Gizlilik Politikası
Kuaför Asistanım İşletme — iOS ve Android uygulaması
Kısaca
- Uygulamada reklam yoktur; hiçbir veri reklam veya izleme (tracking) amacıyla kullanılmaz.
- Verileriniz satılmaz, veri simsarlarıyla (data broker) paylaşılmaz.
- Konum, kamera, fotoğraf, mikrofon ve rehber erişimi istenmez.
- Bildirimleri uygulama içinden kapatabilirsiniz; kapattığınızda cihaz kaydı sunucudan silinir.
1. Veri sorumlusu ve iletişim
Kuaför Asistanım, "Kuaför Asistanım İşletme" mobil uygulamasının ("Uygulama") işletmecisi ve 6698 sayılı Kişisel Verilerin Korunması Kanunu ("KVKK") anlamında veri sorumlusudur. Gizlilik, veri erişimi ve silme talepleriniz için:
2. Uygulama kime yöneliktir?
Uygulama; kuaför, berber ve güzellik salonu işletme sahipleri ile salon personelinin randevu, personel ve hizmet yönetimi için kullandığı bir iş aracıdır. Salonun kendi müşterileri Uygulamayı kullanmaz; müşterilere ait randevu bilgileri salon çalışanı tarafından girilir ve salon adına işlenir. Bu verileri kendi pazarlama faaliyetlerimiz için kullanmayız.
3. Toplanan veriler
| Veri | Nereden gelir | Neden |
|---|---|---|
| Ad soyad | Personel/işletme hesabınız; müşteri kaydı girerken sizin tarafınızdan | Hesabın ve randevunun kime ait olduğunun gösterilmesi |
| E-posta adresi | Giriş bilgileriniz; işletme başvuru formu | Kimlik doğrulama, şifre sıfırlama, randevu ve hesap bildirimleri |
| Telefon numarası | Personel/işletme kaydı; girdiğiniz müşteri kayıtları | Müşteriye ulaşma (arama/WhatsApp/SMS), işletme başvurusunda geri dönüş |
| İşletme adresi | İşletme başvuru formu; dükkân profili ekranı | Şubenin nerede olduğunun gösterilmesi, randevu e-postasındaki yol tarifi bağlantısı |
| Kullanıcı kimliği (hesap numarası) | Sunucunun hesabınıza atadığı kimlik (UUID) | Oturum yönetimi, yetkilendirme, kaydın hangi kullanıcıya ait olduğunun izlenmesi |
| Cihaz bildirim jetonu (push token) | Bildirimlere izin verdiğinizde işletim sisteminden (APNs / FCM) | Yeni randevu bildiriminin doğru cihaza iletilmesi |
| Randevu ve işletme verileri (randevu notu dahil) | Uygulamada sizin girdiğiniz kayıtlar; açtığınız destek talepleri | Randevu, personel, hizmet ve çalışma saati yönetimi |
| Teknik günlük kayıtları | Sunucularımız (istek zamanı, IP adresi, platform, hata izleri) | Güvenlik, kötüye kullanım ve hata tespiti, hizmetin ayakta tutulması |
Toplamadıklarımız
- Konum: Uygulama cihaz konumu istemez ve kullanmaz; harita ekranı yoktur. Adres yazıyla girilir.
- Kamera, fotoğraf, mikrofon, rehber, takvim: erişim istenmez.
- Reklam kimliği (IDFA/AAID): okunmaz; uygulamada reklam ağı veya analitik SDK'sı bulunmaz.
- Ödeme kartı bilgileri: Uygulama içinde toplanmaz. Abonelik ödemesi web portalında, ödeme sağlayıcısının kendi sayfasında yapılır.
- Sağlık, biyometri ve diğer özel nitelikli veriler: işlenmez.
