Privacy Policy

Clear, honest explanation of how your data is collected, used, and protected.

Effective date: 14 Nisan 2026

Version: 3.0

If there is a conflict between the Turkish and English versions, the Turkish text prevails.

1. Data Controller Identity

The data controller for services offered under the Radarlo brand is the following legal entity:

Legal Name

Radarlo (legal entity details being finalized)

Brand

radarlo.com

Registered Address

Istanbul, Türkiye

Tax / Trade Registry No

To be published

Registered e-Mail (KEP)

To be published

Email

info@radarlo.com

This page will be updated once legal entity registration is complete. The current information can be found here and in the §17 Version Log.

2. Data Protection Officer (DPO)

You can reach our Data Protection Officer for all questions about your personal data and to exercise your rights:

Email: dpo@radarlo.com

Postal: Radarlo DPO, Istanbul / Türkiye

For KVKK-scope requests, use the Data Subject Application Form: /kvkk.

3. EU Representative (GDPR Article 27)

For users in the European Economic Area (EEA), an EU representative is being appointed pursuant to GDPR Article 27. Representative details will be published here upon completion:

Representative: To be published (EU-based provider such as Prighter / VeraSafe)

Contact: eu-rep@radarlo.com

A separate UK representative will be appointed for users in the United Kingdom.

4. Data We Collect

Data below is collected only when necessary to provide the service. The legal basis for each category is listed in §5.

Account Information

Email, hashed password, display name, phone (optional), country, preferred language, vehicle type, premium status, IBAN (only if you request a referral payout), promotional consent.

Device Information

Device ID, operating system and version, device model, app version, push notification token (FCM), notification/location/sound/vibration permission states.

Location Data

While the mobile app is active, your GPS location is processed approximately every 10 seconds with a 10 metre distance filter. Location is sent to our server to query nearby radar points and discarded from memory as soon as possible. Raw location trails are not persistently stored server-side. This processing triggers a Data Protection Impact Assessment (DPIA) under GDPR Article 35; public summary: /legal/dpia-summary.

Session Security

Your IP address and user-agent are stored alongside refresh tokens for 30 days to detect session abuse (refresh_tokens table).

Community Contributions

Alerts and reports you voluntarily submit: location, alert type, comment, photo (EXIF GPS is stripped), vote counts. Reports auto-expire after 2 hours.

Subscription and Purchases

Apple App Store and Google Play receipts, product ID, plan, trial and renewal dates. Card and payment details are never transmitted to us; they are handled by Apple/Google.

Analytics and Advertising

If you consent, Firebase Analytics, Google Analytics 4 (G-Z8MPYK1FZT), Firebase Crashlytics and the AdMob advertising identifier (AAID/IDFA) are processed. Without consent these tools are disabled.

Session Telemetry

With your consent, aggregate statistics such as session start/end location, total distance travelled and how many alerts were shown are recorded.

OAuth Links

When you sign in with Google, Apple or Facebook, the provider ID and email are stored; your password is never transmitted to us.

5. Purposes and Legal Bases of Processing

GDPR Art. 6(1) · KVKK Art. 5 · UAE PDPL Art. 5 · KSA PDPL Art. 5

PurposeDataBasis (GDPR)
Account creation, login, password resetAccount6(1)(b) — Contract performance
Showing nearby radar pointsLocation, device6(1)(b) — Contract performance
Push notification deliveryFCM token, device ID6(1)(a) — Explicit consent
Abuse and fraud detectionIP, user-agent, session history6(1)(f) — Legitimate interests
Subscription managementPurchase receipt, plan6(1)(b) — Contract performance
Personalised analyticsFirebase Analytics, GA46(1)(a) — Consent (cookie banner)
Personalised advertising (AdMob)AAID/IDFA6(1)(a) — Consent (UMP form)
Crash reportsCrashlytics6(1)(f) — Legitimate interests
Legal obligations (tax, disputes)Invoices, correspondence6(1)(c) — Legal obligation

For processing requiring explicit consent under KVKK, additional consent is collected via /kvkk/acik-riza-metni.

6. Retention Periods

DataDuration
Account informationUntil account deletion + 30 day archive
Refresh token (refresh_tokens)30 days
Community report / alert2 hours (auto-delete)
Push delivery log90 days
Crash report (Crashlytics)90 days
Analytics events (GA4 / Firebase)14 months
Invoice / payment records10 years (TR Tax Law)
Database backups90 days
Raw GPS trail (server)Not persisted — memory only

7. Sub-processors (GDPR Art. 28)

We have data processing agreements (DPAs) with the following third parties. The current list, with last-updated date, is maintained on this page.

