Kur-alApp Privacy Policy
Last updated: 24 August 2026 Effective date: 18 August 2026 Applies to: the Kur-alApp mobile application (iOS and Android) and https://kur-al.com.tr
This is the English version of our privacy notice. It satisfies the disclosure requirements of the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and serves as the privacy policy required by the Apple App Store and Google Play. In case of conflict, the Turkish version at https://kur-al.com.tr/gizlilik prevails.
1. Who we are
| Legal entity (data controller) | KURAL FİNANSAL TEKNOLOJİLER YAZILIM VE DANIŞMANLIK A.Ş. |
| Address | Üniversiteler Mahallesi, 1597. Cadde, Bilkent Center AVM, No: 3, Door No: 104, Ground Floor, 06800 Bilkent, Çankaya/Ankara, Türkiye |
| Trade registry (MERSIS) | 0593130097500001 |
| Privacy contact | [email protected] |
| Support | [email protected] |
| Website | https://kur-al.com.tr |
2. What Kur-alApp does
Kur-alApp is a price-quotation (tender) platform. A user who wants to buy or sell foreign currency publishes a request, currency exchange offices submit competing price offers, and the user compares those offers and picks one. The app:
- displays the daily reference rates published by the Central Bank of the Republic of Türkiye (TCMB), for information only,
- lets a user create a request (amount, currency, buy/sell direction),
- announces the request to relevant exchange offices via push notification,
- collects the incoming offers and presents them for comparison so the user can select one.
Kur-alApp does not trade currency. It is not a party to any currency transaction, does not carry out exchange operations, does not set rates, never holds funds or currency on a user’s behalf, and does not act as a payment intermediary. The subject of the platform is price discovery; the transaction itself — payment and delivery of the currency — takes place between the parties’ own bank accounts (IBANs), entirely outside the app and with no involvement from Kur-alApp. Status labels shown in the app, such as “awaiting payment”, are set by the parties themselves; Kur-alApp cannot see or verify whether a payment has been made.
3. Data we process
3.1 Data you provide
| Category | Data | When collected |
|---|---|---|
| Identity | Full name, Turkish national ID number (T.C. Kimlik No) | At sign-up |
| Contact | Email address, phone number, city, district | At sign-up |
| Financial / transactional | Bank name, IBAN, account holder name, account currency; your currency requests (amount, currency, buy/sell, date) and the offers you send or receive | When adding an account and transacting |
| Business (exchange-office users only) | Business name, tax office, tax number, business address, city/district, business contact details | At sign-up and when updated from the “My Business” screen |
| Business membership (exchange-office users only) | The business you belong to, your role within it (manager or staff), the permissions granted to you, the date you joined and the identity of the manager who invited you | When membership is created and when permissions change |
| In-business activity record (exchange-office staff only) | The administrative actions you take in the business (member and permission changes, account setup) and the number and value of the offers you make and win — your business manager can see these | Automatically, as you act |
| Credentials | Your password — never stored in clear text, only as a bcrypt hash | At sign-up and password change |
| Consent records | The fact and timestamp of your acceptance of this notice and the Terms of Use | At first login |
3.2 Data generated automatically
| Category | Data | Purpose |
|---|---|---|
| Device / messaging | Push notification device token and platform (iOS/Android) | To deliver notifications to you |
| Device identifier | A persistent device identifier the app generates at install time and sends with every request (not an advertising identifier; it does not identify you in other apps) | To bind your session to the device you use, and to detect and revoke a stolen session |
| Security logs | Request time, requested service path, IP address | Security, debugging, abuse prevention |
| Session | Access token issued after login — stored on your device in the iOS Keychain / Android Keystore | To keep you signed in |
3.3 Data we do NOT collect
We do not access your contacts, photos, camera, microphone, SMS or call logs. We do not use your advertising identifier (IDFA/AAID) and we do not track you across apps or websites owned by other companies. The app contains no advertising and no in-app purchases. There is no social / third-party sign-in. The app contains no analytics or crash-reporting SDK.
3.4 Location
The app does not collect or use your location. It never requests location permission on either platform.
4. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (KVKK Art. 5 / GDPR equivalent) |
|---|---|---|
| Create your account, authenticate you, manage your session | Identity, contact, password hash | Performance of a contract |
| Create your currency request, route it to exchange offices, show you offers | Transaction, financial, contact | Performance of a contract |
| Identify the parties to a financial transaction and meet obligations under financial regulation | National ID, tax number, transaction records | Legal obligation |
| Make sure payment reaches the correct account | Bank name, IBAN, account holder name | Performance of a contract |
| Notify you about requests, offers and status changes | Device token, email | Performance of a contract |
| Keep the service secure, detect faults and abuse | Logs, IP address | Legitimate interest |
| Establish, exercise or defend legal claims | Transaction and consent records | Establishment/exercise/defence of legal claims |
| Set up the business structure on exchange-office accounts; authorise staff and limit their permissions | Business membership, role, permissions | Performance of a contract |
| Record who performed which administrative action within a business and report it to the business manager; detect unauthorised use | In-business activity record | Legitimate interest |
| Send staff invitations to a business | Invited person’s name and email address | Legitimate interest |
Where none of these apply, we ask for your explicit consent first.
