This Privacy Policy explains what personal data Bayzo collects, why we process it, who we share it with, how long we keep it, and what you can require us to do about it. It is written to satisfy our obligations as a data controller under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"), and it is the disclosure Google Play requires under its User Data policy.
1. Data controller
The controller of your personal data is Avelqor, the software studio that operates Bayzo. Avelqor's company registration in Türkiye is in progress; until the trade registry issues them there is no registered trade name, MERSIS number or tax registration for us to publish, and the Contact page says exactly that rather than showing a placeholder.
Registration status does not change who is responsible for your data. Avelqor determines the purposes and the means of the processing described in this policy, and Avelqor is the entity against which you exercise the rights in section 11. We will publish the registration particulars, and update this section, as soon as they are issued.
Data-protection requests go to the privacy mailbox published there. That is the address designated for the purposes of KVKK article 13, and a request sent to it is answered within thirty days.
2. What we collect
What you give us:
- Phone number — when you register and verify through WhatsApp.
- Display name and profile picture — optional, when you set them.
- Business details — shop name, city, description, opening hours, logo and banner, when you build a seller storefront.
- Professional profile details — when you list yourself in the Syria Directory.
- Listing content — title, description, price, category, condition and photographs, when you publish a listing.
- Support messages and attachments — when you open a support ticket.
- Reports — what you tell us when you report a listing or a user.
What we collect automatically:
- IP address — for rate limiting, abuse detection and approximate country.
- Device and browser characteristics — type, operating system, screen size — to render the right layout and to diagnose faults.
- Usage events — pages viewed, searches run, filters applied, listings opened — for product analytics and ranking.
- Contact events — that you tapped a seller's WhatsApp button, on which listing, at what time. This is what gives a seller their demand signal.
- Error reports — a stack trace and the state of the page when something broke.
- Cookies and similar identifiers — see section 8 and the Cookie Policy.
3. What we do not collect
These boundaries are unusual for a marketplace, so they are stated explicitly rather than left to inference:
- We do not see your conversations. Buyer-to-seller messaging happens on WhatsApp. We record that a contact event occurred. We never receive, store or read the message itself, and we cannot recover it for you.
- We do not process payments, so we hold no card numbers, no bank details and no payment history.
- We do not collect precise location. The app never requests GPS permission. Your location preference is a governorate you choose from a list, stored as a text value.
- We do not collect your contacts, your photo library, your calendar, your SMS, your call logs, or any health or biometric data.
- We do not sell personal data, and we do not share it with advertising networks or data brokers.
4. Why we process it, and on what legal basis
KVKK requires a lawful basis for each purpose. Ours are:
- Running your account, publishing your listings, delivering the platform — article 5(2)(c), necessary for the performance of a contract.
- Verifying that you control your phone number — article 5(2)(c), performance of a contract.
- Detecting fraud, scams, spam and abuse; enforcing our policies; keeping the platform secure — article 5(2)(f), our legitimate interests, balanced against your rights and freedoms.
- Measuring how the product is used so we can make it faster and more useful — article 5(2)(f), legitimate interests.
- Answering your support requests and your data-protection requests — articles 5(2)(c) and 5(2)(ç).
- Keeping the records we are required to keep and answering lawful requests from authorities — article 5(2)(ç), legal obligation.
- Push notifications about your listings and your messages — article 5(1), your explicit consent, given when you turn them on and withdrawable at any time from your device settings or your account.
Your listing content is published deliberately. A listing is a public advertisement: its title, description, price, photographs, category, city and the seller's display name are visible to anyone, including search engines. Do not put anything in a listing that you would not put on a public noticeboard.
5. Who we share it with
Other users see your public profile and your listings — never your phone number, for the reason in section 6.
Service providers, who process data only on our written instructions:
- Hetzner Online GmbH — application and database hosting, in Germany and Finland.
- Cloudflare, Inc. — image storage and delivery, and network protection, on a global edge network.
- Meta Platforms (WhatsApp) — delivery of the verification code you send us, and of the link that opens a chat.
- Sentry — error reports and crash diagnostics, in its European region.
- Our transactional email provider — support replies and security notices, in the European Union.
- Google — distribution of the Android app and, if you enable them, push notifications.
Authorities, where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend a legal claim. We do not volunteer user data, and where the law permits us to tell you about a request, we do.
A successor, if the business is sold or merged. You would be told before your data moved, and the buyer would be bound by this policy.
6. Your phone number is never published
This deserves its own section because it is the most consequential privacy decision in the product.
