Legal
Privacy Policy
How we protect your data and what we deliberately do not do.
The English text is for information only. In case of conflict the Turkish text prevails.
This English text is provided for information only. In the event of any inconsistency, the Turkish version prevails.
This policy summarises our approach to privacy. The detailed legal notice on personal data processing is in the KVKK Disclosure Notice.
1. Our principles
We do not store raw IP addresses. A salted one-way hash is used to distinguish unique visitors; the original address cannot be recovered from it.
We never see your card details. Card payments are handled entirely within the licensed payment institution's infrastructure. Card number, expiry and CVV never reach our systems.
We do not sell your data. Your personal data is never sold, rented or shared for marketing purposes.
No advertising trackers. There are no third-party ad pixels or behavioural trackers on the site.
Analytics stay on our own server. Usage statistics are kept on infrastructure we run; visitor data is not sent to an external analytics company.
2. Privacy of people who scan your codes
People scanning your QR codes are not our customers, and their privacy is our responsibility too. They are never identified; location is resolved to country and city only, never street level or device location; code owners see aggregate statistics only; and no device fingerprinting is performed.
3. Hosted content
Content you enter into hosted pages (digital menus, business cards, link pages) is public and remains your responsibility. Responses collected through the form template are shown only to the user who created the form; in that case the form owner is the data controller and is responsible for their own disclosure obligations.
4. Security measures
All traffic is encrypted with HTTPS and HSTS. Passwords are hashed with Argon2id. Two-factor authentication (TOTP) is supported. Access is role-based. Content Security Policy, XSS and clickjacking protections are in place. Uploaded files are checked and images reprocessed to strip embedded content. The database is backed up daily. Rate limiting protects against unauthorised access attempts.
5. Data breach
If personal data is unlawfully obtained by others, the Turkish Personal Data Protection Board is notified as soon as possible and within 72 hours under KVKK art. 12/5. Affected individuals are informed within the shortest reasonable time.
6. Children's privacy
The service is not directed at people under 18. If we learn we hold data belonging to someone under 18, we delete it. Report such cases to destek@qrkarekod.com.