1. Our privacy philosophy
We collect the minimum needed, seal what is sensitive, and open identity only with consent. Privacy is a design constraint, not a policy paragraph.
2. What we collect and why
| Data | Purpose | Lawful basis (GDPR) |
|---|---|---|
| Email, auth identifier | Account, login (passwordless) | Contract (Art. 6(1)(b)) |
| Role, onboarding intent | Route you to the right experience | Contract |
| K1 rumored profile (nickname, age band, region, short story) | Enable dignified matching | Consent (Art. 6(1)(a)); moderated |
| K2 identity + address | Fulfillment of a specific good | Consent + Contract; time-limited |
| Verification data (liveness, ID match, documents) | Prevent fraud, protect the shelf | Legal obligation / legitimate interest / consent, per tier |
| Payment metadata (not card data) | Process contributions | Contract; card data handled by Stripe |
| Device/risk signals | Fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Support/emergency case data | Deliver the outcome | Consent; special-category data under Art. 9 where applicable, with explicit consent |
3. Special-category & sensitive data
Emergency cases may reveal health or hardship data (special category under GDPR Art. 9 / sensitive under KVKK). We process it only with explicit consent, store it sealed (K3), share the minimum with a provider to pay a bill, and never publish it.
4. Minors
We do not knowingly hold accounts for people under 18. Where a minor is helped through an institution/guardian bridge, identity/visibility layers stay closed and safeguarding rules apply.
5. Who sees what (Graduated Visibility)
- •K0 (public): only a need/product card — never a person.
- •K1: rumored profile, to verified Givers, only if the person opens it.
- •K2 (identity + address): only the single Giver fulfilling that good, on mutual consent, time-limited, logged; auto-closes on delivery. Screenshotting is warned against and access is contractually bound.
- •K3 (sealed): documents/risk data — staff/moderation only, never any user.
6. Sharing & processors
We use processors under data-processing agreements: Supabase (hosting/database), Stripe (payments), [EMAIL/SMS PROVIDER] (notifications), affiliate networks (Lane E — no PII in SubIDs; hashed pseudonyms only). We do not sell personal data. We disclose to authorities only when legally required.
7. International transfers
Where data leaves [REGION], we rely on adequacy decisions or Standard Contractual Clauses / equivalent KVKK safeguards.
8. Retention
We keep data only as long as needed for the purpose or as required by law. Inactive need-profiles sleep after 6 months (data minimization); K2 grants expire with the delivery; verification documents are held for the minimum retention required, then deleted.
9. Your rights
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent (KVKK Art. 11 / GDPR Arts. 15–22). Contact [DPO EMAIL]. You may complain to your supervisory authority (KVKK Kurumu in Türkiye; your national DPA in the EU).
10. Security
Row-level security, sealed identity tables, least-privilege access, encrypted transport, audit logs, and a breach-notification process consistent with KVKK/GDPR timelines.
11. Cookies & tracking
Essential cookies for login; analytics and any affiliate tracking only with consent via our consent manager. Withdrawing consent disables optional tracking without breaking core features.