ProcessorPurposeLocation
Google Firebase (Auth, FCM, Analytics, Crashlytics)Auth, push, analytics, crashEU / US
Google AdMobAd servingUS
Google Analytics 4Web analyticsEU / US
Apple App Store / Google PlaySubscription, IAP verificationUS
PayTRTürkiye payment processingTR
Upstash RedisRate limiting, cachingEU / Global
Nodemailer SMTP providerTransactional emailEU / US
Self-hosted (PostgreSQL + PostGIS, 140.245.31.93)Primary databaseRegion being confirmed

8. International Data Transfers

Some of our sub-processors (Google, Apple) may transfer data outside Türkiye and the EU. We rely on appropriate safeguards under GDPR Arts. 44–49 and KVKK Art. 9:

  • EU Standard Contractual Clauses (SCCs, 2021/914)
  • UK International Data Transfer Addendum
  • Binding Corporate Rules approved by the KVKK Board, or explicit consent
  • EU–US Data Privacy Framework participation (for applicable providers)

For direct transfers from Türkiye to the EU we obtain explicit consent or an adequate safeguard under KVKK Art. 9. Copies of the SCCs may be requested from dpo@radarlo.com.

9. Automated Decision-making and Profiling

Radarlo does not carry out solely automated decision-making that produces legal effects concerning you or similarly significantly affects you (GDPR Art. 22).

Prioritising alerts (e.g. showing the nearest radar first) is automated; this does not amount to profiling and has no legal effect on the user.

10. Children's Data

Radarlo is a driving-related service and is not intended for individuals below the driving-licence age. You must be at least 16 (EU), 13 (US/COPPA), and 18 (paid subscriptions) to create an account.

If we learn we have collected data from a child without parental consent, we delete it promptly. Contact dpo@radarlo.com with concerns.

11. Your Rights

Depending on your jurisdiction, you have the following rights:

GDPR / UK GDPR

Access, rectification, erasure, restriction, portability, objection, challenge automated decisions, complaint (local DPA).

KVKK (Türkiye)

Art. 11: know, third parties transferred to, rectify, erase/destroy, compensation for damages, complaint to the Authority.

UAE PDPL

Access, rectification, erasure, restriction, portability, complaint to the UAE Data Office.

KSA PDPL

Be informed, access, correction, destruction, complaint to SDAIA.

CCPA / CPRA (California)

Know, delete, correct, limit sensitive PI, Do Not Sell/Share.

Global

Withdraw consent at any time; learn which providers received your data.

To exercise your rights: /legal/request use the self-service portal or email dpo@radarlo.com. We respond within 30 days.

12. Security Measures

  • TLS 1.2+ encryption in transit
  • bcrypt password hashing; legacy SHA-256 records are upgraded to bcrypt on first login
  • 15 minute JWT access tokens, 30 day refresh tokens with IP + user-agent binding
  • API endpoint rate limiting (Upstash)
  • Least-privilege, role-based access for authorised personnel
  • Annual penetration testing and quarterly security reviews

13. Data Breach Notification

If a breach affecting your personal data occurs, we notify the competent supervisory authority within 72 hours and you without undue delay (GDPR Arts. 33–34, KVKK Art. 12(5)).

14. Cookies and Similar Technologies

Our website obtains your consent before loading non-essential cookies, as required by ePrivacy Directive Art. 5(3). See the itemised list: /cookies.

Advertising consent in the mobile app is collected through the Google User Messaging Platform (UMP) form; you can re-open the form at any time via Settings → Privacy → Ad Consent.

15. Global Privacy Control (GPC)

If your browser sends a Global Privacy Control signal, we treat it as a "Do Not Sell/Share" request under CCPA/CPRA.

16. Changes to This Policy

We may update this policy to reflect changes to the service or legal requirements. Material changes are announced by email or in-app notice before taking effect.

17. Version Log

VersionDateSummary
3.02026-04-14Comprehensive rewrite: real data flows, DPO/EU rep, sub-processor table, retention schedule, KVKK/PDPL/CCPA/GPC sections.
2.x2025-11-25Basic GDPR rights; limited data categories.

Contact

Contact us with any questions about this policy or your data.

General

info@radarlo.com

Data Protection Officer

dpo@radarlo.com

EU Representative

eu-rep@radarlo.com

Address

Istanbul, Türkiye