4. App Store ve Google Play "veri türleri" beyanımız
Apple App Store'daki "Uygulama Gizliliği" ve Google Play'deki "Veri güvenliği" bölümlerinde gösterilen veri türleri aşağıdaki gibidir. Hiçbir veri türü izleme (tracking) amacıyla kullanılmaz ve reklam amacıyla üçüncü taraflarla paylaşılmaz.
| Veri türü | Toplanıyor | Kimliğe bağlı | İzleme | Amaç |
|---|---|---|---|---|
| İletişim — Ad | Evet | Evet | Hayır | Uygulama işlevselliği |
| İletişim — E-posta adresi | Evet | Evet | Hayır | Uygulama işlevselliği |
| İletişim — Telefon numarası | Evet | Evet | Hayır | Uygulama işlevselliği |
| İletişim — Adres | Evet | Evet | Hayır | Uygulama işlevselliği |
| Tanımlayıcılar — Kullanıcı kimliği | Evet | Evet | Hayır | Uygulama işlevselliği |
| Tanımlayıcılar — Cihaz kimliği (bildirim jetonu) | Evet | Evet | Hayır | Uygulama işlevselliği |
| Kullanıcı içeriği — Diğer kullanıcı içeriği (randevu notu, destek mesajı) | Evet | Evet | Hayır | Uygulama işlevselliği |
| Teşhis — Diğer teşhis verileri | Evet | Evet | Hayır | Uygulama işlevselliği (güvenlik ve hata tespiti) |
| Konum, Finansal bilgi, Rehber, Takvim, Fotoğraf ve video, Ses, Sağlık, Tarama geçmişi, Kullanım verisi, Reklam verisi | Hayır | — | Hayır | — |
5. İşleme amaçları ve hukuki sebepler
- Hesabınızın oluşturulması ve oturum açma: sözleşmenin kurulması ve ifası.
- Randevu, personel, hizmet ve çalışma saati yönetimi: sözleşmenin ifası.
- Randevu bildirimleri (e-posta ve push): sözleşmenin ifası; push bildirimi ayrıca cihaz izninize bağlıdır.
- Kötüye kullanımın önlenmesi, güvenlik ve hata giderme: meşru menfaat.
- İşletme başvurunuzun değerlendirilmesi ve size dönüş yapılması: sözleşme öncesi hazırlık; telefonla aranma izni verdiyseniz açık rıza.
- Yasal yükümlülüklerin yerine getirilmesi: hukuki yükümlülük.
Uygulama üzerinden ticari elektronik ileti (reklam/kampanya) gönderilmez ve bu amaçla izin toplanmaz. Gönderilen tüm e-postalar hizmete ilişkin bildirimlerdir.
6. Paylaşım ve hizmet sağlayıcılar
- Apple (APNs) ve Google (Firebase Cloud Messaging): bildirimin cihazınıza ulaştırılması için cihaz jetonu ve bildirim metni iletilir. Bildirim metni müşteri adı ve randevu saati içerebilir; müşteri e-postası veya diğer kayıtlar iletilmez.
- Expo (EAS Update): uygulama güncellemelerinin dağıtımı; hesap verileriniz iletilmez.
- E-posta gönderim sağlayıcısı: bildirim e-postalarının iletilmesi için alıcı adresi ve mesaj içeriği.
- Barındırma sağlayıcısı: verilerin saklandığı sunucular.
- Ödeme/abonelik sağlayıcısı: yalnızca web portalındaki abonelik işlemleri için; kart bilgileri bize hiçbir zaman ulaşmaz.
- Yetkili kamu kurumları: yalnızca yasal zorunluluk hâlinde.
Veriler pazarlama amacıyla üçüncü taraflara satılmaz veya devredilmez. Bazı sağlayıcıların sunucuları yurt dışında bulunabilir; bu durumda aktarım KVKK'nın yurt dışına aktarım hükümlerine uygun şekilde yapılır.
7. Saklama süreleri
- Hesap ve randevu verileri, hesabınız aktif olduğu sürece saklanır.
- Cihaz bildirim jetonu; bildirimleri kapattığınızda, çıkış yaptığınızda veya jeton geçersizleştiğinde silinir.
- Bildirim e-postası geçmişi 90 gün, teslimat kuyruğu kayıtları 30 gün sonra silinir.
- Sonuçlanmayan/reddedilen işletme başvuruları makul süre sonunda silinir.
- Güvenlik ve teknik günlükler sınırlı bir süre tutulur; daha uzun yasal saklama süreleri saklıdır.
