Kısa özet: Temel hesaplama araçları hesap oluşturmadan kullanılabilir. Üyelik açarsanız e-posta adresinizi; profil, sosyal akış, bildirim ve Premium özelliklerini kullanırsanız bu hizmetler için gerekli verileri işleriz. Hesaplama özetleri, kimliğiniz ve hesabınızla ilişkilendirilmeden ürünü geliştirmek amacıyla takma kimlikli olarak sunucuya gönderilir. Verilerinizi satmayız.
1. Veri sorumlusu ve kapsam
6698 sayılı Kişisel Verilerin Korunması Kanunu ("KVKK") kapsamında veri sorumlusu Burak Altıntaş (Antalya, Türkiye) olup, iletişim adresleri burak.altintas@yahoo.com.tr ve info@bankaci.app adresleridir.
Bu politika aşağıdaki ürünler için geçerlidir:
- Bankacı mobil uygulaması (iOS ve Android)
- bankaci.app ve aynı içeriği sunan Bankacı web alanları
Bankacı bağımsız bir profesyonel yardımcı araçtır; banka veya finans kuruluşu değildir, kredi kullandırmaz ve finansal danışmanlık garantisi vermez.
Talep linki: Premium bir bankacı, kendi paylaştığı bağlantı üzerinden müşterilerinden üyelik gerektirmeyen kredi talebi toplayabilir. Bu formu dolduran müşterinin kişisel verileri bakımından, müşteriyle ilişkiyi kuran ve talebi kendi işi için kullanan ilgili bankacı bağımsız veri sorumlusudur; Bankacı ise formun teknik olarak sunulması ve talebin yalnızca doğru bankacıya iletilmesi bakımından hizmet sağlayıcı/aracı konumundadır. Talep formu bu Gizlilik Politikası'na bağlantı verir; formu gönderen müşteri bu metinle bilgilendirilmiş sayılır. İleride devreye alınacak kampanya gibi başka özellikler için bu politika ve uygulama içi aydınlatmalar önceden güncellenecektir.
2. İşlediğimiz veriler, amaçlar ve hukuki sebepler
| Veri | Amaç | Hukuki dayanak |
|---|---|---|
| Üyelik ve güvenlik: e-posta adresi, tek kullanımlık kod kayıtları, kod talebi IP adresi, oturumun tek yönlü özeti, cihaz adı, oturum ve son görülme zamanları | Hesap oluşturma, e-posta koduyla kimlik doğrulama, oturum güvenliği, kötüye kullanım ve sahteciliğin önlenmesi | Sözleşmenin kurulması/ifası ve meşru menfaat (KVKK m.5/2-c, m.5/2-f) |
| Profil ve sosyal akış: görünen ad; isteğe bağlı biyografi, banka/iş unvanı ve profil fotoğrafı; gönderi, fotoğraf, beğeni, yorum, rapor ve engelleme kayıtları | Profil ve bankacılar arası sosyal akışın sunulması, moderasyon, güvenlik ve şikâyetlerin incelenmesi | Sözleşmenin kurulması/ifası, kullanıcının paylaşımı ve meşru menfaat (KVKK m.5/2-c, m.5/2-d, m.5/2-f) |
| Premium: RevenueCat takma kullanıcı kimliği, doğrulanmış hesap e-postası, entitlement, ürün, satın alma/yenileme/iptal olayları, platform ve uygulama sürümü | Premium hakkının doğrulanması, cihazlar arasında taşınması, satın alımların geri yüklenmesi, reklamların kapatılması ve destek sırasında hesabın bulunması | Sözleşmenin kurulması/ifası ve hukuki yükümlülük (KVKK m.5/2-c, m.5/2-ç) |
| Premium avantaj kullanımı: yararlandığınız avantajın kod kaydı (hangi avantaj, hesap kimliği ve kodun alınma zamanı) | Premium üyelere özel partner avantajlarının sunulması, indirim kodunun yalnızca Premium ve giriş yapmış üyeye verilmesi ve her avantajdan kaç/hangi üyenin yararlandığının raporlanması | Sözleşmenin ifası ve meşru menfaat (KVKK m.5/2-c, m.5/2-f) |
