OnMez

Gizlilik Politikası / Privacy Policy
🇹🇷 Türkçe
🇬🇧 English

🔒 Gizlilik Politikası

Son güncelleme: Temmuz 2026  ·  Yürürlük tarihi: 1 Temmuz 2026

👋

1. Giriş

OnMez ("uygulama", "biz", "şirket"), Türkiye'nin Kuşadası/Didim bölgesine odaklanan bir sosyal ve tanışma platformudur. Bu Gizlilik Politikası, 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) ve Avrupa Birliği Genel Veri Koruma Yönetmeliği (GDPR) kapsamındaki yükümlülüklerimizi yerine getirmek amacıyla hazırlanmıştır.

Uygulamayı kullanarak bu politikayı kabul etmiş sayılırsınız. Kabul etmiyorsanız lütfen uygulamayı kullanmayınız.

📋

2. Topladığımız Kişisel Veriler

Veri Kategorisi Toplanan Veriler Hukuki Dayanak
Kimlik Bilgileri Ad, soyad, doğum tarihi, cinsiyet Sözleşme ifası, açık rıza
İletişim Bilgileri Telefon numarası, e-posta adresi Hesap kimlik doğrulaması
Konum Verileri GPS konumu, check-in mekan bilgisi Açık rıza (her kullanımda)
Profil Fotoğrafları Yüklenen fotoğraflar (galeri/kamera) Açık rıza
Konum Tercihi Kullanıcının belirttiği şehir/ilçe Sözleşme ifası
Mesajlar Kullanıcılar arası sohbet içerikleri Sözleşme ifası
Kimlik Doğrulama Manuel kimlik belgesi (yönetici incelemesi) Açık rıza, meşru menfaat
Cihaz Bilgileri Push bildirim token'ı, işletim sistemi Meşru menfaat
İşlem Verileri Jeton/token satın alma geçmişi (aktif değil) Sözleşme ifası

⚠️ Önemli: Konum verileri yalnızca açık onayınızla toplanır. İzni istediğiniz zaman cihaz ayarlarından geri alabilirsiniz.

🎯

3. Verilerinizi Nasıl Kullanıyoruz

  • Hesap oluşturma, kimlik doğrulama ve güvenliğin sağlanması
  • Eşleştirme ve yakındaki kullanıcıları gösterme (konum bazlı)
  • Mekan check-in sistemi (QR kod ve GPS doğrulaması)
  • Kullanıcılar arası mesajlaşma hizmetinin sunulması
  • Push bildirimleri gönderilmesi (eşleşme, mesaj, etkinlik)
  • Kimlik doğrulama (profil güvenilirliğinin artırılması)
  • Hizmet kalitesinin korunması ve kötüye kullanımın önlenmesi
  • Yasal yükümlülüklerin yerine getirilmesi

📊 Analitik: Uygulamamızda üçüncü taraf analitik aracı (Sentry, PostHog vb.) bulunmamaktadır. Verileriniz reklam amaçlı kullanılmaz veya üçüncü taraflarla paylaşılmaz.

🗄️

4. Veri Depolama ve Güvenlik

Altyapı: Tüm veriler, AB veri merkezlerinde barındırılan Supabase üzerinde depolanır. Supabase, ISO 27001 ve SOC 2 Type II sertifikalarına sahiptir.

Güvenlik önlemleri:

  • Aktarım sırasında TLS 1.2+ şifreleme
  • Depolamada AES-256 şifreleme
  • Satır düzeyinde güvenlik (Row-Level Security) politikaları
  • Kimlik doğrulama için JWT tabanlı oturum yönetimi
  • Fotoğraflar Supabase Storage'da erişim kontrolüyle saklanır
  • Kimlik belgeleri kısıtlı erişimli özel klasörlerde tutulur

Saklama süresi: Hesabınızı sildiğinizde verileriniz 30 gün içinde kalıcı olarak silinir. Mesaj verileri hesap silinmesiyle birlikte anonimleştirilir.

