Privacy Policy and KVKK Disclosure Notice
Last updated: 29 September 2026
This is an English translation provided for convenience. If it differs from the Turkish original, the Turkish version prevails.
This notice explains how personal data is collected on tapiko.app (including the Tapiko card customers open in their browser and the business dashboard) and in the Tapiko mobile app, why it is processed, who it is shared with, how long it is kept, and how to exercise your rights under Turkey's Personal Data Protection Law No. 6698 ("KVKK"). It covers customers who collect stamps, visitors to the site, business owners and their staff, and anyone who writes to us.
Reading this notice does not mean you give consent. For the one activity that rests on explicit consent (transfer abroad, see section 10), your consent is asked for separately, with its own checkbox.
1. Data controller
The data controller is Cevdet Aslan (Pendik V.D. 0870214606), registered at Kurtköy Mah. Ankara Cad. Yelken Plaza No: 289 İç Kapı No: 21, Pendik / İstanbul ("Tapiko", "we"). Phone: +90 539 322 17 37. For any request: info@tapiko.app
2. The roles of Tapiko and the businesses
We decide the purpose and means of opening accounts, sign-in, verifying stamps, keeping the platform secure, subscriptions and billing; for those, we are the data controller.
Each business that uses Tapiko decides the rules and reward of its own loyalty program, the announcements it sends its customers, and its own customer relationship; for those activities the business is also a data controller in its own right. A request about a business's own campaign or customer relationship may need to go to that business; if you write to us, we will help you reach the right place.
3. What data do we process?
Account information
Your email address, your name and — if you have one — your profile photo; your phone number if you signed in with it. When you sign in with Apple or Google, the name and email those services pass to us are used; the passwords of those accounts never reach us. If you choose, you add your birthday (day and month only, never the year) on the Profile page, so shops that give a birthday gift can leave you one on the day; it is optional and you can remove it at any time. Our authentication is provided by Clerk; your password is not stored on our servers.
Location
When you receive a stamp, your phone's location is read to confirm that you are near the shop at that moment. This is the one mechanism that prevents stamp fraud. Your location is not stored as a trail; it is used at the moment of the check and is not written to the stamp record. Your location is read only at the moment you tap a stamper, with the permission your browser asks you for, and never at any other time. It is not read at all for stamps you receive by scanning the QR code shown on the shop's screen. You can turn location permission off at any time in your browser or phone settings.
Stamp and reward records
Which branch you received stamps from, when, and how many; how each stamp was verified (stamper, QR code or the shop's screen); the staff member who issued it (for stamps given by QR code); which reward you used and when; and the badges you earned from these are recorded. This record is both your card and the shop's ledger.
Your QR code and Wallet pass
A key specific to your account is created to generate your QR code. If you add your card to Apple Wallet or Google Wallet, an identifier for the pass and an access key for its updates are created; for Apple Wallet we also store your device's registration identifier issued by Apple and the notification key used to update the pass.
Notifications
If you allow notifications, your browser's push subscription (a notification address and encryption keys) or, in the mobile app, your phone's push token and device type are stored. Whether you have read the messages in your inbox is recorded too.
What is stored on your device
So that your QR code can be shown without an internet connection, the personal key that generates it and the list of your cards are kept in this browser's own storage, and the My cards page is cached in your browser so it opens offline. Signing out or clearing your browser data removes them. Details are in the Cookie Policy.
Follow reward and link clicks
When you receive a bonus stamp for following a shop's social media account, which branch and which channel you received it for is recorded. When you tap a shop's social media link from your card, which channel you tapped and when is recorded, and the shop can see this with your name. Taps on the Google review link are counted only as a number, without recording who made them.
Business owners and staff
At sign-up, business owners give their full name, phone number, business type and, optionally, how they heard about us; business details such as the branch's name, address, location, opening hours and social media accounts; for invoicing, the company name, tax office and tax number (for a sole proprietorship this may be the national ID number), trade registry number, billing address and email; and the delivery address for the stamper kit. Some branch details are filled in from the Google Maps listing the owner selects. Staff are recorded with the name the owner typed when inviting them, their email address and their role (Staff, Manager, Admin); QR actions a staff member performs are marked with their name.
Payment information
For subscription payments, card details are sent from the form on the Subscription page directly to the licensed payment institution PayTR; they never reach our servers. We store only the payment's amount, time and result, the card reference PayTR issues for renewals, and the payer's IP address, which PayTR requires for its security check.
Support and contact
When you contact us by email or phone, your name, contact details and the content of the correspondence are kept until your request is resolved and for as long as a possible dispute requires.