| Bildirim: Expo push tokenı, platform, cihaz adı, bildirim ticket/receipt ve teslimat durumu | İzin verdiğiniz bildirimleri göndermek ve teslimat sorunlarını gidermek | Sözleşmenin ifası ve meşru menfaat (KVKK m.5/2-c, m.5/2-f); işletim sistemi izni ayrıca alınır |
| Hesaplama kullanım verisi: rastgele kurulum kimliğinin HMAC özeti, olay kimliği, hesaplama türü, kredi/plan türü, tutar, vade, oran, vergi oranları, sonuç özeti, platform ve uygulama sürümü | Hesaplayıcıları geliştirme, kullanım eğilimlerini takma kimlikli ve toplu olarak ölçme, hata ve kötüye kullanımı tespit etme | Temel haklara zarar vermemek kaydıyla meşru menfaat (KVKK m.5/2-f) |
| Reklam: reklam kimliği/IDFA (izin varsa), IP, yaklaşık konum, cihaz/uygulama bilgisi ve reklam etkileşimi | Yalnız Premium olmayan kullanımda reklam sunma, ölçüm ve sahtecilik önleme | Kişiselleştirme/uygulamalar arası takip için açık rıza; zorunlu olmayan takip dışındaki işlemler için uygulanabilir diğer hukuki sebepler |
| Kredi talepleri (talep linki): bir bankacının paylaştığı bağlantıdaki formu dolduran müşterinin ad-soyadı, telefonu, isteğe bağlı e-postası, talep/kredi ayrıntıları, müşteri notu ve eklediği belgeler; talebin iletildiği bankacı, oluşturulma zamanı ve durum kayıtları | Talebin, bağlantıyı paylaşan bankacıya iletilmesi ve uygulama içinde takip edilmesi; kötüye kullanım ve sahteciliğin önlenmesi. İlgili bankacı bu veriyi kendi müşteri ilişkisi için bağımsız veri sorumlusu olarak kullanır | Talebin yerine getirilmesi (müşterinin kendi başvurusu) ve meşru menfaat (KVKK m.5/2-c, m.5/2-f) |
| İletişim: bize ilettiğiniz e-posta, talep içeriği ve yanıt kayıtları | Destek, KVKK başvuruları ve uyuşmazlıkların yönetimi | Talebin yerine getirilmesi, hukuki yükümlülük ve hakkın tesisi/kullanılması/korunması (KVKK m.5/2-c, m.5/2-ç, m.5/2-e) |
OTP kodunun kendisi düz metin saklanmaz; salt ve HMAC özeti tutulur. Oturum tokenının da yalnız tek yönlü özeti saklanır. Hesaplama olaylarına ad, e-posta, telefon, profil veya RevenueCat kimliği eklenmez ve bu olaylar üyelik hesabıyla ilişkilendirilmez. Ancak takma kimlikli veriler, ek bilgilerle eşleştirilebilme ihtimali nedeniyle tamamen anonim veri olarak değerlendirilmez.
3. Cihazınızda kalan veriler
Hesaplama girişlerinin ve geçmişinin uygulama içindeki yerel kopyası, tercihler ve cihazda üretilen PDF'ler cihazınızda tutulur. PDF'ye eklediğiniz müşteri bilgilerini kiminle paylaşacağınıza siz karar verirsiniz; Bankacı bunları PDF üretimi amacıyla sunucuya yüklemez. Uygulamayı silmek cihazdaki yerel verileri siler; üyelik hesabını ve sunucudaki verileri tek başına silmez.
Banka/kart bilgisi, T.C. kimlik numarası, kesin konum, rehber, mikrofon veya mesaj içeriği istemeyiz. Fotoğraf erişimi yalnız sizin seçtiğiniz profil/feed görselini yüklemek için kullanılır.
4. Toplama yöntemi
Veriler; mobil uygulama ve web formları, sizin yükleme/paylaşma işlemleriniz, cihaz ve işletim sistemi API'leri, Apple/Google mağaza kayıtları, RevenueCat webhookları, Expo bildirim altyapısı ve hizmet güvenliği için otomatik teknik kayıtlar yoluyla elektronik ortamda elde edilir. Aydınlatma, açık rıza gereken işlemlerden ayrıdır; politika metnini okumak her işlem için açık rıza verdiğiniz anlamına gelmez.
