Privacy Policy
Last updated: 8 August 2026 · Türkçe
This policy explains what data is collected when you use the Shelvo mobile app, what it is used for, how long it is kept, and how you can exercise your rights. It is written to meet the disclosure duty under Article 10 of Turkish Personal Data Protection Law No. 6698 (KVKK) and Articles 13–14 of the GDPR.
Data controller
The controller of the personal data covered by this policy is Çağlar Enes Sezgün (Istanbul, Türkiye).
How to reach us:
- Email: support@shelvo.app
- Registered Electronic Mail (KEP — Türkiye's registered electronic delivery system, for users in Türkiye): caglarenes.sezgun@hs03.kep.tr
Under the Turkish Data Protection Authority's Communiqué on the Procedures and Principles of Application to the Data Controller, you may submit your request through either channel above.
Shelvo is operated from Türkiye, and your data is stored on servers run by the providers listed below. If you are in the European Economic Area or the United Kingdom, we process your data under Article 3(2) of the GDPR. We have not appointed a representative under Article 27 of the GDPR; if you are in the EEA or the UK, contact us directly at the address above and we will handle your request under the same 30-day deadline.
What we collect
- Account details: email address, username, display name, profile and cover images, bio, country and currency preference.
- Your collection data: the records you add, quantities, notes, lists and the photos you upload. If you enter a purchase price or place of purchase, those are included too.
- Social data: who you follow, your likes, users you block, and reports you submit.
- Technical data: session cookie, the IP address and app/browser version (User-Agent) of the device you sign in from, and error logs. IP and device information is kept solely for session security, abuse prevention and fault diagnosis; it is never used for advertising or profiling.
- Usage measurement: which screens you open and when, app open/close events, and a small set of product events (searches, adding an item, photo uploads, sign-in attempts). Only if measurement is switched on — see "Usage analytics".
- If you sign in with Google: the authentication tokens Google passes to us. Your Google password never reaches us.
Why we process it
- To provide the service — creating your account, storing your collection, showing your lists and profile. Legal basis: performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6(1)(b)).
- Security and abuse prevention — session validation, rate limiting, reports and moderation records. Legal basis: our legitimate interest in keeping the service secure and preventing abuse (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)).
- Fault diagnosis and improvement — error logs. Legal basis: our legitimate interest in finding and fixing faults (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)).
- Understanding and improving how the app is used — usage analytics: which screens are opened, whether searches return results, how long common tasks take. Legal basis: your explicit consent (açık rıza under KVKK Art. 5/1; GDPR Art. 6(1)(a)). Measurement is off until you switch it on, and you can withdraw at any time from Settings. See "Usage analytics".
- Meeting legal obligations — notifying competent authorities upon request. Legal basis: legal obligation (KVKK Art. 5/2-ç; GDPR Art. 6(1)(c)).
- Contributing a photo to the catalog — only when you propose one. Legal basis: your consent (açık rıza under KVKK; GDPR Art. 6(1)(a)) — see "Contributing to the community catalog".
What we do not collect
We do not collect device location. EXIF data (including location) is stripped from the photos you upload on the server; when your photo is shown to others, that information is not in it. We do not use an Advertising ID and we do not send data to third-party ad networks. Your country is a preference you choose during onboarding, not a location measured from your device; deriving location from IP is switched off on analytics requests too. We can measure how the app is used — see "Usage analytics" below — but only if you switch it on, and that measurement never includes your name, email address, or the words you type into search.
Data only you can see
Purchase price, place of purchase and your private notes are visible only to you. They do not appear on your public profile, in the feed, or anywhere else other users can see.
Sign-in and authentication
You sign in with a one-time email link or a Google account. We do not store passwords. Your session is carried by a secure cookie held on your device.
Contributing to the community catalog
When you propose a photo for the community catalog and it is approved, that photo becomes a permanent part of the catalog and remains there even if you delete your account — because other collectors' records link to it. This is a separate permission you grant when you submit a catalog proposal; you are not required to propose catalog photos, and you can use the rest of the service without granting it. A photo kept in the catalog is not linked to your identity. If you want it removed, write to support@shelvo.app.
Sharing your data
We do not sell your data. We only use the providers the service needs to run:
- Cloudflare R2 — photo and image storage
- Resend — delivery of sign-in link emails
- Sentry — server-side error and diagnostic logs
- Google — authentication, only if you choose "Sign in with Google"
- Expo (Expo Push Service) — delivering notifications to your device, only if you allow notifications
- Google (Firebase Cloud Messaging) — delivery to Android devices, only if you allow notifications
- PostHog (EU Cloud, Germany) — usage analytics, only while measurement is switched on in Settings
These providers access the data solely to provide their service to us; they may not use it for their own purposes.
Notifications
If you do not allow notifications, none of the data in this section is processed. If you do, we store a notification identifier (push token) for your device and the platform (Android/iOS). This identifier points to your device, not to you; it contains no name, email or collection data.
Why: to send notifications only for events you chose — a series you follow gets a new piece, you are one piece away from completing a set, an event is coming up. We do not send advertising or marketing notifications.
