Privacy Notice

Last updated:

GatherMiles is a travel-first app for meeting other travelers through small activities. It is for adults only (18+). This notice explains what personal data we process, why, and what control you have. It describes the app as it works today; features that are not available yet are named as such.

1. Who is responsible

The data controller (KVKK: “veri sorumlusu”) is Suphi Atılım Çeliköz, a sole proprietor (şahıs işletmesi) trading as SafeCargo Yazılım Teknoloji ve Danışmanlık Hizmetleri, Mehmet Akif Ersoy Mahallesi, Mimar Sinan Caddesi, Samyeli Konutları B Blok, Kapı No: 1, Çiftlikköy / Yalova, Türkiye (tax office: Yalova Vergi Dairesi, tax number 2410396271).

For privacy questions or to use your rights, write to [email protected]. You may also send a written request by post to the address above.

2. What we collect

Data Details
Account email Used to send your 6-digit sign-in code. There are no passwords. Your email is shown only to you.
Date of birth Asked once, before anything else, to check that you are 18 or older. It is stored in a protected area, cannot be read back through the app or shown to anyone, and is used only for the age check.
Profile Display name, home country, languages, interests, travel style, a short bio, and one optional photo.
Photo Resized and re-saved on your device (which removes hidden metadata such as GPS tags), then stored privately. Only you can see it. Other members cannot see photos yet; we will tell you here before that changes.
Location See section 4. Raw coordinates are never stored.
Activities The activities you create or join: title, description, time, public area, optional meeting note and, if you choose to share it, the exact meeting point.
Blocks and reports Who you block, and reports you file or that are filed about you (reason, optional details, a snapshot of the reported profile at that moment).
Technical data Your app language and theme are kept on your device. Our systems apply rate limits and basic abuse checks to keep the service safe. Our providers (section 5) process technical data such as IP addresses only as far as they need to deliver their service.

We do not collect your contacts, your precise position history, or your photo library (you pick one photo with the system picker). The app does not use background location.

3. Why we use it, and on what basis

Purpose Data Legal basis
Run your account, profile and activities Email, profile, activities Contract (GDPR Art. 6(1)(b))
Show your city and nearby activities and people Device location, chosen city Your own request through the system permission and the in-app explanation, with a manual city as the alternative
Show an approximate distance band to others, when that option is available Rounded area Your consent, which you can withdraw at any time
Keep minors out of an adults-only service Date of birth, refused-age hash Contract and legitimate interest
Safety, abuse and fraud prevention, handling reports Reports, safety signals, blocks Legitimate interests (GDPR Art. 6(1)(f)); evidence needed for legal claims

For users in Türkiye, the corresponding processing conditions of KVKK Article 5 apply.

We do not ask for consent where another basis applies, and refusing an optional choice does not block the core service. Acknowledging this notice is not a consent.

4. Location

  • The app reads your device location only after you ask it to (a tap on a location button) or while the People screen is open and you already shared from this device. Never at start-up, sign-in or in the background. You can choose a city by hand instead.
  • Your phone’s coordinates are rounded to about 110 m and sent once. The server finds your city, district and province, and then discards the point. We do not store raw coordinates and keep no location history.
  • Other members can see your city or province and district names. They never see your exact position, an exact distance, or whether you are online.
  • Only if you choose the approximate level, we also keep the centre of a roughly 1 km grid cell; it is cleared 24 hours after its last refresh. Your presence record is deleted 30 days after its last update.
  • An activity shows everyone a public area: the host’s area label and the centre of a roughly 1 km privacy cell. The exact meeting point and meeting note are visible only to the host and to members who have joined, and only if the host shares them. They are cleared when the activity is cancelled or completed.
  • Safety records about misuse (for example spoofed locations) hold city identifiers only, never coordinates, and are kept up to 90 days. Profile views are logged per day with your city for 30 days to detect stalking patterns.

5. Who receives your data

We use service providers (processors) only as far as the product needs them:

Provider Role Notes
Supabase Database, authentication, file storage Runs in the EU (Frankfurt, Germany).
Resend Sends your sign-in code email Runs in the EU region (Ireland).
Cloudflare Hosts this website; DNS and email forwarding for the domain Global network.
OpenFreeMap Map tiles Your device requests map tiles directly. The provider can see technical data such as your IP address and which tiles are requested. The map opens on a city centre and no member ID is sent.

Other members see only what is described in sections 2 and 4. We do not sell personal data. No analytics, advertising or crash-reporting tools are enabled in the app. Authorities may receive data where the law requires it.

This website sets no cookies.

6. International transfers

Some of our providers are outside Türkiye (in the EU, and companies headquartered in the United States). We make transfers abroad only in line with Article 9 of the KVKK and, where it applies, Chapter V of the GDPR.

7. How long we keep data

These are GatherMiles retention rules, as maximum periods. The location data cleanup runs automatically today; the other periods will be enforced by scheduled cleanup before the app is released in the app stores.

  • Raw coordinates: never stored.
  • Presence record: deleted 30 days after the last update; anchor cell cleared after 24 hours.
  • Profile views (with your city): 30 days. Safety signals: up to 90 days.
  • Sign-in codes expire after 10 minutes.
  • Hash of an email refused by the age check: up to 90 days.
  • Profile, photo, settings, blocks and participation: until you delete your account or remove them.
  • Activities: text and photos of ended activities are kept for 24 months after the activity ends, unless they are deleted earlier with your account; after that only an aggregate record (city, category, date, counts) remains.
  • Reports about a member and their evidence snapshots: kept for safety, also after account deletion, for 12 months after the case is closed, or 36 months if the case is referred to an authority or under a legal hold.
  • Records of the approximate-sharing consent: kept as proof for the life of the account plus 36 months.
  • Records of your privacy requests: 36 months, as proof that we handled them.
  • Provider technical logs (for example IP addresses): only as long as the provider needs them to deliver and secure the service.
  • Backups: deleted data can remain in daily backups, which roll off within 7 days.

8. Your rights

Under KVKK Article 11 you may ask whether we process your data, learn the purpose and recipients, ask for access and a copy, have errors corrected, have data erased or destroyed, object to a result against you, and claim compensation for damage. Where the GDPR applies, you also have the rights of access, rectification, erasure, restriction, portability and objection, and you may withdraw consent at any time. You can edit your profile in the app and delete your account in Settings (see Delete your account).

To use a right, send an email to [email protected] from the email address of your account, or write to the postal address in section 1. We answer at the latest within 30 days (KVKK Article 13). We may need to check your identity first. A self-service data export is not built; we provide a copy of your data on request.

You may complain to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) or, where the GDPR applies, to the competent EU supervisory authority.

9. Children

GatherMiles is for people aged 18 and over. We check date of birth at sign-up, before collecting any other profile data. If you are under 18 your account is refused, and there is no parental-consent option. We keep only a salted hash of the email for up to 90 days so the same person cannot simply try again. If you believe a minor is using GatherMiles, report the profile in the app or see Safety.

10. Security

Sign-in uses one-time codes, and the app keeps your session in your phone’s secure storage. Access to data is limited by database rules, and the app never holds privileged keys. Logs are designed to leave out emails, dates of birth, coordinates and message text. No system is perfectly secure, so we cannot guarantee absolute security.

11. Changes

We will update this notice when our processing changes, especially before launching chat, trips, notifications, verification or premium features. The date at the top shows the latest version.