Privacy Policy

Last updated: 9 October 2026

In short:

This policy explains how personal data is processed when you use the Seferim mobile app and the seferim.tr website. It is written with the EU General Data Protection Regulation (GDPR) and Türkiye's Personal Data Protection Law No. 6698 (KVKK) in mind. The Turkish version also serves as our KVKK information notice.

1. Who we are

The controller for Seferim account and usage data is:

Panda Yazılım
Address: Ostim OSB Mah. 100. Yıl Bul. No:55, Yenimahalle, Ankara, Türkiye
Tax office / number: Ostim / 1020650170
Email: [email protected]

"We" and "us" in this policy refer to this company.

2. What data we process

2.1 Your account

We don't use passwords. You sign in with a one-time code sent to your email, with Sign in with Apple, or with Google sign-in. There is no SMS sign-in. If you choose to hide your email with Sign in with Apple, we receive the relay address Apple gives us.

2.2 Your firm and business records

The business information you enter in the app:

2.3 Data about other people (your customers, brokers, fuel stations)

You can enter the names, phone numbers, emails and tax numbers of your customers, brokers and fuel stations.

For this data, you (your firm) are the controller. We process it only on your behalf and on your instructions, to provide the service; we act as your processor. You must have a lawful basis for entering this data (for example, your business relationship with them) and inform those people where required.

2.4 Device and technical data

3. What stays on your phone

4. Why we process data

5. What we never do

6. Who we share data with

We share data only with the following providers that help us run the service, and only as much as they need. They may not use your data for their own purposes (Apple's and Google's own services are also governed by their own policies).

ProviderPurposeLocation
SupabaseDatabase, authentication, file (photo) storageEU — Frankfurt, Germany (AWS eu-central-1)
Amazon Web Services (SES)Sending sign-in code emailsEU / may include USA
Apple App Store, Google PlaySubscription payments (we never see your card details)Global
RevenueCatSubscription status managementUSA
Google Firebase Cloud Messaging, Apple Push Notification serviceSending notificationsGlobal
SentryError reportingMay include USA
Apple, GoogleSign in with Apple / Google sign-in (if you choose them)Global

Apart from these, we disclose data only where the law requires it (for example, a court order or a request from a competent authority).

When you share outputs such as a statement, a trip PDF or the accountant CSV file (for example via WhatsApp or email), that sharing happens through the app you choose and is your responsibility.

7. Who sees what inside a firm

Each firm's records are kept separate; one firm cannot see another firm's data. Inside a firm, access depends on role:

The firm owner decides who joins the firm and with which role.

8. Verification links

When you share a statement or trip PDF, it carries a QR code or link. Whoever opens it can verify a snapshot of the document as it was when shared. The link shows only that shared snapshot, gives no access to anything else in your account, and expires after 180 days.

9. International transfers

Your records are stored in the European Union (Germany). Some of our providers (RevenueCat, Sentry, Google, Apple, AWS) may also process data in other countries, including the USA.

For these transfers we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, recognised certification frameworks. For transfers from Türkiye, we follow the transfer rules in Article 9 of the KVKK (for example, standard contracts approved by the Turkish Personal Data Protection Board), and where the law requires your explicit consent, we ask for it separately.

10. How long we keep data

Important: your firm's own bookkeeping and record-keeping obligations (for example under tax law) are your responsibility. Before deleting your account, we recommend exporting your records using the app's PDF statements and the accountant CSV export. More details: Delete your account.

11. Security

No system is perfectly secure. If a personal data breach occurs, we will notify the competent authority and affected people as the law requires.

12. Subscriptions and payments

You can try Seferim free for 30 days without entering a card. After that, paid plans are sold through the Apple App Store or Google Play. Apple or Google takes the payment; we never see your card details. We track your subscription status (which plan, valid until when) through RevenueCat.

13. Children

Seferim is not intended for anyone under 18. We do not knowingly collect data from people under 18. If you believe this has happened, contact us and we will delete it.

15. Your rights (GDPR)

If you are in the European Economic Area (or a country with similar rules), you have the right to:

To exercise these rights, email [email protected] from the email address registered to your Seferim account. We reply within one month. Some things you can do yourself in the app: export PDF statements and the accountant CSV file, and delete your account.

If your request concerns data that a firm entered about you (for example, you are a customer of a Seferim user), the firm is the controller; please contact them first. We will help them respond.

16. Users in Türkiye (KVKK)

Under Article 11 of the KVKK you may, among other things, learn whether your data is processed, request information about it, learn the purpose and whether it is used accordingly, know the third parties it is transferred to in Türkiye or abroad, request correction or deletion, request that third parties be notified of these, object to adverse results arising solely from automated analysis, and claim compensation for damage caused by unlawful processing.

Apply by email to [email protected] from your registered email address, or in writing to Ostim OSB Mah. 100. Yıl Bul. No:55, Yenimahalle, Ankara, Türkiye, in line with the Communiqué on the Procedures and Principles of Application to the Data Controller. We respond free of charge within 30 days. If your application is rejected or unanswered, you may complain to the Personal Data Protection Board (KVKK Kurulu). Full details are in the Turkish version.

17. This website

seferim.tr uses no cookies and contains no visitor tracking or analytics tools.

The site is hosted on Cloudflare (Cloudflare, Inc.). To deliver the pages, Cloudflare briefly processes visitors' IP addresses and request data for security and to operate the service; this data is not used for profiling or advertising.

18. Changes to this policy

We may update this policy from time to time. If we make an important change, we will let you know in the app or by email. The current version is always on this page; the date at the top shows the last update. If the English and Turkish versions differ, the Turkish version prevails.

Questions? Email [email protected].