App Privacy Policy & KVKK Data Protection Notice

1. Privacy Policy

This Privacy Policy explains how personal data is processed within the Randeviz app itself - the business side, the customer side, and the install-free public booking page - covering business accounts, customer accounts and appointment data. It is separate from the marketing-site Privacy Policy, which covers only randeviz.com and the early-access list.

1.1. Scope

This policy covers the Randeviz mobile app and the public booking page at /b/<code>: business (owner/staff) accounts, customer accounts - including guest bookings made without ever setting a password - and the appointment, waitlist and notification data created through them. It does not cover randeviz.com or the early-access list; those are covered by the separate marketing-site Privacy Policy.

1.2. Data controller

Your personal data is processed by Heval Söğüt, a real person, as data controller. Address: Fırat Mah., Doğa Evleri A Blok, Diyarbakır 21070, Türkiye. Contact: iletisim@randeviz.com.

1.3. Personal data we process - business accounts

If you create a business account (as an owner), we process:

  • Identity & contact - your full name, phone number and email address.
  • Business profile - your business's name, category, address, city and map coordinates (only if you turn on map/nearby discovery), and logo image.
  • Language preference - Turkish or English.
  • Push notification token - an Expo-issued device token used to deliver booking alerts.
  • Business settings - working hours, services, staff list, and whether bookings need your approval before they're confirmed.
  • Booking code - the unique code customers use to find and book your business.

1.4. Personal data we process - customer accounts

If you create a customer account, or book as a guest on the public booking page, we process:

  • Identity & contact - your full name and phone number. An email address is only collected if you sign in with email/password, Google, or Sign in with Apple; a guest booking made without setting a password has no email at all.
  • Language preference.
  • Push notification token, if you allow notifications on your device.
  • Booking history - the appointments, reschedules, cancellations and waitlist entries linked to your account.

1.5. Personal data we process - appointments

Every booking, whether made by an account holder or a guest, creates an appointment record containing:

  • The business, staff member and service you selected.
  • The date, time and duration of the appointment.
  • Its status (pending, confirmed, cancelled, completed or no-show) and any notes the business adds.
  • Your name and phone number as they stood at the time of booking. These are stored on the appointment record itself, separately from your account, so the business keeps its booking history even if you later change your details or delete your account.

1.6. Purposes of processing

Your personal data is processed to: (i) create and operate business and customer accounts; (ii) let customers find and book appointments, and let businesses manage their calendar, staff and services; (iii) send booking-related push notifications - confirmations, reminders, cancellations, waitlist openings; (iv) show a business on the map/nearby discovery list, only once that business has opted in; (v) prevent abuse and keep the service secure. Your data is not sold and is not used for advertising.

1.7. Legal basis for processing (KVKK art. 5)

Creating your account and performing the booking you request from a business is based on KVKK art. 5/2-c) (performance of a contract to which you are a party). Push notifications implementing that same booking rest on the same basis; you can turn them off in your device settings at any time. The cross-border transfer described in §1.8 is based on your explicit consent (KVKK art. 5/1), given at signup. Security and abuse-prevention processing rests on the data controller's legitimate interest (KVKK art. 5/2-f).

1.8. Method of collection

Your personal data is collected electronically: directly from you through the app's sign-up, sign-in and booking forms; from Google or Apple when you use their sign-in buttons; and automatically, as booking, notification and device-token data generated while you use the service.

1.9. Data transfers and cross-border transfer

To provide the service, Randeviz uses the following service providers (data processors). Because their servers are located outside Türkiye, in the United States, your personal data is processed and stored abroad. This cross-border transfer is based on your explicit consent (açık rıza) under KVKK art. 9, which you give at signup - Randeviz does not rely on an adequacy decision or Standard Contractual Clauses for this transfer:

  • Hosting, database and authentication - Supabase. All account, business and appointment data is stored here; its servers are outside Türkiye.
  • Sign-in - Google Sign-In and Sign in with Apple, used only if you choose those sign-in options. Google or Apple processes the identity token needed to sign you in; their servers are outside Türkiye.
  • Push notifications - Expo's push notification service delivers booking confirmations, reminders and cancellations to your device. It receives your device's push token and the notification content (e.g. business and service name); its servers are outside Türkiye.

