraud signals to initiate additional review. Where a material legal effect for a person would arise solely from an automated flag, the safeguards prescribed by applicable law will apply.
Article 53. Submitting a Request and Supervisory Authority
53.1. For a request relating to personal data, you may email support@mivo.ge.
53.2. Under the current legal framework of Georgia, the relevant supervisory authority in the field of personal data protection is the State Audit Office of Georgia. Contacting Mivo does not limit the right to apply to the State Audit Office, a court or another competent authority.
IX. Other Provisions
Article 54. Third-Party Services, Policy Updates and Contact
54.1. If a User leaves the Mivo Platform for an independent third-party website or service, that third party’s own privacy rules may apply to the service.
54.2. Mivo may update this Policy when there are changes to a function, data category, service provider, security practice, legal requirement or another material circumstance. Where appropriate, additional notice of a material change will be provided through an appropriate channel.
54.3. Company: MivoApp LLC
Identification Number: 445831565
Registered Address: No. 66 Khasan Khelimishi Street, Batumi, Georgia
Website: mivo.ge
Email: support@mivo.ge