Version 0.2 (beta) · Last updated: 8 October 2026
Under Article 10 of the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the Communiqué on the Procedures and Principles of the Duty to Inform, we, as the data controller, inform you about the personal data processed in the Tribün mobile application ("App").
1. DATA CONTROLLER
Tribün is provided by its developer, Mervan Yuşa Torlak, a natural person; "we" in this notice refers to him.
- Name: Mervan Yuşa Torlak
- E-mail (KVKK applications and support): info@tribundeyiz.com
- VERBİS: we are not required to register with the Data Controllers' Registry, under the Personal Data Protection Board's decision exempting data controllers whose annual number of employees and annual balance sheet total are below the thresholds set by the Board and whose main activity is not the processing of special categories of personal data.
2. PERSONAL DATA PROCESSED, PURPOSES AND LEGAL GROUNDS
2.1 Identity and account data
- Data: e-mail address, password (only as an irreversible hash), username, invite code, e-mail confirmation and sign-in records; when Sign in with Google or Apple is chosen, the identifier and e-mail address of that account.
- Purposes: membership, authentication, account security, providing the App, answering support requests.
- Legal ground: being directly related to the conclusion or performance of a contract (KVKK Art. 5/2-c).
2.2 Profile data
- Data: profile photo, the club supported, national team, home city and country (the city's centre coordinate), language and time zone.
- Purposes: creating the profile and showing it to friends, calculating leaderboards (country and club) and statistics, measuring distances from the home city, notifications about your team's matches.
- Legal ground: KVKK Art. 5/2-c.
2.3 Location data
- Data: the device's location (latitude, longitude, accuracy) while the App is open and the user starts an action, with the distance to the stadium and the result of the attempt.
- Purposes: verifying "I'm at the stadium" and proven visits (being within about 1 km of the stadium and within the match window), preventing fraud, showing nearby matches and distances.
- Legal ground: KVKK Art. 5/2-c and the controller's legitimate interest (KVKK Art. 5/2-f). Location is not collected in the background. The location sent for distances and nearby matches is not stored in the database.
2.4 Visual data
- Data: live proof photo and its thumbnail, archive photos, profile photo; results of automated moderation and moderator decisions. EXIF/GPS data is removed from photos before upload.
- Purposes: building the collection and showing it to friends, story and season summary cards, checking photos against the rules automatically and, when needed, by people.
- Legal ground: KVKK Art. 5/2-c; for moderation KVKK Art. 5/2-f and legal obligation (KVKK Art. 5/2-ç). Photos are not processed for face recognition or biometric identification.
2.5 In-app activity data
- Data: visits (stadium, match, date, proven or archive), "I'm at the stadium" check-ins, "I'm going" plans, "Me too" joins, likes, stadiums the user wants to visit, stadium ratings, missing-stadium reports, badges, missions, statistics and leaderboards.
- Purposes: providing the collection, feed, leaderboard, badge, mission and season summary features.
- Legal ground: KVKK Art. 5/2-c.
2.6 Social data
- Data: friend requests and friendships, blocks, reports (reason and a note of up to 500 characters), additions through invite links and QR codes.
- Purposes: providing the friendship features, applying visibility rules, reviewing reports, community safety.
- Legal ground: KVKK Art. 5/2-c and f.
2.7 Contact matching data
- Data: when "Find from contacts" is used, SHA-256 hashes of the e-mail addresses in the contacts, computed on the device.
- Purposes: finding acquaintances who use the App, at the user's request.
- Legal ground: KVKK Art. 5/2-f. Names and phone numbers in the contacts never leave the device; the hashes are not stored after matching, and only the number of hashes sent is kept for 2 days to prevent abuse.
- Being found by your e-mail: this is optional and off by default; only if you turn on "Let people find me by my email" (profile set-up or Settings › Privacy) do you appear, with your username and profile photo, in other users' contact matching, and you can turn it off at any time with the same setting.
2.8 Notification data
- Data: push token (FCM token), platform, App version, notification preferences and in-app notification history.
- Purposes: sending push and in-app notifications.
- Legal ground: KVKK Art. 5/2-c. The permission is managed in the device settings, the topics in the App's Settings.
2.9 Transaction security data
- Data: IP address, request time, device and App information, session data, abuse counters, crash reports (technical details of the error, App version, phone model, operating system and a random installation identifier; kept in Firebase Crashlytics for 90 days).
- Purposes: information security, preventing abuse and fraud, debugging, answering requests from competent authorities.
- Legal ground: KVKK Art. 5/2-f, being expressly provided for by law and legal obligation (KVKK Art. 5/2-a and ç), the establishment, exercise or protection of a right (KVKK Art. 5/2-e).
We have no processing activity based on explicit consent.