🌍

5. Veri Aktarımı ve Üçüncü Taraflar

Verilerinizi satmıyor, kiralamıyor veya reklam amaçlı paylaşmıyoruz. Aşağıdaki sınırlı durumlar dışında üçüncü taraflarla paylaşım yapılmaz:

  • Supabase (AB): Veri tabanı, kimlik doğrulama ve dosya depolama altyapısı
  • Apple / Google (Push): Bildirim iletimi için yalnızca cihaz token'ı iletilir; mesaj içeriği aktarılmaz
  • Yetkili makamlar: Yalnızca yasal zorunluluk halinde ve mahkeme kararıyla

🌐 Supabase AB veri merkezlerini kullandığından verileriniz GDPR güvencesi altında işlenmektedir.

⚖️

6. Kullanıcı Hakları (KVKK Md. 11 & GDPR Md. 15–22)

🔍
Erişim Hakkı
Hangi verilerinizi işlediğimizi öğrenme
✏️
Düzeltme Hakkı
Yanlış verilerin düzeltilmesini isteme
🗑️
Silme Hakkı
Hesabınızın ve verilerinizin silinmesi
📦
Taşınabilirlik
Verilerinizi JSON formatında dışa aktarma
🚫
İtiraz Hakkı
İşlemenin durdurulmasını talep etme
🔒
Kısıtlama
İşlemenin geçici olarak kısıtlanması

Bu haklarınızı kullanmak için [email protected] adresine e-posta gönderin. Talepler 30 gün içinde yanıtlanır. Ayrıca Kişisel Verileri Koruma Kurumu (KVKK)'na şikayette bulunma hakkınız saklıdır.

🍪

7. Çerez Politikası

OnMez mobil uygulama olarak geleneksel web çerezleri kullanmamaktadır. Uygulama içinde aşağıdaki yerel depolama teknolojileri kullanılmaktadır:

  • AsyncStorage / SecureStore: Oturum token'ı ve kullanıcı tercihleri (cihazda yerel)
  • Expo Secure Store: Kimlik doğrulama bilgilerinin şifreli depolanması

Bu veriler cihazınızda yerel olarak tutulur ve sunucularımıza gönderilmez. Uygulamayı kaldırdığınızda otomatik olarak silinir.

👶

8. Reşit Olmayanlar

OnMez yalnızca 18 yaş ve üzeri kullanıcılara yöneliktir. Kayıt sırasında doğum tarihi doğrulaması yapılmaktadır. 18 yaşından küçük kişilerden bilerek veri toplamıyoruz. Böyle bir durumu fark ederseniz lütfen bize bildirin; ilgili hesabı derhal kapatacağız.

📢

9. Push Bildirimleri

Uygulama; eşleşme, mesaj ve etkinlik bildirimleri göndermek için Expo Push Notification altyapısını kullanmaktadır. Bildirimler için:

  • İzin, yükleme sırasında veya ilk kullanımda ayrıca istenir
  • Cihaz ayarlarından veya uygulama içinden her zaman devre dışı bırakabilirsiniz
  • Bildirim içerikleri Apple/Google sunucularından geçerken şifrelenmektedir
📝

10. Politika Değişiklikleri

Bu politikayı zaman zaman güncelleyebiliriz. Önemli değişiklikler söz konusu olduğunda uygulama içi bildirim ve/veya e-posta yoluyla bilgilendirilirsiniz. Değişikliklerin ardından uygulamayı kullanmaya devam etmeniz güncel politikayı kabul ettiğiniz anlamına gelir.

📬

11. İletişim

Veri Sorumlusu: OnMez

Adres: Kuşadası/Didim, Aydın, Türkiye

E-posta: [email protected]

🔒 Privacy Policy

Last updated: July 2026  ·  Effective date: 1 July 2026

👋

1. Introduction

OnMez ("app", "we", "us") is a social and dating platform focused on the Kuşadası/Didim region of Turkey. This Privacy Policy fulfills our obligations under Turkey's Personal Data Protection Law No. 6698 (KVKK) and the European Union's General Data Protection Regulation (GDPR).

By using the app, you agree to this policy. If you do not agree, please discontinue use of the application.

