DuoUp

DuoUp Privacy Policy

Last updated: 31 July 2026

1. Introduction and Data Controller

This Privacy Policy explains how your personal data is processed when you use the DuoUp mobile application (“DuoUp”, the “App”).

2. Scope and Applicable Law

As DuoUp is offered in more than one country, this policy is based on the following regulations:

3. Personal Data We Collect

Data categoryExamplesSource
Identity and contactFull name, email addressDirectly from you
AuthenticationYour password (stored only as a hashed value / bcrypt; we cannot see the plaintext), session tokensDirectly from you / automatically
ProfileDate of birth (the full date is stored; only your age is shown to others, the full date stays private), profile photoDirectly from you
LocationYour device location, and the exact geographic coordinates (latitude/longitude) together with a location label are stored persistently in the listings you createFrom your device (with permission)
ActivityThe sports/activities and skill levels you selectDirectly from you
Usage contentListings, applications, matches, in-match messages (content stored as plain text — see Section 7), ratings you give/receive (stars + predefined tags), friend connectionsDirectly from you
Device and notificationPush notification token, device platform (iOS/Android)Automatically
Technical dataIP address, request/access logs, error and performance logsAutomatically

DuoUp does not use an advertising ID, ad tracking, or marketing cookies/trackers. The push token is used solely to send notifications.

Social sign-in (OAuth) with Google/Apple may be added in the future; it is not currently active and no data is collected from such providers. This policy will be updated when it becomes active.

4. Purposes of Processing and Legal Bases

In accordance with GDPR Article 6 and KVKK Article 5, each processing activity relies on a legal basis:

PurposeLegal basis
Account creation, sign-in, authenticationPerformance of a contract
Location-based event/match suggestionsYour explicit consent (location permission)
In-app messaging and notificationsPerformance of a contract
Security, prevention of misuse, fraud preventionLegitimate interest
Error tracking and measuring service qualityLegitimate interest
Fulfilling legal obligationsLegal obligation

For processing based on explicit consent (e.g., location), you may withdraw your consent at any time; this does not affect the lawfulness of processing before withdrawal.

5. Third-Party Service Providers (Data Processors)

To provide the service, some of your data is shared, only to the extent necessary, with the providers below. These process data on our behalf and on our instructions:

ProviderData processedPurpose
Cloudflare R2Profile photosFile storage
Google Maps (react-native-maps)Location and map interactionMap display. Google also processes this data under its own privacy policy.
ExpoPush notification tokenNotification delivery
SentryContext data at the moment of a technical errorError tracking. Sensitive fields such as passwords and session tokens are automatically redacted from logs and are never sent.

Other than these providers, your data is not shared or sold to third parties unless legally required.

6. International Data Transfers

The infrastructure of the above providers may be located outside Türkiye and/or the EU:

Your personal data is therefore transferred abroad. For these transfers, we take the necessary steps to ensure appropriate safeguards required by applicable law (such as data processing agreements and standard contractual clauses).

7. Confidentiality of Messages

Your in-match messages are stored in plain text on our servers and are not end-to-end encrypted. This means messages may be accessed when necessary for security, investigating misuse complaints, and legal obligations. Please treat messaging not as a private/confidential channel but as an application feature subject to moderation.

8. Retention Periods

9. Data Security

We take appropriate technical and organizational measures to protect your data: passwords are stored hashed irreversibly (bcrypt), communication is encrypted with TLS, session tokens are managed with a revocation mechanism, and sensitive fields are redacted in logs. Although no system is 100% secure, we maintain reasonable measures to protect your data.

10. Your Rights

KVKK (Türkiye) — Article 11

You have the right to learn whether your personal data is processed, to request information, to learn the purpose of processing, to know the third parties to whom it is transferred, to request correction/erasure, to request that these be notified to third parties, to object to results arising against you from automated analysis, and to claim compensation for damages.

GDPR (EU users)

You have the rights of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection to processing, withdrawal of consent, and to lodge a complaint with a supervisory authority.

CCPA/CPRA (California residents)

You have the right to know what data is collected, to request deletion, to opt out of the “sale/sharing” of data (DuoUp does not sell data), and to non-discrimination for exercising these rights.

To exercise these rights, you can reach us at contact@duoup-app.com. We respond to your request within the statutory time frames.

11. Children's Privacy

DuoUp is intended only for individuals aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we determine that we have processed data belonging to someone under 18, we delete that data.

12. Changes

This policy may be updated from time to time. You will be informed within the app of significant changes. The current version is always published on this page.

13. Contact and Complaint Authorities

For questions and requests: contact@duoup-app.com