Home

PRIVACY POLICY

Türkçe oku
Contents
  1. 1. Controller
  2. 2. In short
  3. 3. Data we process
  4. 4. Purposes and legal bases
  5. 5. What other users see
  6. 6. Service providers and international transfers
  7. 7. How long we keep data
  8. 8. Security
  9. 9. Permissions
  10. 10. Children
  11. 11. Your rights
  12. 12. Users in the EEA and the UK
  13. 13. Changes
  14. 14. Contact

Version 0.2 (beta) · Last updated: 8 October 2026

This policy explains which personal data we process when you use the Tribün app ("App"), why, who we share it with, how long we keep it and what your rights are. Users in Türkiye can also read the KVKK Information Notice. If you live in the European Economic Area (EEA) or the United Kingdom, section 12 applies to you as well.

1. CONTROLLER

Tribün is provided by its developer, Mervan Yuşa Torlak, a natural person; "we" in this policy refers to him.

  • Name: Mervan Yuşa Torlak
  • E-mail (privacy requests and support): info@tribundeyiz.com
  • EU representative (GDPR Art. 27): will be appointed and named here when the service is offered to people in the European Union, if the GDPR requires it.

2. IN SHORT

  • We only use your location while the App is open and you start an action: "I'm at the stadium", the proof photo, nearby matches and distances. We do not track your location in the background.
  • We only use the camera for the live proof photo and for scanning QR codes. Location and device data (EXIF/GPS) are removed from photos before upload.
  • From your contacts, only hashes (SHA-256) of the e-mail addresses, computed on your phone, are sent. Names and phone numbers never leave your phone, the hashes are not stored, and no text messages are sent. Letting others find you by your e-mail is optional and off by default.
  • Only your friends see your visits, photos and city.
  • We do not sell your data or use it for advertising.
  • When you delete your account, your data is deleted.

3. DATA WE PROCESS

Account: your e-mail address, your password (stored only as an irreversible hash that we cannot see), e-mail confirmation and sign-in records, your username and your invite code. If you choose Sign in with Google or, on iPhone, Sign in with Apple, the identifier and e-mail address of that account.

Profile: your profile photo, the club you support, your national team, your home city and country (the city's centre coordinate, not your home address), your language and time zone.

Location: your device's location (latitude, longitude, accuracy) while the App is open and you start an action.

  • For "I'm at the stadium" and the proof photo: our server checks whether you are within about 1 km of the stadium and within the match window (from 3 hours before kick-off to 2 hours after the final whistle). A record of this attempt (location, accuracy, distance to the stadium, result, time) is kept.
  • For matches and stadium details: your approximate location is sent to show nearby matches and distances such as "12 km from you"; the location sent for this is not stored in the database. Without the location permission, distances are measured from your home city.

Photos: your live proof photo and its thumbnail, gallery photos you add to archive visits, your profile photo; the results of automated moderation (labels and scores) and moderator decisions. Other people may appear in your photos.

Visits and activity: your visits (stadium, match, date, proven or archive), "I'm at the stadium" check-ins, "I'm going" plans, "Me too" joins, likes, stadiums you want to visit, stadium ratings, missing-stadium reports, badges, missions, statistics and leaderboard position.

Friends and community: friend requests and friendships, people you block, reports you make and reports about you (reason and a note of up to 500 characters), additions through invite links and QR codes.

Contact matching: if you use "Find from contacts", the e-mail addresses in your contacts are lower-cased and hashed with SHA-256 on your phone. Only these hashes are sent and compared with the hashes of users who have confirmed their e-mail address and chose to be found by it. The hashes are not stored after the comparison; to prevent abuse we only keep the number of hashes you sent, for 2 days.

Being found by your e-mail: this is optional and off by default; only if you tick "Let people find me by my email" when setting up your profile or turn it on in Settings › Privacy do users who have your e-mail address in their contacts see your username and profile photo in "Find from contacts", and you can turn it off at any time with the same setting.

Notifications: your device's push token (FCM token), platform (iOS or Android), App version, notification preferences and in-app notification history.

Technical and security data: server logs such as IP address, request time, device and App information, session data and abuse counters (e.g. attempts per hour).

