Privacy Policy

Which of your data we process when you use Foodnomad, why, and your rights over that data.

Last updated: 1 October 2026

1. Scope and data controller

This policy covers the personal data processed when you use the www.foodnomad.app website and the Foodnomad mobile app. The data controller is Örnek Teknoloji Ltd. Şti. (Örnek Mah. Örnek Cad. No: 1 D: 1, 34000 Kadıköy/İstanbul).

Detailed information under Law No. 6698 on the Protection of Personal Data ("KVKK") is given in the KVKK Privacy Notice.

2. Data we collect

  • Account information: email address, an irreversible hash of your password, first name, last name, phone number (if you add one), profile photo (if you add one), language and notification preferences.
  • Social sign-in information: the name, email address and account ID that Google or Facebook share with us when you sign in with them.
  • Passkey information: your passkey's public key, its ID and the device name you give it. Your fingerprint or face data never leaves your device; we never have access to it.
  • Content you share: reviews, ratings, photos, your favourite venues and the feedback you send us.
  • Device and usage information: IP address, browser or device type, operating system, app version, session and sign-in records, and a device token for sending notifications.
  • Location: used only when you allow it on your device, in real time, to show venues near you; your location history is not stored in your account.
  • Error logs: technical details of errors that occur in the app or on the site.

3. How we use your data

  • To create your account, verify your sign-in and keep your account secure,
  • To show venues, routes and options near you, and to store your favourites and reviews,
  • To send email verification, password reset and security notifications,
  • To deliver the notifications you have allowed,
  • To prevent abuse, fake accounts and automated attacks,
  • To detect and fix errors and to improve the service,
  • To meet our legal obligations and respond to requests from the competent authorities.

We do not use your data for advertising profiles and we do not sell it to third parties.

4. Service providers we share data with

To run the Platform, we share data with the following service providers, only to the extent each service requires:

ProviderPurposeLocation
Hosting Dünyam Bilişim Teknolojileri Tic. Ltd. Şti.Hosting the application server and databaseTürkiye
NetGSM İletişim ve Bilgi Teknolojileri A.Ş.Sending SMS messages to verify phone numbersTürkiye
Cloudflare, Inc.Hosting and delivering the website, storing images and files, bot protection (Turnstile), forwarding incoming emailAbroad
Mailgun Technologies, Inc.Sending verification, password reset and informational emailsAbroad (EU)
Functional Software, Inc. (Sentry)Collecting and analysing error logsAbroad
650 Industries, Inc. (Expo)Delivering mobile notifications to your deviceAbroad
Google LLC, Meta Platforms, Inc.Authentication when you choose to sign in with these servicesAbroad

Apart from these, we share your data only with the competent public authorities and institutions when there is a legal obligation to do so.

5. International transfers

The database holding account and content data is located on servers in Türkiye. Transfers to the providers marked as abroad in the table above are made under Article 9 of KVKK: for countries without an adequacy decision, by entering into the standard contracts published by the Personal Data Protection Board and notifying the Board of these contracts within five business days of signing. For one-off operations that you initiate, such as social sign-in, the transfer takes place on an incidental basis under KVKK Art. 9/6.

6. Notifications and commercial electronic messages

Email verification, password reset, security and account notifications are part of the service and are not commercial electronic messages.

Commercial electronic messages containing campaigns, promotions or recommendations are sent only if you give your consent, under Law No. 6563 and the Regulation on Commercial Communication and Commercial Electronic Messages, and are recorded in the Message Management System (İYS). You can withdraw your consent at any time using the opt-out link in each message, from the notification settings in the app, or via iys.org.tr.

7. Cookies and local storage

The website uses only cookies and browser storage that are strictly necessary for the service to work; no advertising or analytics cookies are used. Under the Personal Data Protection Authority's Guide on Cookie Practices, explicit consent is not required for strictly necessary cookies; these cookies are processed under KVKK Art. 5/2-c and Art. 5/2-f.

NamePurposeDuration
access_token, refresh_tokenKeeping you signed in (readable only by the server)For the session, at most 24 hours
NEXT_LOCALERemembering the language you choseUntil you close the browser
foodnomad.theme (local storage)Remembering your light or dark theme preferenceUntil you delete it
foodnomadtr.mobile-auth-context (session storage)Returning you to the app after a sign-in opened from the appUntil you close the tab

The bot check on the sign-in and password reset forms is performed by Cloudflare Turnstile, inside Cloudflare's own frame.

8. Retention periods

We keep your account information for as long as your account is open. When you freeze your account, your data is kept so that you can reactivate it. When you delete your account, your personal data is deleted, destroyed or anonymised at the latest in the first periodic destruction cycle (6 months), in line with the Regulation on the Deletion, Destruction or Anonymisation of Personal Data.

Traffic data kept in our capacity as a hosting provider is stored for no less than 1 year and no more than 2 years, under Law No. 5651 and the Regulation on Hosting Providers. Statutory limitation periods and retention obligations are reserved.

9. Security

All connections are encrypted (HTTPS). Passwords are stored as irreversible hashes, session cookies cannot be read by scripts in the browser, and access to our systems is limited to authorised people.

If personal data is obtained by others through unlawful means, we notify the Board within 72 hours at the latest from the moment we learn of it, under KVKK Art. 12/5 and Personal Data Protection Board Decision No. 2019/10, and notify the affected users as soon as possible.

10. Your rights

Under Article 11 of KVKK, you have the right to learn whether your personal data is processed, to request information about it, to ask for it to be corrected, deleted or destroyed, and to object to its processing. Your rights and how to exercise them are explained in detail in the KVKK Privacy Notice.

You can edit most of your profile information yourself in the app, and delete your account from the app's settings.

11. Children's privacy

The Platform is not intended for people under 18; people under 18 may use the Platform only with the consent of their parent or guardian. If we find that we are processing a child's data without that consent, we delete it.

12. Changes

When we update this policy, we change the date at the top of the page; we also announce significant changes on the Platform or by email.

13. Contact

You can send privacy questions to support@foodnomad.app.