To reach your device, the notification is relayed through Expo and from there through Google (Firebase Cloud Messaging); on iOS the Apple Push Notification service is used. These providers carry the notification and may not use it for their own purposes.
You can withdraw the permission at any time from your phone settings or the in-app Settings screen; when you do, your device identifier is deleted.
Usage analytics
To understand which parts of the app are useful and where people get stuck, we measure how the app is used. This is processed by PostHog on servers in Germany (EU Cloud).
What is measured:
- Screens you open and when — this is how we calculate time spent in the app
- App lifecycle: installed, opened, sent to the background, brought back
- Catalogue searches — the length of your query and how many results came back. The words you type are never sent.
- Adding an item: when you start, when you finish, and how long it took
- Photo uploads: whether they succeeded, how long they took, the file size
- Sign-in attempts and successes, and which method was used (email link or Google)
- Your randomly generated account ID once you are signed in, and a random device ID before that
- Your country and currency preference
- Device and app information — technical fields the measurement component attaches to every event automatically: app name, version and build number, device type, operating system, screen dimensions, library version, session ID, and your device's language and time zone setting. The time zone is read from your device setting; location is not derived from your IP address (see below).
What is never sent to analytics: your name, display name, username, email address, biography, phone number, passwords or session tokens, and the text of your searches. There is no session recording, no screen recording, and no Advertising ID. Your IP address is not stored alongside the measurement records, and deriving location from IP (GeoIP) is switched off — both settings are enabled on the app side and in the measurement provider's project settings.
Measurement is off by default. It only starts if you switch it on under Settings → Usage measurement, and you can switch it back off at any time. While it is off, nothing is sent from that device and no feature of the app is limited. The setting is stored on the device itself. Legal basis: your explicit consent (açık rıza under KVKK Art. 5/1; GDPR Art. 6(1)(a)).
International transfers
The servers of the providers above are located outside Türkiye. These transfers are made under KVKK Art. 9 and Chapter V of the GDPR, on the basis of standard contractual clauses (SCCs) and data processing agreements signed with those providers.
Moderation data
When you report content, your report, the reason you selected and any explanation you add are passed to the moderation team. Your identity is never disclosed to the user you reported. The report record includes a copy of the content as it was at the time of the report, so that the review can be carried out.
Retention periods
| Data | Period |
|---|---|
| Your account and collection data, your photos | For as long as your account is open |
| Notification identifier (push token) | Until you withdraw permission, uninstall the app, or sign out |
| Deleted account | Permanently erased with all its data 30 days after the deletion request |
| Session record (IP, device information) | For the duration of the session; deleted together with the account |
| Incomplete photo upload | Cleaned up automatically after 24 hours |
| Reports and moderation records | 2 years after the report is closed; if your account is deleted, the link to your identity is removed |
| Photos you contributed that were approved for the catalog | Indefinite, unless you ask us to remove it — part of the community catalog, not linked to your identity |
| Error and crash logs | 90 days (the retention period of our error tracking provider) |
| Usage analytics events | Held for at least 12 months, depending on our analytics provider's (PostHog) plan. Switching measurement off in Settings stops new records; you can request deletion of past records at destek@shelvo.app |
Your rights
Under KVKK Art. 11 and the GDPR you have the right to:
- Learn whether your personal data is processed, and request information if it is
- Learn the purpose of processing and whether it is used in line with that purpose
- Know the third parties, in Türkiye or abroad, to whom your data is transferred
- Request correction if it is processed incompletely or inaccurately
- Request erasure or destruction
- Request that corrections and erasures be notified to third parties the data was transferred to
- Object to an adverse outcome produced by analysis through automated systems
- Claim compensation if you suffer damage due to unlawful processing
- Object to processing and withdraw the consent you gave
- Ask us to restrict processing while a dispute about accuracy or lawfulness is resolved (GDPR Art. 18)
Send your requests to support@shelvo.app from the email address registered to your account. We conclude requests within 30 days at the latest.
Requesting a copy of your data (data portability)
If you want a machine-readable copy of your collection and account data, write to support@shelvo.app from the email address registered to your account; we will send it within 30 days (GDPR Art. 20).
Automated decision-making
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (GDPR Art. 22).
Your right to complain
If your request is refused, you find our answer inadequate, or you receive no answer in time, you may lodge a complaint with the Turkish Personal Data Protection Board (kvkk.gov.tr). If you live in the European Union, you may apply to the data protection authority of your country.
Data breach
If we determine that your personal data has been unlawfully obtained by others, we notify the Turkish Personal Data Protection Board within 72 hours, and, where the GDPR applies, the competent supervisory authority in the EEA within the same period (GDPR Art. 33). If the breach carries a high risk to your rights and freedoms, we also inform you without delay, in the app and by email.
Children's data
Where the law of your country sets a higher minimum age for using online services, that age applies. Shelvo is not directed at children under 13 and we do not knowingly collect data from that age group. You declare that you are over 13 when you register. If we determine that a user under 13 has opened an account, we close the account and delete its data. If you believe your child has given us data, write to support@shelvo.app; we will delete the data once we have verified the request.
Changes
This policy may be updated. You will be informed in the app of significant changes.
Controller contact: support@shelvo.app
Use this address for data requests, privacy questions and complaints.