Legal · Privacy
Privacy Policy
Last updated: · v2026.05.17
1. Who we are
The controller of personal data processed in connection with the Service is [Şirket — kuruluş aşamasında] (Poi Geo). Postal address: [Şirket — kuruluş aşamasında].
You can reach our privacy team at privacy@poigeo.app and our Data Protection Officer at dpo@poigeo.app. Users in the EU/EEA may also contact our EU representative at [kuruluş aşamasında]; users in the UK may contact our UK representative at [kuruluş aşamasında]. Users in Türkiye may contact our KVKK desk at kvkk@poigeo.app.
2. Scope of this Policy
This Policy describes how we handle personal data when you visit our websites, use the Service, communicate with us, or otherwise interact with the Poi Geo brand. It does not cover (i) data we process on behalf of business customers under their own privacy notices (those customers are the controller — see Section 7 and our DPA), or (ii) third-party websites or services we link to.
Where you reside in a jurisdiction with specific privacy law, the relevant regional supplement adds to and, in case of conflict, overrides this Policy.
3. Information we collect
We collect the following categories of personal data:
- Identity & contact. Email address; optional display name; password (hashed, never seen in clear).
- Account & billing. Plan tier, subscription status, analysis quota, invoices. Payment card numbers are handled by our Merchant of Record, Lemon Squeezy, and its payment processors, and never reach our servers; we store only the last four digits and a Lemon Squeezy order/customer reference.
- Usage data. Analyses you run (timestamp, latitude/longitude or polygon, radius, sector filters), the resulting Reports, page views, click events, interface preferences (language, theme), and error/diagnostic logs.
- Device & connection data. IP address (stored as a salted hash for anti-abuse, kept up to 30 days), browser User-Agent, screen resolution, OS, and a non-tracking browser fingerprint hash (canvas + WebGL) used solely to detect multi-accounting and trial abuse. Approximate country and region are derived from your IP at the edge (Vercel / Cloudflare) and never stored linked to your Account.
- Communications. Support emails and chats; metadata about transactional emails (open / bounce status).
- Location inputs. The geographic coordinates you analyse. These arenot your personal location — they are the points you choose to study. They are cached at the H3-cell level (not tied to your Account) to reduce cost and improve speed.
We do not collect:precise device GPS, browsing history outside the Service, contacts, social-graph data, biometrics, or sensitive categories of personal data unless you explicitly send them to us in support correspondence (please don't).
4. How we use information
We use personal data for the following purposes:
- to provide, operate, secure, and improve the Service;
- to generate Reports and AI Outputs requested by you;
- to authenticate sessions, enforce plan limits, detect fraud and abuse (anti-multi- accounting, anti-scraping, rate-limiting);
- to bill you and collect payment via Lemon Squeezy (our Merchant of Record);
- to communicate with you (account, billing, security, service-impact, and — only with your consent where required — product updates);
- to perform analytics necessary to improve the Service (we do not use third-party advertising or cross-context behavioural analytics);
- to comply with law, including tax, accounting, sanctions, anti-money-laundering, and information-request obligations; and
- to establish, exercise, or defend legal claims.
5. Legal bases (GDPR / UK-GDPR)
Where the GDPR or UK-GDPR applies, our legal bases are:
- Contract (Art. 6(1)(b)) — to provide the Service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent fraud and abuse, debug and improve the product, defend legal claims, and run our business. We balance these against your rights and you may object at any time.
- Legal obligation (Art. 6(1)(c)) — to keep tax, accounting, and sanctions records and respond to lawful requests.
- Consent (Art. 6(1)(a)) — where we ask for it (e.g. optional product updates). You can withdraw consent at any time without affecting prior lawful processing.
6. Cookies & similar technologies
We use a small number of strictly necessary, first-party cookies: an authentication session cookie (Supabase), a locale-preference cookie, and short-lived anti-abuse cookies. We do not place advertising, social, or cross-site analytics cookies, and we do not allow third parties to read or write cookies through our pages other than as listed on the Sub-processor page. See the full list and durations in the Cookie Policy.
7. Sharing & recipients
We share personal data only as follows:
- Sub-processors — vendors that process data on our behalf under written contracts (including Standard Contractual Clauses where applicable). The current list is at /legal/sub-processors.
- Business customers acting as controllers — for example, if your employer paid for your seat, we provide them with administrative information about your Account (not the content of your analyses unless they enable that explicitly).
- Authorities & legal claimants — where required by law, court order, or to establish, exercise, or defend legal claims, subject to the safeguards described in our regional supplements.
- Corporate transactions — in connection with a merger, acquisition, financing, reorganisation, bankruptcy, or sale of assets, subject to confidentiality.
We do not sell personal data and we do not share it for cross-context behavioural advertising as those terms are defined by the California Consumer Privacy Act / California Privacy Rights Act or analogous laws.
8. International data transfers
Our infrastructure providers operate globally. Your data may be processed in the United States, the European Union, the United Kingdom, and other jurisdictions where our providers operate (see Sub-processors).
