DuoUp Privacy Policy
Last updated: 31 July 2026
1. Introduction and Data Controller
This Privacy Policy explains how your personal data is processed when you use the DuoUp mobile application (“DuoUp”, the “App”).
- Data Controller: Nuri Kon (individual)
- Contact: contact@duoup-app.com
2. Scope and Applicable Law
As DuoUp is offered in more than one country, this policy is based on the following regulations:
- KVKK — Law No. 6698 on the Protection of Personal Data (Türkiye)
- GDPR — European Union General Data Protection Regulation (EU users)
- CCPA/CPRA — California Consumer Privacy Act (U.S., California residents)
3. Personal Data We Collect
| Data category | Examples | Source |
|---|---|---|
| Identity and contact | Full name, email address | Directly from you |
| Authentication | Your password (stored only as a hashed value / bcrypt; we cannot see the plaintext), session tokens | Directly from you / automatically |
| Profile | Date of birth (the full date is stored; only your age is shown to others, the full date stays private), profile photo | Directly from you |
| Location | Your device location, and the exact geographic coordinates (latitude/longitude) together with a location label are stored persistently in the listings you create | From your device (with permission) |
| Activity | The sports/activities and skill levels you select | Directly from you |
| Usage content | Listings, applications, matches, in-match messages (content stored as plain text — see Section 7), ratings you give/receive (stars + predefined tags), friend connections | Directly from you |
| Device and notification | Push notification token, device platform (iOS/Android) | Automatically |
| Technical data | IP address, request/access logs, error and performance logs | Automatically |
DuoUp does not use an advertising ID, ad tracking, or marketing cookies/trackers. The push token is used solely to send notifications.
Social sign-in (OAuth) with Google/Apple may be added in the future; it is not currently active and no data is collected from such providers. This policy will be updated when it becomes active.
4. Purposes of Processing and Legal Bases
In accordance with GDPR Article 6 and KVKK Article 5, each processing activity relies on a legal basis:
| Purpose | Legal basis |
|---|---|
| Account creation, sign-in, authentication | Performance of a contract |
| Location-based event/match suggestions | Your explicit consent (location permission) |
| In-app messaging and notifications | Performance of a contract |
| Security, prevention of misuse, fraud prevention | Legitimate interest |
| Error tracking and measuring service quality | Legitimate interest |
| Fulfilling legal obligations | Legal obligation |
For processing based on explicit consent (e.g., location), you may withdraw your consent at any time; this does not affect the lawfulness of processing before withdrawal.
5. Third-Party Service Providers (Data Processors)
To provide the service, some of your data is shared, only to the extent necessary, with the providers below. These process data on our behalf and on our instructions:
| Provider | Data processed | Purpose |
|---|---|---|
| Cloudflare R2 | Profile photos | File storage |
| Google Maps (react-native-maps) | Location and map interaction | Map display. Google also processes this data under its own privacy policy. |
| Expo | Push notification token | Notification delivery |
| Sentry | Context data at the moment of a technical error | Error tracking. Sensitive fields such as passwords and session tokens are automatically redacted from logs and are never sent. |
Other than these providers, your data is not shared or sold to third parties unless legally required.
6. International Data Transfers
The infrastructure of the above providers may be located outside Türkiye and/or the EU:
- Cloudflare R2 — storage region: Eastern Europe
- Sentry, Expo — United States
- Google — global infrastructure
Your personal data is therefore transferred abroad. For these transfers, we take the necessary steps to ensure appropriate safeguards required by applicable law (such as data processing agreements and standard contractual clauses).
7. Confidentiality of Messages
Your in-match messages are stored in plain text on our servers and are not end-to-end encrypted. This means messages may be accessed when necessary for security, investigating misuse complaints, and legal obligations. Please treat messaging not as a private/confidential channel but as an application feature subject to moderation.
8. Retention Periods
- Account and profile data: When you delete your account, data is not deleted immediately; your account is kept in a “suspended” state for 30 days (during which you can restore it by signing in again). After 30 days, your personal data is irreversibly anonymized.
- Content such as listings, messages, ratings: Tied to your account; when the account is anonymized, the personal link in this content is also removed.
- Technical/error logs: IP/access and error logs are kept for a limited period for security and the operation of the service.
9. Data Security
We take appropriate technical and organizational measures to protect your data: passwords are stored hashed irreversibly (bcrypt), communication is encrypted with TLS, session tokens are managed with a revocation mechanism, and sensitive fields are redacted in logs. Although no system is 100% secure, we maintain reasonable measures to protect your data.
10. Your Rights
KVKK (Türkiye) — Article 11
You have the right to learn whether your personal data is processed, to request information, to learn the purpose of processing, to know the third parties to whom it is transferred, to request correction/erasure, to request that these be notified to third parties, to object to results arising against you from automated analysis, and to claim compensation for damages.
GDPR (EU users)
You have the rights of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection to processing, withdrawal of consent, and to lodge a complaint with a supervisory authority.
CCPA/CPRA (California residents)
You have the right to know what data is collected, to request deletion, to opt out of the “sale/sharing” of data (DuoUp does not sell data), and to non-discrimination for exercising these rights.
To exercise these rights, you can reach us at contact@duoup-app.com. We respond to your request within the statutory time frames.
11. Children's Privacy
DuoUp is intended only for individuals aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we determine that we have processed data belonging to someone under 18, we delete that data.
12. Changes
This policy may be updated from time to time. You will be informed within the app of significant changes. The current version is always published on this page.
13. Contact and Complaint Authorities
For questions and requests: contact@duoup-app.com
- Türkiye: You may file a complaint with the Personal Data Protection Authority (KVKK).
- EU: You may file a complaint with the data protection supervisory authority of your country of residence.