Privacy Policy
Last updated: 2026-05-24 Effective: 2026-05-24 Version: 1.0
At Nakliye360 ("we", "Company"), we care about the privacy of our users. This Privacy Policy explains how personal data is processed, with whom it is shared, and your rights when using the Nakliye360 platform (website, mobile apps — iOS and Android, web admin panel, APIs).
For the formal disclosure notice under Turkish Law 6698 (KVKK), see KVKK Disclosure. This document has been prepared for compliance with Apple App Store, Google Play, and Facebook OAuth policies.
1. Company Information (Data Controller)
| Field | Detail |
|---|---|
| Legal Name | [TODO: Legal company name] |
| Mersis No | [TODO] |
| Tax No | [TODO] |
| Address | [TODO: Registered address] |
| Contact | [email protected] |
| KEP | [TODO] |
2. Scope
This Policy covers:
- nakliye360.com website and subdomains
- Nakliye360 iOS mobile app
- Nakliye360 Android mobile app
- Web admin panel (corporate users)
- Nakliye360 REST API
- Marketing, newsletter, and announcement communications
3. Data We Collect
3.1. Account and Profile Data
- First and last name
- Mobile phone (E.164)
- Password (Argon2id-hashed; irreversible)
- OAuth provider identifiers (Google, Apple, Facebook sub claim, email)
- Profile photo (if provided)
- Organisation info (company name, role)
- KYC document info (driver/carrier: licence class, SRC, ADR, authorisation document, etc.)
3.2. Operational Data
- Cargo posting content
- Offers given and received
- Messaging content (in-app)
- Reviews and ratings
3.3. Location Data
- Pickup/delivery coordinates from cargo postings
- Driver live GPS — collected only during an active shipment; permission is requested from mobile OS; collection stops when shipment ends. Driver can revoke permission at any time, disabling live tracking.
- Device IP (approximate location at country/city level)
3.4. Payment Data
- Iyzico subscription / payment token
- Iyzico transaction id, amount, status
- Billing address
- Important: Card PAN, CVV, expiration date are NOT stored on Nakliye360 systems. All card data is held by PCI-DSS Level 1 certified Iyzico.
3.5. E-Invoice Data
- Tax ID (corporate) or National ID (individual)
- Tax office
- Invoice items
- EDM Bilisim integration record
3.6. Device and Technical Data
- IP
- Device type, OS version
- App version
- Language and timezone
- Browser (web)
- Expo Push Token (iOS APNs / Android FCM)
- Session / cookie identifiers
3.7. Usage Data
- Page views, clicks (anonymous aggregate)
- Error logs (Sentry — IP, user id, stack trace)
- Performance metrics
3.8. Marketing Data (Explicit Consent Only)
- Newsletter status
- Segment preferences
- Ad interactions (where rationing Meta Pixel is enabled)
3.9. Children's Data
Nakliye360 services are intended for users 18 years and older. We refuse to offer services to children under 13. If we discover we have inadvertently collected data from a child under 13, we will delete it immediately. Users between 13–18 cannot register without a legal guardian; accounts found to be in violation are suspended.
4. How We Collect Data
- Directly from users (forms, mobile app input, web admin)
- Automatically (cookies, logs, telemetry)
- Via third-party providers (OAuth sub, Iyzico token, EDM e-invoice result)
5. Purposes of Use
| Purpose | Description |
|---|---|
| Service performance | Account creation, cargo posting / offer matching, messaging |
| Authentication | OTP, email verification, OAuth sign-in |
| Operational communication | Shipment notifications, password reset, security alerts |
| Payment | Subscription start, renewal, cancellation |
| E-invoice | Mandatory invoicing per Tax Procedure Law |
| Location services | Live tracking; ETA estimation |
| Customer support | Request and complaint handling |
| Account security | Anomaly detection, brute-force protection |
| Error tracking | Sentry for application error diagnosis |
| Analytics | Anonymous / aggregate metrics (optional Google Analytics) |
| Legal compliance | Court / authority / KVKK Authority orders |
| Marketing (explicit consent) | Newsletter, campaigns, product announcements |
6. Sharing of Data
Your data is not sold. It is shared on a limited, purpose-bound basis with:
6.1. Service Providers (Data Processors)
| Provider | Service | Location | Data |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting | Germany (EU) | All platform data |
| Cloudflare, Inc. | CDN, DDoS, WAF | Global edge | IP, request metadata |
| Sentry | Error tracking | US/EU | Stack trace, IP, user id |
| Iyzico Odeme Hizmetleri | Payment | Turkey | Name, email, IP, payment token |
| EDM Bilisim | E-invoice | Turkey | Tax ID, invoice items |
| Expo (650 Industries) | Push notifications | US | Push token, message body |
| Apple Inc. | APNs, Apple Sign-In | US/EU | Push token, sub claim, email |
| Google LLC | FCM, Google Sign-In, optional GA | US | Push token, sub claim, behaviour |
| Meta Platforms | Facebook Sign-In, optional Pixel | US | Sub claim, interactions |
All service providers are bound by Data Processing Agreements (DPA) and may process data only for the defined purpose.
