Gizlilik Politikası

Son güncelleme: 15 Mayıs 2026 · Yürürlük tarihi: Yayın tarihi · Sürüm 1.0

Bu Gizlilik Politikası TipsWall mobil uygulaması (com.tipswall.app) ve api.tipswall.com arka uç servisi tarafından işlenen kişisel verileri ve verinin nasıl kullanıldığını açıklar. Hizmeti kullanarak bu politikayı kabul etmiş sayılırsın.

Veri sorumlusu: Ethem Serce · İletişim: ethemserce@gmail.com

1. Hangi verileri topluyoruz?

VeriAmaçHukuki dayanakSaklama
E-posta, kullanıcı adı, parolanın hash'iHesap oluşturma, giriş, parola sıfırlamaKVKK m.5/2(c) — sözleşmenin kurulmasıHesap silinene kadar
Apple / Google sign-in JWT'sinden gelen sub kimliği ve doğrulanmış e-postaSosyal medya hesabıyla girişKVKK m.5/2(c) — sözleşmenin kurulması; ilgili sağlayıcı şartlarına tâbiHesap silinene kadar
Cihaz UUID'si (sadece üye olmadan kullanan ziyaretçiler için)Günlük tahmin kotasını uygulamakKVKK m.5/2(f) — meşru menfaat90 gün
JWT erişim + yenileme jetonlarıOturum yönetimiKVKK m.5/2(c) — sözleşmenin kurulmasıRefresh: 30 gün; access: 1 saat
Cihaz dilini gösteren tercih, tema seçimi, oran gizleme bayrağıUygulamayı kullanıcı tercihine göre çalıştırmaKVKK m.5/2(f) — meşru menfaatCihazda yerel — sunucuya iletilmez
Anonim kullanım olayları (ekran açılışı, butona tıklama)Uygulamayı iyileştirmeKVKK m.5/1 — açık rıza (uygulama içinde toggle)Firebase varsayılan: 14 ay
Hata izleri (stack trace, anonim cihaz modeli, OS sürümü)Çökme ve hata teşhisiKVKK m.5/2(f) — meşru menfaatSentry varsayılan: 90 gün
Sunucu istek kayıtları (IP adresi, User-Agent, istek yolu, durum kodu)Güvenlik, kötüye kullanım engelleme, hata tespitiKVKK m.5/2(f) — meşru menfaat30 gün

Toplamadıklarımız: hassas kişisel veri (ırk, din, sağlık, biyometri), tam ad, doğum tarihi, telefon numarası, fiziksel konum (GPS / IP konum), kişi rehberi, fotoğraf rulosu, herhangi bir finansal/ödeme verisi.

2. Reklam ve takip

TipsWall hiçbir reklam ağı kullanmaz, üçüncü taraflarla pazarlama amacıyla veri paylaşmaz, kişiselleştirilmiş reklam yayınlamaz. Cihazın reklam kimliğini (Android Advertising ID / IDFA) okumaz.

3. Analitik (isteğe bağlı)

Uygulamayı geliştirmek için Firebase Analytics (Google LLC) aracılığıyla anonim kullanım istatistikleri topluyoruz. Bu özellik varsayılan olarak kapalıdır; ilk açılışta gösterilen onay penceresinde "Kabul ediyorum"u seçmen halinde etkinleşir. İstediğin zaman Ayarlar → Kullanım verisi paylaş üzerinden kapatabilirsin. Toplanan veriler hesabınla doğrudan ilişkilendirilmez. Firebase'in kendi gizlilik bildirimi: firebase.google.com/support/privacy.

4. Hata raporlama

Beklenmeyen hataları teşhis etmek için Sentry (Functional Software Inc.) kullanılır. Stack trace ile birlikte anonim cihaz modeli ve işletim sistemi sürümü gönderilir. Sentry varsayılan PII kaldırma kuralları etkindir; e-posta, kullanıcı adı veya IP adresi gönderilmez.

5. Üçüncü taraf işleyiciler

İşleyiciRolKonum
Google LLC (Firebase Analytics, Authentication)Analitik, isteğe bağlı; sosyal giriş için ID jetonu doğrulamaABD
Apple Inc. (Sign in with Apple)Sosyal giriş için ID jetonu doğrulamaABD
Functional Software Inc. (Sentry)Hata izlemeABD
SportMonks BVSpor verisi (maç, lig, oyuncu, oran). Bu sağlayıcıya senin kişisel verin gönderilmez.Hollanda
GoDaddy / HetznerSunucu barındırmaAB veya ABD

6. Veri aktarımları

Sunucularımız AB içinde bulunabilir. Analitik ve hata raporlama hizmetleri, sağlayıcının altyapısı gereği ABD'ye veri aktarımı içerebilir. Aktarımlar KVKK m.9 ve ilgili sağlayıcının Standart Sözleşme Maddeleri'ne dayanır.

