Citiveo is a city-guide and local-business platform. This policy explains which personal data we process when you use Citiveo, why we process it, with whom we share it, and what rights you have in relation to it.
Data controller: Ebtnet Bilişim ve İnternet Hizmetleri Limited Şirketi, Esenyalı Mah. Yanyol Cad. Varyap Plaza No:61 İç Kapı No:247, Pendik / İstanbul (0323141039100001). Contact: kvkk at citiveo.com.
1. What data we process
Account data. Registration on Citiveo is carried out using e-mail address and password only. We store your e-mail address, the irreversible hash of your password (bcrypt), your name if provided, and your preferred language. Upon registration, we send a verification link valid for 24 hours to your e-mail address.
Phone number — optional. A phone number is not a sign-in method on Citiveo. It is stored solely as a notification and communication channel, and only if you choose to add it and verify it by SMS. You may remove it from your profile at any time.
Content you generate. Your reviews and ratings, saved places, routes you have created, and photos you have uploaded.
Coupon and passport data. Single-use coupon codes you have obtained, whether those codes have been redeemed, points you have earned, and your city-passport stamps.
Business-ownership data. The application information you submit in order to claim a business listing, and the verification documents you upload (such as a tax certificate, licence, or guide badge). These documents are not publicly accessible; they are viewed only by authorised personnel reviewing the application, and any location metadata (EXIF data) is stripped at the time of upload.
City-partner data. Information you submit when applying to the city-partner programme (region preference, experience, references), together with — for active partners — the name, IBAN, and tax-identification details required for service-fee payments, as well as service-fee and payment records. Any change to an IBAN is verified through a dual-channel process using both e-mail and SMS.
Usage measurement. We measure events such as which business pages are viewed and whether the call, WhatsApp, directions, or social-media buttons are tapped. This measurement is non-identifying: no IP address is stored, no cookies are used, and the browser's "Do Not Track" signal is honoured. Measurement data is presented to the business owner in their dashboard as aggregate counts only.
Google Analytics 4 — with your explicit consent only. If you enable the Analytics category in your cookie preferences, Google Analytics 4 is loaded to measure how you use the site. In that case, the data processed comprises: pseudonymous online identifiers (a cookie ID placed in your browser), the pages you view and your interactions on those pages, and device and browser information. Your IP address is anonymised; Google Analytics 4 does not record or store IP addresses. If you do not grant consent, Google Analytics 4 is not loaded at all.
Two-factor authentication data. When you use two-factor authentication (mandatory for business, city-partner, and administration accounts): the secret key paired with your authenticator app is stored in encrypted form, your recovery codes are stored as irreversible hashes only, and a record is kept of devices for which you have selected the "remember this device" option.
Location. We use your location only when you grant permission and only for the duration of that session (for "near me" features). We do not track your location in the background and we do not store your location.
Payments. For business subscriptions, your card details never reach us. Payment is taken on iyzico's own secure page; we hold only the card tokens generated on the iyzico side, together with subscription status, amount, currency, and invoice records.
2. Why we process data and our legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Creating your account and enabling sign-in | e-mail address, password hash | Formation and performance of a contract |
| Issuing coupons and validating them at the point of redemption | coupon code, redemption record | Performance of a contract |
| Publishing reviews | content, account name | Performance of a contract / legitimate interests |
| Verifying business ownership | application information and documents | Performance of a contract, legal obligation |
| Subscription billing and invoicing | payment and invoice records | Legal obligation (tax legislation) |
| Preventing abuse | rate limiting, human verification | Legitimate interests |
| Business-dashboard statistics | non-identifying measurement events | Legitimate interests |
| Newsletter and marketing communications | e-mail address, phone number | Explicit consent (including IYS registration), withdrawable at any time |
| Measuring how the site is used (Google Analytics 4) | pseudonymous identifiers, pages viewed, device and browser information | Explicit consent, withdrawable at any time via cookie preferences |
| Protecting your account with two-factor authentication | encrypted authenticator key, recovery-code hashes, remembered-device records | Performance of a contract and data-security obligation (KVKK Art. 12) |
Consent to marketing is separate from your sign-in and use of the service. Unsubscribing from the newsletter has no effect on your account.
