Privacy Notice
explore.istanbul · IMPROHIVE LLC Revision date: 6 October 2026 · Version: 1.0-RC4
Scope
This notice explains personal data processing in the explore.istanbul mobile app, explore.istanbul website and business panel. Sections 1 and 5 provide common information for everyone. Sections 2–4 also apply when the relevant law's scope requirements are met; applicability does not depend solely on citizenship or interface language.
This is a notice, not a request for blanket consent. Reading it or using the service does not mean that you consent to every processing activity. Where consent is required, a purpose-specific choice is requested. Differences between the Turkish source text and translations do not override mandatory local-language rules or your statutory rights.
1.1 Controller and contact details
IMPROHIVE LLC operates the service and is responsible for its own processing activities described here.
- Full business/address for service: 30 N Gould Street, Suite 4128, 82801 Sheridan, WY, United States
- Privacy and support: privacy@improhive.com
- Representative in Türkiye: Çağrı BİÇER · privacy@improhive.com (appointment in progress)
- EEA representative: {{AEA_TEMSILCI_AD_UNVAN_ADRES_EPOSTA}} (appointment in progress; once completed, the representative’s name, title, address and contact details will be stated in this section)
- UK representative: {{UK_TEMSILCI_AD_UNVAN_ADRES_EPOSTA}} (appointment in progress; once completed, the representative’s name, title, address and contact details will be stated in this section)
- Swiss representative: As we carry out no marketing or targeting activity directed at Switzerland, we consider that no separate representative is required under Swiss data protection law; this assessment will be revisited if our activities change
You may contact the relevant representative or us directly. We provide the service as a commercial business.
1.2 How we collect data
Data is collected electronically through account/profile and route forms, device features you permit, app and website use, support correspondence, the business panel, and subscription notifications from Apple/RevenueCat, by wholly or partly automated means. Authorised staff may also review support requests.
An email address and authentication information are necessary for account-based features. Route generation requires the relevant preferences; entering a free-text starting point is optional. Your name and profile photo are optional. Refusing location permission does not prevent you from using your account or features that do not require location. Subscription status must be verified to enable paid features.
1.3 Data categories and purposes
| Data | Purpose |
|---|---|
| Email, password hash, account identifier, registration/last sign-in times and session information | Account creation, secure sign-in, password reset and access management |
| Optional name and profile photo | Providing the profile appearance you choose |
| Age-16 declaration and its timestamp; no date of birth is collected | Applying the service's age requirement |
| Route interests, transport preference, duration, language, optional starting-point text and address-search inputs | Providing the route planning, address search and directions services you request; when using the free version, selecting sponsored recommendations based on the categories and locations of stops on the route (Section 5.3) |
| Sponsored-card impression and click events | Aggregating impressions and clicks by business and day and preparing performance reports for the relevant business; reports contain no user or device identifiers (Section 5.3) |
| Saved route title/description, duration, stops and coordinates, favourite status and creation time; sharing link | Saving routes and sharing them at your choice |
| Current/precise device location, with permission | Showing your position and calculating directions to a selected stop |
| Subscription status, transaction identifiers and purchase/renewal/refund events | Verifying paid access, support and dispute management |
| Account-linked product interaction events and usage counters | Measuring feature use and service limits; improving the product |
| Error/crash records and session-health data (session start/end and whether it ended in a crash), app version, device model and operating system; technical identifiers are explained in Section 1.4 | Identifying faults and maintaining reliability |
| IP and technical connection information processed during connections | Establishing communications and operating the infrastructure; see Section 1.4 for direct connections |
| Support correspondence and information you supply to resolve a request | Answering questions and managing requests and disputes |
| Business name, representative name/phone, tax information, address/coordinates, website, photos, campaign and approval information | Operating business accounts and commercial relationships; publishing selected business information |
| Account identifier, Unsplash photo identifier and download time | Managing image-use/download reporting and compliance with provider conditions |
| Text to be spoken, voice selection and generated audio | Providing the audio guide and reducing repeated processing through caching |
We do not receive your payment card details; payments are handled through Apple. We do not access your contacts or use IDFA for advertising tracking. IDFV is not the same as an advertising identifier; other identifiers used by SDKs are considered under Section 1.4.
