🔒 Gizlilik Politikası
Son güncelleme: Temmuz 2026 · Yürürlük tarihi: 1 Temmuz 2026
1. Giriş
OnMez ("uygulama", "biz", "şirket"), Türkiye'nin Kuşadası/Didim bölgesine odaklanan bir sosyal ve tanışma platformudur. Bu Gizlilik Politikası, 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) ve Avrupa Birliği Genel Veri Koruma Yönetmeliği (GDPR) kapsamındaki yükümlülüklerimizi yerine getirmek amacıyla hazırlanmıştır.
Uygulamayı kullanarak bu politikayı kabul etmiş sayılırsınız. Kabul etmiyorsanız lütfen uygulamayı kullanmayınız.
2. Topladığımız Kişisel Veriler
| Veri Kategorisi | Toplanan Veriler | Hukuki Dayanak |
|---|---|---|
| Kimlik Bilgileri | Ad, soyad, doğum tarihi, cinsiyet | Sözleşme ifası, açık rıza |
| İletişim Bilgileri | Telefon numarası, e-posta adresi | Hesap kimlik doğrulaması |
| Konum Verileri | GPS konumu, check-in mekan bilgisi | Açık rıza (her kullanımda) |
| Profil Fotoğrafları | Yüklenen fotoğraflar (galeri/kamera) | Açık rıza |
| Konum Tercihi | Kullanıcının belirttiği şehir/ilçe | Sözleşme ifası |
| Mesajlar | Kullanıcılar arası sohbet içerikleri | Sözleşme ifası |
| Kimlik Doğrulama | Manuel kimlik belgesi (yönetici incelemesi) | Açık rıza, meşru menfaat |
| Cihaz Bilgileri | Push bildirim token'ı, işletim sistemi | Meşru menfaat |
| İşlem Verileri | Jeton/token satın alma geçmişi (aktif değil) | Sözleşme ifası |
⚠️ Önemli: Konum verileri yalnızca açık onayınızla toplanır. İzni istediğiniz zaman cihaz ayarlarından geri alabilirsiniz.
3. Verilerinizi Nasıl Kullanıyoruz
- Hesap oluşturma, kimlik doğrulama ve güvenliğin sağlanması
- Eşleştirme ve yakındaki kullanıcıları gösterme (konum bazlı)
- Mekan check-in sistemi (QR kod ve GPS doğrulaması)
- Kullanıcılar arası mesajlaşma hizmetinin sunulması
- Push bildirimleri gönderilmesi (eşleşme, mesaj, etkinlik)
- Kimlik doğrulama (profil güvenilirliğinin artırılması)
- Hizmet kalitesinin korunması ve kötüye kullanımın önlenmesi
- Yasal yükümlülüklerin yerine getirilmesi
📊 Analitik: Uygulamamızda üçüncü taraf analitik aracı (Sentry, PostHog vb.) bulunmamaktadır. Verileriniz reklam amaçlı kullanılmaz veya üçüncü taraflarla paylaşılmaz.
4. Veri Depolama ve Güvenlik
Altyapı: Tüm veriler, AB veri merkezlerinde barındırılan Supabase üzerinde depolanır. Supabase, ISO 27001 ve SOC 2 Type II sertifikalarına sahiptir.
Güvenlik önlemleri:
- Aktarım sırasında TLS 1.2+ şifreleme
- Depolamada AES-256 şifreleme
- Satır düzeyinde güvenlik (Row-Level Security) politikaları
- Kimlik doğrulama için JWT tabanlı oturum yönetimi
- Fotoğraflar Supabase Storage'da erişim kontrolüyle saklanır
- Kimlik belgeleri kısıtlı erişimli özel klasörlerde tutulur
Saklama süresi: Hesabınızı sildiğinizde verileriniz 30 gün içinde kalıcı olarak silinir. Mesaj verileri hesap silinmesiyle birlikte anonimleştirilir.
5. Veri Aktarımı ve Üçüncü Taraflar
Verilerinizi satmıyor, kiralamıyor veya reklam amaçlı paylaşmıyoruz. Aşağıdaki sınırlı durumlar dışında üçüncü taraflarla paylaşım yapılmaz:
- Supabase (AB): Veri tabanı, kimlik doğrulama ve dosya depolama altyapısı
- Apple / Google (Push): Bildirim iletimi için yalnızca cihaz token'ı iletilir; mesaj içeriği aktarılmaz
- Yetkili makamlar: Yalnızca yasal zorunluluk halinde ve mahkeme kararıyla
🌐 Supabase AB veri merkezlerini kullandığından verileriniz GDPR güvencesi altında işlenmektedir.
6. Kullanıcı Hakları (KVKK Md. 11 & GDPR Md. 15–22)
Bu haklarınızı kullanmak için [email protected] adresine e-posta gönderin. Talepler 30 gün içinde yanıtlanır. Ayrıca Kişisel Verileri Koruma Kurumu (KVKK)'na şikayette bulunma hakkınız saklıdır.
7. Çerez Politikası
OnMez mobil uygulama olarak geleneksel web çerezleri kullanmamaktadır. Uygulama içinde aşağıdaki yerel depolama teknolojileri kullanılmaktadır:
- AsyncStorage / SecureStore: Oturum token'ı ve kullanıcı tercihleri (cihazda yerel)
- Expo Secure Store: Kimlik doğrulama bilgilerinin şifreli depolanması
Bu veriler cihazınızda yerel olarak tutulur ve sunucularımıza gönderilmez. Uygulamayı kaldırdığınızda otomatik olarak silinir.