5. Hizmet sağlayıcılar ve alıcı grupları
Aşağıdaki hizmet sağlayıcılar, yukarıdaki amaçlarla sınırlı olarak veri işler:
- Google LLC ve grup şirketleri — Google Cloud Run, PostgreSQL/GCS altyapısı, Google Play, Firebase/FCM ve Google AdMob dağıtım, barındırma, medya, bildirim, ödeme ve reklam hizmetleri. Google'ın veri kullanımı · Gizlilik politikası
- RevenueCat, Inc. (ABD) — abonelik durumunun doğrulanması ve yönetimi; doğrulanmış hesap e-postasının destek sırasında abonelik kaydıyla eşleştirilmesi. Gizlilik politikası
- Apple Inc. ve grup şirketleri — App Store dağıtımı, ödeme, abonelik ve APNs bildirim altyapısı. Gizlilik politikası
- Expo / 650 Industries, Inc. — push tokenı, bildirim gönderimi ve teslimat sonucu.
- E-posta hizmet sağlayıcısı — OTP ve yeni hesap hoş geldin e-postalarının teslimi.
- Yetkili kamu kurumları ve hukuki danışmanlar — yalnız kanuni zorunluluk, hak tesisi veya yetkili talep hâlinde.
Verilerinizi satmayız veya kiralamayız. Hizmet sağlayıcılara yalnız ilgili hizmet için gerekli veri kategorileri aktarılır.
6. Ödemeler, Premium ve reklamlar
Abonelik ödemeleri tamamen Apple App Store veya Google Play üzerinden gerçekleşir. Kart bilgilerinizi görmüyor, işlemiyor ve saklamıyoruz. RevenueCat mağaza makbuzu, entitlement durumu, takma kullanıcı kimliği ve destek sırasında hesabı bulabilmek için doğrulanmış hesap e-postasını işler. E-posta, RevenueCat'te ana entitlement kimliği veya reklam takibi amacıyla kullanılmaz. İptal ve iade ilgili mağazanın kurallarına tabidir. Hesabı silmek mağaza aboneliğini otomatik iptal etmez; ayrıca App Store veya Google Play abonelik ayarından iptal etmeniz gerekir.
Premium kullanıcıya reklam gösterilmez ve reklam kaldırma kontrolü sunulmaz. Premium olmayan kullanımda AdMob veri işleyebilir. iOS uygulamalar arası izleme ve mevzuatın gerektirdiği reklam kişiselleştirme tercihleri ayrı izin mekanizmalarıyla yönetilir.
7. Yurt dışına aktarım
Google, Apple, RevenueCat, Expo ve e-posta sağlayıcısının altyapısı Türkiye dışında veya küresel olarak çalışabilir. Bu nedenle ilgili veri kategorileri yurt dışına aktarılabilir.
Aktarımlar KVKK m.9'daki yürürlükteki mekanizmalardan uygulanabilir olanına; yeterlilik kararı, uygun güvence (örneğin Kurulca ilan edilen standart sözleşme) veya kanundaki arızi hâllerden birine dayanılarak gerçekleştirilir. Açık rıza gereken bir aktarım varsa bu rıza aydınlatmadan ayrı şekilde istenir. Avrupa Ekonomik Alanı kullanıcıları için uygulanabildiği ölçüde GDPR Bölüm V mekanizmaları kullanılır.
8. Saklama süreleri
- OTP: kod 10 dakika geçerli ve tek kullanımlıktır; güvenlik/rate-limit kayıtları amaca uygun teknik temizlik süresine kadar tutulur.
- Session: 90 gün sonra geçersiz olur veya logout ile iptal edilir; güvenlik kayıtları periyodik temizliğe kadar sınırlı erişimle tutulabilir.
- Hesap/profil/feed: hesap silinene veya ilgili içerik silinene kadar; rapor/moderasyon ve hukuki uyuşmazlık kayıtları gerekli süre boyunca sınırlı tutulabilir.
- Kredi talepleri: formda iletilen ad, telefon, isteğe bağlı e-posta, müşteri notu ve belgeler talep linkinin sahibi bankacı tarafından takip edilir; hizmet, güvenlik ve hukuki yükümlülükler için gerekli süreden uzun tutulmaz. İletişim verileri anonim ürün analitiğine dahil edilmez.