We do not request health data, biometric identification data or similar special categories of data. Profile photos are not used for facial recognition. However, an address, support message or image you provide may contain personal or sensitive information. Do not provide unnecessary personal information or other people's private information. Precise location is sensitive personal information under some US laws; see Section 5.2.
1.4 Recipients and disclosures
We use the providers below to deliver the service. We do not sell your personal data or share it for cross-context behavioural advertising. For server-mediated calls, the recipient sees our server's IP unless the user's IP is separately forwarded. An IP visible at network level during a direct connection is different from an IP field filtered out of an application event.
| Provider / service | Information and purpose |
|---|---|
| Supabase — authentication, database and file storage | Accounts, profiles, routes, files and service records; project region eu-west-1, Ireland |
| RevenueCat — subscriptions | Account UUID and purchase/subscription events; our integration does not send name, email or advertising identifiers |
| Sentry — error monitoring | Filtered error/crash records and session-health data (whether a session ended in a crash), app version, device model and operating system; no direct account identity is sent. Instead, a random installation identifier (UUID) generated on the device is sent: it has no mathematical link to your account, e-mail address or user ID, it is regenerated if the app is deleted and reinstalled, and it only measures how many separate installations saw the same error and the crash-free session rate. Performance monitoring, screenshots, session replay and network traces are disabled. |
| Google — via our servers (Places, Routes/Directions) | Contracting party Google LLC; for users in the EEA and Switzerland, Google Ireland Limited. Google processes this data as an independent controller. For address search, the text you type and a random search session token that is not derived from your app account identifier are sent. We do not add your account identifier, name or email address to this token. For walking and public transport directions, your device location as the starting point, the destination stop's coordinates, travel mode, language and time. Your account identifier, email and IP address are not sent; Google sees our server's IP address for these calls |
| Google — Maps SDK on your device (map) | The map connects directly from your device to Google. Google collects IP address, device and map usage data directly for its own service as an independent controller; see the Google Privacy Policy |
| OpenAI — routes and historical content | Interests, duration, transport preference, language and neighbourhood/district-level starting area; no name, email, account identity, device coordinates or raw starting address Historical-summary requests contain only the place name and language. |
| Google Cloud — audio guide (Chirp 3 HD) | Narration text, language and fixed narrator voice; no account identity or device location is sent. European endpoint is used |
| ElevenLabs — legacy audio cache | Not used for new synthesis; existing audio files remain subject to retention and erasure rules |
| Unsplash — images | City/category query and download notification; these server calls do not include account identity; see below for image connections |
| OpenWeather — weather | City-level request for Istanbul; no device location |
| Apple — purchases and distribution | Payments, renewals and refunds through the Apple account; we receive subscription/transaction information |
| Resend — account e-mails | Your e-mail address and message content (including the one-time link) for sign-up confirmation, password reset and e-mail change messages; open and click tracking are disabled |
| DigitalOcean — website, business-panel hosting and deletion-record copy | Requests to the website and business panel (IP address, browser information, server logs) and business information processed in the panel; a copy of the account deletion record kept independently of database backups (the deleted account's ID and time of deletion); servers and storage located in Frankfurt (Germany) |
| Google Workspace — e-mail | Messages and attachments you send to our support and privacy e-mail addresses; handling support requests and data-subject requests |
Google Maps SDK and Sentry directly connect from the device, making the user's IP visible at network level. IP retention is disabled in Sentry; filtering event fields does not prevent network visibility. Other direct SDK, authentication and image connections: Supabase (authentication, database, file storage and server functions), RevenueCat (subscription SDK) and Unsplash/imgix image addresses also connect directly from the device; Apple's purchase flow runs through the operating system. Measured on 23 September 2026: with no account created, the only outbound connection during first launch and the intro flow is Sentry — connections to Supabase and RevenueCat are added once you sign in.