Where data is transferred outside the EEA, the United Kingdom, Switzerland, Türkiye, Brazil, or other countries with cross-border restrictions, we rely on appropriate safeguards including: the European Commission's Standard Contractual Clauses (2021) and UK Addendum; supplementary technical and organisational measures (encryption in transit and at rest, access controls); KVKK Art. 9 standard contractual undertakings; LGPD Art. 33 contractual safeguards; and the equivalents under Swiss and Australian law. You may request a copy of the safeguards in place by emailing privacy@poigeo.app.
9. Retention
We retain personal data only for as long as necessary. Indicative periods:
- Account data — while the Account is active, then 30 days after closure for backups.
- Analysis Reports — for as long as you keep them, up to subscription end + 30 days.
- Analysis cache (H3-cell keyed, not Account-linked) — 30–180 days depending on data type, then automatically purged.
- Hashed IP / fingerprint anti-abuse log — up to 30 days.
- Billing records / invoices — as required by tax law, typically 10 years.
- Support correspondence — 3 years.
- Security logs — 12 months.
10. Security
We implement technical and organisational measures appropriate to the risk, including TLS for all data in transit, encryption at rest for our database, single-tenant logical isolation per customer, principle-of-least-privilege access, multi-factor authentication for staff, regular dependency audits, and incident-response runbooks. No system is perfectly secure; if you believe you have found a vulnerability please email abuse@poigeo.app.
11. Breach notification
In the event of a personal data breach likely to result in risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours (GDPR Art. 33 / UK-GDPR; comparable timelines under KVKK, LGPD, FADP, and Australian Notifiable Data Breaches). If the risk is high, we will also notify affected data subjects without undue delay.
12. Your rights
Subject to applicable law and verification of your identity, you have the right to (i) access your personal data, (ii) request correction of inaccurate data, (iii) request deletion, (iv) restrict or object to processing, (v) data portability, (vi) withdraw consent where processing is based on consent, and (vii) lodge a complaint with your supervisory authority.
To exercise your rights, email privacy@poigeo.app. We respond within 30 days (one month under GDPR; 30 days under KVKK; 45 days under CCPA — with a possible 45-day extension). We will not discriminate against you for exercising your rights.
13. Automated decision-making & AI
We use AI components (currently Google Gemini) to generate Reports. The AI Outputs are decision-support, not automated decisions producing legal or similarly significant effects on you within the meaning of GDPR Art. 22. You remain the decision-maker. See our AI Disclosure for details about training data, model providers, and the limits of the technology.
Our Terms of Service §14 prohibits using AI Outputs for decisions about housing, credit, employment, insurance, or government benefits, or to evaluate identifiable persons.
14. Children
The Service is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 16 (under 13 in the United States within the meaning of COPPA). If you believe a child has provided personal data, contact privacy@poigeo.app and we will delete it.
15. Sensitive / special category data
The Service is not designed to process special category data within the meaning of GDPR Art. 9 (racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric data, health data, sex life, sexual orientation), KVKK Art. 6, or analogous categories in other regimes. Aggregate, neighbourhood-level cultural or demographic estimates produced by our AI from public points-of-interest are not intended as inferences about specific individuals, and you must not use them as such (see Terms §14).
16. Do not sell / do not share
As stated in Section 7, we do not sell or “share” personal data for cross-context behavioural advertising under the CCPA/CPRA, nor do we engage in comparable practices under other jurisdictions' laws. Because no sale or sharing occurs, there is no need to opt out — but you may still submit a request to confirm this at privacy@poigeo.app.
17. How to contact us & complain
Email privacy@poigeo.app or write to [Şirket — kuruluş aşamasında]. If you are not satisfied, you have the right to lodge a complaint with the supervisory authority in your country of residence — for example, your national Data Protection Authority within the EU, the UK ICO (ico.org.uk), the Kişisel Verileri Koruma Kurumu in Türkiye (kvkk.gov.tr), the Autoridade Nacional de Proteção de Dados in Brazil (gov.br/anpd), the Office of the Australian Information Commissioner (oaic.gov.au), the Office of the Privacy Commissioner of Canada (priv.gc.ca), the Personal Information Protection Commission in Japan (ppc.go.jp), or the Federal Data Protection and Information Commissioner in Switzerland (edoeb.admin.ch).
18. Changes to this Policy
We may update this Policy. Material changes will be notified at least 30 days before taking effect (by email or in-app banner). The “Last updated” date at the top reflects the most recent revision.
19. Regional supplements
The following supplements add to and, where conflicting, override this Policy in respect of users in the listed jurisdictions:
- California — CCPA / CPRA Supplement
- United States — Federal & non-CA state Supplement
- Türkiye — KVKK Aydınlatma Metni
- Canada — PIPEDA Supplement
- Australia — Privacy Act Supplement
- Brazil — LGPD Supplement
- Japan — APPI Supplement
- Switzerland — FADP Supplement
For users in the European Union, EEA, or United Kingdom: this Policy is written to be GDPR / UK-GDPR aligned. We do not currently maintain an Article 27 representative or an ICO registration; if you reside in those regions, please contact us directly using the addresses in Section 1 and we will respond in line with GDPR/UK-GDPR requirements.
Not legal advice. This Policy explains our practices. It is not legal advice. Where local mandatory law gives you stronger rights than appear here, those rights apply.