Shelvo

Privacy Policy

Last updated: 8 August 2026 · Türkçe

This policy explains what data is collected when you use the Shelvo mobile app, what it is used for, how long it is kept, and how you can exercise your rights. It is written to meet the disclosure duty under Article 10 of Turkish Personal Data Protection Law No. 6698 (KVKK) and Articles 13–14 of the GDPR.

Data controller

The controller of the personal data covered by this policy is Çağlar Enes Sezgün (Istanbul, Türkiye).

How to reach us:

Under the Turkish Data Protection Authority's Communiqué on the Procedures and Principles of Application to the Data Controller, you may submit your request through either channel above.

Shelvo is operated from Türkiye, and your data is stored on servers run by the providers listed below. If you are in the European Economic Area or the United Kingdom, we process your data under Article 3(2) of the GDPR. We have not appointed a representative under Article 27 of the GDPR; if you are in the EEA or the UK, contact us directly at the address above and we will handle your request under the same 30-day deadline.

What we collect

Why we process it

What we do not collect

We do not collect device location. EXIF data (including location) is stripped from the photos you upload on the server; when your photo is shown to others, that information is not in it. We do not use an Advertising ID and we do not send data to third-party ad networks. Your country is a preference you choose during onboarding, not a location measured from your device; deriving location from IP is switched off on analytics requests too. We can measure how the app is used — see "Usage analytics" below — but only if you switch it on, and that measurement never includes your name, email address, or the words you type into search.

Data only you can see

Purchase price, place of purchase and your private notes are visible only to you. They do not appear on your public profile, in the feed, or anywhere else other users can see.

Sign-in and authentication

You sign in with a one-time email link or a Google account. We do not store passwords. Your session is carried by a secure cookie held on your device.

Contributing to the community catalog

When you propose a photo for the community catalog and it is approved, that photo becomes a permanent part of the catalog and remains there even if you delete your account — because other collectors' records link to it. This is a separate permission you grant when you submit a catalog proposal; you are not required to propose catalog photos, and you can use the rest of the service without granting it. A photo kept in the catalog is not linked to your identity. If you want it removed, write to support@shelvo.app.

Sharing your data

We do not sell your data. We only use the providers the service needs to run:

These providers access the data solely to provide their service to us; they may not use it for their own purposes.

Notifications

If you do not allow notifications, none of the data in this section is processed. If you do, we store a notification identifier (push token) for your device and the platform (Android/iOS). This identifier points to your device, not to you; it contains no name, email or collection data.

Why: to send notifications only for events you chose — a series you follow gets a new piece, you are one piece away from completing a set, an event is coming up. We do not send advertising or marketing notifications.

To reach your device, the notification is relayed through Expo and from there through Google (Firebase Cloud Messaging); on iOS the Apple Push Notification service is used. These providers carry the notification and may not use it for their own purposes.

You can withdraw the permission at any time from your phone settings or the in-app Settings screen; when you do, your device identifier is deleted.

Usage analytics

To understand which parts of the app are useful and where people get stuck, we measure how the app is used. This is processed by PostHog on servers in Germany (EU Cloud).

What is measured:

What is never sent to analytics: your name, display name, username, email address, biography, phone number, passwords or session tokens, and the text of your searches. There is no session recording, no screen recording, and no Advertising ID. Your IP address is not stored alongside the measurement records, and deriving location from IP (GeoIP) is switched off — both settings are enabled on the app side and in the measurement provider's project settings.

Measurement is off by default. It only starts if you switch it on under Settings → Usage measurement, and you can switch it back off at any time. While it is off, nothing is sent from that device and no feature of the app is limited. The setting is stored on the device itself. Legal basis: your explicit consent (açık rıza under KVKK Art. 5/1; GDPR Art. 6(1)(a)).

International transfers

The servers of the providers above are located outside Türkiye. These transfers are made under KVKK Art. 9 and Chapter V of the GDPR, on the basis of standard contractual clauses (SCCs) and data processing agreements signed with those providers.

Moderation data

When you report content, your report, the reason you selected and any explanation you add are passed to the moderation team. Your identity is never disclosed to the user you reported. The report record includes a copy of the content as it was at the time of the report, so that the review can be carried out.

Retention periods

DataPeriod
Your account and collection data, your photosFor as long as your account is open
Notification identifier (push token)Until you withdraw permission, uninstall the app, or sign out
Deleted accountPermanently erased with all its data 30 days after the deletion request
Session record (IP, device information)For the duration of the session; deleted together with the account
Incomplete photo uploadCleaned up automatically after 24 hours
Reports and moderation records2 years after the report is closed; if your account is deleted, the link to your identity is removed
Photos you contributed that were approved for the catalogIndefinite, unless you ask us to remove it — part of the community catalog, not linked to your identity
Error and crash logs90 days (the retention period of our error tracking provider)
Usage analytics eventsHeld for at least 12 months, depending on our analytics provider's (PostHog) plan. Switching measurement off in Settings stops new records; you can request deletion of past records at destek@shelvo.app

Your rights

Under KVKK Art. 11 and the GDPR you have the right to:

Send your requests to support@shelvo.app from the email address registered to your account. We conclude requests within 30 days at the latest.

Requesting a copy of your data (data portability)

If you want a machine-readable copy of your collection and account data, write to support@shelvo.app from the email address registered to your account; we will send it within 30 days (GDPR Art. 20).

Automated decision-making

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (GDPR Art. 22).

Your right to complain

If your request is refused, you find our answer inadequate, or you receive no answer in time, you may lodge a complaint with the Turkish Personal Data Protection Board (kvkk.gov.tr). If you live in the European Union, you may apply to the data protection authority of your country.

Data breach

If we determine that your personal data has been unlawfully obtained by others, we notify the Turkish Personal Data Protection Board within 72 hours, and, where the GDPR applies, the competent supervisory authority in the EEA within the same period (GDPR Art. 33). If the breach carries a high risk to your rights and freedoms, we also inform you without delay, in the app and by email.

Children's data

Where the law of your country sets a higher minimum age for using online services, that age applies. Shelvo is not directed at children under 13 and we do not knowingly collect data from that age group. You declare that you are over 13 when you register. If we determine that a user under 13 has opened an account, we close the account and delete its data. If you believe your child has given us data, write to support@shelvo.app; we will delete the data once we have verified the request.

Changes

This policy may be updated. You will be informed in the app of significant changes.

Controller contact: support@shelvo.app
Use this address for data requests, privacy questions and complaints.