Selecting EU storage does not mean every support access or subprocessor is in the EU. Recipient legal entities, countries, controller/processor roles and transfer safeguards are stated in Sections 2.3 and 3.4. Providers may be independent controllers for certain processing relating to their own services, to which their own notices also apply. This does not remove our responsibility for our own processing.
We do not use a separate third-party product-analytics SDK. Events are written to our database on our hosting infrastructure; this does not mean the hosting provider processes no data. Analytics event fields are restricted: email, full address and precise coordinates are not written to these events. Events linked to account identifiers remain personal data.
People holding a route link can see the route you choose to share; other users can see business information you make public. Necessary information may also be disclosed to competent authorities and professional advisers for legal obligations or the establishment, exercise or defence of legal claims.
1.5 Retention
Periods run from creation of the record or event unless another starting point is specified. A maximum does not mean data is always kept for that entire period. If the purpose ends earlier and there is no other legal reason, data is deleted earlier.
| Data | Period or determining criterion |
|---|---|
| Account, age declaration, profile and photo | While the account exists; optional profile fields are deleted when removed or when the account is deleted |
| Saved routes | Until you delete the route or account |
| Sharing links | Accessible for 30 days; physical deletion in the first daily cleanup after a further 7-day support period |
| Raw starting/address-search text and current device coordinates | For processing the request; we do not create a permanent usage/location history from them. Saved route stops are a separate category |
| Product interaction events | Limited event details for the first 6 months; event types are narrowed and detail fields cleared after month 6; raw records deleted or truly anonymously aggregated by month 12 at the latest |
| Subscription event records | Up to 24 months; account deletion and mandatory retention are distinguished below |
| Error, crash and session-health records | On our current provider plan, retention is 30 days for error records (90 days on a higher plan). Session-health data is subject to the provider's own retention rules |
| Audio-guide cache | Up to 90 days + at most 1 day. Audio generated from the text of a route you saved is deleted when you delete your account, without waiting for that period; an earlier erasure request is met the same way (the audio file is located again from your own text, and no separate tracking record is kept) |
| Account-linked Unsplash download records | At most 30 days; the record exists only so that the download notification is not repeated for the same photo, and it is deleted automatically when the account is deleted |
| Address-search session records | 1 day; this does not mean retaining raw address text |
| Usage counters | 13 months; earlier if the account is deleted |
| Aggregate business daily statistics | Daily totals for 12 months; they are then converted into monthly totals, which are kept for at most 24 months. Businesses are shown totals for completed days only. Records containing personal data remain subject to deletion rules |
| Truly anonymous monthly statistics | Without a fixed time limit while individuals cannot be reidentified |
| Support and rights-request records | Support correspondence for at most 12 months; requests under KVKK/GDPR and our responses for 3 years from the date the request is closed (evidence against legal claims) |
| Security/access records and evidence of consent and acceptance of terms | Evidence of consent and acceptance is kept with the account and deleted together with it; security/access records up to 12 months |
| Data copy file produced on request | 30 days; the download link expires after 1 hour and the previous file is deleted when a new copy is produced |
| Backups | Daily database backups are kept by our hosting provider (Supabase, Ireland); deleted data leaves the backups within 8 days at the latest. Files (photos, audio, data copies) are not backed up |
| Account deletion record | The deleted account's ID and time of deletion for 30 days, only to re-apply the deletion if a backup ever has to be restored. A copy of the same record is kept at DigitalOcean (Frankfurt) independently of database backups and is deleted by an automatic rule after 30 days |
| Financial records | We keep the records needed to verify accounting, tax and financial transactions for 7 years as a rule, counted from the end of the relevant financial year. Where applicable legislation, an ongoing audit or a legal dispute requires longer retention, we keep only the relevant records for as long as necessary. When the retention requirement ends we delete the records or anonymise them where appropriate. This period does not apply to your user profile, your location data or your routes as a whole |
Subscription events are retained for up to 24 months for verification, support, renewal/refund review and potential dispute management. Accounting and tax records concerning revenue received from Apple are separate. Apple's handling of payments does not remove the company's own financial record obligations.
