[email protected]

🇹🇷 Bu sayfayı Türkçe okuyun

Kur-alApp Privacy Policy

Last updated: 24 August 2026 Effective date: 18 August 2026 Applies to: the Kur-alApp mobile application (iOS and Android) and https://kur-al.com.tr

This is the English version of our privacy notice. It satisfies the disclosure requirements of the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and serves as the privacy policy required by the Apple App Store and Google Play. In case of conflict, the Turkish version at https://kur-al.com.tr/gizlilik prevails.


1. Who we are

Legal entity (data controller)KURAL FİNANSAL TEKNOLOJİLER YAZILIM VE DANIŞMANLIK A.Ş.
AddressÜniversiteler Mahallesi, 1597. Cadde, Bilkent Center AVM, No: 3, Door No: 104, Ground Floor, 06800 Bilkent, Çankaya/Ankara, Türkiye
Trade registry (MERSIS)0593130097500001
Privacy contact[email protected]
Support[email protected]
Websitehttps://kur-al.com.tr

2. What Kur-alApp does

Kur-alApp is a price-quotation (tender) platform. A user who wants to buy or sell foreign currency publishes a request, currency exchange offices submit competing price offers, and the user compares those offers and picks one. The app:

  • displays the daily reference rates published by the Central Bank of the Republic of Türkiye (TCMB), for information only,
  • lets a user create a request (amount, currency, buy/sell direction),
  • announces the request to relevant exchange offices via push notification,
  • collects the incoming offers and presents them for comparison so the user can select one.

Kur-alApp does not trade currency. It is not a party to any currency transaction, does not carry out exchange operations, does not set rates, never holds funds or currency on a user’s behalf, and does not act as a payment intermediary. The subject of the platform is price discovery; the transaction itself — payment and delivery of the currency — takes place between the parties’ own bank accounts (IBANs), entirely outside the app and with no involvement from Kur-alApp. Status labels shown in the app, such as “awaiting payment”, are set by the parties themselves; Kur-alApp cannot see or verify whether a payment has been made.

3. Data we process

3.1 Data you provide

CategoryDataWhen collected
IdentityFull name, Turkish national ID number (T.C. Kimlik No)At sign-up
ContactEmail address, phone number, city, districtAt sign-up
Financial / transactionalBank name, IBAN, account holder name, account currency; your currency requests (amount, currency, buy/sell, date) and the offers you send or receiveWhen adding an account and transacting
Business (exchange-office users only)Business name, tax office, tax number, business address, city/district, business contact detailsAt sign-up and when updated from the “My Business” screen
Business membership (exchange-office users only)The business you belong to, your role within it (manager or staff), the permissions granted to you, the date you joined and the identity of the manager who invited youWhen membership is created and when permissions change
In-business activity record (exchange-office staff only)The administrative actions you take in the business (member and permission changes, account setup) and the number and value of the offers you make and win — your business manager can see theseAutomatically, as you act
CredentialsYour password — never stored in clear text, only as a bcrypt hashAt sign-up and password change
Consent recordsThe fact and timestamp of your acceptance of this notice and the Terms of UseAt first login

3.2 Data generated automatically

CategoryDataPurpose
Device / messagingPush notification device token and platform (iOS/Android)To deliver notifications to you
Device identifierA persistent device identifier the app generates at install time and sends with every request (not an advertising identifier; it does not identify you in other apps)To bind your session to the device you use, and to detect and revoke a stolen session
Security logsRequest time, requested service path, IP addressSecurity, debugging, abuse prevention
SessionAccess token issued after login — stored on your device in the iOS Keychain / Android KeystoreTo keep you signed in

3.3 Data we do NOT collect

We do not access your contacts, photos, camera, microphone, SMS or call logs. We do not use your advertising identifier (IDFA/AAID) and we do not track you across apps or websites owned by other companies. The app contains no advertising and no in-app purchases. There is no social / third-party sign-in. The app contains no analytics or crash-reporting SDK.

3.4 Location

The app does not collect or use your location. It never requests location permission on either platform.

PurposeDataLegal basis (KVKK Art. 5 / GDPR equivalent)
Create your account, authenticate you, manage your sessionIdentity, contact, password hashPerformance of a contract
Create your currency request, route it to exchange offices, show you offersTransaction, financial, contactPerformance of a contract
Identify the parties to a financial transaction and meet obligations under financial regulationNational ID, tax number, transaction recordsLegal obligation
Make sure payment reaches the correct accountBank name, IBAN, account holder namePerformance of a contract
Notify you about requests, offers and status changesDevice token, emailPerformance of a contract
Keep the service secure, detect faults and abuseLogs, IP addressLegitimate interest
Establish, exercise or defend legal claimsTransaction and consent recordsEstablishment/exercise/defence of legal claims
Set up the business structure on exchange-office accounts; authorise staff and limit their permissionsBusiness membership, role, permissionsPerformance of a contract
Record who performed which administrative action within a business and report it to the business manager; detect unauthorised useIn-business activity recordLegitimate interest
Send staff invitations to a businessInvited person’s name and email addressLegitimate interest

Where none of these apply, we ask for your explicit consent first.