3. With whom we share data
The following are the service providers we actually use in order to operate the service. We do not sell your personal data to anyone for advertising purposes.
| Provider | Purpose | What is transferred |
|---|---|---|
| iyzico (Turkey) | Subscription billing, 3D Secure | Name, e-mail address, amount, subscription reference. Card data goes directly to iyzico and never passes through us |
| Resend (US/EU) | Transactional and newsletter e-mails | E-mail address, message content |
| Cloudflare Turnstile (US) | Bot/human verification on forms | Technical data relating to the verification request |
| Anthropic (Claude) (US) | Content translations and city-assistant responses | The text content being translated; the question you ask the assistant |
| CollectAPI (Turkey) | On-call pharmacy data | Province/district information only — no personal data is transferred |
| Open-Meteo (EU) | Weather and sea conditions | City coordinates only — no personal data is transferred |
| AeroDataBox / RapidAPI | Flight information board | Airport code only — no personal data is transferred |
| OpenFreeMap / OpenStreetMap | Map tiles | Technical request data from the browser displaying the map |
| Cloudflare | CDN, security, and image delivery | Technical connection data |
| Google (Google Analytics 4) (US) | Site-usage statistics — with explicit consent only | Pseudonymous identifiers, pages viewed, device and browser information; IP address is anonymised |
International transfers. Some of the providers listed above are located outside Turkey. In such cases, personal data is transferred pursuant to KVKK Art. 9 and GDPR Chapter V, on the basis of the provider's standard contractual clauses and technical security commitments. No personal data is sent to the on-call pharmacy, weather, or flight providers; only geographic information such as a city name or airport code is transmitted to them.
International transfers of Google Analytics 4 data. Data processed through Google Analytics 4 is transferred to Google's servers in the United States. This transfer is based on your explicit consent under KVKK Art. 9: if you do not enable the Analytics category, Google Analytics 4 is not loaded and this transfer does not take place. You may withdraw your consent at any time by disabling the Analytics category via the "Cookie preferences" link at the bottom of every page; upon withdrawal, collection ceases, but data already transmitted cannot be recalled.
4. How long we retain data
- Account data: for as long as your account remains open.
- Reviews: for as long as they remain published; if you delete your account, reviews are anonymised under the label "deleted user".
- Coupons and passport stamps: if you delete your account, unused coupons are invalidated and stamps are deleted.
- Ownership-verification documents: retained for a reasonable period after the application is concluded, then deleted.
- Payment and invoice records: 10 years, as required by tax legislation.
- City-partner service-fee and payment records: 10 years, as required by tax legislation.
- Non-identifying usage measurement: may be retained indefinitely as aggregate statistics, as it contains no personal data.
- Google Analytics 4: identifier cookies remain in the browser for a maximum of 2 years; event data on Google's side is deleted upon expiry of the retention period configured in Google Analytics.
- Two-factor authentication: the secret key and recovery-code hashes are retained for as long as two-factor authentication is enabled; remembered-device records expire after 30 days. All three are deleted when two-factor authentication is disabled.
5. Your rights and how to exercise them
Under KVKK Art. 11 and GDPR Arts. 15–22, you have the right to access, rectify, erase, and port your data, and to object to its processing. Citiveo has built two of these directly into the product:
- Download your data. From your profile page, you can obtain an immediate machine-readable export of the data associated with your account.
- Delete your account. You may submit a deletion request from your profile. The request is processed with a 30-day waiting period: during this period you may change your mind and cancel the request; once the period expires, your account is irreversibly deleted and your personal data fields are cleared. If you are the sole owner of a business listing, you must first transfer or close the business listing before proceeding.
For all other requests and complaints: kvkk at citiveo.com. We will respond to your request within 30 days at the latest. You also retain the right to lodge a complaint with the Personal Data Protection Authority (Kişisel Verileri Koruma Kurulu).
6. Security
Passwords are stored only as bcrypt hashes. Session cookies are HttpOnly and HTTPS is enforced. Location metadata (EXIF data) is stripped from uploaded images. Rate limiting and Cloudflare Turnstile human verification are applied to guard against abuse. Access to administration screens is role-based. Two-factor authentication is mandatory for business, city-partner, and administration accounts; the authenticator app's secret key is stored in encrypted form, and recovery codes are stored only as irreversible hashes.
7. Children
Citiveo is not designed for persons under the age of 18 and does not knowingly collect personal data from children.
8. Changes
When we update this policy, we will change the "last updated" date at the top of the page. For material changes, we will notify registered users by e-mail.