Technical data collected automatically
Request logs contain standard technical data such as IP address, device and browser information, timestamps and error logs. These are used for security, abuse prevention and debugging. We do not use advertising trackers, or anything that follows you across other sites. We count how often the public pages and business setup are opened with Vercel Web Analytics, which uses no cookies and shows us only totals (see Cookie Policy, section 3a). We also keep our own count of how often a stamper's link is opened, as one number per branch per day, with no personal data.
4. How do we collect data?
We collect data directly from you (sign-up and profile forms, stamp and reward actions), through the Apple, Google or phone verification you sign in with, from your browser (location, only with your permission and at the moment of a stamp), from the Google Maps listing a business owner selects, and from PayTR for payments; by electronic, automated or partly automated means.
5. Why do we process it, and on what legal basis?
| Processing activity | Legal basis (KVKK art. 5) |
|---|---|
| Opening the account, sign-in and authentication | Formation and performance of a contract |
| Recording stamps and rewards, showing your card | Performance of a contract |
| Location check at the moment of a stamp, preventing repeat and fake actions | Legitimate interest; performance of a contract |
| Giving a business its own customer list, statistics and weekly summary | Legitimate interest; performance of the contract with the business |
| Birthday gift | Performance of the service you requested, once you add your birthday yourself |
| Push notifications | The notification permission you grant in your browser or phone |
| Subscription, invoicing and shipping the stamper kit | Performance of a contract; legal obligation |
| Keeping invoice and accounting records | Required by law; legal obligation |
| Answering support requests | Performance of a contract; legitimate interest |
| Security logs and debugging | Legitimate interest |
| Requests from authorities, disputes | Legal obligation; establishing, exercising or protecting a right |
| Transferring data to infrastructure providers abroad | Your explicit consent (KVKK art. 9, see section 10) |
6. What does a business see about you?
A business where you hold a card sees only your relationship with its own branches: your name, when you joined that business, the number of stamps you collected there, the cards you completed, your pending gifts, your last visit, your customer group at that business (see section 8) and the social media links you tapped from your card. Your email address, phone number and birthday are not shown to the business.
Businesses cannot see each other's customers; your history at one business is not shown to another. A business sends you announcements only through the Tapiko inbox and, if you allowed them, notifications; it does not gain access to your contact details that way.
7. How a stamp is verified
A stamp or reward recorded in someone else's name is a false record that misleads both the shop and you. So a stamp is issued only in one of these ways: tapping the stamper near the branch while signed in to your account, staff scanning the short-lived, rotating QR code on your phone, or scanning the single-use QR code shown on the shop's screen with your own phone. Saying a person's name, phone number or any other fixed detail is not enough to receive a stamp. Repeating the same action is blocked at the database level; suspicious or incorrect actions may be corrected or reversed.
8. Customer groups and automated analysis
We show a business its customers grouped by number of visits: New (one visit), Regular (2–4), Loyal (5 or more) and Dormant (no visit in 30 days). These groups are calculated only from your visits to that business and are used so the business can choose which customers receive its announcement. We do not take decisions based solely on automated systems that produce legal effects on you or affect you in a similarly significant way.
9. Who do we share it with?
Businesses
A business where you receive stamps sees the information listed in section 6.
Our service providers
The providers we work with to deliver the service, who process data only on our behalf:
- Clerk — authentication and account management.
- Neon — database (PostgreSQL).
- Vercel — application hosting, storage of business logos and cookieless visit counting on the public pages.
- Your browser's push service (Apple, Google or Mozilla) — delivers notifications to your browser; the content is sent to it encrypted.
- Apple and Google — creating and updating your pass if you add your card to Apple Wallet or Google Wallet.
- Expo — delivering notifications to your phone if you use the Tapiko mobile app.
- PayTR — subscription payments (businesses only).
- Resend — emails to businesses (invitations, payments and the weekly summary).
- Meta (WhatsApp) — the weekly summary message to the business owner.
- Google Places — when a business owner searches for their branch; no customer data is sent.
- Courier company — the business's delivery address and contact details, to ship the stamper kit.
Authorities
When required by law or on a lawful request, we share data with competent authorities such as courts, prosecutors, law enforcement and tax authorities, only to the extent requested.
Advisers and corporate transactions
We may share data as needed with advisers bound by confidentiality for accounting, audit and legal advice, and with parties bound by confidentiality in a possible merger, transfer or investment.
We do not sell, rent or transfer your personal data to anyone for advertising.
10. Transfer abroad
The servers of our providers other than PayTR and the courier company are outside Turkey (mainly in the United States and the European Union), so your data is transferred abroad. This transfer rests on your explicit consent under Article 9 of the KVKK. You give it with a separate checkbox when you create an account — or after your first sign-in with Apple or Google — and the moment you give it is recorded on your account. Accepting this notice is not, on its own, consent to the transfer. The data transferred is limited to what each service requires.