About the in-business activity record: it is visible only to the manager of the business you belong to — never to other businesses or users. It is not used for general performance appraisal or for decisions taken solely by automated means. Staff are told plainly in the app that the record is kept; there is no covert monitoring.

5. Who we share data with

RecipientDataReason
The counterparty of your transaction (exchange office or customer)Name, contact details and the selected bank account (IBAN) — only after an offer is accepted. Where the counterparty is an exchange office, this is visible to that business’s manager and the staff they have authorisedTo complete the transaction
The manager of the business you belong to (exchange-office staff only)Name, email, phone, your role and permissions, and your in-business activity recordSo the business can manage and audit its own team
Google (Firebase Cloud Messaging)Device push token and notification contentPush delivery
Google (Gmail / Workspace SMTP)Your email address and message contentReport and notification emails
SH Online İletişim A.Ş. (Türkiye)All data stored in our database and logsServer hosting
Competent public authoritiesRequested dataWhere required by law

We do not sell, rent or trade your personal data. The providers above act as processors on our instructions.

Where your data is stored: our database and server logs are hosted in Türkiye, in the data centre of SH Online İletişim A.Ş. Your identity, contact, bank account and transaction data are not moved abroad.

International transfers: only two services involve a transfer outside Türkiye:

ServiceData transferredPurpose
Google — Firebase Cloud MessagingDevice push token and notification contentTo deliver push notifications to you
Google — Gmail / Workspace SMTPYour email address and the content of the messageTo send report and notification emails

Google may process this data on servers outside Türkiye, including the United States. These transfers are made under Article 9 of the KVKK on the basis of the standard contractual clauses signed with Google, notified to the Turkish Data Protection Authority pursuant to Article 9/2.

6. Security

  • All traffic between the app and our servers is encrypted with TLS/HTTPS; the app is configured to reject cleartext connections.
  • Passwords are stored only as irreversible bcrypt hashes.
  • The session token is kept in the operating system’s secure storage (iOS Keychain / Android Keystore).
  • Authentication and authorization are enforced centrally at our API gateway; users can only act on their own records.
  • Database access is limited to authorized personnel and is logged.

No system is completely secure. In the event of a personal data breach we notify affected users and the Turkish Data Protection Authority without undue delay (within 72 hours).

7. Retention

DataRetention
Account and profile dataWhile your account is active; after a deletion request, your personal data is erased or anonymised immediately and is purged from technical backups within 1 month
Bank account (IBAN) dataWhile your account is active; deleted on account deletion
Request, offer and transaction records5 years as required by financial record-keeping law, decoupled from your identity
Push device tokenUntil account deletion or until notifications are disabled
Server logs (incl. IP)5 years
Consent records5 years
Unaccepted staff invitationsThe name and email in an invitation are deleted or anonymised within 90 days of the invitation being cancelled or expiring
In-business activity record2 years for the business’s own audit needs, then deleted
Business and membership recordsFor as long as the business operates. When a staff membership ends the record is deactivated rather than deleted, so past transactions remain attributable

After the retention period data is deleted, destroyed or anonymised.

8. Your rights

You have the right to: learn whether we process your data; request information about the processing and its purpose; learn the third parties to whom it is transferred in Türkiye or abroad; have inaccurate or incomplete data corrected; request erasure or destruction; require that corrections and erasures be notified to recipients; object to decisions produced solely by automated analysis that affect you adversely; and claim compensation for damage caused by unlawful processing.

How to exercise them: email [email protected] or write to Üniversiteler Mahallesi, 1597. Cadde, Bilkent Center AVM, No: 3, Door No: 104, Ground Floor, 06800 Bilkent, Çankaya/Ankara, Türkiye. We respond within 30 days, free of charge.

Account and data deletion: in-app under Profile → Delete account, or follow https://kur-al.com.tr/en/account-deletion.

9. Children

Kur-alApp is not directed to anyone under 18 and we do not knowingly collect data from minors. If we learn that we hold data about a person under 18 we delete the account and the data. Please contact [email protected] if you believe this has happened.

10. Exchange rate data

Rates shown in the app are fetched directly by your device from the public TCMB endpoint (https://www.tcmb.gov.tr/kurlar/today.xml). No personal data is sent to TCMB; as with any internet request, your IP address is visible to that server. Rates are for information only, are not investment advice, and may be delayed.

11. Changes to this policy

We update the “last updated” date whenever this policy changes. For material changes we show an in-app notice and, where required, ask for your consent again.

12. Contact

Support[email protected]
Privacy / data requests[email protected]
PostKURAL FİNANSAL TEKNOLOJİLER YAZILIM VE DANIŞMANLIK A.Ş., Üniversiteler Mahallesi, 1597. Cadde, Bilkent Center AVM, No: 3, Door No: 104, Ground Floor, 06800 Bilkent, Çankaya/Ankara, Türkiye