Anonymous statistics exclude direct identifiers, identity hashes and row-level timestamps; time resolution is monthly and cells representing fewer than 20 people are not published. Below-threshold data may only be combined into wider groups meeting anonymity requirements; otherwise it is deleted. Failure to reach the threshold does not extend retention of raw personal data. This threshold alone does not guarantee anonymity. We also assess reidentification through matching, small groups and comparisons between successive reports. Records that cannot be made anonymous remain protected as personal data with limited retention.
1.6 Account deletion
You can delete your account in the app or ask for help at privacy@improhive.com. Deletion covers the active account/profile, photo, saved routes and links, usage counters, product interaction events, business-account content and operational subscription records. A deletion request is sent for the RevenueCat customer record; completion of the queued action is followed up within a maximum of 7 days (the provider does not publish a maximum completion time, so this is our own verification commitment; if it has not completed, we escalate to the provider in writing).
Account-linked image-download records and audio containing personal data are also included in erasure assessment. Completed deletion is irreversible. Existing session tokens on other devices expire within one hour at the latest. Disabling access and destroying all backup/provider copies are different processes:
- Backups are removed within the cycle in Section 1.5 and are not restored for ordinary use. If disaster recovery is necessary, deletion records are reapplied; for this purpose your account ID and the time of deletion are kept in a separate deletion record for 30 days. A copy of this record is also kept for the same period at a separate provider, independently of database backups (Section 1.4, DigitalOcean).
- Minimum records needed for statutory retention or establishing, exercising or defending a specific legal claim may be kept with restricted access until that reason ends. This does not authorise retention of the entire account.
- Technical Sentry records may remain until their retention period ends. Absence of an account identifier does not itself make them anonymous. Linkable records remain subject to personal data rights.
- Truly anonymous statistics and shared caches without personal data are unaffected by account deletion. An audio file may contain personal data even when its filename has no account identifier; such files are not excluded from erasure assessment. Relevant route/content details may be requested to help locate them; we do not collect unnecessary identity documents or new identity data solely to create a link.
- Apple's own records are subject to Apple's obligations. Deleting your account does not cancel your Apple subscription. Stop renewal separately in Apple's subscription settings.
- Language and introduction preferences may remain on the device and can be cleared through device/OS settings. Backup or secure-storage behaviour means uninstalling the app does not guarantee deletion of every local record.
1.7 Security
We apply measures such as transport/storage security, access authorisation, row-level controls and separation of administrative keys from the client. Authorised staff and providers may access data as needed for their roles; shared or public content follows its visibility settings. Profile and business images are re-encoded before upload to remove metadata that may contain location. No system can be guaranteed entirely risk-free.
1.8 Children
The service is not directed to children under 16, who may not create accounts. When we learn of such an account, we suspend its use, investigate as necessary and delete personal data except minimum records legally required. Users aged 16–17 need their legal representative's approval where required; the age-16 rule does not establish contractual capacity in every country.
1.9 Changes
We show the update date here and provide additional notice of significant changes through an appropriate channel. If a new purpose requires consent, notice or continued use does not replace that consent.
2.1 Controller and registration
Controller/contact details are in Section 1.1. {{VERBIS_YERLESIKLIK_SONUCU}}. Establishment and representation are assessed under KVKK and are not inferred solely from tax-residence status.
