Privacy Policy
Last updated: 9 October 2026
In short:
- We use your data only to run Seferim.
- No ads. We don't sell your data. No profiling.
- The app contains no advertising or third-party analytics (tracking) tools.
- Your records are stored in the European Union (Frankfurt, Germany).
- Receipt scanning runs on your phone; receipt photos are not sent anywhere for it.
- You can delete your account from inside the app at any time.
This policy explains how personal data is processed when you use the Seferim mobile app and the seferim.tr website. It is written with the EU General Data Protection Regulation (GDPR) and Türkiye's Personal Data Protection Law No. 6698 (KVKK) in mind. The Turkish version also serves as our KVKK information notice.
1. Who we are
The controller for Seferim account and usage data is:
Panda YazılımAddress: Ostim OSB Mah. 100. Yıl Bul. No:55, Yenimahalle, Ankara, Türkiye
Tax office / number: Ostim / 1020650170
Email: destek@seferim.tr
"We" and "us" in this policy refer to this company.
2. What data we process
2.1 Your account
- Email address
- Name
- Phone number (optional)
- If you sign in with Apple or Google: the profile picture URL they provide (if any)
We don't use passwords. You sign in with a one-time code sent to your email, with Sign in with Apple, or with Google sign-in. There is no SMS sign-in. If you choose to hide your email with Sign in with Apple, we receive the relay address Apple gives us.
2.2 Your firm and business records
The business information you enter in the app:
- Firm: firm name, tax number and tax office (optional), currency
- Vehicles: plate, type, model year, odometer, purchase and loan details
- Trips: route (as text), dates, freight, VAT, commission, km
- Expenses: category, amount, litres, receipt photos
- Money movements: payments and collections
- Cheques and promissory notes: their details and photos
- Reminders: dates such as vehicle inspection and insurance
- Notes
- Firm members and their roles, and invitations (the invitee's email)
- Change history (audit log): who changed what, and when
2.3 Data about other people (your customers, brokers, fuel stations)
You can enter the names, phone numbers, emails and tax numbers of your customers, brokers and fuel stations.
For this data, you (your firm) are the controller. We process it only on your behalf and on your instructions, to provide the service; we act as your processor. You must have a lawful basis for entering this data (for example, your business relationship with them) and inform those people where required.
2.4 Device and technical data
- Push notification token: if you turn on notifications, so we can send them to your phone.
- App language.
- Crash and error reports (Sentry): if the app crashes or hits an error, technical details of the error are sent. These reports are configured not to include your personal data (such as name, email or IP address). About 20% of sessions are sampled to measure performance.
- Server logs: while running the service, our infrastructure provider keeps technical logs such as request times and IP addresses. We use them only for security and debugging.
3. What stays on your phone
- Receipt scanning: reading the amount and litres from a receipt happens on your phone (Apple Vision / Google ML Kit). Receipt photos are not sent to any server for this. If you attach the photo to an expense, it is stored with that record.
- Voice trip entry: this uses your phone's built-in speech recognition. Depending on your phone's settings, your voice may be processed by Apple's or Google's speech services under their own privacy policies. We don't receive or store the audio; we only use the resulting text. Using this feature is optional.
4. Why we process data
- To provide the service: keep your trips, expenses, receivables and payables; prepare statements and reports; send reminders.
- To verify your identity and let you sign in.
- To send sign-in codes and service notifications.
- To manage your subscription.
- To keep the service secure and prevent abuse.
- To find and fix errors.
5. What we never do
- No advertising; we don't use your data for ads.
- We don't sell or rent your data.
- No profiling and no automated decision-making about you.
- No third-party analytics or advertising SDKs in the app.
6. Who we share data with
We share data only with the following providers that help us run the service, and only as much as they need. They may not use your data for their own purposes (Apple's and Google's own services are also governed by their own policies).
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file (photo) storage | EU — Frankfurt, Germany (AWS eu-central-1) |
| Amazon Web Services (SES) | Sending sign-in code emails | EU / may include USA |
| Apple App Store, Google Play | Subscription payments (we never see your card details) | Global |
| RevenueCat | Subscription status management | USA |
| Google Firebase Cloud Messaging, Apple Push Notification service | Sending notifications | Global |
| Sentry | Error reporting | May include USA |
| Apple, Google | Sign in with Apple / Google sign-in (if you choose them) | Global |
Apart from these, we disclose data only where the law requires it (for example, a court order or a request from a competent authority).
When you share outputs such as a statement, a trip PDF or the accountant CSV file (for example via WhatsApp or email), that sharing happens through the app you choose and is your responsibility.
