Privacy Policy
Valid from August 11, 2026
This Policy explains what personal data GEEKSHOP processes, for which purposes, who may receive it, how it is protected, and how users can exercise their rights.
The policy applies to geekshop.uz, user account, orders, requests and agreed GEEKSHOP communication channels.
- 1. Operator and scope
- 2. What data and where do we get it from?
- 3. Objectives and legal basis
- 4. Data retention and deletion
- 5. Cookies and local storage
- 6. Google Analytics 4
- 7. Recipients and handlers
- 8. Cross-border processing and storage
- 9. Data protection
- 10. User rights
- 11. Withdrawal of consent, account deletion and restrictions
- 12. Reviews, questions, and publicly available data
- 13. Minors
- 14. Changes, requests and complaints
1. Operator and scope
Personal data operator: individual entrepreneur NOSIROV ISMOILJON MUROD O'G'LI. Phone: +998 50 477 70 77. Email for data subject requests: info@geekshop.uz.
The date, time and place of transfer of a confirmed order for pickup are agreed upon separately with the manager.
The policy applies to the data of visitors, registered users, customers, purchasers and persons contacting support.
2. What data and where do we get it from?
We do not ask you to provide full bank card details, passport details or other redundant information in a free comment. If such data is not needed for a specific legitimate purpose, it will be deleted or access restricted.
- Data you provide: name, phone number, email address, Telegram ID or username, delivery or pickup address, comments, and the content of requests, reviews, and questions.
- Account and transaction data: orders, cart, favorites, last viewed products, bonuses, consents, statuses, returns and interaction history.
- Technical data: IP address, access date and time, language, browser and device information, technical identifiers, required cookies and local storage, security and error logs.
- Data from agreed services: SMS delivery confirmation, Telegram login and messages, payment or delivery statuses when the corresponding service is actually used.
3. Objectives and legal basis
The amount of data must be necessary and sufficient for the previously stated purpose. If there is an incompatible change of purpose, a new basis or consent is requested.
- Registration, login using a one-time confirmation code or via Telegram and account protection - consent, provision of the requested service and a proportionate legitimate interest in security.
- Shopping cart, favorites, viewed products and support responses - fulfillment of the requested function and a proportionate legitimate interest that does not violate the user's rights.
- Placing and checking an order - actions at the user’s request before the possible conclusion of a contract, response to requests and consent when required.
- Order confirmation, contract, receipt, guarantee, return and accounting - conclusion and execution of a contract, legal requirements and defense of legal claims.
- Optional analytics and marketing require separate voluntary consent, which may be withdrawn.
- Preventing abuse, diagnosing and protecting infrastructure is a proportionate legitimate interest and legal obligation.
4. Data retention and deletion
When the goal is achieved, the consent period has expired or the consent is revoked and there is no other basis, the data is deleted, destroyed or anonymized. Legal blocking for a dispute or mandatory accounting is limited to the required composition of data.
- Login verification information is stored only for a limited period of time necessary to complete or reject the login attempt.
- Active session data is stored for a limited period and becomes invalid after logging out, terminating the session, blocking or deleting the account.
- The prepared export of personal data is available to the user only for a limited period, after which the link becomes invalid.
- Favorites are kept until the user deletes them or the account is deleted; browsing history is limited in scope.
- Order, contract, and payment records are retained for as long as necessary for performance, warranty service, claims, and tax and accounting purposes. If deletion is requested, personal data in order records may be retained in limited form for the standard internal period of up to five years, after which it is anonymized unless a legal basis requires longer retention.
- Optional analytics data in a GA4 resource is stored for up to 14 months; Your browser consent choice remains until you change it or clear your storage.
Official sources: Personal Data Law, Articles 10, 17–19, Accounting Law, Article 29
5. Cookies and local storage
Necessary cookies and local storage are used to log in, operate the shopping cart, select language and theme, and save privacy settings. They are not used for optional analytics without separate consent.
Necessary identifiers are stored for a limited period of time and are updated or deleted when the corresponding purpose is no longer needed. The user can delete cookies in the browser, but the login and shopping cart may not work.
Optional analytics IDs are not generated by GEEKSHOP until analytics is specifically enabled.
6. Google Analytics 4
With separate voluntary consent, Google Analytics 4 may collect customer ID, page views and actions, session, approximate region, browser and device information, and anonymized speed and stability metrics.
We prohibit sending phone number, email, delivery address, Telegram username, recipient name, tokens, secrets and free comments to analytics. The IP address may be used by Google when receiving data to determine the approximate region; According to Google's documentation, it is not recorded in GA4 as a normal event field.