2.2 Purposes, methods and legal grounds
Collection methods are in Section 1.2 and purposes in Section 1.3. Grounds are limited to what the particular processing requires:
| Activity | Ground under Law No. 6698 |
|---|---|
| Necessary account/authentication processing, route generation/saving/sharing and requested address search | Necessity for entering into or performing a contract, Art. 5(2)(c) |
| Optional name and profile photo | Explicit consent based on separate information for these fields, Art. 5(1); removal/withdrawal does not affect the core service |
| Optional device location | Purpose-specific explicit consent, Art. 5(1); see Section 5.2 for the device-permission flow |
| Subscription access and operational transaction management | Contract performance, Art. 5(2)(c) |
| Specific disputes and necessary evidence | Establishment, exercise or protection of rights, Art. 5(2)(e) |
| Product interaction analysis | Legitimate interests without harming fundamental rights/freedoms, Art. 5(2)(f); separate consent is obtained where required for device access |
| Selecting sponsored recommendations based on the categories and locations of route stops when using the free version | Article 5(2)(f) of Turkish Law No. 6698 (KVKK): Processing necessary for our legitimate interest in providing contextual sponsored recommendations that help fund the free service, provided that the data subject’s fundamental rights and freedoms are not harmed. |
| Aggregating sponsored-card impressions and clicks by business and day and preparing performance reports for the relevant business | For stages involving personal data, Article 5(2)(f) of the KVKK: Processing necessary for our legitimate interest in providing businesses with aggregate reports on sponsored impressions and interactions, provided that the data subject’s fundamental rights and freedoms are not harmed. |
| Security, troubleshooting, age eligibility and usage limits | Legitimate interests as necessary, Art. 5(2)(f); Art. 5(2)(c) for counters necessary to perform the service |
| Support, rights requests and financial records | According to the request: Art. 5(2)(c), legal obligation Art. 5(2)(ç), express statutory provision Art. 5(2)(a), or protection of rights Art. 5(2)(e) |
| Image-download records and audio caches containing personal data | Processing necessary for the service: Art. 5(2)(c); additional records/caching: Art. 5(2)(f), subject to necessity and balancing |
| Business-owner contracts and representative communications | Art. 5(2)(c) for individual contracting parties; Art. 5(2)(f) for business contacts of corporate representatives; Art. 5(2)(ç) for applicable financial obligations |
Domestic disclosures are assessed under the relevant processing condition and Article 8; international transfers also require Article 9 conditions. Accepting this notice does not replace those grounds.
2.3 International transfers
International data flows arise from our US company, overseas infrastructure, the providers in Section 1.4 and their authorised subprocessors/access locations. Transient transmission or pseudonymisation does not automatically remove the need for this assessment.
{{KVKK_AKTARIM_TABLOSU_ALICI_TUZEL_KISI_ULKE_ROL_AMAC_VERI_MEKANIZMA}}
The table identifies the Article 9 mechanism actually implemented for each relevant transfer. Contact privacy@improhive.com for information about safeguards. A location or AI permission screen does not replace the mechanism required for routine international transfers.
2.4 Rights and requests
Under Article 11, you may learn whether your data is processed, request information, learn its purposes and whether it is used accordingly, identify domestic/international recipients, request correction, request deletion/destruction where legally available, and request notification of these actions to recipients. You may object to an adverse result produced solely by automated analysis and seek compensation for damage from unlawful processing.
Write from your registered email to privacy@improhive.com or send a written request to the address in Section 1.1; other statutory submission methods remain available. Provide enough information to identify you and your request, without unnecessary identity documents. Proportionate verification may be requested. We respond as soon as possible and within 30 days at the latest. Requests are generally free; any legally permitted charge is explained in advance.
If the request is rejected, answered inadequately or not answered in time, you may complain to the Board within 30 days of learning the response and in any event within 60 days of your request, subject to statutory procedures.
3.1 Legal bases
Where EU GDPR or UK GDPR applies, necessary account, route and subscription services rely on contract performance (Art. 6(1)(b)); optional profile fields and device location on consent (Art. 6(1)(a)); security, product improvement and necessary business communications on legitimate interests (Art. 6(1)(f)). Legal obligation (Art. 6(1)(c)) is used for obligations recognised by the applicable GDPR regime; a foreign tax law does not automatically establish that basis. Necessary legal-claim records are processed under legitimate interests or an applicable obligation, as appropriate. For image-download reporting, necessary service quotas and audio caches containing personal data, processing necessary for the requested service relies on contract performance; additional operational records/caching rely on legitimate interests subject to necessity and balancing.
