Skip to content
Legal

Privacy Policy

Explains which personal data the Ağrı Sosyal Şehir app processes, why, with whom it is shared and for how long it is kept.

Version 2026-09-26.3Last updated: 29 September 2026All legal documents

The data controller's identity has not been filled in for this installation yet; it is marked "[…]" in the text. The identity form in the factory panel must be completed before the app is submitted to the stores.

1. Data controller

This policy explains how the Ağrı Sosyal Şehir mobile application, the website at agricebinde.com and the attached panels process personal data. Under the Turkish Personal Data Protection Law No. 6698 (KVKK) the data controller is the person identified below.

  • Legal name: […]
  • Address: […]
  • Registry / tax details: […]
  • Contact for requests: […]
  • Support: destek@sosyalsehir.com

The app is installed for Ağrı only; the data is kept within this installation, and no accounts, messages or posts are shared with other cities.

2. Personal data processed

Data is processed only for the features you use and only as far as needed.

  • Identity and contact: name, e-mail address, phone number, username, profile photograph, bio, website link, date of birth, gender and profession. Of these the name, either the e-mail or the phone, and the date of birth are required; gender is asked at registration and "prefer not to say" can be chosen; the rest is optional. Your date of birth is never shown anywhere, is used only to apply the age rules and, once saved, can be corrected only through support. The city administration decides whether your profession is shown on your profile.
  • Account and session: the irreversible hash of your password, session records (session token, IP address, browser and device information), e-mail and phone verification records, the type, version and date of the consents you gave, and your notification permissions. For notifications, your device's push token and platform are stored.
  • Content you produce: your posts, comments, listings, messages, reviews, poll answers, confessions, game scores, SAHNE entries (without your age) and the images and videos you upload.
  • Order and service records: your food and flower orders, delivery addresses, chosen payment method (cash or card on delivery; no card data is taken), taxi requests and tradesman requests.
  • Usage records: which posts and news items you viewed, who visited your profile, which videos you swiped past and the text of the questions you asked the assistant by typing or by voice.
  • Voice assistant: a spoken question is transcribed by your phone's speech-recognition service; the audio never reaches us and is not stored, we receive only the recognised text. The microphone runs only when you open it and closes on silence; the city administration can switch the voice assistant off.
  • Payment: in-app purchases are made through the App Store and Google Play; your card details never reach us. We keep only the purchase receipt the store returns and which entitlement is open until when. If a business owner pays by card from the web panel, we keep the transaction id, the amount and masked card details (last four digits and card brand).
  • Performance and error records: so that we can measure its speed, the app sends anonymous, aggregated counts (start-up and screen open times, round-trip time of server requests, app and OS version, voice-assistant timings). These are kept as daily totals and contain no account id, IP address, location or question text. When the app crashes, the error message and stack trace are sent with any e-mail addresses, phone numbers and long digit sequences scrubbed. None of these measurements go to third parties.

3. Location data

Location is used in three features, at a different precision in each.

  • GALA live map: your device's location is read only when you say "I am here", and when written to the server it is rounded to a grid of about 500 metres; no sharper point is stored anywhere. The map shows your profile photograph, this approximate location and the colour of your pin's frame; the colour comes from the gender on your profile (grey if you did not state it or for a business account), and the map cannot be filtered by gender. Your name, share photograph and caption are shown only to someone who opens your person card. Your own location is not recorded while you watch the map. Accounts under eighteen or without a date of birth on file do not appear on the map. You can remove your share at any moment; its coordinate and photograph are deleted 24 hours after it ends.
  • Check-in: when you check in at a venue the coordinate is stored exactly and permanently, so a disputed venue leadership can be examined later.
  • Taxi: when you hail a taxi the pickup and drop-off points, and in driver mode the location pings sent during the trip, are stored as is.

You can withdraw location permission in the operating system settings at any time; without it these three features do not work, the rest of the app does.

4. Purposes of processing

Personal data is processed to create and secure your account, to provide the services of the modules you choose, to send you notifications, to run content moderation and abuse review, to recognise the entitlements you purchased, to measure and improve the service, to resolve reports and disputes and to fulfil legal obligations. No advertising profile is built and personal data is not sold to third parties for advertising.

5. Legal bases

Under Article 5 of the KVKK, data is processed on the basis that it is necessary for the formation or performance of a contract (your account, orders, purchases), for compliance with a legal obligation (financial records, requests from competent authorities), for the legitimate interests of the controller (security, prevention of abuse, continuity of the service) and, for everything else, on the basis of your explicit consent. Location sharing, marketing messages and transfers abroad to AI providers rest on explicit consent. Special categories of personal data under Article 6, such as health data, are not collected as profile data in this app. The blood type, hospital name and contact number you write in a blood donation appeal are published publicly as part of the appeal; they are not processed separately as a health record about you, and you can close the appeal at any time.

6. Who it is shared with

Personal data is transferred to the following providers only for the relevant function and only as far as needed. This is the complete list.

