Personal Data Disclosure Notice
How your personal data are processed, under Article 10 of Law No. 6698 and the Communiqué on the Procedures for Fulfilling the Disclosure Obligation.
Last updated: 1 October 2026
This is an English rendering provided for convenience. The seller is established in Türkiye, the contract is governed by Turkish law, and in the event of any discrepancy the Turkish text prevails.
1. Data controller
The controller of the personal data covered by this notice is the natural person whose identity and contact details are set out below (Article 4/1-a of the Communiqué on the Procedures and Principles for Fulfilling the Disclosure Obligation).
- Trade name
- Meriç Değirmencioğlu
- Status
- Sole proprietor (natural person, registered for tax)
- Brand
- GeoSpy AI
- Website
- geospys.com
- Tax office
- Akhisar Vergi Dairesi
- Tax identification number
- 2731091902
- Registered address
- Hacı İshak Mahallesi, 150. Sokak No: 52 Daire: 8, Akhisar / Manisa
- Telephone
- 0541 945 92 87
- meric1357@icloud.com
- Payments and refunds
- meric1357@icloud.com
- Data protection requests
- meric1357@icloud.com
- Contractual notices
- meric1357@icloud.com
2. Data processed and how they are collected
Your personal data are obtained through geospys.com and through our iOS applications, by wholly or partly automated means, either because you provide them directly or because they arise from your use of the service (Article 5/1-i of the Communiqué).
- Identity and contact data: your name, surname and email address when you sign in with a Google account.
- Transaction security data: your IP address and a device fingerprint derived from characteristics your browser already reports. The fingerprint is a one-way digest; it is not a MAC address or a hardware serial number, and browsers do not make those available to websites in any case.
- Usage data: the number and time of the analyses you run, the rounds you were shown in the game, your guesses and your scores.
- Image data: the photograph you upload for analysis. It is held in memory only for the duration of the request; it is not written to disk, not written to a log and not stored in a database.
- Customer transaction data: when you make a purchase, the payment and order records — the order number, the plan, the amount and currency, the date and time of the order and of your approvals at the payment step, the status of the payment, the bank’s authorisation code and reference number, the last four digits of your card, and your email address and IP address — and, for a subscription, also the renewal payments the bank takes, the status of the subscription and the date on which it is cancelled or ends.
- Records of paid use and order evidence: for an account with a subscription, each photo analysis (its date and time, your IP address and the device fingerprint) and each Street View game session (its date and time, your IP address, browser/user-agent information and the approximate country derived from the IP address); and, for each order, the time of the order, the amount, the result of the 3D Secure verification, your IP address at the time of the order, and the time and text version of the approvals you gave.
- Traffic data: the pages you open on the site and when, the domain of the site that referred you, your IP address, the user-agent string your browser sends and the device type, operating system and browser derived from it, the approximate location (country, region, city) derived from your connection, and the network your IP address belongs to (internet service provider or data centre).
- Purchase-funnel data: when you open the checkout page or press the pay button, and when the app-offer window is shown to you, when you click its App Store link and when you close it — the type of event, its time, the page, your country, your device type, your IP address and browser information and, if you are signed in, your account id.
Payment card details are not collected by the Seller. You type them into the card form on the site’s checkout page, but they are sent from your browser directly to the payment system of Türkiye Garanti Bankası A.Ş. and never pass through or are stored on the Seller’s servers. So that the renewal payments can be taken, the bank keeps the card on its recurring-payment record; the Seller does not. From the bank the Seller receives only the result of the payment, the authorisation code, the bank reference number and the last four digits of the card.
3. Purposes of processing and their legal grounds
Your data are processed for the purposes below, relying for each purpose on the legal ground of Article 5 of Law No. 6698 shown against it (Article 5/1-h of the Communiqué):
- Providing the service, creating your account, keeping the access you bought active on it, and informing you by e-mail about your order and your subscription — Article 5/2-c: directly related to the conclusion or performance of a contract.
- Enforcing the free-usage limit and preventing abuse — Article 5/2-f: the legitimate interests of the controller.
- Analysing the photograph with an AI model to produce a location estimate — Article 5/2-c: performance of the contract (this is the service you asked for).
- Collecting the subscription payments — the first payment and the renewals — and keeping the payment and order records needed to perform the contract and prove it — Article 5/2-c: directly related to the conclusion or performance of a contract, and Article 5/2-ç: compliance with a legal obligation.
- Deciding refund requests (including whether the service has been used since the payment concerned), answering payment disputes (chargebacks) and showing that the paid service was provided, including, in such a case, by sending the records of paid use and the order evidence to the bank that processed the payment — Article 5/2-e: processing is necessary for the establishment, exercise or protection of a right; and, where it concerns the performance of the contract, Article 5/2-c.
- Invoicing and refunds, and the accounting and retention obligations arising from tax legislation — Article 5/2-a: expressly provided for by law, and Article 5/2-ç: compliance with a legal obligation.
- Responding to your requests and complaints, and the establishment and protection of rights in disputes — Article 5/2-e.
- Producing aggregate statistics about use of the site and distinguishing real visitors from automated traffic — Article 5/2-f: legitimate interests.
- Measuring, from the purchase-funnel data, at which step buyers leave the checkout and whether the app offer helps — Article 5/2-f: legitimate interests.