| Processing purpose | GDPR legal basis and legitimate interest |
|---|---|
| Selecting sponsored recommendations based on the categories and locations of route stops when using the free version | Art. 6(1)(f) — Legitimate interests: Providing sponsored recommendations relevant to the route context to help fund the free service. This basis applies only where the processing is necessary for that purpose and is not overridden by the user’s interests or fundamental rights and freedoms. |
| Aggregating sponsored-card impressions and clicks by business and day and providing performance reports to the relevant business | For stages involving personal data, Art. 6(1)(f) — Legitimate interests: Measuring sponsored-card impressions and interactions and providing the relevant business with aggregate performance information. Reports provided to businesses contain the business, date, impression count and click count, without user or device identifiers. This basis applies only where the processing is necessary and is not overridden by the user’s interests or fundamental rights and freedoms. |
For product analytics, our interest is understanding usability problems and seasonal feature needs. Events exclude email, full address, precise location and advertising identifiers; we do not build advertising profiles. Twelve months is not a statutory period. This maximum applies only to the extent that shorter retention or earlier aggregation cannot meet the need; seasonality alone does not make 12 months of account-linked events necessary. After month 6, event types are reduced and detail fields cleared; account-linkable records remain personal data at this stage. Necessity is reviewed periodically.
Your right to object to processing based on legitimate interests is explained in Section 3.3. Where applicable law requires consent for storing or accessing information on your device or for analytics, legitimate interests do not replace that consent.
3.2 Representatives
EEA and UK representative details are in Section 1.1. These appointments do not substitute for one another. Swiss representation is separately assessed under the conditions of Swiss law.
3.3 Rights
Where the conditions are met, you have rights of access, rectification, erasure, restriction, portability and objection. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Portability applies to data you provided that is automatically processed on the basis of consent or contract.
Right to object. You may object at any time, on grounds relating to your particular situation, to processing based on GDPR Art. 6(1)(f). We will stop the relevant processing unless an exception under Art. 21(1) applies. You may object to the processing of your personal data for direct marketing at any time, free of charge and without giving reasons; we will then stop processing your data for that purpose. You can contact us at privacy@improhive.com.
Contact privacy@improhive.com. The app has no automatic data-download or analytics-off switch, so these requests are received by email. Data meeting portability requirements is provided in an appropriate commonly used machine-readable format, such as JSON or CSV. GDPR requests are normally answered within one month. If a lawful extension of up to two additional months is necessary, we explain the reason within the first month. Proportionate identity verification may be needed. Requests are generally free; any legally permitted refusal or fee is explained. You may complain to a competent supervisory authority, particularly where you habitually reside, work or believe an infringement occurred; in the UK, to the ICO.
Switzerland's Federal Act on Data Protection (FADP/DSG) applies separately. Where legally available, you may request information/access, correction, delivery/transfer of data and protection against unlawful processing, and contact the FDPIC/EDÖB. Switzerland is not treated as a country where GDPR automatically applies.
3.4 International transfers
Transfers to recipients outside the EEA, UK or Switzerland are separately assessed under the conditions of each relevant regime.
