Privacy Policy
1. Introduction
Swipela ("Swipela", "we", "us", or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, process, store, and protect your personal data through the swipela.app website and the Swipela mobile application (collectively, the "Service").
This Policy has been prepared in accordance with the Turkish Personal Data Protection Law No. 6698 ("KVKK"), the European Union General Data Protection Regulation ("GDPR"), and all other applicable data protection legislation.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Policy, please do not use the Service.
2. Data Controller
The data controller responsible for processing your personal data is Swipela. You can contact the data controller using the following information:
- Email: support@swipela.app
- General Contact: support@swipela.app
3. Personal Data We Collect
We collect the following categories of personal data in connection with the provision of the Service:
3.1. Data You Provide Directly
- Account Information: Name, email address, password (stored in hashed form), and profile photo (optional).
- Style Preferences: Style quiz results, body type information, fashion preferences, and likes.
- Contact Information: Name, email address, and message content submitted through the contact form.
- User-Generated Content: Items added to the wardrobe, outfits created, community posts, and comments.
3.2. Data Collected Automatically
- Device Information: Device type, operating system, browser type and version, screen resolution, and unique device identifiers.
- Usage Data: Swipe interactions, like and skip preferences, products viewed, in-app navigation data, and session durations.
- Location Data: Approximate location based on IP address (country and city level only).
- Cookie and Tracking Data: Data collected through cookies, pixel tags, and similar technologies (see Section 8 for details).
- Analytics Data: Anonymous usage statistics collected via Google Analytics.
3.3. Data Obtained from Third Parties
- Social Media Data: Basic profile information obtained from the relevant platform if you sign in using a social media account.
- Brand and Retailer Data: Product information, pricing, and availability data obtained from third-party brands.
4. Purposes of Processing
Your personal data is processed for the following purposes:
- Service Delivery: Account creation, authentication, and provision of the core functionalities of the Service.
- Personalisation: Product recommendations based on your style preferences, personalised wardrobe and outfit suggestions.
- Price Comparison: Comparing product prices across different brands and presenting the best deals.
- Community Features: Facilitating user interactions, sharing, and community management.
- Notifications: Discount alerts, price change notifications, and campaign communications aligned with your preferences.
- Communication: Responding to your enquiries and handling support requests.
- Analytics and Improvement: Analysing Service usage, monitoring performance, and improving user experience.
- Security: Preventing fraud and abuse, and ensuring the security of the Service.
- Legal Obligations: Fulfilling legal obligations arising from applicable legislation.
5. Legal Basis for Processing
Your personal data is processed on the following legal bases:
- Consent: Your explicit consent for marketing communications, personalised recommendations, and non-essential cookies.
- Performance of a Contract: Data processing activities necessary for the provision of the Service (KVKK Art. 5/2-c; GDPR Art. 6/1-b).
- Legitimate Interest: Improving the Service, ensuring security, and preventing fraud (KVKK Art. 5/2-f; GDPR Art. 6/1-f).
- Legal Obligation: Compliance with applicable legal requirements (KVKK Art. 5/2-รง; GDPR Art. 6/1-c).
6. Sharing and Transfer of Personal Data
Your personal data may be shared with third parties under the following circumstances and conditions:
6.1. Service Providers
Your data may be shared with service providers in the following categories for the purpose of delivering the Service:
- Cloud hosting and infrastructure providers
- Analytics and performance monitoring tools (including Google Analytics)
- Email and notification service providers
- Customer support platforms
6.2. Business Partners
Limited data may be shared with brands and retailers with whom we cooperate for the purpose of price comparison and product information delivery.
6.3. Legal Requirements
Your personal data may be disclosed to relevant authorities where required by law, court order, or a request from a competent authority.
6.4. International Transfers
Some of our service providers are located outside of Turkey and/or the European Economic Area. Where your personal data is transferred internationally, such transfers will be carried out subject to appropriate safeguards (such as Standard Contractual Clauses or an adequacy decision) in accordance with KVKK Art. 9 and GDPR Chapter V.
7. Data Retention
Your personal data is retained for as long as necessary for the purposes for which it was collected, or as required by our legal obligations:
- Account Data: Retained while your account is active and deleted within 30 days of an account deletion request.
- Usage Data: Retained for a maximum of 26 months from the date of collection.
- Contact Data: Retained for a maximum of 2 years from the date your enquiry is resolved.
- Analytics Data: May be retained indefinitely in aggregated, anonymised form for statistical purposes.
- Legal Obligations: Retained for the period required by applicable legislation.
Data that has exceeded its retention period is securely deleted, destroyed, or anonymised.
8. Cookies and Tracking Technologies
Our Service uses the following types of cookies:
- Essential Cookies: Cookies required for the core functionality of the Service (session management, security).
- Analytics Cookies: Cookies used to collect anonymous usage statistics (Google Analytics).
- Preference Cookies: Cookies used to remember your language and display preferences.
Non-essential cookies are only used with your explicit consent. You may change your cookie preferences at any time through your browser settings or the cookie management tool provided on the Service.
Google Analytics: Our website uses Google Analytics, provided by Google Inc. Google Analytics is configured with IP anonymisation enabled. For more information, please refer to Google's Privacy Policy.
9. Data Security
We implement the following technical and organisational measures to ensure the security of your personal data:
- SSL/TLS encryption to protect data in transit
- Industry-standard hashing algorithms for password storage
- Regular security assessments and updates
- Access controls and authorisation mechanisms
- Data breach notification procedures
While no method of data transmission or storage is 100% secure, we take commercially reasonable security measures in line with industry standards to protect your data.
10. Your Rights
Under KVKK Art. 11 and the GDPR, you have the following rights:
- Right to Information: The right to learn whether your personal data is being processed.
- Right of Access: The right to request access to your processed personal data.
- Right to Rectification: The right to request correction of incomplete or inaccurate data.
- Right to Erasure: The right to request deletion or destruction of your personal data.
- Right to Restriction: The right to request the restriction of processing under certain conditions.
- Right to Data Portability: The right to receive your data in a structured, commonly used, and machine-readable format.
- Right to Object: The right to object to processing based on legitimate interest.
- Right to Withdraw Consent: The right to withdraw your consent at any time (withdrawal does not affect the lawfulness of processing carried out prior to withdrawal).
- Automated Decision-Making: The right to obtain information about and object to decisions based solely on automated processing.
- Right to Lodge a Complaint: The right to file a complaint with the Turkish Personal Data Protection Authority or the relevant EU data protection supervisory authority.
To exercise your rights, please contact us at support@swipela.app. Your requests will be responded to within 30 days at the latest.
11. Children's Privacy
Our Service is not directed at children under the age of 16. We do not knowingly collect personal data from individuals under the age of 16. If we become aware that we have collected personal data from a child under 16, we will take immediate steps to delete such data. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at support@swipela.app.
12. Third-Party Links
Our Service may contain links to third-party websites and applications (including brand and retailer websites). When you follow these links, the privacy policy of the respective third party will apply. We are not responsible for the privacy practices of third-party websites and recommend that you review their privacy policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. In the event of material changes, we will notify you through an in-app notification, email, or a notice on the website. The updated policy will take effect on the date of publication. Your continued use of the Service after such changes constitutes your acceptance of the updated policy.
14. Contact Us
For any questions, requests, or complaints regarding this Privacy Policy, please use the following contact channels:
- Email (Privacy): support@swipela.app
- Email (General): support@swipela.app