Privacy Policy
Effective date: 25 July 2026
This policy explains what data we process when you use Afiets, why we process it, and what rights you have over it.
The Turkish version is the governing text. Where a translation differs, the Turkish version prevails.
1. Who we are
Afiets is a software service operated by İverbex Eğitim Yazılım Ticaret Limited Şirketi, a company established in Türkiye. In this policy, "we", "us" and "our" mean that company.
You can reach us about any privacy matter at [email protected] or +90 548 856 41 83.
2. We act in two different roles
For data about you, we are the controller. This covers your business details, the contact details of the person responsible for the account, and your subscription records.
For data about your own customers, we are a processor. The details of the people who order from you belong to you. We process them only to run the service on your behalf and on your instructions. We do not use them for our own commercial purposes, we do not sell them, and we do not market to those people ourselves.
3. What we collect from you
- Account details: business name, owner name, email, phone and your password. Passwords are stored as irreversible bcrypt hashes and are never held in plain text anywhere.
- Business profile: address, city and district, location coordinates, opening hours, description and any images you upload.
- Billing details you choose to enter: tax number, company registration number, bank account or IBAN.
- Subscription records: your Stripe customer and subscription identifiers, subscription status and trial end date.
- Technical records: IP address, browser and device information, error and access logs.
- Support conversations and any messages you send us.
- Your device notification token, if you have granted notification permission.
4. Your card details never reach us
Payments are taken through Stripe. Your card number, expiry date and security code go directly to Stripe. They never pass through our servers at any point and we never store them. All we see is the customer and subscription identifier Stripe issues, and whether a payment succeeded.
5. Customer data we process on your behalf
The data arriving from your ordering site is: the name and phone of the person ordering, their email if provided, their delivery address and coordinates, the contents of the order, any order note, and their order history.
We process this only so the order reaches you, so its status can be tracked, and so it can be reported back to you.
6. Why we process data
- Performance of our contract with you: opening your account, running your site and panel, delivering orders, and billing your subscription.
- Legitimate interests: keeping the service secure, preventing abuse and fraud, and improving the infrastructure.
- Legal obligations: keeping accounting and tax records, and responding to properly made requests from authorities.
- Consent: marketing emails, sent only if you have opted in. Operational notices about the service are not covered by this and continue regardless.
7. Who we share data with
We do not sell personal data. To run the service, and to measure whether our advertising works, we rely on the following providers only:
- Stripe: payment and subscription management.
- Hetzner Online GmbH (Germany): server and database hosting. This is where your data primarily lives.
- Amazon Web Services (SES, Sweden): sending account and order emails.
- Cloudflare: domain management, content delivery, image storage and TLS certificates.
- Google: map services for address lookup, push notification delivery if you have enabled notifications, and usage measurement through Google Analytics if you have accepted analytics cookies.
- Meta (Facebook): only if you have accepted analytics cookies, to measure whether our advertising produces results.
8. Where your data is held
Your database and files are held on our servers in Germany. Some of the providers listed above may process data in the European Union or the United States. Where a transfer outside your country is required, we rely on standard contractual clauses and equivalent safeguards required by applicable law.
9. How long we keep it
- Your account and business data are kept for as long as your account is open.
- If you end your subscription, your account data is kept for 90 days so that everything is still in place if you come back. After that it is deleted or irreversibly anonymised.
- Invoice and payment records are kept for as long as the accounting and tax rules that apply to us require.
- Your customers’ data belongs to you. On request we export it to you and then delete it.
10. Your rights
Depending on where you are, you have rights to access your personal data, to have it corrected or deleted, to restrict how it is processed, to receive it in a portable format, to object to processing, and to withdraw consent you have given. You also have the right to complain to your data protection authority.
To exercise any of these, write to [email protected]. We respond within 30 days.
If you are a customer of a restaurant and your request concerns your order data, please contact that business first. When they refer the request to us, we provide the technical assistance they need.
11. Security
No system can promise absolute security. If a breach affecting your data occurs, we will notify you, and the relevant authorities where required, within the period the law prescribes.
- All traffic is encrypted with TLS.
- Passwords are stored as bcrypt hashes; no plain text password is kept.
- Integration API keys are stored only as SHA-256 hashes. The key itself is shown once when it is created and can never be viewed again.
- The database is backed up regularly and backups are held in a separate location.
- Panel access is limited by role-based permissions.
12. Cookies
We use strictly necessary cookies and browser storage to keep you signed in and to remember your language preference. These are required for the service to work and cannot be turned off.
In addition, we use Google Analytics and the Meta (Facebook) pixel to measure how the site is used and whether our advertising works. These cookies are optional and load only if you accept them. If you decline, none of them load and only the strictly necessary cookies remain.
You can reverse your choice at any time by clearing this site’s data in your browser. This measurement data is used for aggregate statistics, not to identify you as an individual.
13. Children
Afiets is a business service and is not directed at anyone under 18. We do not knowingly collect data from children.
14. Changes to this policy
When we update this policy we change the effective date on this page. If a change materially affects your rights, we email the address on your account before it takes effect.
İverbex Eğitim Yazılım Ticaret Limited Şirketi