3. METHOD OF COLLECTION
Personal data is collected electronically, by fully and partly automated means: from the information you enter in the App, from your device's location, camera, photo and contact features with your permission (only when you start the related action), from the notification infrastructure, from server logs and from the App's crash reports. It may also be collected through other users when they send you a friend request or report you. Match data comes from API-Football and contains no personal data.
4. TRANSFERS OF PERSONAL DATA
4.1 Other users
Your username, profile photo, your place on the country and club leaderboards and your number of proven stadiums are visible to all users; appearing on these leaderboards also indirectly shows your country and which club you support. Your club, national team, city, approved visits, photos, plans, "I'm at the stadium" check-ins, badges and other statistics are visible only to your friends. Your city's coordinate is not shown to anyone. Blocked users do not see each other.
4.2 Recipients in Türkiye
Authorised public bodies and courts, upon request and as far as the law requires (KVKK Art. 8/2-a).
4.3 Service providers abroad
Because the App's technical infrastructure is provided by service providers (processors) abroad, your personal data is transferred, limited to the purposes above, to these recipients:
- Supabase, Inc. (USA): database, authentication and server functions; data is hosted in Germany (Frankfurt). All data categories.
- Cloudflare, Inc. (USA): photo storage (R2) and delivery; Cloudflare automatically chooses the data centre where the photos are stored, and its cache servers are worldwide. Visual data.
- Amazon Web Services EMEA SARL (Luxembourg) / Amazon Web Services, Inc. (USA): automated photo moderation with Amazon Rekognition, Ireland (eu-west-1). Visual data. Until AWS's AI services opt-out is enabled, AWS may use the moderated photos to improve its own services and may store them for that purpose in AWS regions outside Ireland; we plan to enable this opt-out.
- OpenAI, L.L.C. (USA): additional automated photo moderation, if enabled. Visual data.
- Google LLC (USA) and Apple Inc. (USA): delivering push notifications (Firebase Cloud Messaging, Apple Push Notification service). Notification data and notification content.
- Google LLC (USA): collecting crash reports (Firebase Crashlytics). Transaction security data (crash reports).
- Resend, Inc. (USA): sending confirmation and password reset e-mails. E-mail address.
- Google LLC and Apple Inc. (USA): Sign in with Google and, on iPhone, Sign in with Apple, if the user chooses them. Identity data.
Because these transfers are regular, they rely on the standard contracts announced by the Personal Data Protection Board under KVKK Art. 9/4; the standard contracts are notified to the Personal Data Protection Authority within 5 business days of signing.
4.4 Map service
The maps in Stadiums and Matches are loaded from OpenFreeMap's (openfreemap.org) servers. For this your phone connects to these servers directly, and your IP address and the area shown on the map reach that service; your location is not sent.
5. AUTOMATED DECISIONS
Uploaded photos are first checked by automated systems. A photo found clearly against the rules may not be published automatically; when the systems are unsure, a moderator decides. If you think an automated check produced a result against you, you can object under KVKK Art. 11/1-g and ask for a human review at info@tribundeyiz.com.
6. RETENTION
Personal data is kept for as long as the purposes of processing require, as a rule while your account is open, and deleted when you delete your account. Detailed periods (such as 7 days for rejected photo records, 90 days for location attempts not linked to a visit (1 day for the location of a failed attempt), 180 days for in-app notifications and 2 days for contact matching and abuse counters) are in section 7 of the Privacy Policy. Expired data is deleted or anonymised under the Regulation on the Deletion, Destruction or Anonymisation of Personal Data.
7. YOUR RIGHTS UNDER KVKK ART. 11
By applying to the data controller you have the right to:
- learn whether your personal data is processed,
- request information if it has been processed,
- learn the purpose of processing and whether it is used accordingly,
- know the third parties in Türkiye or abroad to whom it is transferred,
- ask for its correction if it is incomplete or inaccurate,
- ask for its deletion or destruction under the conditions of KVKK Art. 7,
- ask that the correction, deletion or destruction be notified to the third parties it was transferred to,
- object to a result against you arising from analysis exclusively by automated systems,
- claim compensation if you suffer damage because of unlawful processing.
8. HOW TO APPLY
Under the Communiqué on the Procedures and Principles of Applications to the Data Controller you can send your request:
- from the e-mail address registered in the App to info@tribundeyiz.com,
- signed with a secure electronic signature or mobile signature, to info@tribundeyiz.com.
Your application should state your name and surname, your username and e-mail address in the App, your request and an address for notices. We conclude applications within 30 days at the latest and, as a rule, free of charge; if the action has an additional cost, the fee in the Board's tariff may be charged. If your application is rejected, the answer is insufficient or not given in time, you can complain to the Personal Data Protection Board within 30 days of learning the answer and in any case within 60 days of your application.