Privacy policy
Last updated
- Hashiv has no server of its own. Your invoices are read from taxservice.am straight to your phone.
- Your taxservice.am username and password go only to taxservice.am, and are stored encrypted on your device.
- We never see your invoices, amounts, counterparties or company data.
- The app sends anonymous diagnostics to Google Firebase. You can switch that off in Profile.
- This website sets no cookies and has no analytics.
Who is responsible
Hashiv is published by TO BE COMPLETED, TO BE COMPLETED. For anything on this page, write to beta@hashiv.am.
Hashiv is an independent application. It is not affiliated with taxservice.am, the State Revenue Committee, or any government body.
Your taxservice.am login
When you sign in, your TIN, username and password are sent directly from your phone to taxservice.am — to ews.taxservice.am and e-invoicing.taxservice.am. They do not pass through any server belonging to us, because there is no such server.
If you ask the app to remember them, they are stored on your device using Android's EncryptedSharedPreferences, with the encryption key held in the device's hardware-backed Keystore. They are never included in any backup: a key sealed by one phone's Keystore cannot be restored onto another, so backing up the credentials would produce nothing usable anyway.
Your invoices
Invoice data — amounts, counterparties, TINs, line items, statuses — is read live from taxservice.am each time you open the app, and held only in your phone's memory and local storage. None of it is transmitted to us or to anyone else. We could not show you your own invoices from our side, because we do not have them.
Hashiv is read-only. It never signs, approves, cancels or submits anything on taxservice.am.
What you add yourself
Project and material tags, payment statuses, reminders, the CEO name and bank details you enter are yours and stay on your device. taxservice.am does not store them and neither do we.
They are included in Android's own backup, so that reinstalling or moving to a new phone does not lose them. That backup goes to your Google account, encrypted, not to us. It covers only the app's local bookkeeping and cached logos. Your credentials and your list of signed-in accounts are deliberately excluded from it.
Diagnostics
The app reports crashes and anonymous usage to Google Firebase (Crashlytics and Analytics), so that we can find out what breaks during the beta. You can turn this off entirely in Profile → Privacy. Switching it off disables collection inside Google's SDKs, so nothing is queued or sent while it is off — though it cannot delete what was already uploaded.
Usage events record that something happened and nothing about its content. An event carries no parameters at all — not an amount, not a name, not a TIN. The complete list is:
account_signed_in,account_added,account_removedscreen_home,screen_invoices,screen_analytics,screen_notifications,screen_profile,screen_invoice_detailinvoice_marked_paid,project_tagged,material_tagged,reminder_set,ceo_name_added,requisites_sharedfeedback_prompt_shown,feedback_submittedlogin_failed,invoice_load_failed
Being straight about the limits of that: while diagnostics are on, Firebase also collects its own standard data that we do not control — an app instance identifier, device model, operating system version, app version, approximate country, and first-open and session-start events. Crash reports contain a stack trace, the device model and the app version. We never attach a user id or any custom key to them.
Diagnostics are on by default during the closed beta. That is a deliberate choice for a small, known group of testers who were told about it, and it will be revisited before any public release.
This website
This site sets no cookies, runs no analytics, has no forms and stores nothing about you. Two things are still worth naming:
- Fonts load from Google Fonts, so Google receives your IP address and browser details when a page loads. We plan to host the fonts ourselves, which removes that.
- The site is hosted on Google Firebase Hosting, which keeps standard web server logs.
The “Join the beta” button opens Firebase App Distribution, which is Google's service and asks you to sign in with a Google account. What you do there is covered by Google's privacy policy, not this one. We see the email address of testers who join, and nothing else.
What we never do
- We do not sell, rent or share your data with anyone.
- We do not show ads in the app, and there are no advertising or tracking SDKs in it.
- We do not build profiles of you or your business.
- We do not read, store or transmit your invoice contents.
Your choices
- Diagnostics: Profile → Privacy, any time.
- Stored credentials: sign out, or remove the account in Profile, and they are deleted from the device.
- Everything else: uninstalling removes all local data. If you also want it gone from Android's backup, delete the app's backup in your Google account settings.
- Requests: write to beta@hashiv.am. Since we hold no account and no invoice data, there is usually nothing on our side to export or erase — but ask, and we will tell you exactly what exists.
Children
Hashiv is a tool for businesses and is not intended for anyone under 18.
Changes
If this policy changes in a way that affects what is collected, the date at the top changes and testers are told in the release notes.