Crash reports: if the App crashes or hits an unexpected error, the technical details of the error, the App version, phone model, operating system and a random installation identifier. Your username, e-mail and location are not added to the report.

We do not aim to collect special categories of personal data (such as health, religion, political opinions or biometric data). Photos are not used for face recognition or biometric identification; automated moderation only checks whether the content follows the rules. Photos with political banners or signs are not published under our rules.

  • Creating your account and providing the App (collection, feed, friends, leaderboards, badges, season summary, support): conclusion and performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6/1-b).
  • Verifying proven visits and preventing cheating (location, server time, live camera): performance of a contract and our legitimate interest (KVKK Art. 5/2-c and f; GDPR Art. 6/1-b and f).
  • Moderating photos, reviewing reports and protecting the community: our legitimate interest and legal obligations (KVKK Art. 5/2-f and ç; GDPR Art. 6/1-f and c).
  • Sending notifications (friends' activity, match reminders, likes, badges): performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6/1-b). You manage the permission in your phone's settings and the topics in the App's Settings.
  • Finding friends from your contacts (at your request): legitimate interest (KVKK Art. 5/2-f; GDPR Art. 6/1-f). Your contacts' data is only used as hashes and is not stored.
  • Security, abuse prevention and debugging: legitimate interest (KVKK Art. 5/2-f; GDPR Art. 6/1-f).
  • Legal obligations, requests from authorities and legal disputes: legal obligation and the establishment, exercise or defence of a right (KVKK Art. 5/2-ç and e; GDPR Art. 6/1-c and f).

We do not send marketing messages or build advertising profiles.

5. WHAT OTHER USERS SEE

  • Everyone: your username, profile photo, your place on the country (e.g. Türkiye) and club leaderboards and your number of proven stadiums. Appearing on these leaderboards also indirectly shows your country and which club you support.
  • Your friends: in addition, your club, national team, city, approved visits and photos, plans, "I'm at the stadium" check-ins, feed activity, badges and other statistics. Your city's coordinate is not shown to anyone.
  • People you block and people who block you do not see each other in search, profiles, the feed, leaderboards or notifications.
  • If you share your story card or season summary in an app such as Instagram or WhatsApp, whoever can see that post there can see it; it is subject to that app's rules.

6. SERVICE PROVIDERS AND INTERNATIONAL TRANSFERS

We only share your data with the following service providers (processors), bound by contracts, to provide the service:

  • Supabase, Inc. (USA): database, authentication and server functions. Data is hosted in Germany (Frankfurt, AWS eu-central-1).
  • Cloudflare, Inc. (USA): photo storage (R2) and delivery. Cloudflare automatically chooses the data centre where the photos are stored. Published photos may be cached temporarily on Cloudflare's servers worldwide for fast delivery.
  • Amazon Web Services EMEA SARL (Luxembourg) / Amazon Web Services, Inc. (USA): automated photo moderation with Amazon Rekognition in the Ireland (eu-west-1) region. Until AWS's AI services opt-out is enabled, AWS may use the moderated photos to improve its own services and may store them for that purpose in AWS regions outside Ireland. We plan to enable this opt-out.
  • OpenAI, L.L.C. (USA): additional automated photo moderation, if enabled.
  • Google LLC (USA): push notifications with Firebase Cloud Messaging and crash reports with Firebase Crashlytics. On iOS devices, notifications are delivered through Apple Inc.'s (USA) Apple Push Notification service.
  • Resend, Inc. (USA): sending confirmation and password reset e-mails (your e-mail address and the content of the e-mail).
  • Google LLC and Apple Inc. (USA): authentication, if you choose Sign in with Google or, on iPhone, Sign in with Apple.

Match data comes from API-Football; none of your personal data is sent to that provider.

The maps in Stadiums and Matches are loaded from OpenFreeMap's (openfreemap.org) map servers. Your phone connects to these servers directly, so your IP address and the area shown on the map reach that service. Your location is not sent to it; the location dot on the map is drawn on your phone only.

