Privacy Policy
Merilin Yemek – PRIVACY POLICY & KVKK NOTICE
Version: 1.2.1 | Effective: 2 Haziran 2026
This notice is provided under Turkey’s Personal Data Protection Law No. 6698 (KVKK) for personal data processed through the Merilin Yemek mobile app and related services (“Platform”).
1. DATA CONTROLLER
Individual tax resident operating the Merilin Yemek brand at İzmir, Türkiye (not an incorporated legal entity).
Privacy: kvkk@merilinapp.com | Support: support@merilinapp.com | Web: https://merilinapp.com
2. SCOPE
Covers buyer discovery, seller accounts, support, notifications, analytics, and ads where enabled. The Platform is informational only; visits, payments, and communications between buyers and businesses occur outside the Platform.
3. DATA CATEGORIES
Buyers: device/OS/app version, session/device identifiers, FCM token, language, location (with permission), saved addresses, favorites, alerts, radar radius, map interaction logs, crash logs, ad interaction summaries (if applicable).
Sellers: email, shop profile, phone, address, coordinates, listings, verification data (national/tax IDs, tax office, birth year, MERSIS), social links, session/IP/device data.
Common: support/abuse records, security logs, legal dispute records.
We do not aim to process special-category data except where legally required for seller verification.
4. PURPOSES AND LEGAL BASES
Account/OTP/session – contract (KVKK Art. 5/2-c).
Map discovery/distance – legitimate interest and/or consent.
Favorites/alerts/addresses – contract / legitimate interest.
Shop management/verification – contract and legal obligation.
Operational push – contract / legitimate interest.
Marketing push – explicit separate consent only.
Security/fraud – legitimate interest.
Analytics/debugging – legitimate interest.
Advertising (if enabled) – legitimate interest and/or consent per device settings.
Legal retention – legal obligation.
5. COLLECTION
App forms, device permissions, automated logs, API calls, and support channels.
6. RECIPIENTS, PROCESSORS, AND CROSS-BORDER TRANSFERS
Cloud hosting, email/OTP, Firebase/FCM, map/geocoding (TomTom), analytics, ad networks (Google AdMob if enabled), and error monitoring may process limited data under contractual safeguards. Some providers are independent controllers with their own policies. Cross-border transfers follow KVKK Art. 9 safeguards. Disclosures to authorities only when legally required.
7. ADVERTISING AND ANALYTICS
Third-party ad SDKs may process device/ad identifiers. Personalized ads can be managed in OS/ad settings. Analytics are used for service quality and security; data is not sold for marketing profiles.
8. AUTOMATED PROCESSING
Distance-based sorting and similar technical processing serve the app only; no legal-effect profiling or discrimination.
9. RETENTION
Account data while active plus statutory periods. Verification records per tax/commercial law (typically ≥10 years). Security logs ~2 years. Support ~3 years after closure. Marketing until consent withdrawn.
10. SECURITY
Access controls, TLS, secure sessions, least privilege, monitoring. No absolute security guarantee on the internet; reasonable measures are applied.
11. YOUR RIGHTS (KVKK Art. 11)
Access, rectification, erasure, learn recipients, object to automated processing, and claim damages where applicable.
12. REQUESTS
Email kvkk@merilinapp.com with identity verification. Response within 30 days.
13. CONSENT
Marketing and permission-based features require separate consent, withdrawable in app settings or via kvkk@merilinapp.com. Operational notifications may remain necessary for service delivery.
14. CHILDREN AND AGE DECLARATION
14.1. The Platform is not directed at users under 18; we do not knowingly collect personal data from anyone under 18.
14.2. By using the service, you declare that you are at least 18 years old; we do not perform separate identity or age verification.
14.3. If underage use is reported or discovered, access is terminated, processing stops, and data is deleted or anonymized where applicable.
14.4. We do not target advertising or profiling at users under 18.
15. LIMITATION OF LIABILITY
Subject to mandatory law, we are not liable for third-party processor breaches beyond our contractual diligence, user device security failures, or data shared outside the Platform. The Platform is provided “as is” without uninterrupted or error-free processing guarantees.
16. CHANGES
We may update this policy; the current version is available in-app and at https://merilinapp.com. Material changes may require renewed acceptance.
17. CONTACT
kvkk@merilinapp.com | support@merilinapp.com | İzmir, Türkiye