8. Güvenlik
- Tüm bağlantılar HTTPS/TLS ile şifrelenir.
- Oturum jetonlarınız cihazın güvenli deposunda (iOS Keychain / Android Keystore) tutulur.
- Parolalar geri döndürülemez biçimde (Argon2id + sunucu tarafı gizli anahtar) saklanır.
- Başarısız giriş denemeleri sınırlanır; her giriş denemesi güvenlik amacıyla kaydedilir.
- Her işletmenin verisi yalıtılır; bir salon başka bir salonun verisine erişemez.
9. Haklarınız
KVKK m.11 kapsamında; verilerinizin işlenip işlenmediğini öğrenme, bilgi talep etme, düzeltilmesini, silinmesini ya da bir kopyasının tarafınıza iletilmesini isteme haklarına sahipsiniz. Talebinizi info@kuaforasistanim.com adresine iletebilirsiniz; başvurular en geç 30 gün içinde yanıtlanır.
Hesap ve veri silme
Personel hesapları işletme sahibi tarafından uygulamadan çıkarılabilir. Hesabınızın ve ilişkili verilerinizin tamamen silinmesini istiyorsanız, kayıtlı e-posta adresinizden info@kuaforasistanim.com adresine yazmanız yeterlidir. Yasal saklama yükümlülüğü bulunan kayıtlar dışındaki veriler silinir veya anonimleştirilir.
Bildirimler
Push bildirimlerini Ayarlar → Bildirimler ekranından kapatabilirsiniz. Kapattığınızda cihaz kaydınız sunucudan silinir ve o cihaz için bildirim üretilmez. Cihaz ayarlarından da kapatabilirsiniz.
10. Çocukların gizliliği
Uygulama işletme sahipleri ve salon personeli için tasarlanmıştır, çocuklara yönelik değildir ve bilerek 18 yaşından küçüklerden veri toplamaz. Böyle bir verinin işlendiğini fark edersek sileriz.
11. Değişiklikler
Bu politika güncellendiğinde en güncel sürüm bu sayfada yayımlanır ve yukarıdaki "Son güncelleme" tarihi değiştirilir. Önemli değişikliklerde uygulama içinde veya e-posta ile bilgilendirme yapılır.
12. İletişim
Sorularınız için: info@kuaforasistanim.com
Privacy Policy
Kuaför Asistanım İşletme — iOS and Android app
In short
- The app contains no advertising, and no data is used for tracking.
- We never sell your data or share it with data brokers.
- The app requests no access to location, camera, photos, microphone or contacts.
- You can turn notifications off in the app; doing so deletes that device's registration from our servers.
1. Data controller and contact
Kuaför Asistanım operates the "Kuaför Asistanım İşletme" mobile application (the "App") and is the data controller for the personal data described here.
2. Who the app is for
The App is a business tool used by barbershop and salon owners and their staff to manage appointments, staff and services. A salon's own customers do not use the App; customer appointment details are entered by salon staff and processed on behalf of the salon. We do not use that data for our own marketing.
3. Data we collect
| Data | Source | Why |
|---|---|---|
| Name | Your staff/owner account; customer records you enter | Showing who an account or appointment belongs to |
| Email address | Your sign-in credentials; the business application form | Authentication, password reset, appointment and account notifications |
| Phone number | Staff/business records; customer records you enter | Contacting the customer (call/WhatsApp/SMS); replying to a business application |
| Business address | The merchant application form; the shop profile screen | Showing where the branch is, and the directions link in appointment e-mails |
| User ID | An identifier (UUID) assigned to your account by our servers | Session management, authorization, attributing records to a user |
| Device push token | The operating system (APNs / FCM) once you allow notifications | Delivering new-appointment notifications to the right device |
| Appointment and business data (including appointment notes) | Records you enter in the App; support requests you open | Managing appointments, staff, services and working hours |
| Technical logs | Our servers (request time, IP address, platform, error traces) | Security, abuse and error detection, keeping the service running |
What we do not collect
- Location: the App never requests or uses device location; there is no map screen. Addresses are typed in.
- Camera, photos, microphone, contacts, calendar: no access is requested.
