Privacy Policy

Last updated: August 20, 2026

This policy explains which data is collected when you use Rezervasyon Bizde, what it is used for and who it is shared with. Your rights under Turkish data protection law (KVKK) are set out separately in the Data Protection Notice.

This text is a draft written from what the application actually collects and processes. Before going live it must be reviewed by a lawyer and the company details marked in square brackets must be filled in.

Account data

When you register we take your name and email address. Your password is not stored in plain text; only an irreversible digest of it (scrypt) is kept.

When you sign in, a session record is created on the server: a digest of the session token, the browser's self-description (User-Agent) and the last-seen time. The raw token lives only in the cookie in your browser.

Usage data

We take the women/men split so that the approval rules a business sets for itself can be applied. This information is shown to the business in its reservation list.

  • Reservations: date, time, party size, the women/men split of the group, discount rate, code and status
  • Ratings and favourites
  • In-app notifications and your notification preferences

Location data

To sort businesses near you we take your location from the browser, if you allow it. Your location is held in memory on your device only; it is never written to our database and is lost when you close the page.

Because the sorting happens on the server, your coordinates are sent to the server in the request body. They are never written into the address bar or into links.

To show the name of where you are, your coordinates are rounded to roughly 110 metres and sent to OpenStreetMap's Nominatim service. Your exact location never reaches that service.

ONE EXCEPTION: if you turn on "Nearby deals" push notifications, we store your area until you turn it off. What we store is a coordinate rounded to roughly one kilometre and a readable area name (for example "Muratpaşa / Antalya") — not your exact address or your movements. We use it only to tell you when a new discount opens near you. Turning the switch off deletes the record, and you can always see what we stored on the Settings screen.

Business registration data

If you open a business record we process: the business name, company type, tax number or national ID number, the name and phone number of the authorised person, the business address and its map coordinates, and the documents you upload (tax certificate, signature circular).

These documents are not public. They can only be viewed by site administrators and users who hold a role at that business, through an endpoint that checks authorisation. The business's cover photo is public, because it is shown to guests.

What we use the data for

  • Creating your account and keeping you signed in
  • Listing businesses that are near you and discounted right now
  • Creating your reservations, passing them to the business, and cancelling them
  • Reviewing business applications and preventing abuse
  • Showing in-app notifications

Who we share it with

When you book, your name, time, party size and the group's split are shown to that business. Your email address is not shown to the business.

Beyond that we do not sell your data or share it for marketing. Sharing only happens to the extent technically necessary with parties required for the service to run, such as the address lookup service described above (OpenStreetMap Nominatim), our email delivery service (Resend), our menu reading service (Anthropic) and our hosting provider.

How long we keep it

Account data is kept while your account is open. Session records expire on their own after 30 days.

Reservation and business records are kept for the duration of commercial and tax retention obligations. Concluded business applications and change requests are not deleted, so that it remains possible to show who changed what and when.

Security

  • Passwords are stored as irreversible digests
  • The session cookie is closed to browser scripts (httpOnly) and, in production, sent only over a secure connection
  • Sign-in attempts are rate limited per account and per IP address
  • The type of an uploaded file is verified from the file's own contents, not from what the browser claims

Email delivery

Notifications are currently shown only inside the application; we do not send email or push notifications. The email and notification preferences on the settings page are saved and will apply once those channels are switched on.

Children

The platform is not designed for people under 18. Businesses may additionally set their own age limits, which are shown on the business's page.

Contact

You can send privacy questions to destek@rezervasyonbizde.com.

This site only uses cookies that are strictly necessary: keeping you signed in, remembering the business you manage, and securing sign-in. We do not use advertising or tracking cookies. Cookie Policy