Privacy Notice and Privacy Policy
This notice explains, under Article 10 of the Turkish Personal Data Protection Law No. 6698 (KVKK), which personal data is processed while you use the Planliyoo app, for what purpose and for how long. A notice is not consent: you are not asked to approve separately the processing that is not marked "explicit consent" below.
1. Data controller
Planliyoo. The company's legal name, address and MERSİS number will be added to this section once the company is incorporated. For requests under KVKK: privacy@planliyoo.com.
2. Personal data processed
- Account details: Phone number (for sign-in verification and security; not shown to other users), birth year (your profile shows only an age range; the date of birth you enter when signing up is used only to confirm that you are 18 or older and is not stored), pseudonym, an optional short bio and gender (female, male or "I'd rather not say"; only you see it, it is not shown to other users and is not used for matching). No phone number is taken for guest sign-in; a guest account cannot open or join an activity.
- Activity requests: The text of your request, the activity type you choose, the day, time, number of people and filters.
- Invites: The links you create to bring a friend into a group; if you joined through a link in your first week, who invited you. If you entered an invite code when signing up, the channel the code came from (for example a promotional event); this is reported only as totals.
- Weekly activities: If you make a meetup weekly, a new meetup opens every week on the same day and time. If you took part in the last two meetups of a weekly activity, that participation is used to hold a place for you in the next one.
- Interests ("Notify me"): The activity type you want to hear about, the approximate district and distance (rounded to about 500 metres), days, times and how many offers a week you want at most. Nobody can see it; it is kept until you delete it or your account.
- Location: An approximate location, taken only while the app is open and only if you allow it. The location is rounded to about 500 metres before it leaves your device; the exact location is not stored or shared with anyone. Other users see only an approximate distance such as "< 1 km". If you do not give your location, the centre of the district you type is used. The location of a meetup check-in is separate (below).
- Meetup check-in (QR code): When you meet, you and another member scan each other's QR code (or type the 6-digit code under it). The camera is on only while scanning; no image is recorded, stored or sent, and the microphone is not used. If you prefer not to open the camera, you can type the code instead. At in-person meetups, to confirm that the two phones are together (within 200 metres), your phone's current location is sent while showing and scanning the code; this location is kept only with the current code, shown to no one, and deleted when the check-in window closes (3 hours after the meetup starts). The attendance record keeps only that the check-in happened, with whom, and the distance between the two phones (in metres). No location is taken for online activities.
- Chat and ratings: Messages in group and friend chats, ratings after a meetup and notes that only the moderation team sees. Messages pass through an automatic content filter.
- Safety and moderation: Reports (including optional screenshots; file details such as location in the images are removed on the device), blocks, cancellations you make as an organiser, attempts stopped by the content filter (the text written is not stored), moderation decisions and appeals.
- Notifications: In-app notifications and the notification key specific to your device used to send them.
- Hadi Points and rewards: Your points history, level, badges and the sponsor coupons you claimed.
- Identity verification (optional): Only with your explicit consent; the document and the face capture are processed directly by the verification provider, and we keep only the result.
- Crash reports: App errors are sent after details such as phone numbers, e-mail addresses and verification codes are removed on the device.
- Feedback: A bug report or suggestion you send from the app, with the app version and platform; kept for one year, and unlinked from you when you delete your account.
- Usage statistics: Steps such as opening the app or creating a request are recorded without the account ID, the IP address or the text written, with a random session ID renewed at every launch; these records cannot be linked to a person.
3. Purposes and legal grounds
| Purpose | Legal ground (KVKK Articles 5 and 6) |
|---|---|
| Opening the account, matching requests, arranging the group chat and the meetup | Formation and performance of the contract |
| The age limit of 18, account security, preventing harassment and fraud, reviewing reports | Legitimate interest; legal obligation |
| Confirming with a QR code that a meetup took place (reading the code with the camera; at in-person meetups, confirming with the current location that the two phones are together), attendance and no-show records | Performance of the contract; legitimate interest (preventing false attendance and no-shows) |
| Fixing app errors and anonymous usage statistics | Legitimate interest |
| Awarding Hadi Points, badges and sponsor rewards | Performance of the contract |
| Finding nearby activities by location, suggestions based on interests, campaign notifications | Explicit consent (optional; Explicit Consent Notice) |
| Identity and liveness verification (biometric data) | Explicit consent (optional) |
| Lawful requests from the competent authorities | Legal obligation |
4. Who the data is transferred to
Data is not sold or shared for advertising or profiling. The following service providers process data to provide the service: Supabase (database and sign-in; EU region), an SMS provider in Turkey (sign-in code), a web hosting provider (public pages and the staff console; EU region), e-mail service providers (support and request mailboxes, e-mails to staff accounts), Expo (delivering notifications), Sentry (crash reports), the App Store, Google Play and RevenueCat (subscriptions), SumSub (optional identity verification) and, only if it is turned on separately, Google Gemini (turning the text of your request into activity details; it is off by default, and if it is turned on the text is sent after details such as phone numbers, e-mail addresses, links and IBANs are removed, and without your account ID; chat messages are never sent). Some of these providers are abroad; transfers abroad are made under the conditions of KVKK Article 9 and are confirmed in the legal review. In lawful judicial requests, data may be shared with the competent authorities.
5. How data is collected
Data is collected electronically from the information you enter in the app, from the records created while you use it and (if you gave it) from your device's location permission. For a meetup check-in, the camera is used only to read the code and only when you start it; the location at the check-in is taken while showing and scanning the code on the check-in screen.
6. Retention periods
| Data | Period |
|---|---|
| Group chat messages | Deleted 30 days after the meetup ends or is cancelled; a chat under report review is kept until the review ends |
| Current location at a meetup check-in | Deleted when the check-in window closes (3 hours after the meetup starts); only the distance (in metres) stays in the attendance record |
| Completed requests | After 90 days the text and location are deleted, and only anonymous statistics remain |
| Notifications | 90 days |
| Blocked content attempts | 90 days |
| Anonymous usage statistics | 180 days |
| Organiser cancellation records | 1 year |
| Claimed coupons | 2 years |
| Report and moderation files, evidence images | 3 years |
| Audit records | 5 years |
| Judicial request records | 10 years |
7. When you delete your account
You can get a copy of your data from the app (Profile → Privacy → Download my data); the copy also includes the moderation decisions made about you and your appeals and statements, but not who reported you.
You can delete your account from the app (Profile → Privacy). Your pseudonym and bio are anonymised; your birth year, phone number, settings, notifications, notification keys, blocks, friendships and messages in friend chats, points history, badges, coupons, subscription and identity verification records are deleted, and your open requests are cancelled. Your messages in group chats stay under an anonymous name and are deleted when the 30-day period ends. If there is an open report review, a restriction or a legal hold about you, the deletion waits until the review ends. Details are on the Account Deletion page.
8. Your rights (KVKK Article 11)
You have the right to learn whether your data is processed, to ask for information about it, to learn whether it is used for its purpose, to know who it is transferred to, to ask for it to be corrected, deleted or destroyed, to ask for those it was transferred to be told of this, to object to a result against you produced by automated systems, and to ask for your damage to be compensated. You can get a copy of your data from the app right away (Profile → Privacy → Download my data).
You can send your requests from the app or to privacy@planliyoo.com, with your registered phone number. Requests are answered within 30 days at the latest. If you find the answer insufficient, you can complain to the Turkish Personal Data Protection Board.