📋

2. Personal Data We Collect

Data Category Data Collected Legal Basis
Identity First name, last name, date of birth, gender Contract performance, explicit consent
Contact Phone number, email address Account authentication
Location GPS coordinates, venue check-in data Explicit consent (per-use)
Profile Photos Uploaded images (gallery/camera) Explicit consent
Location Preference City/district specified by user Contract performance
Messages Chat content between users Contract performance
ID Verification Identity document (admin review only) Explicit consent, legitimate interest
Device Info Push notification token, OS type Legitimate interest
Transactions Token/jeton purchase history (not yet active) Contract performance

⚠️ Important: Location data is only collected with your explicit permission. You can revoke this at any time through your device settings.

🎯

3. How We Use Your Data

  • Account creation, authentication, and security
  • Matching and showing nearby users (location-based)
  • Venue check-in system (QR code and GPS verification)
  • Providing in-app messaging services
  • Sending push notifications (matches, messages, events)
  • Identity verification (to enhance profile credibility)
  • Maintaining service quality and preventing abuse
  • Fulfilling legal obligations

📊 Analytics: We do not use any third-party analytics tools (Sentry, PostHog, etc.). Your data is never used for advertising or shared with third parties for commercial purposes.

🗄️

4. Data Storage & Security

Infrastructure: All data is stored on Supabase, hosted in EU data centers. Supabase holds ISO 27001 and SOC 2 Type II certifications.

Security measures:

  • TLS 1.2+ encryption in transit
  • AES-256 encryption at rest
  • Row-Level Security (RLS) policies enforced on all tables
  • JWT-based session management for authentication
  • Photos stored in Supabase Storage with access controls
  • Identity documents held in restricted-access private buckets

Retention: When you delete your account, your data is permanently erased within 30 days. Message data is anonymized upon account deletion.

🌍

5. Data Transfers & Third Parties

We do not sell, rent, or share your data for advertising. Sharing only occurs in the following limited circumstances:

  • Supabase (EU): Database, authentication, and file storage infrastructure
  • Apple / Google (Push): Only the device token is transmitted for notification delivery; message content is never shared
  • Authorities: Only when legally required and with a valid court order

🌐 Because Supabase uses EU data centers, your data is processed under GDPR safeguards.

⚖️

6. Your Rights (KVKK Art. 11 & GDPR Art. 15–22)

🔍
Right to Access
Know what data we hold about you
✏️
Right to Rectification
Request correction of inaccurate data
🗑️
Right to Erasure
Request deletion of your account and data
📦
Data Portability
Export your data in JSON format
🚫
Right to Object
Request that processing be stopped
🔒
Right to Restrict
Temporarily restrict processing of your data

To exercise any of these rights, email [email protected]. Requests are processed within 30 days. You also have the right to lodge a complaint with the Personal Data Protection Authority (KVKK) in Turkey, or the relevant supervisory authority in your country of residence.

🍪

7. Cookie Policy

As a mobile application, OnMez does not use traditional web cookies. The following local storage technologies are used within the app:

  • AsyncStorage / SecureStore: Session tokens and user preferences (stored locally on-device)
  • Expo Secure Store: Encrypted storage of authentication credentials

This data is stored locally on your device and is not sent to our servers independently. It is automatically removed when you uninstall the application.

👶

8. Minors

OnMez is intended solely for users aged 18 and over. Date of birth is verified at registration. We do not knowingly collect data from minors. If you become aware that a minor is using the app, please contact us immediately; we will close the account without delay.

📢

9. Push Notifications

The app uses Expo's push notification infrastructure to deliver match, message, and event alerts. Regarding notifications:

  • Permission is requested separately during onboarding or first use
  • You can disable notifications at any time via device settings or within the app
  • Notification content is encrypted while passing through Apple/Google servers
📝

10. Policy Updates

We may update this policy from time to time. For material changes, you will be notified via an in-app notification and/or email. Continued use of the app after changes constitutes your acceptance of the updated policy.

📬

11. Contact

Data Controller: OnMez

Address: Kuşadası/Didim, Aydın, Turkey

Email: [email protected]