The processing above rests on the legal grounds shown against each item, not on explicit consent. The exception is the measurement cookies: the Personal Data Protection Authority’s Guidelines on Cookie Practices require explicit consent for those, a consent mechanism is being prepared, and until it is in place they can be blocked from your browser settings — the Cookie Policy explains how. If any other processing requiring explicit consent is introduced, that consent will be sought separately from and independently of this notice (Article 5/1-f of the Communiqué).
4. Transfers, including transfers abroad
Your personal data are transferred to the recipient groups below, for the purposes shown against each, so that the service can be provided (Article 5/1-ı of the Communiqué). The bank and the public authorities are in Türkiye; the servers of the other providers are located outside Türkiye, so transfers to them are transfers abroad within the meaning of Article 9 of Law No. 6698:
- Hosting provider (Vercel Inc., United States): running the site and its server functions.
- Database provider (Supabase, Inc., United States; servers in Frankfurt, Germany): storing account, usage, transaction-security, traffic, purchase-funnel and order records.
- E-mail provider (Apple Inc., United States — iCloud Mail): the correspondence you send to our e-mail addresses, and the e-mails sent to you after a purchase — the order confirmation (order details, amount, last four digits of the card, and the contract texts) and, for a subscription, the renewal, cancellation and end notices.
- AI provider (Google LLC — Gemini, United States): analysing the photograph and producing the location estimate. The photograph is transferred only for the duration of the analysis.
- Authentication provider (Google LLC — OAuth 2.0, United States): allowing you to sign in to your account.
- Map provider (Google Maps Platform, United States): displaying Street View panoramas, on the game page only.
- Map tile providers (OpenStreetMap Foundation, United Kingdom; Esri, United States): drawing the world map you drop your guess on, in the game only.
- Measurement providers (Google LLC — Google Analytics, United States; Meta Platforms, Inc. — Meta Pixel, United States): measuring site traffic and advertising performance. The cookies these set, and how to block them, are described in the Cookie Policy.
- Payment institution (Türkiye Garanti Bankası A.Ş., Türkiye): carrying out the card payments — the first payment, verified with 3D Secure, and the renewal payments — and examining refund requests and payment disputes. With the payment the bank receives the order number, the amount, your email address and your IP address; the card details reach it directly from your browser, and the bank keeps the card on its recurring-payment record in order to take the renewals. In a refund request or payment dispute, the records of paid use and the order evidence may be sent to the bank and, through it, to the card scheme concerned (Visa, Mastercard or troy). The transfer to the bank is a transfer within Türkiye under Article 8 of Law No. 6698, relying on Article 5/2-c and, in a dispute, Article 5/2-e; it is not a transfer abroad.
- Competent public authorities: in the cases and within the limits laid down by law.
Transfers abroad are made within the framework of Article 9 of Law No. 6698 and only to the extent necessary for the service in question to be provided. For each provider, the data transferred are limited to what that service requires.
The card details themselves are not transferred by the Seller: they go from your browser directly to the bank and are never in the Seller’s possession.
5. Retention periods
Data are retained for as long as is necessary for the purpose for which they were processed, and at the end of that period are erased, destroyed or anonymised:
- Account data: for as long as your account exists. Deleted when you delete your account.
- Photograph uploaded for analysis: for the duration of a single request, a matter of seconds. Not retained.
- IP address and device fingerprint: for as long as the account exists, so that the free-usage limit can be enforced; deleted together with the account.
- Game records: ninety days, so that the daily limit can be enforced.
- Traffic data: the IP address, user-agent string, city and region for ninety days, after which they are erased; the remaining page counts are kept as statistics that do not identify anyone.
- Purchase-funnel data: the IP address, browser information and the link to your account for ninety days, after which they are erased (the account link at once if you delete the account); the rest of the record is kept as statistics that do not identify anyone.
- Order, payment and subscription records: three years under Article 20 of the Distance Contracts Regulation; the retention periods arising from tax and commercial legislation are reserved.
- Records of paid use and order evidence: for as long as the payment concerned can be disputed under card-scheme rules, counted from that payment, separately from the periods above. When an account is deleted, a summary of each subscription’s use — the number of uses, the first and last use, and the list of uses with their date, time and IP address — is kept with the subscription record for the same purpose and the same period.
6. Your rights as a data subject
Under Article 11 of Law No. 6698 you may apply to the data controller to exercise the following rights:
- To learn whether your personal data are being processed.
- To request information if your personal data have been processed.
- To learn the purpose of processing and whether the data are used in accordance with that purpose.
- To know the third parties in Türkiye or abroad to whom the data are transferred.
- To request correction of data that have been processed incompletely or inaccurately.
- To request erasure or destruction of the data under the conditions of Article 7 of the Law.
- To request that corrections, erasures and destructions be notified to the third parties to whom the data were transferred.
- To object to a result adverse to you arising from analysis of the data exclusively by automated systems.
- To claim compensation for damage suffered as a result of unlawful processing.
7. How to apply
You may submit applications by the routes below, under Article 13 of Law No. 6698 and the Communiqué on the Procedures and Principles of Application to the Data Controller. An application must contain your name and surname, a signature or secure electronic signature, your Turkish identity number if you are a Turkish citizen, an address for service and the subject of your request.
- In writing, by a signed letter sent to the registered address: Hacı İshak Mahallesi, 150. Sokak No: 52 Daire: 8, Akhisar / Manisa
- From the email address registered in our systems, to meric1357@icloud.com
Your application is concluded free of charge as soon as possible and in any event within thirty days, depending on the nature of the request. If the process incurs a separate cost, the fee in the tariff set by the Board may be charged. If your application is refused, you may lodge a complaint with the Personal Data Protection Board.