Seszil ("we", "us", "the app") helps you create QR codes ("QR points") so people can reach you
without exposing your personal contact details. This policy explains what data we collect, why,
and your rights. The service is operated by Eren Duran, based in
Turkey. Contact: admin@seszil.com.
1. Information we collect
Account data
Email address and a securely hashed password (we never store passwords in plain text).
If you use Sign in with Apple or Sign in with Google: your email
and name as provided by Apple/Google (we never receive your password).
Email verification status and account/session tokens.
Content you create
Your QR points and the public "identity" details you choose to show scanners.
Images you upload (e.g. profile or QR visuals).
Messages from scanners ("interactions")
When someone scans your QR point and submits a message, we collect that message and related
metadata (such as the time) and deliver it to you. Visitors are not required to create an account.
Device & push data
A device push token (Apple APNs / Google FCM) so we can send you notifications.
Basic device/app info (platform, app version, language) for delivery and support.
Purchases (if you subscribe)
Subscription/entitlement status processed via our payments provider. We do not
receive your full card details — payments are handled by Apple and our purchases provider.
Security / anti-abuse
We use Cloudflare Turnstile to block bots and spam on public forms.
2. How we use your data
To provide the service: authentication, creating and managing QR points, delivering scanner
messages, and sending push notifications.
To operate subscriptions and enforce plan limits.
To secure the service, prevent abuse, and comply with legal obligations.
3. Legal bases (GDPR / KVKK)
Performance of a contract — to provide the app you signed up for.
Legitimate interests — security, abuse prevention, and improving the service.
Consent — push notifications (you can disable them anytime in your device settings).
Legal obligation — where the law requires retention or disclosure.
4. Sharing & third parties
We do not sell your personal data. We share data only with service providers that help us run Seszil:
Amazon Web Services (AWS) — hosting and storage, in the EU (Frankfurt).
Apple (APNs) and Google (FCM) — to deliver push notifications.
Apple / Google sign-in — only if you choose those login methods.
Cloudflare — bot and spam protection.
Our payments provider — subscription processing, if you purchase.
5. Data retention
Account data is kept while your account is active.
Scanner messages / notifications are retained according to your plan (for example,
the free plan keeps notifications for 7 days; paid plans longer).
When you delete your account, we delete or anonymize your personal data within a reasonable period,
except where we must keep it for legal reasons.
6. Your rights
Depending on your location (GDPR, Turkey's KVKK, and similar laws), you can request to
access, correct, delete, export, or restrict processing of your data, and
object to certain processing. To exercise these rights, contact
admin@seszil.com.
Deleting your account: you can delete your account from within the app, or by emailing
admin@seszil.com. Deleting your account removes your device push
registrations and personal data as described above.
7. Security
We use encryption in transit (HTTPS/TLS), hashed passwords, and the device keychain for sensitive
tokens. No method is 100% secure, but we take reasonable measures to protect your data.
8. Children
Seszil is not directed to children under 13 (or the minimum age in your country). We do not knowingly
collect their data.
9. International transfers
Your data is processed in the EU (Frankfurt). Where data is transferred internationally, we rely on
appropriate safeguards as required by law.
10. Changes
We may update this policy; we will post the new version here with an updated effective date.