1.10. Retention period

Deleting your account removes your account and profile immediately, whether you are an owner or a customer. If you are a business owner, your business listing is also stripped of its identifying details (name, address, phone, email, logo) at that same moment; the emptied business record and its appointment/waitlist history are then kept for up to 30 days before an automated job permanently destroys them - this window exists so the business's history with its other, still-active customers isn't wiped the instant one owner account is removed. If you are a customer, your name and phone number are stripped from every appointment record immediately; the business keeps the now-anonymised appointment as its own booking history. While your account is active, your data is kept for as long as the account exists. Guest bookings made on the public booking page without ever setting a password do not yet have an automatic expiry; a guest's data is kept until deletion is requested through §2.7, or until the business they booked with closes and its own 30-day purge (above) runs.

1.11. Data security

Reasonable technical and administrative measures are taken to prevent unlawful processing of your personal data and unauthorised access to it; data is transmitted over encrypted connections (HTTPS) and access to it is restricted by row-level security policies. While no method can guarantee absolute security, we take care to protect your data.

1.12. Changes to this text

This policy may be updated from time to time. The current version is always published at this address; material changes will be reflected here.

2. KVKK Data Protection Notice

The following notice is prepared under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and the related Communiqué, to inform data subjects who use the Randeviz app as a business or a customer.

2.1. Identity of the data controller

Data controller: Heval Söğüt, Fırat Mah., Doğa Evleri A Blok, Diyarbakır 21070, Türkiye. Contact: iletisim@randeviz.com.

2.2. Personal data processed

Identity and contact data, business profile data, appointment data, and device push tokens, as listed in the Privacy Policy above (§1.3–1.5).

2.3. Purposes of processing

To operate business and customer accounts, enable booking between them, deliver booking-related push notifications, support opt-in business discovery, and keep the service secure. Full detail is in §1.6.

2.4. Legal bases for processing

Performance of the account and booking contract (KVKK art. 5/2-c); explicit consent for the cross-border transfer in §2.5 (KVKK art. 5/1); the data controller's legitimate interest for security and abuse prevention (KVKK art. 5/2-f).

2.5. Transfer of personal data

Your personal data is transferred abroad to the service providers listed in §1.9 (Supabase, Google/Apple sign-in, Expo push notifications), to the extent each needs to provide its part of the service. This is a cross-border transfer; its lawful basis is your explicit consent (KVKK art. 9), given at signup - not an adequacy decision or Standard Contractual Clauses. Beyond this, your data is not shared with third parties.

2.6. Rights of the data subject (KVKK art. 11)

Under Article 11 of the KVKK, by applying to the data controller you have the right to:

  • Learn whether your personal data is being processed.
  • Request information if your personal data has been processed.
  • Learn the purpose of processing and whether the data is used in line with that purpose.
  • Know the third parties within Türkiye or abroad to whom your personal data is transferred.
  • Request that your personal data be corrected if it has been processed incompletely or inaccurately.
  • Request the erasure or destruction of your personal data within the conditions set out in the KVKK and related legislation.
  • Request that correction, erasure or destruction be notified to the third parties to whom your personal data has been transferred.
  • Object to a result against you arising from the analysis of the processed data exclusively by automated systems.
  • Claim compensation if you suffer damage due to the unlawful processing of your personal data.

2.7. How to exercise your rights

You can exercise the rights above by emailing iletisim@randeviz.com, or by using the in-app account-deletion screen for erasure requests. Your request will be concluded as soon as possible and within thirty days at the latest, under KVKK art. 13. Withdrawing your consent to the cross-border transfer in §2.5 means the service - which depends on hosting outside Türkiye - can no longer be provided to you; in that case we will discuss deleting your account with you instead.

2.8. Explicit consent statement

When you create a business or customer account in the app - by email/password, or via Google/Apple sign-in - you must actively check a consent box before sign-up can complete; it is not pre-ticked, and sign-up is blocked without it. Checking it is your explicit consent (açık rıza) to the cross-border transfer described in §1.9/§2.5, and this consent is recorded, not just gated: the server stamps the exact moment (as your account is created, or as your role is confirmed for a social sign-in) together with the version of this notice you consented to. The app itself has no way to set or backdate this record - only the server does, at that moment. Guest bookings made on the public booking page without creating an account do not yet have a dedicated consent checkbox or record - this is a known gap, to be closed before the guest flow is treated as fully compliant.

2.9. VERBİS registration

The data controller has assessed that there is no obligation to register with VERBİS (the Data Controllers' Registry Information System).

Contact

For all questions and requests regarding privacy and your personal data: iletisim@randeviz.com. Data controller: Heval Söğüt, Fırat Mah., Doğa Evleri A Blok, Diyarbakır 21070, Türkiye.