Account Deletion
Last updated: 2026-05-24 Effective: 2026-05-24 Version: 1.0 Reference: ADR-032 Account Deletion Flow, ADR-010A Data Anonymisation, KVKK Articles 7 and 11
At Nakliye360, we are committed to supporting your right to delete your account. This page has been prepared in compliance with Apple App Store, Google Play, and Facebook OAuth platform requirements.
1. Account Deletion Channels
You can delete your account through any of the following 3 channels:
1.1. Via Mobile App (Recommended)
In the Nakliye360 iOS or Android app:
- Open the app
- Tap Profile at the bottom right > Settings or My Account > Account Management
- Tap Delete Account
- (Optional) Select a reason and continue
- Confirm the deletion with phone verification (OTP)
- If 2FA is enabled, provide additional verification
- On the confirmation screen, the 30-day grace period begins
Note: Per Apple App Store Review Guidelines 5.1.1(v), this flow is fully completed within the app — no external browser redirect — including for users who signed in with Apple Sign-In.
1.2. Via Web Admin
At webadmin.nakliye360.com:
- Log in with your account
- From the top-right profile menu, Profile > Account Management
- Delete Account button at the bottom of the page
- Phone OTP + 2FA verification
- 30-day grace period begins after confirmation
1.3. Via Email Request
From your registered email address:
- To: [email protected] (cc: [email protected])
- Subject: Account Deletion Request
- Body:
- First and last name
- Account email and phone
- Registered organisation (if any)
- Explicit statement confirming your request
Email is responded to within 3 business days. Phone OTP verification is requested; after confirmation, the 30-day grace period begins.
1.4. Facebook Data Deletion Callback
If you signed into Nakliye360 with Facebook:
- Go to Facebook Settings > Your account > Apps and Websites
- Find Nakliye360 and tap Remove
- Facebook will send us a Data Deletion Callback with the deletion request
- You will receive a confirmation email with your request id
- 30-day grace period begins
Status check: nakliye360.com/legal/en/account-deletion?fb_dd=<request_id>
2. Account Deletion Flow (ADR-032)
[User Request] -> [Phone OTP + 2FA] -> [Soft Delete] -> [30-day grace]
|
[If user wants to return: ReactivateAccount]
|
[End of grace: HardDelete + Anonymise]
2.1. Step 1 — Soft Delete
When the request is confirmed, your account is immediately suspended:
- Login is blocked
- Your cargo postings are deactivated
- Your active offers are cancelled
- Push, SMS, email notifications stop
- Active shipments are allowed to complete (to avoid harm to the counterparty)
2.2. Step 2 — 30-Day Grace Period
During the 30 days:
- If you wish to return, email [email protected] to reactivate your account.
- During this period your data remains accessible only to you; other users cannot view your profile.
- Data subject to legal retention (e-invoice, logs) is kept in a separate segment.
2.3. Step 3 — Hard Delete + Anonymise
After 30 days:
- Personal data is deleted or anonymised (ADR-010A)
- Data under legal retention is isolated; name/contact fields are masked
- Soft-delete-only flag ends
3. Which Data is Deleted, Anonymised, or Retained?
3.1. Data Fully Deleted
- Password hash (Argon2id)
- OAuth identifiers (Google sub, Apple sub, Facebook user id)
- Push tokens
- Profile photo
- Profile description
- Reviews and ratings (if anonymise option is selected)
- KVKK application records (separately deleted after 5 years)
- Marketing preference record (deleted 3 years after consent revoked)
3.2. Data Anonymised
Kept for metrics without identifying owner:
- Cargo posting history (owner displayed as
[Deleted User]) - Offers given/received
- Shipment statistics (total km, average rating, completion rate — aggregated and anonymous)
- Reviews/ratings (alias
[Deleted User]) - Message content (only operational continuity portion)
3.3. Data Retained for Legal Obligations
The following items are not deleted due to legal obligations; however, access is restricted and KVKK Article 6 sensitive data protection applies:
| Data | Period | Basis |
|---|---|---|
| E-invoice | 10 years | Tax Procedure Law (TPL) m.253, e-invoice regulation |
| Payment transaction record (Iyzico ref) | 10 years | TPL m.253, TCC m.82 |
| Commercial correspondence (contract evidence) | 10 years | TCC m.82 |
| Traffic log (Law 5651) | 2 years | Law 5651 m.5 |
| Audit log (KVKK evidence) | 5 years | Administrative statute of limitations |
| Documents that may be requested by tax inspector | 5 years | TPL |
These are stored in isolated segments; name/contact fields are masked; access is restricted unless requested by a competent authority.
