Personal Data Protection Notice (KVKK)
Explains which of your personal data we process, for which purposes and on which legal basis under Turkish Law No. 6698 on the Protection of Personal Data.
Data Controller
This notice has been prepared under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"). PlanMEET is operated by a sole proprietorship; the party acting as data controller is Ümit Koştu, with the following contact details:
- Data controller: Ümit Koştu (sole proprietorship)
- Address: Mordoğan Mah. İzmir Cad. No: 329/A, Karaburun / İzmir, Türkiye
- Tax office: Karaburun
- Tax identification number: 5810530369
- VERBİS registration status: Muaf (exempt from registration)
- KVKK application e-mail: kvkk@planmeet.app
Personal Data We Process
Because of the nature of the service, PlanMEET processes the categories of data listed below. Each category is used only for the purpose stated next to it.
| Data category | Data it contains |
|---|---|
| Identity | Full name or display name, date of birth, gender (optional) |
| Contact | E-mail address, phone number (optional) |
| Location | Approximate location (city/district) and fuzzed coordinates |
| Visual | Profile photos, plan photos, verification selfie |
| Transaction security | IP address, device information, session records, sign-in attempts |
| User activity | Plans you create, join requests, matches, messages, ratings |
| Financial | Subscription status, transaction identifier from the payment provider (card details never reach PlanMEET) |
| Consent records | Which version of which document you accepted and when, plus the IP address and browser information at the moment of consent |
How Location Data Is Processed
Location is required for "discover plans near you", PlanMEET's core function. However, your precise location is never shared with other users under any circumstances.
- When your coordinates are stored they are fuzzed by roughly 300 metres using a fixed, per-user offset vector. Your real coordinates are never written to the database.
- Other users only see a bucketed distance ("under 1 km", "5 km", "50+ km"). No response ever contains a decimal distance.
- A location update is recorded at most once every five minutes.
- You can turn location sharing off completely under Privacy and Security settings; plans are then shown based on city matching.
- If you share a meeting location inside a conversation, that is your deliberate action and it is delivered only to the person you matched with.
Purposes of Processing and Legal Bases
| Purpose | Legal basis (KVKK art. 5) |
|---|---|
| Creating membership and managing the account | Conclusion and performance of a contract (art. 5/2-c) |
| Creating, discovering and matching plans | Performance of a contract (art. 5/2-c) |
| Messaging and call features | Performance of a contract (art. 5/2-c) |
| Showing nearby plans (location) | Explicit consent (art. 5/1) |
| Detecting fraud, harassment and fake accounts | Legitimate interest (art. 5/2-f) |
| Reviewing reports and moderation | Legitimate interest (art. 5/2-f) and legal obligation (art. 5/2-ç) |
| Subscription and payment operations | Performance of a contract (art. 5/2-c) |
| Marketing messages | Explicit consent (art. 5/1) |
| Statutory retention obligations | Legal obligation (art. 5/2-ç) |
Parties Data Is Transferred To
PlanMEET uses a limited number of service providers in order to deliver the service. Some of these providers host their servers outside Türkiye, which may constitute a transfer abroad under Article 9 of the KVKK.
| Provider | Data transferred and purpose |
|---|---|
| Cloudflare R2 (cloud storage) | Profile and plan photos |
| Resend (e-mail) | E-mail address — verification, security and notification messages |
| Agora (voice/video calls) | Call session information — call CONTENT is not recorded |
| AWS Rekognition (image moderation) | Uploaded images and verification selfie — not retained after matching |
| Sentry (error tracking) | Technical error records and user identifier — e-mail and IP are not sent |
| RevenueCat (subscription management) | Subscription status and transaction id (card details never reach PlanMEET) |
| iyzico (web payments) | Payment transaction (card details go directly to iyzico, never to PlanMEET) |
| Expo / Firebase (push notifications) | Device notification token and notification title/body |
| Amplitude (product analytics) | Anonymous event records — name, e-mail, location and message content are NOT sent |
| Google Places (venue search) | Search query only — no user identifier is sent |
Retention Periods
The periods below are enforced AUTOMATICALLY: a cleanup job deletes these records at regular intervals. We do not make vague promises like "deleted when necessary" — those cannot be verified.
| Record type | Retention period |
|---|---|
| Profile, plans, messages | While the account is active |
| All personal data after account deletion | 30 days (so you can withdraw the request) |
| Verification selfie | 30 days at the latest — then deleted automatically |
| Plan photos | 7 days after the plan ends |
| Verification codes (OTP) | 1 day |
| Revoked session records | 7 days |
| Notification history | 90 days |
| Call records (duration/status only) | 90 days |
| IP and browser data in audit records | 365 days — the record stays, IP/UA is removed |
| Audit records | 365 days |
| Reports and moderation decisions | Longer, to detect repeat violations |
| Invoice and payment records | The period required by tax legislation |
Your Rights Under Article 11 of the KVKK
The law grants you the following rights, and PlanMEET provides the means for you to exercise all of them:
- To learn whether your personal data is being processed
- To request information if it has been processed
- To learn the purpose of processing and whether the data is used in line with that purpose
- To know the third parties to whom the data is transferred, in Türkiye or abroad
- To request correction if the data is incomplete or inaccurate
- To request erasure or destruction
- To request that correction, erasure and destruction be notified to the third parties the data was transferred to
- To object to a result against you produced by analysis carried out solely by automated systems
- To claim compensation if you suffer damage due to unlawful processing
How to Exercise Your Rights
You can carry out the following directly inside the app — no request needs to be submitted:
- View and download your data: Settings → Privacy and Security → Download my data
- Correct your profile information: Settings → Profile
- Withdraw location processing consent: Settings → Privacy and Security
- Withdraw marketing consent: Settings → Notifications
- Delete your account and your data: Settings → Account → Delete my account
How to Apply
For requests that cannot be resolved inside the app, you may apply in writing to Mordoğan Mah. İzmir Cad. No: 329/A, Karaburun / İzmir, Türkiye or by e-mail to kvkk@planmeet.app. Your application will be concluded within thirty days at the latest, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller.
If your application is rejected or you find the response insufficient, you may file a complaint with the Turkish Personal Data Protection Board within thirty days of learning the response and in any case within sixty days of the application date.