- Premium avantaj kod kayıtları: ilgili avantaj yayında olduğu ve hesabınız açık kaldığı sürece tutulur; avantaj kaldırıldıktan veya hesabınız silindikten sonra yalnızca raporlama için gereken toplulaştırılmış/sınırlı kayıtlar saklanabilir.
- Hesaplama analitiği: ham takma kimlikli olaylar en fazla 180 gün; dış raporlar yalnız toplulaştırılmış ve en az 20 farklı kurulum eşiğini sağlayan gruplardan üretilir.
- Push tokenı: logout, cihaz kaydının kapatılması, sağlayıcının geçersiz bildirmesi veya hesap silme işlemine kadar.
- Satın alma ve reklam kayıtları: Apple, Google, RevenueCat ve reklam sağlayıcısının kendi saklama süreleri ile yasal zorunluluklar boyunca.
- Destek/KVKK başvuruları: talebin sonuçlanması ve olası uyuşmazlık zamanaşımı için gerekli süre boyunca.
9. Veri güvenliği
HTTPS/TLS, tek yönlü token özetleri, OTP HMAC, erişim kontrolleri, Google Cloud IAM, dosya türü/boyut doğrulaması, rate limit ve yapılandırılmış güvenlik logları kullanılır. Hiçbir sistem için mutlak güvenlik garanti edilemez.
10. Sosyal akış, bildirimler ve görünürlük
Feed okumak public olabilir. Profilinizde ve feed'de paylaştığınız görünen ad, fotoğraf, biyografi, meslek/banka bilgisi ve içerikler diğer kullanıcılarca görülebilir. Özel nitelikli kişisel veri, müşteri sırrı, banka sırrı, üçüncü kişiye ait finansal/iletişim bilgisi veya paylaşma yetkiniz olmayan içerikleri yüklemeyin.
Bildirim izni işletim sistemi tarafından istenir ve cihaz ayarlarından kapatılabilir. Bildirim payload'ına yorum metni, e-posta veya yorum yapan kişinin adı konulmaz.
11. Web sitesinde çerezler
`bankaci.app` tanıtım ve hukuki bilgi sayfalarının yanında, bankacının paylaştığı bağlantı üzerinden üyelik gerektirmeyen kredi talep formu sunabilir. Form verileri açık onayla ilgili bankacıya iletilir; web üzerinden ödeme yapılmaz. Zorunlu teknik loglar dışında reklam/analitik çerezi kullanılmaya başlanırsa bu bölüm ve gerektiğinde çerez tercih mekanizması önceden güncellenecektir.
12. Çocukların gizliliği
Bankacı profesyonellere yöneliktir ve 18 yaş altındaki kişilere yönelik değildir. Bir çocuğa ait verinin yetkisiz işlendiğini fark edersek doğrulama sonrasında silme ve gerekli koruma adımlarını uygularız.
13. Hesap silme ve KVKK hakları
KVKK m.11 kapsamında verilerinizin işlenip işlenmediğini öğrenme, bilgi isteme, amacına uygun kullanılıp kullanılmadığını öğrenme, aktarılan üçüncü kişileri bilme, eksik/yanlış verinin düzeltilmesini, şartları varsa silinmesini/yok edilmesini ve bu işlemlerin alıcılara bildirilmesini isteme, otomatik analiz aleyhinize sonuç doğurursa itiraz etme ve kanuna aykırı işleme nedeniyle zararın giderilmesini talep etme haklarına sahipsiniz.
Hesabınızı mobil uygulamada Ayarlar sayfasının en altındaki “Hesabı sil” seçeneğinden, iki aşamalı onay sonrasında doğrudan silebilirsiniz. Diğer taleplerinizi konuya “Bankacı KVKK Başvurusu” yazarak aşağıdaki e-posta adresine iletebilirsiniz. Güvenlik için hesabın size ait olduğunu doğrulamamız istenebilir. Talepler en kısa sürede ve en geç 30 gün içinde; ayrıca maliyet doğarsa Kurul tarifesindeki koşullar saklı olmak üzere sonuçlandırılır.