4. Phone Verification and 2FA Requirement
Before hard delete:
- Mobile app: Phone OTP required
- Web admin: Phone OTP + TOTP/passkey if 2FA enabled
- Email request: Phone OTP required (email alone insufficient)
- Facebook callback: Facebook-verified email and callback verification sufficient (phone confirmation in the confirmation email)
This ensures the account cannot be maliciously deleted by another party.
5. Effects of Account Deletion
5.1. Ongoing Shipments
If you have active shipments at request time:
- Carrier/driver work continues but no new offers can be made
- Shipper work continues but no further postings can be made
- Account deletion flow is triggered after shipment completion
This prevents mid-flight cancellation harming the counterparty.
5.2. Payment Obligation
If you have an active subscription or unpaid commission:
- Subscription continues through end of period (no refund)
- Outstanding commission must be settled before account deletion
5.3. Corporate Account (Multi-User)
If you are the admin of an organisation:
- You are first asked to assign an alternative admin
- If you are the sole admin, the organisation is suspended and other members are notified
- Data transfer / archive requests are evaluated
5.4. Return Possibility
During 30-day grace period:
- Account can be reactivated by emailing
- After 30 days, return is not possible; you must re-register
- Old data does not return after re-registration
6. Apple App Store Policy Compliance
Per Apple App Review Guidelines 5.1.1(v):
- Account deletion is fully available within the app — no external browser; Settings > Delete Account completes the flow directly.
- For users who signed in with Apple Sign-In, deletion also revokes the Apple Sign-In token.
- This page is declared in App Store Connect as the Account Deletion URL.
7. Google Play Policy Compliance
Per Google Play Developer Program Policy "Account Deletion":
- As an off-app deletion method, this web page (nakliye360.com/legal/en/account-deletion) is declared in Google Play Console > Data Safety.
- In-app deletion is also available (Section 1.1).
- After the 30-day grace period, all user data is fully deleted or anonymised (excluding legally retained items).
8. Facebook OAuth Policy Compliance
Per Meta Platform Terms:
- Data Deletion Request URL: nakliye360.com/legal/en/account-deletion
- Data Deletion Callback Endpoint: nakliye360.com/api/v1/auth/facebook/data-deletion-callback (POST)
- When the callback arrives with the request id parameter, the account deletion flow triggers.
- A confirmation email is sent to the user.
9. KVKK Article 11 — Right to Erasure
Per KVKK Articles 11 and 7:
- You have the right to "request erasure, destruction, or anonymisation of personal data".
- Request is responded to within a maximum of 30 days.
- All data is deleted/anonymised except data under legal retention.
Submit a formal KVKK request via the Data Subject Application Form.
10. Frequently Asked Questions
Q: Can I recover my account after deletion? A: Yes within the 30-day grace period by emailing [email protected]. Not after 30 days.
Q: What happens to my reviews?
A: They are anonymised; the alias [Deleted User] is shown.
Q: I deleted my driver account but a shipper wrote me a review. Does the review remain? A: The review text remains; for reviews/ratings you made, the alias becomes anonymous.
Q: Is my e-invoice data also deleted? A: No, TPL m.253 mandates 10-year retention. However, it is kept in an isolated segment and name/address fields are masked beyond legal retention.
Q: Are mobile push tokens deleted? A: Yes, they are removed the moment the account is suspended; you stop receiving notifications.
Q: I signed in with Apple Sign-In. After deletion, can I re-enable Apple Sign-In? A: No, the sub claim is deleted. On re-registration, Apple Sign-In starts the permission flow as if for the first time.
Q: What about data requested by authorities while my account existed? A: Data provided to authorities remains in the legal-retention segment beyond the grace period.
11. Contact
| Topic | Address |
|---|---|
| Account deletion request / cancellation | [email protected] |
| KVKK Article 11 erasure request | [email protected] |
| Data protection | [email protected] |
| Phone verification support | [TODO: Support phone] |
| KEP | [TODO] |
| Address | [TODO] |