Minfour Privacy Policy
1. Introduction
Minfour ("the App", "we", "us", "our") is a group meet-up and social friendship platform that takes your privacy seriously. This Privacy Policy explains what personal data we collect when you use the Minfour mobile application, how we process it, who we share it with, how long we retain it, and what rights you have.
This policy is designed to comply with the EU General Data Protection Regulation ("GDPR"), the Turkish Personal Data Protection Law ("KVKK", Law No. 6698), and the privacy requirements of Apple App Store and Google Play.
By downloading and using the App you confirm that you have read, understood and accepted the terms of this Policy.
2. Data We Collect
2.1 Account & Identity Data
- Phone number (required — verified via SMS)
- Email address (optional — for support and account recovery)
- Display name / username
- Date of birth / age (to enforce 17+ age restriction)
- Gender (optional)
2.2 Profile Data
- Profile photo(s)
- Bio text
- Interests / tags
- City or region
- Instagram username (optional, only if you link it)
- Occupation (optional)
2.3 Location Data
- Approximate location (city / district level)
- Precise location (only if you explicitly grant permission; used to rank nearby gatherings)
- The App requests location only while in use and never tracks you in the background.
2.4 Content Data
- Titles, descriptions, venue and time information of gatherings you create
- Messages and photos you send in group chats
- Ratings you give other users
- Reports and abuse complaints you submit
2.5 Device & Technical Data
- Device model, operating system version
- App version
- Language and time zone preferences
- IP address (only for security and fraud prevention)
- Push notification token (FCM / APNs)
- Crash reports and performance logs
2.6 Usage & Analytics Data
- Which screens you visit and for how long
- Tap, scroll and button interaction data
- Gathering join / cancel behaviour
- Such data is processed in aggregated, de-identified form.
2.7 Payment Data (Premium subscribers)
We never directly collect or store your credit card or banking details. All payments are processed by Apple App Store (StoreKit) and Google Play Billing. We only store metadata such as your subscription status, purchase date and subscription identifier.
3. Why We Process Your Data and Legal Basis
| Purpose | Data Used | GDPR Legal Basis |
|---|---|---|
| Account creation & authentication | Phone, name, age | Contract (Art. 6(1)(b)) |
| Discovering and joining gatherings | Location, profile, content | Contract |
| Messaging infrastructure | Content data | Contract |
| Sending notifications | Device token | Consent (Art. 6(1)(a)) |
| Age verification & safety | Date of birth | Legal obligation |
| Fraud prevention, abuse detection | IP, device, content | Legitimate interest (Art. 6(1)(f)) |
| Analytics and product improvement | Usage data | Consent |
| Premium subscription management | Purchase metadata | Contract |
| Responding to legal requests | All relevant data | Legal obligation |
4. Who We Share Data With
We do not sell your personal data. We share it only in the limited cases below.
4.1 Service Providers (Data Processors)
- Google Firebase (Google Ireland Ltd. / Google LLC) — Authentication, Firestore database, Cloud Storage, Cloud Messaging, Analytics, Crashlytics. Data may be processed in EU and US data centres under Standard Contractual Clauses (SCC).
- Apple Inc. — APNs (push notifications), App Store payment infrastructure.
- Google LLC — Google Play Services, Google Play Billing.
- SMS providers (via Firebase Auth) for phone number verification.
4.2 Other Users
Your name, photo, age, bio, interests and the gatherings you create are visible to other Minfour users. This is required for the core function of the App.
4.3 Legal Authorities
We may respond to lawful requests from courts, prosecutors and other competent public authorities.
4.4 Business Transfers
In the event of a sale, merger or acquisition, your data may be transferred to the acquirer, provided the same level of protection is maintained. We will notify you in advance.
5. International Data Transfers
Because our service providers operate globally, your data may be processed on servers located in the European Union and the United States. Such transfers are made:
- under your explicit consent (KVKK Art. 9), and
- under Standard Contractual Clauses and appropriate safeguards (GDPR Art. 46).
6. Data Retention
| Data Category | Retention Period |
|---|---|
| Active account data | While the account is active |
| Profile / content after deletion | Anonymised or deleted within 30 days |
| Chat history (your portion) | Deleted within 30 days of account deletion |
| Crash reports / logs | 90 days |
| Analytics (de-identified) | 14 months (Firebase default) |
| Records kept for legal compliance | As required by applicable law |
| Moderation / abuse records | 2 years |
7. Your Rights
Under GDPR Articles 15–22 (and analogous KVKK Art. 11) you have the right to:
- Be informed about the processing of your personal data
- Access your personal data
- Have inaccurate data rectified
- Have your data erased ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing (including automated processing)
- Withdraw consent at any time
- Lodge a complaint with your local data protection authority
How to Exercise Your Rights
- In-app: Profile → Settings → "Delete My Account" / "Download My Data".
- Email: raif@rekastudios.com — please include enough information to verify your identity.
- We will respond within 30 days.
8. Children's Privacy
Minfour is intended for users 17 years of age or older. The App is not directed at children. If we discover that a user below this age has created an account, we will close the account and delete the related data. Please contact raif@rekastudios.com if you believe a minor is using the App.
9. Security
- All traffic is encrypted with HTTPS / TLS 1.2+.
- Passwords and credentials are protected by Firebase Auth standards.
- We apply role-based access control and the principle of least privilege.
- Regular security audits and penetration tests are conducted.
- In the event of a data breach, affected users and authorities will be notified within 72 hours in line with GDPR Art. 33–34.
10. Cookies and Similar Technologies
Minfour is a mobile application and does not use traditional browser cookies. Instead, session and preference data is stored locally on your device using AsyncStorage. Uninstalling the App removes this local data.
11. Third-Party Links
When you tap an Instagram username on a profile, the link opens in the Instagram app or your browser, where the third party's privacy policy applies. Minfour is not responsible for the content or privacy practices of external sites.
12. Changes to This Policy
We may update this Policy from time to time. Significant changes will be announced through:
- in-app notification,
- email to your registered address (if any), and
- updating the "Last updated" date at the top of this page.
Continued use of the App after changes take effect constitutes acceptance of the updated Policy.
13. Contact
For any question, request or complaint regarding this Privacy Policy, our data practices or your rights:
Email: raif@rekastudios.com
Mail: Mithatpasa Mah. Bahcekoy Cad. No:55 B17 D:1, Cesmeler Vadisi Sitesi, Eyupsultan/Istanbul, Turkey
Data Controller: REKA YAZILIM TURIZM TICARET VE SANAYI A.S.
You are also free to lodge a complaint with the data protection authority of your country of residence.
This document is provided for information purposes and does not constitute legal advice.