Hesap silme; aktif sessionları, profil ve ilişkili verileri silme veya hukuken gerekli kayıtları anonimleştirme/sınırlama sürecini başlatır. Public feed içeriği de hukuken tutulması gerekmiyorsa silinir. Uygulamayı silmek hesabı silmez; hesabı silmek de Apple veya Google aboneliğini iptal etmez. Başvurular: info@bankaci.app.
Başvurunun reddi, cevabın yetersizliği veya süresinde cevap verilmemesi hâlinde cevabı öğrendiğiniz tarihten itibaren 30 ve her hâlde başvuru tarihinden itibaren 60 gün içinde Kişisel Verileri Koruma Kurulu'na şikâyet hakkınız vardır. EEA kullanıcılarının uygulanabilir GDPR hakları ve yerel denetim makamına başvuru hakkı ayrıca saklıdır.
Resmî bilgi için KVKK aydınlatma yükümlülüğü ve ilgili kişi başvuruları sayfalarını inceleyebilirsiniz.
14. Değişiklikler
Bu politika zaman zaman güncellenebilir. Her güncellemede bu sayfadaki yürürlük tarihi ve sürüm numarası değişir. Haklarınızı önemli ölçüde etkileyen değişikliklerde, değişiklik yürürlüğe girmeden önce uygulama içinde bilgilendirme yapılır ve gerekiyorsa yeniden onayınız istenir.
15. İletişim
Veri sorumlusu: Burak Altıntaş — Antalya, Türkiye
E-posta:
burak.altintas@yahoo.com.tr
·
info@bankaci.app
Web:
burak-altintas.com
In short: The core calculators work without an account. If you create an account we process your email address; if you use the profile, social feed, notification and Premium features we process the data those services need. Calculation summaries are sent to our server on a pseudonymous basis — not tied to your identity or account — to improve the product. We never sell your data.
1. Data controller and scope
Under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"), the data controller is Burak Altıntaş (Antalya, Türkiye), reachable at burak.altintas@yahoo.com.tr and info@bankaci.app.
This policy covers:
- the Bankacı mobile application (iOS and Android), and
- bankaci.app and other Bankacı web properties serving the same content.
Bankacı is an independent professional helper tool; it is not a bank or a financial institution, it does not extend loans and it does not guarantee financial advice.
Request link: a Premium banker may collect membership-free loan requests from their customers through a link they share. For the personal data of the customer who fills in that form, the banker who establishes and uses the customer relationship is the independent data controller; Bankacı acts as a service provider/intermediary only for technically serving the form and delivering the request to the correct banker. The request form links to this Privacy Policy, so the customer who submits it is deemed informed by this text. Any further features such as future campaigns will be reflected in this policy and in in-app notices in advance.
2. Data we process, purposes and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| Membership and security: email address, one-time-code records, IP address of a code request, a one-way digest of the session, device name, session and last-seen times | Account creation, email-code authentication, session security, prevention of abuse and fraud | Establishment/performance of a contract and legitimate interests (KVKK Art. 5/2-c, 5/2-f) |
| Profile and social feed: display name; optional bio, bank/job title and profile photo; post, photo, like, comment, report and block records | Providing the profile and the social feed among bankers, moderation, security and handling complaints | Performance of a contract, your own sharing and legitimate interests (KVKK Art. 5/2-c, 5/2-d, 5/2-f) |
| Premium: RevenueCat pseudonymous user id, verified account email, entitlement, product, purchase/renewal/cancellation events, platform and app version | Verifying the Premium entitlement, carrying it across devices, restoring purchases, disabling ads and locating the account during support | Establishment/performance of a contract and legal obligation (KVKK Art. 5/2-c, 5/2-ç) |
| Premium advantage redemptions: the code record of the advantage you used (which advantage, your account id and when the code was revealed) | Offering premium-only partner perks, disclosing a discount code solely to a signed-in Premium member, and reporting how many and which members used each perk | Performance of a contract and legitimate interests (KVKK Art. 5/2-c, 5/2-f) |
| Notifications: Expo push token, platform, device name, notification ticket/receipt and delivery status | Sending the notifications you allow and troubleshooting delivery | Performance of a contract and legitimate interests (KVKK Art. 5/2-c, 5/2-f); the operating-system permission is obtained separately |
| Calculation usage data: HMAC digest of a random install id, event id, calculation type, loan/plan type, amount, term, rate, tax rates, result summary, platform and app version | Improving the calculators, measuring usage trends in a pseudonymous and aggregate way, detecting errors and abuse | Legitimate interests, provided fundamental rights are not harmed (KVKK Art. 5/2-f) |