- Advertising identifiers (IDFA/AAID): not read. The App contains no ad network or analytics SDK.
- Payment card details: never collected in the App. Subscription payments happen on the web portal, on the payment provider's own page.
- Health, biometric or other special-category data: not processed.
4. Our App Store and Google Play data declaration
The data types shown in the App Store's "App Privacy" and Google Play's "Data safety" sections are listed below. No data type is used for tracking or shared with third parties for advertising.
| Data type | Collected | Linked to you | Tracking | Purpose |
|---|---|---|---|---|
| Contact Info — Name | Yes | Yes | No | App Functionality |
| Contact Info — Email Address | Yes | Yes | No | App Functionality |
| Contact Info — Phone Number | Yes | Yes | No | App Functionality |
| Contact Info — Physical Address | Yes | Yes | No | App Functionality |
| Identifiers — User ID | Yes | Yes | No | App Functionality |
| Identifiers — Device ID (push token) | Yes | Yes | No | App Functionality |
| User Content — Other User Content (appointment notes, support messages) | Yes | Yes | No | App Functionality |
| Diagnostics — Other Diagnostic Data | Yes | Yes | No | App Functionality (security and error detection) |
| Location, Financial Info, Contacts, Calendar, Photos and Videos, Audio, Health, Browsing History, Usage Data, Advertising Data | No | — | No | — |
5. Purposes and legal bases
- Creating your account and signing you in: performance of a contract.
- Managing appointments, staff, services and working hours: performance of a contract.
- Appointment notifications (email and push): performance of a contract; push additionally depends on your device permission.
- Preventing abuse, security and troubleshooting: legitimate interest.
- Assessing and replying to a business application: pre-contractual steps; explicit consent where you agreed to be telephoned.
- Meeting legal obligations: legal obligation.
We send no marketing or promotional messages through the App and collect no consent for them. Every email we send is a service notification.
6. Sharing and service providers
- Apple (APNs) and Google (Firebase Cloud Messaging): the device token and notification text, so the notification reaches your device. The text may contain a customer name and appointment time; no other records are sent.
- Expo (EAS Update): distribution of app updates; no account data is sent.
- Email delivery provider: recipient address and message content for notification emails.
- Hosting provider: the servers where data is stored.
- Payment/subscription provider: only for subscription transactions on the web portal; card details never reach us.
- Competent public authorities: only where legally required.
Data is never sold or transferred to third parties for marketing. Some providers' servers may be located abroad; such transfers are made in line with applicable data protection law.
7. Retention
- Account and appointment data is kept while your account is active.
- The device push token is deleted when you turn notifications off, sign out, or the token becomes invalid.
- Notification email history is deleted after 90 days, delivery queue records after 30 days.
- Business applications that do not proceed are deleted after a reasonable period.
- Security and technical logs are kept for a limited period; longer statutory retention periods may apply.
8. Security
- All connections are encrypted with HTTPS/TLS.
- Session tokens are stored in the device's secure storage (iOS Keychain / Android Keystore).
- Passwords are stored irreversibly (Argon2id with a server-side secret).
- Failed sign-in attempts are rate limited, and every attempt is logged for security.
- Each business's data is isolated; one salon cannot reach another salon's data.
9. Your rights
You may ask whether we process your data, request a copy of it, and ask for it to be corrected or deleted. Write to info@kuaforasistanim.com; we answer within 30 days at the latest.
Account and data deletion
Staff accounts can be removed from a business by its owner. If you want your account and its data deleted entirely, email info@kuaforasistanim.com from your registered address. Everything except records we must keep by law is deleted or anonymised.
Notifications
You can turn push notifications off under Settings → Notifications in the App. Doing so deletes that device's registration from our servers, so nothing is produced for it. You can also turn them off in your device settings.
10. Children's privacy
The App is designed for business owners and salon staff. It is not directed at children and we do not knowingly collect data from anyone under 18. If we learn that we have, we delete it.
11. Changes
When this policy changes, the current version is published on this page and the "Last updated" date above is revised. We notify users in the App or by email about significant changes.
12. Contact
Questions: info@kuaforasistanim.com