A seller's phone number is not present in the HTML of any page, in any public API response, or in the JavaScript delivered to any browser — for anyone except the owner of that number. When a buyer taps the contact button, our server builds the WhatsApp link for that single request and returns it. There is no page you can view the source of to harvest numbers, and no endpoint that returns them in bulk.
7. Transfers outside Türkiye
Some of the providers in section 5 are outside Türkiye. Under KVKK article 9 we transfer personal data abroad on the basis of the safeguards the law permits — standard contractual clauses notified to the Personal Data Protection Authority, or your explicit consent where no other basis is available.
8. How long we keep it
- Account record and profile — while your account is open, then deleted within 30 days of account deletion.
- Live listings — while published, then 90 days after expiry or withdrawal.
- Listing photographs — deleted with the listing, including from image storage and its caches.
- Contact events — 24 months.
- Analytics events — 14 months, then aggregated and the raw rows deleted.
- Server and security logs, including IP addresses — 90 days.
- Verification code exchanges — 30 days.
- Support tickets — 24 months after the ticket is closed.
- Reports and moderation decisions — 36 months, so that patterns of abuse stay detectable.
- Record of a ban, held as a one-way hash of the phone number — 5 years, so that a banned user cannot immediately re-register.
- Records required by Turkish commercial and tax law — for the statutory period, currently ten years.
Backups roll on a 30-day cycle. Data deleted from the live system disappears from backups as that cycle completes.
9. Cookies
We set a small number of first-party cookies: your session, an anti-forgery token, an anonymous identifier used for abuse limits, and three preference cookies for language, currency and location. We run no advertising cookies and no third-party tracking cookies. Each one is named, explained and dated in the Cookie Policy.
10. Security
Data is held on servers in the European Union, encrypted in transit with TLS and encrypted at rest. Access is limited to the staff who need it, over authenticated and logged connections, and administrative actions are written to an audit trail. There is no password database to lose — the platform authenticates you with a one-time code, so we never store a password. The platform's row-level authorisation rules are tested automatically on every change.
No system is perfectly secure. If a breach occurs that is likely to create a risk to you, we will notify the Personal Data Protection Authority and the affected users as KVKK requires, and we will tell you plainly what happened and what to do about it.
11. Your rights
Under KVKK article 11 you may:
- learn whether we process your personal data, and be informed if we do;
- ask what it is used for and whether it is used consistently with that purpose;
- learn the third parties, in Türkiye or abroad, to whom it has been transferred;
- have incomplete or inaccurate data corrected, and have that correction passed on to those third parties;
- have your data erased or destroyed when the grounds for processing it fall away, and have that erasure passed on;
- object to a result produced solely by automated analysis where it works to your disadvantage;
- claim compensation for damage caused by unlawful processing.
How to exercise them. Write to the privacy mailbox on the Contact page from the phone number or email address on your account, and say which right you are exercising. That mailbox is our designated application channel: until our company registration completes there is no registered postal address to write to, and we will publish one on the Contact page as soon as there is. We verify that the request comes from the account holder before we act on it — that is a protection for you, not an obstacle. We reply within thirty days at the latest, free of charge unless the request is manifestly repetitive.
Two of these you can do yourself, immediately, without writing to anyone: edit your profile and listings from your account, and delete your account from the bottom of your profile page. Deleting asks you to confirm the code we send to your WhatsApp, so that nobody holding your phone can close your account; the deletion page sets out exactly what goes and what we are required to keep.
If you are not satisfied with our answer you may complain to the Personal Data Protection Authority — Kişisel Verileri Koruma Kurumu, kvkk.gov.tr.
12. Children
Bayzo is for adults; you must be 18 or over to hold an account. We do not knowingly collect data from children and the service is not directed at them. If we discover that an account belongs to someone under 18 we close it and delete the data. If you believe a child has given us data, write to the privacy mailbox and we will remove it.
13. Automated decisions
We use automated systems to score listings and accounts for signs of spam, fraud and prohibited content, and to apply rate limits. These can hide a listing or restrict an account pending review. A person reviews every decision that suspends or bans an account before it becomes permanent, and every such decision can be appealed — see section 10 of the Terms of Service.
14. Changes to this policy
We update this policy when the product or the law changes, and the effective date at the top of the page always reflects the current version. If a change materially affects how we use your data, we give notice in the app at least 30 days before it takes effect.
15. Contact
Data-protection requests, questions about this policy, and complaints about how we answered them all go to the privacy mailbox on the Contact page.