7. Who sees what inside a firm
Each firm's records are kept separate; one firm cannot see another firm's data. Inside a firm, access depends on role:
- Owner and Manager: manage the firm's records.
- Driver: sees only the vehicles assigned to them.
- Accountant and Viewer: see what their role allows.
The firm owner decides who joins the firm and with which role.
8. Verification links
When you share a statement or trip PDF, it carries a QR code or link. Whoever opens it can verify a snapshot of the document as it was when shared. The link shows only that shared snapshot, gives no access to anything else in your account, and expires after 180 days.
9. International transfers
Your records are stored in the European Union (Germany). Some of our providers (RevenueCat, Sentry, Google, Apple, AWS) may also process data in other countries, including the USA.
For these transfers we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, recognised certification frameworks. For transfers from Türkiye, we follow the transfer rules in Article 9 of the KVKK (for example, standard contracts approved by the Turkish Personal Data Protection Board), and where the law requires your explicit consent, we ask for it separately.
10. How long we keep data
- We keep your data while your account is active.
- When you delete your account, data is removed from our live systems immediately and purged from backups within 30 days.
- If the law requires us to keep certain data, we keep it only for that period and that purpose.
Important: your firm's own bookkeeping and record-keeping obligations (for example under tax law) are your responsibility. Before deleting your account, we recommend exporting your records using the app's PDF statements and the accountant CSV export. More details: Delete your account.
11. Security
- All traffic between the app and our servers is encrypted in transit (TLS).
- Stored data is encrypted at rest by our infrastructure provider.
- The database enforces row-level access control: each person can only reach records of their own firm, as their role allows.
- Since we don't use passwords, there is no password to steal.
No system is perfectly secure. If a personal data breach occurs, we will notify the competent authority and affected people as the law requires.
12. Subscriptions and payments
You can try Seferim free for 30 days without entering a card. After that, paid plans are sold through the Apple App Store or Google Play. Apple or Google takes the payment; we never see your card details. We track your subscription status (which plan, valid until when) through RevenueCat.
13. Children
Seferim is not intended for anyone under 18. We do not knowingly collect data from people under 18. If you believe this has happened, contact us and we will delete it.
14. Legal bases
- Performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)): your account, sign-in, keeping your records, statements and reminders, your subscription.
- Legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)): requests from authorities, statutory retention.
- Legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)): security, abuse prevention, error reports and improving reliability, provided your rights and freedoms are not overridden.
- Consent (GDPR Art. 6(1)(a); KVKK Art. 5(1)): push notifications (you give it via your phone's notification permission and can withdraw it any time in your phone settings), and international transfers where consent is legally required.
15. Your rights (GDPR)
If you are in the European Economic Area (or a country with similar rules), you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict processing in certain cases;
- Data portability: receive your data in a structured, machine-readable format;
- Object to processing based on legitimate interests;
- Withdraw consent at any time, without affecting earlier processing;
- Lodge a complaint with your local data protection authority.
To exercise these rights, email destek@seferim.tr from the email address registered to your Seferim account. We reply within one month. Some things you can do yourself in the app: export PDF statements and the accountant CSV file, and delete your account.
If your request concerns data that a firm entered about you (for example, you are a customer of a Seferim user), the firm is the controller; please contact them first. We will help them respond.
16. Users in Türkiye (KVKK)
Under Article 11 of the KVKK you may, among other things, learn whether your data is processed, request information about it, learn the purpose and whether it is used accordingly, know the third parties it is transferred to in Türkiye or abroad, request correction or deletion, request that third parties be notified of these, object to adverse results arising solely from automated analysis, and claim compensation for damage caused by unlawful processing.
Apply by email to destek@seferim.tr from your registered email address, or in writing to Ostim OSB Mah. 100. Yıl Bul. No:55, Yenimahalle, Ankara, Türkiye, in line with the Communiqué on the Procedures and Principles of Application to the Data Controller. We respond free of charge within 30 days. If your application is rejected or unanswered, you may complain to the Personal Data Protection Board (KVKK Kurulu). Full details are in the Turkish version.
17. This website
seferim.tr uses no cookies and contains no visitor tracking or analytics tools.
The site is hosted on Cloudflare (Cloudflare, Inc.). To deliver the pages, Cloudflare briefly processes visitors' IP addresses and request data for security and to operate the service; this data is not used for profiling or advertising.
18. Changes to this policy
We may update this policy from time to time. If we make an important change, we will let you know in the app or by email. The current version is always on this page; the date at the top shows the last update. If the English and Turkish versions differ, the Turkish version prevails.
Questions? Email destek@seferim.tr.