  • File storage: the photographs and videos you upload are kept in an object storage service; the installation may use its own server or Cloudflare R2. Published media links are at unguessable addresses but are publicly accessible.
  • Push notifications: notifications are delivered through Google Firebase Cloud Messaging; your device token and the notification text are transferred to Google.
  • Store and payment: in-app purchases run through the Apple App Store and Google Play; they are the merchant. To verify the receipt, a purchase id and account mapping pass between the store and us. If the city administration has chosen RevenueCat, the same receipt data also goes to RevenueCat.
  • Card payment (web business panel only): the payment is made on the provider's own page (iyzico or PayTR); name, e-mail, IP address, amount and order id are passed to the provider; card data never touches us.
  • SMS: to send a verification code your phone number and the message text are transferred to the SMS provider (Netgsm).
  • E-mail: for messages such as password resets your e-mail address and the message text are transferred to the e-mail provider (Resend).
  • Weather: for the weather on the home screen only the city's fixed coordinate is sent to the weather service (Open-Meteo), not your location.
  • City assistant: if the city administration has enabled an AI model from the panel, the text of your question, the previous questions and answers in the same conversation and city data that is already public in the app are sent to the selected provider: Google (Gemini), Groq (Llama models) or Anthropic (Claude). If several are enabled, they are tried in order. Your account id, phone number and e-mail address are not sent; personal information you write into your question yourself goes with the text. When no model is enabled the assistant answers only from the data on our own server.
  • Speech recognition: in a spoken question your voice goes to your phone's operating system speech-recognition service (Apple on iOS, Google or the device's own service on Android).
  • Spoken reply: if the city administration has enabled the server voice, the text of the assistant's reply (not your voice or identity) is sent to Google Cloud Text-to-Speech to be converted to audio. The generated audio file is tied to the sentence, not to a person.
  • Maps: mobile maps are drawn with Apple Maps on iOS and the Google Maps component on Android; your device fetches the tiles directly. The map in the administration panel uses OpenStreetMap tiles; that request carries no resident data.
  • Competent authorities: where legislation requires it, data may be transferred to competent public institutions.

Some of the providers above are established abroad; to that extent data is transferred abroad within the meaning of Article 9 of the KVKK, and the transfer rests on your explicit consent or on the other conditions the law provides.

7. Retention periods

Data that is deleted automatically, and when:

  • Coordinate and photograph of a GALA live-map share: 24 hours after it expires.
  • Stories: 24 hours after they expire.
  • Profile visits: 90 days.
  • Post view records: up to 180 days, depending on the age of the post.
  • Record of videos you swiped past: 45 days.
  • Deleted account: anonymised after 30 days.
  • Database backups: 14 days.
  • Anonymous performance totals: 8 days; app error records: 30 days.

There is no defined automatic deletion period for check-in coordinates, taxi trip and driver location records, questions asked to the assistant, message contents, administration audit logs, moderation and report records, or payment records; when an account is deleted they are handled as described in section 8. Uploaded images may remain in storage even after the record that carried them is deleted; the three things that are truly deleted together with their file are videos, live-map photographs and SAHNE images.

8. Deleting your account

In the app: Profile > Settings (gear icon) > Security > Delete Account. The moment you do, your sessions are closed, your device notification records, saved addresses and profile visit records are deleted, your follow links are removed in both directions, and your open live-map shares are ended with their coordinate and photograph cleared.

Without the app: if you cannot or do not want to use the app, you can request the deletion of your account and its associated data by e-mailing destek@sosyalsehir.com from the e-mail address registered to your account, with the subject "Account deletion request"; if you signed up with your phone number, state the registered number. We may ask for further details to confirm that the account is yours. Your request is completed within 30 days at the latest, as Article 13 of the KVKK requires, and your account is then handled as if you had deleted it in the app.

After 30 days the account is anonymised: your name is replaced with a placeholder and your e-mail address is changed irreversibly; your phone number, profile photograph, bio, website link, username, date of birth, gender, profession and sign-in credentials are deleted; videos you shared are permanently deleted together with their files.

What is not deleted: your posts, comments, listings, check-ins, orders and reviews remain visible under the anonymised name; messages you sent remain in the other party's conversation. The records with no automatic deletion period (section 7) and your consent records are kept linked to the anonymised account for security, disputes and legal obligations; payment and invoice records are kept for the statutory retention periods (up to ten years for commercial books and documents). If you own a business you must close it first; store subscriptions must be cancelled separately through the App Store or Google Play.

9. Your rights

Under Article 11 of the KVKK you have the right to learn whether your data is processed, to request information if it is, to learn the purpose of processing and whether it is used accordingly, to know the third parties it is transferred to, to request its correction if it is incomplete or wrong, its erasure or destruction and the notification of these to the third parties it was transferred to, to object to a result against you produced exclusively by automated analysis, and to claim compensation for your damage.

  • What you can do in the app: correct your profile details, make your account private, switch off profile-view tracking, turn off notifications per module, block people and delete your account.
  • Deleting without closing your account: you can remove your posts, comments, marketplace and job listings, stories, GALA share and SAHNE entry one by one in the app and retract a message you sent within its first 10 minutes; you can ask for other data to be deleted by e-mailing destek@sosyalsehir.com with the subject "Data deletion request", and your request is completed within 30 days.
  • What you can do by request: to obtain a copy of your data, to withdraw your marketing consent and to exercise your other rights, write to […] or destek@sosyalsehir.com. Your request is answered within thirty days at the latest.

10. Children's data

This app is not directed at children. A date of birth is asked at registration: persons under thirteen cannot open an account, persons under eighteen are expected to use the app with a parent's permission, and GALA and SAHNE are open only to those eighteen and over. The date of birth is self-declared and not checked against an identity document. We delete the data of an account we learn belongs to a person under thirteen; you can report such a case with the "Under 18" report reason or to destek@sosyalsehir.com.

11. Security

Passwords are stored irreversibly, all traffic is encrypted, and access to resident data in the administration panel is two-tiered: a moderator sees contact details masked, only the city administrator sees them in clear, and every such view leaves a separate audit record. Password hashes and session tokens are not shown on any administration screen; message contents are reviewed only when reported, together with the report. Write to the City (confession) texts are published under your name and are read by a moderator before publication.

12. Changes and requests

When this policy changes the version date is updated. A significant change is announced within the app and, where required, your consent is requested again. You can send your KVKK requests in writing to […] or destek@sosyalsehir.com.