| Recipient | Country | Role | EU/EEA safeguard | UK safeguard | Swiss safeguard |
|---|---|---|---|---|---|
| Supabase Pte. Ltd. | Singapore (data stored in Ireland, eu-west-1) | Processor | EU Standard Contractual Clauses (SCCs) Module 2 | SCCs + UK Addendum (ICO) | SCCs adapted for Switzerland |
| RevenueCat, Inc. | USA | Processor | SCCs Module 2 | SCCs + UK Addendum (ICO) | SCCs adapted for Switzerland |
| Functional Software, Inc. (Sentry) | USA (event data stored in the EU, Frankfurt) | Processor | EU-U.S. Data Privacy Framework (DPF); fallback SCCs Module 2 | UK Extension to the DPF; fallback SCCs + UK Addendum | Swiss-U.S. DPF; fallback SCCs adapted for Switzerland |
| OpenAI OpCo, LLC | USA | Processor | OpenAI DPA §4.1: OpenAI Ireland Limited for EEA data; SCCs or adequacy for onward transfers | OpenAI DPA §4.2: SCCs + UK Addendum | OpenAI DPA §4.1: OpenAI Ireland Limited for Swiss data and applicable transfer safeguards |
| Eleven Labs Inc. | USA | Processor | EU-U.S. DPF and SCCs Module 2 | UK Extension to the DPF and UK Addendum | Swiss-U.S. DPF and SCCs adapted for Switzerland |
| Plus Five Five, Inc. (Resend) | USA | Processor | EU-U.S. DPF and SCCs Module 2 | SCCs completed by the UK Addendum | SCCs adapted for Switzerland |
| DigitalOcean, LLC | USA (servers and storage in Frankfurt) | Processor | EU-U.S. DPF; fallback SCCs Module 2 | UK Addendum (IDTA Addendum) | Swiss-U.S. DPF |
| Google LLC (Google Workspace) | USA | Processor | Google Cloud Data Processing Addendum: alternative transfer solution (EU-U.S. DPF), otherwise SCCs (controller to processor) | Under the same addendum | Under the same addendum |
| Google (Maps Platform — via our server) | Ireland / USA | Independent controller: Google Ireland Limited for the EEA and Switzerland; Google LLC for the UK | Only the transfer from us to Google Ireland Limited: a permitted European transfer under Google's controller terms (recipient in the EU). Google's own onward transfers are subject to Google's transfer solution | Google LLC: UK Extension to the DPF; where SCCs apply, Module 1 + UK Addendum | Recipient Google Ireland Limited (country with adequate protection) |
For the Google Maps SDK on your device, the Apple purchase flow and Unsplash image links, the provider collects data, including your IP address, directly from your device as an independent controller for its own service; this is not a transfer made by us. Our server's calls to Unsplash and OpenWeather contain no personal data (a city/category query, a download notification without an account ID, and a fixed Istanbul coordinate).
Contact privacy@improhive.com for a copy of the safeguards or information on accessing them. Necessary redactions may protect trade secrets and other people's rights. A provider's EU server region alone does not establish the absence of overseas access or subprocessor transfers.
3.5 Automated processing
Route suggestions are generated automatically. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. Route personalisation does not mean cross-app behavioural tracking for advertising.
State privacy laws apply where their scope and threshold requirements are met. Categories, sources, purposes, recipients and retention are described in Section 1.
We do not sell personal data, share it for cross-context behavioural advertising or provide it to data brokers. Sponsored suggestions are selected using the context in Section 5.3. Precise location may be sensitive data under applicable state law and is used for the map/directions functions you permit.
Depending on applicable law, you may have rights to access, correct, delete or obtain a portable copy, opt out of sale/sharing/targeted advertising, and limit or consent to certain uses of sensitive data. Contact privacy@improhive.com. We consider authorised-agent requests where permitted and perform necessary identity/authority verification. We do not unlawfully discriminate for exercising rights.
We respond within the applicable state's time limit. If a request is refused, we explain why and any statutory appeal route; you may write to the same address with “Privacy Appeal” in the subject line. Legally required global opt-out/universal preference signals are considered within their applicable scope. This notice does not claim that every state's law currently applies to us.
5.1 Artificial intelligence
Routes and some historical content are generated through OpenAI. Route requests contain interests, transport preference, duration, language and a neighbourhood/district-level starting area where provided. Raw starting text first goes through address resolution, during which the address-search provider may process it. Not sending a full address to OpenAI does not mean no provider processes that address.
For example, a successfully resolved address may be represented only as “Feneryolu, Kadıköy”. The flow is designed to exclude street, building number, postcode and device coordinates from the AI prompt. Area reduction lowers linkability risk but is not itself a guarantee of anonymity.
Before data is first sent to OpenAI for AI route generation, the app explains which data will be sent and for what purpose, and requests your explicit permission. Your choice is recorded in your account with its version and date. Without permission no such disclosure takes place; AI route generation is unavailable, while the rest of the app keeps working. You can withdraw permission at any time in the app under Profile → Preferences → “Routes with AI”; withdrawal stops future disclosures and does not undo earlier ones. You can also tell us your preference at privacy@improhive.com. This permission is distinct from the legal basis for contractual route generation and from international-transfer safeguards.