About the in-business activity record: it is visible only to the manager of the business you belong to — never to other businesses or users. It is not used for general performance appraisal or for decisions taken solely by automated means. Staff are told plainly in the app that the record is kept; there is no covert monitoring.
5. Who we share data with
| Recipient | Data | Reason |
|---|---|---|
| The counterparty of your transaction (exchange office or customer) | Name, contact details and the selected bank account (IBAN) — only after an offer is accepted. Where the counterparty is an exchange office, this is visible to that business’s manager and the staff they have authorised | To complete the transaction |
| The manager of the business you belong to (exchange-office staff only) | Name, email, phone, your role and permissions, and your in-business activity record | So the business can manage and audit its own team |
| Google (Firebase Cloud Messaging) | Device push token and notification content | Push delivery |
| Google (Gmail / Workspace SMTP) | Your email address and message content | Report and notification emails |
| SH Online İletişim A.Ş. (Türkiye) | All data stored in our database and logs | Server hosting |
| Competent public authorities | Requested data | Where required by law |
We do not sell, rent or trade your personal data. The providers above act as processors on our instructions.
Where your data is stored: our database and server logs are hosted in Türkiye, in the data centre of SH Online İletişim A.Ş. Your identity, contact, bank account and transaction data are not moved abroad.
International transfers: only two services involve a transfer outside Türkiye:
| Service | Data transferred | Purpose |
|---|---|---|
| Google — Firebase Cloud Messaging | Device push token and notification content | To deliver push notifications to you |
| Google — Gmail / Workspace SMTP | Your email address and the content of the message | To send report and notification emails |
Google may process this data on servers outside Türkiye, including the United States. These transfers are made under Article 9 of the KVKK on the basis of the standard contractual clauses signed with Google, notified to the Turkish Data Protection Authority pursuant to Article 9/2.
6. Security
- All traffic between the app and our servers is encrypted with TLS/HTTPS; the app is configured to reject cleartext connections.
- Passwords are stored only as irreversible bcrypt hashes.
- The session token is kept in the operating system’s secure storage (iOS Keychain / Android Keystore).
- Authentication and authorization are enforced centrally at our API gateway; users can only act on their own records.
- Database access is limited to authorized personnel and is logged.
No system is completely secure. In the event of a personal data breach we notify affected users and the Turkish Data Protection Authority without undue delay (within 72 hours).
7. Retention
| Data | Retention |
|---|---|
| Account and profile data | While your account is active; after a deletion request, your personal data is erased or anonymised immediately and is purged from technical backups within 1 month |
| Bank account (IBAN) data | While your account is active; deleted on account deletion |
| Request, offer and transaction records | 5 years as required by financial record-keeping law, decoupled from your identity |
| Push device token | Until account deletion or until notifications are disabled |
| Server logs (incl. IP) | 5 years |
| Consent records | 5 years |
| Unaccepted staff invitations | The name and email in an invitation are deleted or anonymised within 90 days of the invitation being cancelled or expiring |
| In-business activity record | 2 years for the business’s own audit needs, then deleted |
| Business and membership records | For as long as the business operates. When a staff membership ends the record is deactivated rather than deleted, so past transactions remain attributable |
After the retention period data is deleted, destroyed or anonymised.
8. Your rights
You have the right to: learn whether we process your data; request information about the processing and its purpose; learn the third parties to whom it is transferred in Türkiye or abroad; have inaccurate or incomplete data corrected; request erasure or destruction; require that corrections and erasures be notified to recipients; object to decisions produced solely by automated analysis that affect you adversely; and claim compensation for damage caused by unlawful processing.
How to exercise them: email [email protected] or write to Üniversiteler Mahallesi, 1597. Cadde, Bilkent Center AVM, No: 3, Door No: 104, Ground Floor, 06800 Bilkent, Çankaya/Ankara, Türkiye. We respond within 30 days, free of charge.
Account and data deletion: in-app under Profile → Delete account, or follow https://kur-al.com.tr/en/account-deletion.
9. Children
Kur-alApp is not directed to anyone under 18 and we do not knowingly collect data from minors. If we learn that we hold data about a person under 18 we delete the account and the data. Please contact [email protected] if you believe this has happened.
10. Exchange rate data
Rates shown in the app are fetched directly by your device from the public TCMB endpoint (https://www.tcmb.gov.tr/kurlar/today.xml). No personal data is sent to TCMB; as with any internet request, your IP address is visible to that server. Rates are for information only, are not investment advice, and may be delayed.
11. Changes to this policy
We update the “last updated” date whenever this policy changes. For material changes we show an in-app notice and, where required, ask for your consent again.
12. Contact
| Support | [email protected] |
| Privacy / data requests | [email protected] |
| Post | KURAL FİNANSAL TEKNOLOJİLER YAZILIM VE DANIŞMANLIK A.Ş., Üniversiteler Mahallesi, 1597. Cadde, Bilkent Center AVM, No: 3, Door No: 104, Ground Floor, 06800 Bilkent, Çankaya/Ankara, Türkiye |