| Loan requests (request link): the full name, phone, optional email, request/loan details, customer note and any documents submitted by the customer who fills the form at a link shared by a banker; the recipient banker, creation time and status records | Delivering the request to the banker who shared the link and letting it be tracked in the app; preventing abuse and fraud. The banker uses this data as an independent controller for their own customer relationship | Performance of the request (the customer's own application) and legitimate interests (KVKK Art. 5/2-c, 5/2-f) |
| Advertising: advertising id/IDFA (where permitted), IP, approximate location, device/app info and ad interactions | Serving ads only in non-Premium use, measurement and fraud prevention | Explicit consent for personalisation/cross-app tracking; other applicable legal bases for processing outside non-essential tracking |
| Communication: the email, request content and reply records you send us | Support, KVKK applications and managing disputes | Performance of the request, legal obligation and establishment/exercise/defence of a right (KVKK Art. 5/2-c, 5/2-ç, 5/2-e) |
The OTP code itself is not stored in plaintext; a salt and an HMAC digest are kept. Only a one-way digest of the session token is stored. Calculation events carry no name, email, phone, profile or RevenueCat id and are not linked to your membership account. Still, because pseudonymous data could in theory be matched with additional information, it is not treated as fully anonymous data.
3. Data that stays on your device
A local copy of your calculation inputs and history inside the app, your preferences and the PDFs generated on the device are kept on your device. You decide with whom to share the customer details you add to a PDF; Bankacı does not upload them to a server for PDF generation. Deleting the app removes the local data on the device; on its own it does not delete your membership account or the data on the server.
We do not ask for bank/card details, national ID number, precise location, contacts, microphone or message content. Photo access is used only to upload the profile/feed image you choose.
4. How we collect data
Data is obtained electronically through the mobile app and web forms, your own upload/share actions, device and operating-system APIs, Apple/Google store records, RevenueCat webhooks, the Expo notification infrastructure and automatic technical logs kept for service security. This notice is separate from the processes that require explicit consent; reading the policy does not mean you have given explicit consent for every processing activity.
5. Service providers and recipient groups
The following service providers process data solely for the purposes above:
- Google LLC and group companies — Google Cloud Run, PostgreSQL/GCS infrastructure, Google Play, Firebase/FCM and Google AdMob for distribution, hosting, media, notifications, payment and advertising. How Google uses data · Privacy policy
- RevenueCat, Inc. (USA) — verifying and managing subscription status; matching the verified account email with the subscription record during support. Privacy policy
- Apple Inc. and group companies — App Store distribution, payment, subscription and APNs notification infrastructure. Privacy policy
- Expo / 650 Industries, Inc. — push token, notification delivery and delivery result.
- Email service provider — delivery of OTP and new-account welcome emails.
- Competent public authorities and legal advisers — only in case of a legal obligation, establishment of a right or a lawful request.
We do not sell or rent your data. Only the data categories required for the relevant service are transferred to service providers.
6. Payments, Premium and ads
Subscription payments are handled entirely through the Apple App Store or Google Play. We do not see, process or store your card details. RevenueCat processes the store receipt, entitlement status, pseudonymous user id and the verified account email so the account can be found during support. The email is not used as the primary entitlement id in RevenueCat or for ad tracking. Cancellation and refunds are subject to the rules of the relevant store. Deleting your account does not automatically cancel the store subscription; you must also cancel it from your App Store or Google Play subscription settings.
No ads are shown to Premium users and no ad-removal control is offered to them. In non-Premium use AdMob may process data. iOS cross-app tracking and legally required ad-personalisation choices are managed through separate permission mechanisms.
7. International transfers
The infrastructure of Google, Apple, RevenueCat, Expo and the email provider may operate outside Türkiye or globally. The relevant data categories may therefore be transferred abroad.