7. Haklarınız (KVKK madde 11)

Veri sorumlusuna başvurarak şu haklarını kullanabilirsin:

Talebini ethemserce@gmail.com adresine yazarak iletebilirsin. Hesabını uygulama içinden Ayarlar → Hesabı sil ile her zaman silebilirsin; talep 30 gün içinde donanım dahil tüm yedeklerden temizlenir.

8. Çocukların gizliliği

TipsWall 18 yaşından küçükler için tasarlanmamıştır. Bu kapsamda çocuklardan bilerek kişisel veri toplamayız. Bir çocuğun bize veri gönderdiğini fark edersek hesabı sileriz.

9. Güvenlik

Parolalar Bcrypt ile hash'lenerek saklanır. Sunucu trafiği uçtan uca TLS (Let's Encrypt) ile şifrelidir. Erişim jetonları (JWT) HMAC-SHA256 imzalıdır ve 1 saat ömürlüdür. Veri tabanı yedekleri günlük olarak alınır ve yalnızca veri sorumlusu tarafından erişilebilir.

10. Bu politikadaki değişiklikler

Bu metin güncellendiğinde uygulamada görünür şekilde duyurulur ve "Son güncelleme" tarihi değiştirilir.

11. İletişim

Sorular ve KVKK talepleri için: ethemserce@gmail.com


Privacy Policy

Last updated: 15 May 2026 · Effective: Publication date · Version 1.0

This Privacy Policy explains what personal data the TipsWall mobile app (com.tipswall.app) and the api.tipswall.com backend collects and how that data is used. By using the service you agree to this policy.

Data controller: Ethem Serce · Contact: ethemserce@gmail.com

1. What data do we collect?

DataPurposeLegal basisRetention
Email, username, password hashAccount creation, sign-in, password resetContract performance (KVKK 5/2(c); GDPR 6(1)(b))Until account deletion
Apple / Google sign-in subject id + verified emailSocial sign-inContract performance; subject to provider termsUntil account deletion
Device UUID (guest users only)Daily prediction quota enforcementLegitimate interest (KVKK 5/2(f); GDPR 6(1)(f))90 days
JWT access + refresh tokensSession managementContract performanceRefresh: 30 days; access: 1 hour
Theme, language, hide-odds preferencePersonalisationLegitimate interestLocal on device — not sent to server
Anonymous usage events (screen views, taps)Improving the appExplicit consent (in-app toggle)Firebase default: 14 months
Error traces (stack, anonymous device model, OS version)Crash diagnosisLegitimate interestSentry default: 90 days
Server request logs (IP, User-Agent, path, status code)Security, abuse prevention, debuggingLegitimate interest30 days

What we do NOT collect: sensitive personal data (race, religion, health, biometrics), full name, date of birth, phone number, precise location (GPS / IP geolocation), contacts, photo roll, any financial or payment data.

2. Advertising and tracking

TipsWall does not use ad networks, does not share data with third parties for marketing, and does not display personalised ads. The app does not read the device advertising id (AAID / IDFA).

3. Analytics (opt-in)

To improve the app we collect anonymous usage statistics via Firebase Analytics (Google LLC). This feature is off by default; it is enabled only if you tap "I accept" on the consent prompt shown at first launch. You can turn it off any time from Settings → Share usage data. The data collected is not directly linked to your account. Firebase's own privacy notice: firebase.google.com/support/privacy.

4. Error reporting

We use Sentry (Functional Software Inc.) to diagnose unexpected errors. Stack traces are sent together with the anonymous device model and OS version. Sentry's default PII scrubbing rules are enabled; email, username and IP address are not transmitted.

5. Third-party processors

ProcessorRoleLocation
Google LLC (Firebase Analytics, Authentication)Analytics (opt-in); ID token verification for social sign-inUSA
Apple Inc. (Sign in with Apple)ID token verification for social sign-inUSA
Functional Software Inc. (Sentry)Error trackingUSA
SportMonks BVSports data (matches, leagues, players, odds). Your personal data is not sent to this provider.Netherlands
GoDaddy / HetznerServer hostingEU or USA

6. International transfers

Our servers may be hosted in the EU. Analytics and error reporting providers process data in the USA. Transfers rely on the relevant provider's Standard Contractual Clauses and the KVKK Article 9 framework.

7. Your rights

You can ask the data controller to:

Send requests to ethemserce@gmail.com. You can also delete your account at any time from Settings → Delete account; the request is purged within 30 days from all backups.

8. Children's privacy

TipsWall is not designed for users under 18 and we do not knowingly collect personal data from children. If we discover that a child has submitted data, we delete the account.

9. Security

Passwords are stored using Bcrypt hashing. All traffic to the server is encrypted in transit (TLS via Let's Encrypt). Access tokens (JWT) are HMAC-SHA256 signed and live for one hour. Database backups are taken daily and accessible only to the data controller.

10. Changes to this policy

Material changes are announced inside the app and the "Last updated" date above is changed.

11. Contact

Questions or KVKK requests: ethemserce@gmail.com