We do not keep content logs of prompts/responses in our systems; routes you save are retained separately. This statement does not cover the provider's own security or service records. OpenAI API data is not used for training by default. We disable Responses storage with `store:false`; this does not guarantee zero retention. OpenAI may keep abuse-monitoring logs for up to 30 days by default, or longer when legally required; model prompt caching has separate retention rules. AI content may be wrong; verify opening hours, transport and safety information.
5.2 Location
The route creation feature does not use your device's current location. In live public transport navigation, however, your device's current location is sent to the server as the starting point, within the scope of your location permission. The server checks whether the starting and destination coordinates in the request fall within the İstanbul service area. This check is not based on the user's nationality or App Store account region.
Location is used only while the app is in use to show your position and calculate walking/public transport directions to a selected stop. Necessary coordinates are sent to Google for directions. We do not maintain a permanent device-location history or track you in the background. Coordinates of saved route stops are different.
The purpose and Google disclosure are explained before permission is requested. OS permission controls technical access; information and free choice necessary for legally valid consent are also provided. You may withdraw permission and consent in device settings, stopping future device-location access. Features that do not require location remain available.
Withdrawing your permission stops future access to your device location and any new location transmissions that depend on it. It does not affect processing lawfully carried out before, and it does not automatically delete data already sent from Google's systems.
5.3 Sponsored content
Free use may include at most one sponsored business suggestion per route, clearly labelled “Reklam”, “Advertisement” or an equivalent in the selected language. Selection uses route categories and stop locations, not your cross-app behavioural history. Because the route may reflect your preferences, the suggestion is related to that route context. Businesses receive aggregate impression/click statistics, not user identity. Paid members see no sponsored content.
Regardless of your country or subscription status, you may object to sponsored recommendations by contacting privacy@improhive.com. Once your request is implemented, sponsored-recommendation selection and the counting of related impressions and clicks stop for your account.
5.4 Cookies and similar technologies
Cookies/local storage used on the website and panel for sessions, theme or other preferences are described in the inventory below. Connections made by embedded services and SDKs are also covered by Section 1.4.
| Name | Where | Provider | Purpose | Duration |
|---|---|---|---|---|
sb-<project>-auth-token | Web cookie and mobile device storage | Supabase | Keeping you signed in (strictly necessary) | For the session; deleted on sign-out |
biz-tema | Web cookie (/business path) | Our own site | Light/dark theme preference | 1 year |
explore_istanbul.language | Mobile device storage | Our own app | Interface language | Until the app is deleted |
explore_istanbul.onboarding_completed | Mobile device storage | Our own app | Not showing the intro flow again | Until the app is deleted |
explore_istanbul.ai_bilgilendirme_goruldu | Mobile device storage | Our own app | Showing the AI notice only once | Until the app is deleted |
sentry_install_id | Mobile device storage | Our own app (sent to Sentry) | Measuring how many installations saw the same error | Until the app is deleted |
We do not use advertising cookies or pixels, and we do not track you across apps or websites for advertising purposes.
Storage/access necessary for your requested service or expressly exempt under applicable law operates subject to those conditions. Non-essential storage/access requiring consent is not enabled before consent. Calling a technology “functional” does not remove the consent requirement. You may manage storage through browser/device settings; blocking necessary items can affect sign-in.
5.5 Route sharing
A sharing link is valid for 30 days. Anyone holding it can see the route title, duration and stops. It does not display your name, email or account number, but route content may reveal sensitive places or preferences. Check before sharing. You can revoke the link; screenshots or copies already made by recipients are outside our control.
5.6 Business panel users
The panel processes a business representative's name and phone, tax information that may relate to an individual, business address, content, photos and campaign details. Private contact information used for account/contract management differs from business information you choose to display to users. Photos are published after approval. Businesses receive aggregate daily impression/click statistics, not lists of individual users. Personal data rights also apply to business users. The contact, retention, transfer and request information in Sections 1–4 also applies to personal data processed through the panel.