You can withdraw your consent at any time by writing to info@tapiko.app. Because the service cannot be provided without these providers, withdrawing consent results in your account being closed; transfers made before you withdrew are not affected.
11. Cookies and on-device storage
We use only the cookies and browser storage strictly needed to keep you signed in and to show your card offline; we do not use analytics, advertising or tracking cookies, and our visit counting uses none. Details: Cookie Policy.
12. Commercial messages
Notifications about your account, payments and security are part of the service and are not marketing messages. We do not send you marketing email or SMS on behalf of Tapiko; if we ever do, it will be only with your separate permission and in line with the relevant rules, including Turkey's Message Management System (İYS).
Announcements from businesses where you hold a card arrive in your inbox; whether they also arrive as notifications depends on the notification permission you gave, which you can turn off at any time. The sending business is responsible for the content of an announcement and its compliance with the relevant law.
13. How long do we keep it?
Your data is kept for as long as the purpose of processing requires, while your account is open and our contract with the business continues. When the purpose ends, data is deleted, destroyed or anonymized. Invoice and payment records of businesses are kept for the periods set by the Tax Procedure Law and the Turkish Commercial Code (generally 10 years). Data in backups stays access-restricted within the backup cycle and is deleted when the cycle completes. Irreversibly anonymized data is no longer personal data and may be kept for statistics.
14. Deleting your account
You can delete your account from the Profile page (tapiko.app/profil) or have it deleted by email as described on the Account Deletion page. On deletion your name, email address, birthday, push keys and subscriptions are deleted; stamp and reward records stay in the business's statistics in anonymous form, no longer linked to you. Records the law requires us to keep are kept for the relevant period.
15. Data security
We take technical and administrative measures proportionate to the risk to protect your data against unauthorized access, loss and misuse: encrypted connections throughout, role-based permissions (business staff reach only their own business's data, as far as their role allows), separation between businesses at the level of every database query, short-lived and single-use verification codes, repeat and rate limits, and access and error logs. Card details never reach our servers. Even so, no transmission over the internet can be guaranteed to be absolutely secure.
16. Data breaches
If we become aware that personal data has been obtained unlawfully by others, we take the measures needed to contain the incident and notify the Personal Data Protection Board and the people affected within the periods and by the methods set by the KVKK and the Board's decisions.
17. Your rights under Article 11 of the KVKK
You have the right to learn whether your personal data is processed; to request information if it is; to learn the purpose of processing and whether it is used for that purpose; to know the third parties it is transferred to in Turkey or abroad; to request correction if it is incomplete or inaccurate; to request its deletion or destruction; to request that these actions be notified to the third parties it was transferred to; to object to a result against you arising exclusively from analysis by automated systems; and to claim compensation if you suffer damage.
18. How to apply
You can send your request from the email address registered to your account to info@tapiko.app, in writing to our address above, or by registered electronic mail (KEP), secure electronic signature or mobile signature. It is enough to state your name, your request and a way to reach you; we may ask for additional information proportionate to the request to verify your identity.
Your request is concluded free of charge within thirty days at the latest; if it involves an additional cost, the fee schedule set by the Personal Data Protection Board may apply. If your request is rejected, you find the answer insufficient, or it is not answered in time, you may file a complaint with the Personal Data Protection Board within thirty days of learning the answer, and in any case within sixty days of your request.
19. Special categories of personal data
Tapiko is not designed to require special categories of personal data such as health, biometrics, religion or political opinion, and does not ask for them. Please do not write such information into free-text fields such as reward text, announcements or support messages.
20. Children
This service is not designed for anyone under 18, and we do not knowingly collect data from children. A parent or guardian who believes a child's data is being processed can write to us; we will delete it.
21. Obligations of businesses
Businesses that use Tapiko agree to:
- Use the customer data they see in the dashboard only for their own loyalty program and lawfully;
- Give dashboard access only to authorized staff and remove departing staff promptly;
- Not transfer the customer list to another system or disclose it to third parties without a legal basis;
- Not perform stamp or reward actions on a customer's behalf without their knowledge;
- Be responsible for the content of the announcements they send and their compliance with commercial messaging law;
- Fulfil their own obligations under the KVKK.
22. Third-party links
Your card may contain links to businesses' social media accounts and to Google Maps. Those sites are responsible for their own data processing; we recommend reading their privacy policies.
23. Changes
We may update this notice when the law, the Board's decisions, product features or the providers we work with change. When we do, we change the date above, and for material changes we let you know on the My cards page; where the law requires it, we ask for your consent again.
24. Contact
Cevdet Aslan · Kurtköy Mah. Ankara Cad. Yelken Plaza No: 289 İç Kapı No: 21, Pendik / İstanbul · +90 539 322 17 37 · info@tapiko.app
See also: Terms of Service, Cookie Policy.