6.2. Sharing between Platform Users
Between shipper and carrier/driver, the following are shared:
- Name/company name (display)
- Live location during active shipment
- Reviews/ratings
- Operational contact (phone — only after a match)
6.3. Competent Authorities and Legal Parties
- Court, prosecutor, law enforcement, KVKK Authority, tax inspector requests
- External legal counsel for dispute handling
6.4. Mergers and Acquisitions
In case of merger, acquisition, or bankruptcy, data may transfer to the acquirer; users will be notified in advance.
7. International Data Transfers
Your data resides on our hosting provider Hetzner's German data centres (within EU). Transfers to US-based providers like Cloudflare global edge, Sentry, Google, Apple, Meta are made under KVKK m.9 and where applicable, GDPR Art. 46 Standard Contractual Clauses (SCCs).
8. Retention Period
For detailed retention table, see KVKK Disclosure Section 7.
Summary:
- While account active + 30-day grace
- E-invoice and accounting: 10 years (TPL, TCC)
- Traffic logs: 2 years (Law 5651)
- Analytics: indefinite after anonymisation
9. Security Measures
- TLS 1.3 encrypted communication
- Argon2id password hashing (never plaintext)
- JWT minimal claim, short-lived tokens
- Database encryption at rest (Hetzner LUKS)
- IP rate-limiting, brute-force protection
- Optional 2FA
- Role-based access control (RBAC) and organisation-based isolation
- Cloudflare WAF, DDoS protection
- Periodic backups
- Audit logs
- KVKK "minimum necessary data" principle
10. Your Rights
All rights under KVKK Article 11 are listed in KVKK Disclosure Section 8.
10.1. Additional Rights for EU / UK Users (GDPR / UK-GDPR)
Due to Hetzner's German hosting, EU / UK residents have the following additional rights under GDPR / UK-GDPR:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16)
- Right to erasure / "right to be forgotten" (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right not to be subject to automated decision-making (Art. 22)
- Right to lodge a complaint with a supervisory authority (Art. 77)
To exercise: [email protected]. Response time: 30 days (extendable to 60 days where necessary; you will be informed).
11. Account Deletion
For account deletion procedures and data deletion/anonymisation flow, see Account Deletion.
12. Cookies and Trackers
See Cookie Policy.
13. Children's Privacy
See Section 3.9. We do not collect data from users under 13.
14. Apple App Store Policy Compliance
Per Apple App Review Guidelines 5.1.1:
- This Privacy Policy URL is published in App Store Connect.
- Account deletion can be performed directly within the iOS app (Settings > Delete Account).
- All collected data categories are declared in the App Privacy section.
15. Google Play Policy Compliance
Per Google Play Developer Program Policies:
- Data Safety form completed according to this policy.
- Account deletion is available both in-app and via the website.
16. Facebook OAuth Policy Compliance
Per Meta Platform Terms:
- This policy is declared as Privacy Policy URL in the Facebook Login app configuration.
- Data deletion instructions are published in Account Deletion as part of the Facebook Data Deletion Callback flow.
17. Contact
| Topic | Address |
|---|---|
| Privacy / Data Protection | [email protected] |
| KVKK Application | [email protected] |
| General | [email protected] |
| KEP | [TODO] |
| Address | [TODO] |
18. Policy Changes
Significant changes are notified by email or in-app. For changes requiring explicit consent, fresh consent will be requested. Version and update date are always at the top of this page.