Transfers rely on whichever of the mechanisms in KVKK Art. 9 is applicable — an adequacy decision, an appropriate safeguard (such as a standard contract announced by the Board) or one of the incidental situations in the law. Where a transfer requires explicit consent, that consent is requested separately from this notice. For users in the European Economic Area, Chapter V mechanisms of the GDPR are used to the extent applicable.
8. Retention periods
- OTP: the code is valid for 10 minutes and single-use; security/rate-limit records are kept until the appropriate technical clean-up.
- Session: expires after 90 days or is revoked on logout; security records may be kept with limited access until periodic clean-up.
- Account/profile/feed: until the account or the relevant content is deleted; report/moderation and legal-dispute records may be kept with limited access for the required period.
- Loan requests: the name, phone, optional email, customer note and documents submitted in the form are tracked by the banker who owns the request link; not kept longer than needed for the service, security and legal obligations. Communication data is not included in anonymous product analytics.
- Premium advantage redemptions: kept while the advantage is live and your account remains open; after the advantage is removed or your account is deleted, only aggregated/limited records needed for reporting may be retained.
- Calculation analytics: raw pseudonymous events for at most 180 days; external reports are produced only from aggregated groups meeting a threshold of at least 20 distinct installs.
- Push token: until logout, disabling the device registration, the provider reporting it invalid, or account deletion.
- Purchase and ad records: for the retention periods of Apple, Google, RevenueCat and the ad provider and for the duration of legal obligations.
- Support/KVKK applications: for the period needed to resolve the request and for any dispute limitation period.
9. Data security
HTTPS/TLS, one-way token digests, OTP HMAC, access controls, Google Cloud IAM, file type/size validation, rate limiting and structured security logs are used. No system can guarantee absolute security.
10. Social feed, notifications and visibility
Reading the feed may be public. The display name, photo, bio, profession/bank information and content you share on your profile and in the feed may be seen by other users. Do not upload special categories of personal data, customer secrets, banking secrets, third-party financial/contact information or content you are not authorised to share.
Notification permission is requested by the operating system and can be turned off in device settings. Comment text, email or the name of the commenter is not placed in the notification payload.
11. Cookies on the website
Alongside its promotional and legal-information pages, `bankaci.app` may offer a membership-free loan-request form via a link shared by a banker. The form links to this Privacy Policy, form data is sent to the relevant banker with explicit approval, and no payment is taken through the web. If advertising/analytics cookies beyond mandatory technical logs start being used, this section and, where needed, a cookie-preference mechanism will be updated in advance.
12. Children's privacy
Bankacı is aimed at professionals and is not directed at persons under 18. If we notice that a child's data has been processed without authorisation, we apply deletion and the necessary protective steps after verification.
13. Account deletion and KVKK rights
Under KVKK Art. 11 you have the right to learn whether your data is processed, to request information, to learn whether it is used for its purpose, to know the third parties to whom it is transferred, to request correction of incomplete/incorrect data, to request erasure/destruction where the conditions are met and notification of these to recipients, to object where an automated analysis produces a result against you, and to claim compensation for damage arising from unlawful processing.
You can delete your account directly from the "Delete account" option at the bottom of the Profile page in the mobile app, after a two-step confirmation. You can send other requests to the email address below with the subject "Bankacı KVKK Application". For security we may need to verify that the account belongs to you. Requests are concluded as soon as possible and within 30 days at the latest; where a cost arises, the conditions in the Board's tariff are reserved.
Account deletion starts the process of deleting active sessions, the profile and related data or anonymising/restricting records that must be kept by law. Public feed content is also deleted unless it must be kept by law. Deleting the app does not delete the account; deleting the account does not cancel your Apple or Google subscription. Applications: info@bankaci.app.
If your application is refused, the reply is inadequate or no reply is given in time, you may complain to the Personal Data Protection Board within 30 days of learning of the reply and in any case within 60 days of the application. Applicable GDPR rights of EEA users and the right to apply to the local supervisory authority are separately reserved.
14. Changes to this policy
This policy may be updated from time to time. Every update changes the effective date and version number on this page. Where a change materially affects your rights, we notify you inside the app before it takes effect and, where required, ask for your consent again.
15. Contact
Data controller: Burak Altıntaş — Antalya, Türkiye
Email:
burak.altintas@yahoo.com.tr
·
info@bankaci.app
Web:
burak-altintas.com