qrkarekodqrkarekod ana sayfa

Legal

Privacy Policy

How we protect your data and what we deliberately do not do.

Version 1.1Last updated: 25 Ağu 2026

The English text is for information only. In case of conflict the Turkish text prevails.

This English text is provided for information only. In the event of any inconsistency, the Turkish version prevails.

This policy summarises our approach to privacy. The detailed legal notice on personal data processing is in the KVKK Disclosure Notice.

1. Our principles

We do not store raw IP addresses. A salted one-way hash is used to distinguish unique visitors; the original address cannot be recovered from it.

We never see your card details. Card payments are handled entirely within the licensed payment institution's infrastructure. Card number, expiry and CVV never reach our systems.

We do not sell your data. Your personal data is never sold, rented or shared for marketing purposes.

No advertising trackers. There are no third-party ad pixels or behavioural trackers on the site.

Analytics stay on our own server. Usage statistics are kept on infrastructure we run; visitor data is not sent to an external analytics company.

2. Privacy of people who scan your codes

People scanning your QR codes are not our customers, and their privacy is our responsibility too. They are never identified; location is resolved to country and city only, never street level or device location; code owners see aggregate statistics only; and no device fingerprinting is performed.

3. Hosted content

Content you enter into hosted pages (digital menus, business cards, link pages) is public and remains your responsibility. Responses collected through the form template are shown only to the user who created the form; in that case the form owner is the data controller and is responsible for their own disclosure obligations.

4. Security measures

All traffic is encrypted with HTTPS and HSTS. Passwords are hashed with Argon2id. Two-factor authentication (TOTP) is supported. Access is role-based. Content Security Policy, XSS and clickjacking protections are in place. Uploaded files are checked and images reprocessed to strip embedded content. The database is backed up daily. Rate limiting protects against unauthorised access attempts.

5. Data breach

If personal data is unlawfully obtained by others, the Turkish Personal Data Protection Board is notified as soon as possible and within 72 hours under KVKK art. 12/5. Affected individuals are informed within the shortest reasonable time.

6. Children's privacy

The service is not directed at people under 18. If we learn we hold data belonging to someone under 18, we delete it. Report such cases to destek@qrkarekod.com.