8. Reşit Olmayanlar
OnMez yalnızca 18 yaş ve üzeri kullanıcılara yöneliktir. Kayıt sırasında doğum tarihi doğrulaması yapılmaktadır. 18 yaşından küçük kişilerden bilerek veri toplamıyoruz. Böyle bir durumu fark ederseniz lütfen bize bildirin; ilgili hesabı derhal kapatacağız.
9. Push Bildirimleri
Uygulama; eşleşme, mesaj ve etkinlik bildirimleri göndermek için Expo Push Notification altyapısını kullanmaktadır. Bildirimler için:
- İzin, yükleme sırasında veya ilk kullanımda ayrıca istenir
- Cihaz ayarlarından veya uygulama içinden her zaman devre dışı bırakabilirsiniz
- Bildirim içerikleri Apple/Google sunucularından geçerken şifrelenmektedir
10. Politika Değişiklikleri
Bu politikayı zaman zaman güncelleyebiliriz. Önemli değişiklikler söz konusu olduğunda uygulama içi bildirim ve/veya e-posta yoluyla bilgilendirilirsiniz. Değişikliklerin ardından uygulamayı kullanmaya devam etmeniz güncel politikayı kabul ettiğiniz anlamına gelir.
11. İletişim
🔒 Privacy Policy
Last updated: July 2026 · Effective date: 1 July 2026
1. Introduction
OnMez ("app", "we", "us") is a social and dating platform focused on the Kuşadası/Didim region of Turkey. This Privacy Policy fulfills our obligations under Turkey's Personal Data Protection Law No. 6698 (KVKK) and the European Union's General Data Protection Regulation (GDPR).
By using the app, you agree to this policy. If you do not agree, please discontinue use of the application.
2. Personal Data We Collect
| Data Category | Data Collected | Legal Basis |
|---|---|---|
| Identity | First name, last name, date of birth, gender | Contract performance, explicit consent |
| Contact | Phone number, email address | Account authentication |
| Location | GPS coordinates, venue check-in data | Explicit consent (per-use) |
| Profile Photos | Uploaded images (gallery/camera) | Explicit consent |
| Location Preference | City/district specified by user | Contract performance |
| Messages | Chat content between users | Contract performance |
| ID Verification | Identity document (admin review only) | Explicit consent, legitimate interest |
| Device Info | Push notification token, OS type | Legitimate interest |
| Transactions | Token/jeton purchase history (not yet active) | Contract performance |
⚠️ Important: Location data is only collected with your explicit permission. You can revoke this at any time through your device settings.
3. How We Use Your Data
- Account creation, authentication, and security
- Matching and showing nearby users (location-based)
- Venue check-in system (QR code and GPS verification)
- Providing in-app messaging services
- Sending push notifications (matches, messages, events)
- Identity verification (to enhance profile credibility)
- Maintaining service quality and preventing abuse
- Fulfilling legal obligations
📊 Analytics: We do not use any third-party analytics tools (Sentry, PostHog, etc.). Your data is never used for advertising or shared with third parties for commercial purposes.
4. Data Storage & Security
Infrastructure: All data is stored on Supabase, hosted in EU data centers. Supabase holds ISO 27001 and SOC 2 Type II certifications.
Security measures:
- TLS 1.2+ encryption in transit
- AES-256 encryption at rest
- Row-Level Security (RLS) policies enforced on all tables
- JWT-based session management for authentication
- Photos stored in Supabase Storage with access controls
- Identity documents held in restricted-access private buckets
Retention: When you delete your account, your data is permanently erased within 30 days. Message data is anonymized upon account deletion.
5. Data Transfers & Third Parties
We do not sell, rent, or share your data for advertising. Sharing only occurs in the following limited circumstances:
- Supabase (EU): Database, authentication, and file storage infrastructure
- Apple / Google (Push): Only the device token is transmitted for notification delivery; message content is never shared
- Authorities: Only when legally required and with a valid court order
🌐 Because Supabase uses EU data centers, your data is processed under GDPR safeguards.
6. Your Rights (KVKK Art. 11 & GDPR Art. 15–22)
To exercise any of these rights, email [email protected]. Requests are processed within 30 days. You also have the right to lodge a complaint with the Personal Data Protection Authority (KVKK) in Turkey, or the relevant supervisory authority in your country of residence.
7. Cookie Policy
As a mobile application, OnMez does not use traditional web cookies. The following local storage technologies are used within the app:
- AsyncStorage / SecureStore: Session tokens and user preferences (stored locally on-device)
- Expo Secure Store: Encrypted storage of authentication credentials
This data is stored locally on your device and is not sent to our servers independently. It is automatically removed when you uninstall the application.
8. Minors
OnMez is intended solely for users aged 18 and over. Date of birth is verified at registration. We do not knowingly collect data from minors. If you become aware that a minor is using the app, please contact us immediately; we will close the account without delay.
9. Push Notifications
The app uses Expo's push notification infrastructure to deliver match, message, and event alerts. Regarding notifications:
- Permission is requested separately during onboarding or first use
- You can disable notifications at any time via device settings or within the app
- Notification content is encrypted while passing through Apple/Google servers
10. Policy Updates
We may update this policy from time to time. For material changes, you will be notified via an in-app notification and/or email. Continued use of the app after changes constitutes your acceptance of the updated policy.