Analytics is disabled by default. You can give or withdraw consent in your account settings; once consent is withdrawn, no new analytics events are sent. Withdrawal does not guarantee deletion of aggregated statistics that have already been processed lawfully, but you may ask the Operator for access or deletion.
7. Recipients and handlers
Only the required volume is transferred. Contracts with processors should limit purposes, ensure confidentiality and security, regulate subcontractors, return or deletion of data, and assistance with incidents. When the law requires individual written notification of inclusion in the database or transfer to a third party, the Operator shall provide such notification separately.
- Authorized employees and contractors of GEEKSHOP - only within the limits of job duties and confidentiality.
- Hosting, database, CDN, backup and information security providers.
- Providers SMS, login confirmation and Telegram - for the selected login method, support or service messages.
- Delivery, payment organization, bank, service center or accounting operator - only when necessary for a specific order or contract.
- Google - only after separate consent to analytics.
- Courts and government bodies - in the presence of a legal and duly formalized demand.
Official sources: Personal Data Law, Articles 22–23 and 31
8. Cross-border processing and storage
As of the date of the Policy, mandatory storage in Uzbekistan directly applies to biometric, genetic data and user data of telecommunications operators to the extent provided by law. Other personal data may be stored abroad only if there is a mechanism permitted by Article 27-1 of the Personal Data Law.
Transfer to a country without sufficient protection is permitted on the basis of Article 15, including express consent where applicable, but such consent does not in itself replace the separate requirements of Article 27-1 for foreign storage. Until the applicable mechanism is confirmed, the relevant optional foreign processing must remain disabled.
Consent to Google Analytics is separate and voluntary. The operator is required to document the applicable mechanism, countries and providers and stop the transfer if there is no legal mechanism.
Official sources: Personal Data Law, Articles 15 and 27-1, Changes of 2026, Law No. ZRU-1125
9. Data protection
The operator applies proportionate legal, organizational and technical protection measures, taking into account the nature of the data and risks. Specific configurations, thresholds, and internal security procedures are not publicly disclosed.
No method of transmission or storage provides an absolute guarantee. The user must protect access to the phone, Telegram and device and immediately report suspicious activity.
Official sources: Personal Data Law, Articles 27, 28 and 31
10. User rights
The request is sent to info@geekshop.uz. To protect data, we have the right to adequately verify identity in a secure manner without asking for excessive information; A passport copy is not requested unless necessary. Correction is made without undue delay, and in cases provided for by law - within three days. A reasoned refusal to provide information is sent in writing within the period established by law.
- Obtain information about the availability, composition, sources, purposes, grounds, methods, processing times and recipients of data.
- Gain access to your data and request correction of inaccurate or outdated information.
- Demand to suspend illegal processing, delete or destroy data if there is a legal basis.
- Give consent, withdraw it in the same accessible way, and separately opt out of analytics or marketing.
- Object to a purely automated decision that has legal consequences and require human intervention.
- Appeal the actions of the Operator to an authorized body or court.
Official sources: Personal Data Law, Articles 11, 17, 22–24, 30–31
11. Withdrawal of consent, account deletion and restrictions
Withdrawal of optional consent applies regardless of account deletion and stops related future processing once the request is received and verified.
A request to delete your account can be submitted in the settings. To protect against erroneous deletion, a cancellation period may apply, the duration of which is communicated to the user when making a request. After it, active sessions are terminated, addresses, shopping cart, favorites and browsing history are deleted, publications are anonymized, and the necessary contractual information is legally saved to a limited extent and then anonymized.
If the data is needed for an unconfirmed or incomplete order, dispute, return, fraud prevention or mandatory accounting, access restriction until the end of the relevant period may apply instead of immediate deletion.
12. Reviews, questions, and publicly available data
The name of the author, text, photo or video in a review or question may become available to an unknown number of people. A separate basis is required before publication and, where required by law, recorded electronic consent for distribution.
The user should not publish other people's personal data. Upon reasonable request, information will be corrected, deleted or anonymized if there is no legal basis for continued publication.
Official sources: Personal Data Law, Articles 14 and 29
13. Minors
A person under the age of majority must place an order and provide data through a parent or other legal representative, unless independent action is permitted by law. Consent to the processing of a minor's data is given by a legal representative in writing or electronically.
If we reasonably learn that data has been obtained without the required consent of a representative, processing will be suspended and the data will be deleted unless there is another legal basis.
Official sources: Personal Data Law, Article 21
14. Changes, requests and complaints
The new version applies from the specified date and does not make previously legal processing illegal retroactively. If there is a significant change in the purposes or terms of consent, we request a new basis or consent. The version associated with the order or consent is saved in history.
Inquiries and complaints: info@geekshop.uz, +998 50 477 70 77. The user also has the right to contact the authorized state body for personal data or the court.
Last updated: August 11, 2026.