Because some of these providers are outside Türkiye (Germany, Ireland, the USA and other countries where Cloudflare has servers), your data is transferred abroad. These regular transfers from Türkiye rely on the standard contracts announced by the Turkish Personal Data Protection Board under KVKK Art. 9. Transfers from the EEA rely on the European Commission's standard contractual clauses or the EU-U.S. Data Privacy Framework.

Apart from this we only disclose your data to authorised public bodies and courts, as far as the law requires. If the App is transferred to another person or company, data may pass to the acquirer, provided it keeps to this policy; we will tell you in advance.

7. HOW LONG WE KEEP DATA

  • Account, profile, visit, photo, friendship and activity data is kept while your account is open. If you delete a visit, the visit, its photos and the feed entries, likes and notifications attached to it are deleted.
  • If you delete your account, your account and all data linked to it are deleted. Photos are removed from storage immediately, or within a few days at the latest through the clean-up queue. Reports you made may be kept with the link to you removed. Copies in backups are deleted when the backups expire, within 7 days at the latest.
  • The visit record of a rejected photo is kept for 7 days so you can see the reason, then deleted.
  • Unfinished uploads are kept for 2 days; moderation records of rejected or failed uploads for 30 days.
  • Location attempts not linked to a visit or check-in are kept for 90 days; linked ones as long as that record exists. For a failed attempt (e.g. too far from the stadium, no match) the location itself is deleted after 1 day; the rest of the attempt (accuracy, distance to the stadium, outcome, time) stays for that period.
  • In-app notifications are kept for 180 days, push delivery records for 14 days.
  • Contact matching and abuse counters are kept for 2 days.
  • Your push token (FCM token) is deleted when you sign out or when it becomes invalid.
  • Crash reports are kept in Firebase Crashlytics for 90 days.
  • Server logs (such as IP address and request time) are kept in our infrastructure provider's logging system for 7 days at most.
  • Data we are legally required to keep is kept for the period required.

8. SECURITY

Connections are encrypted (TLS). Every database table is protected by row-level access rules. Photos are not published before moderation, and raw moderation scores are hidden from users. Passwords are only stored as hashes. Only the people needed to run and moderate the App can access data, and only as far as needed. No system is completely secure; if a data breach happens we will notify the authority and you as the law requires.

9. PERMISSIONS

  • Location (while using the App): "I'm at the stadium", the proof photo, nearby matches and distances.
  • Camera: the live proof photo and scanning QR codes.
  • Photos: picking archive and profile photos (only the photo you pick is read).
  • Contacts: "Find from contacts" (only e-mail hashes are sent).
  • Notifications: push notifications.

You can turn off any permission at any time in your phone's settings; the related feature then stops working.

10. CHILDREN

The App is not meant for children under 13. If you are under 18 and the law where you live requires it, you should use the App with the knowledge of a parent or guardian. If we learn that we process data of someone under 13, we delete the account and the data.

11. YOUR RIGHTS

You have the right to learn whether your personal data is processed, to ask for information and a copy, to have it corrected or deleted or its processing restricted, to object, to receive your data in a portable format and to complain. Details are in the KVKK Information Notice.

  • You can change most of your information in the App's Settings and delete your account and data in Settings > Delete account.
  • For other requests, write to info@tribundeyiz.com. We answer within 30 days at the latest, as a rule free of charge.
  • You can ask for a human review of a photo rejected by automated moderation.
  • You can complain to the Turkish Personal Data Protection Board, or, if you live in the EEA or the UK, to the data protection authority of your country.

12. USERS IN THE EEA AND THE UK

Under the EU General Data Protection Regulation (GDPR) and the UK GDPR we rely on the legal bases above. You have the rights of access, rectification, erasure, restriction, portability and to object to processing based on legitimate interests. Where we ask for consent, you can withdraw it at any time. When the service is offered to people in the European Union, we will appoint an EU representative if GDPR Art. 27 requires it and name them in this policy.

13. CHANGES

We may update this policy. We will announce material changes in advance in the App or by e-mail. The current version is always available in the App and at tribundeyiz.com.

14. CONTACT

Mervan Yuşa Torlak, info@tribundeyiz.com

This is the same text as in the app.