1. Data Controller
İsar Group
Address: İskenderpaşa Mahallesi Ahmediye Caddesi No:4 Fatih / İSTANBUL, Turkey
Email: info@isar.co
Phone: +90 212 524 3240
This Privacy Policy explains how SılaGo mobile application collects, uses, stores, and shares your personal data in accordance with GDPR and Turkish KVKK.
2. Personal Data We Collect
Identity & Contact Data
First name, last name, email, phone number, username, profile photo.
Location Data
Real-time GPS location (latitude/longitude), last known location, convoy tracking shared location.
Vehicle Data
License plate number, vehicle brand, model, color, and type.
Document Data
Driver's license, vehicle registration, insurance, passport, and document metadata.
Communication Content
Chat messages, voice messages, media files, read/delivery receipts.
Device Contacts
Phone numbers from your contacts (for matching with app users).
Device & Technical Data
Device ID, platform (iOS/Android), FCM token, app and OS version.
Usage Data
Help requests, ratings, reviews, online/offline status.
Social Login Data
Google/Apple account information (email, name, profile photo, identity token).
Special Category Data
Help request type related to health (medical emergency, accident).
3. Purposes and Legal Bases
- Account creation and authentication: Contract performance
- Location-based help matching: Legitimate interest
- Continuous location tracking: Consent
- Convoy tracking: Consent
- Messaging service: Contract performance
- Document storage (local on device only): Consent
- Contacts synchronization: Consent
- Emergency help request: Vital interest
- Crash reports (Crashlytics): Legitimate interest
- Push notifications: Contract performance
- OCR and translation: Consent
4. Third-Party Data Sharing
Your data is shared with:
- Google LLC (USA): Firebase Crashlytics, FCM, Google Maps, Cloud Vision OCR, Google Sign-In
- Apple Inc. (USA): Apple Sign-In
- LiveKit Inc. (USA): Voice communication infrastructure
International transfers are carried out under GDPR Standard Contractual Clauses (SCCs) and KVKK Art. 9 explicit consent.
5. Data Retention
- Account data: Until account deletion
- Location data: Only last known location stored
- Chat messages: Until account deletion (anonymized upon deletion)
- Documents: Until deleted by user (local)
- Crash reports: 90 days
- Audit logs: 1 year
6. Local Storage
- Encrypted storage: Access/refresh tokens, user ID, email
- Preferences: Theme, language, session state, last location, device ID
- Local database: Chat history, pending messages
- File system: Uploaded documents, cached images
7. Your Rights
Under GDPR (Art. 15-22) and KVKK (Art. 11):
- Right of access and information
- Right to rectification and erasure
- Right to restriction of processing
- Right to data portability
- Right to object
Contact: Settings > Privacy > Data Request or info@isar.co
8. Data Security
- HTTPS/TLS encryption
- JWT authentication (access: 30 min, refresh: 90 days)
- BCrypt password hashing
- iOS Keychain / Android KeyStore encrypted storage
- API rate limiting
- Role-based access control
9. Children's Privacy
This App is not intended for persons under 18. We do not knowingly collect data from children.
10. Policy Changes
Changes will be communicated through the App. Significant changes will be notified via push notification.
11. Contact
Email: info@isar.co
Address: İskenderpaşa Mahallesi Ahmediye Caddesi No:4 Fatih / İSTANBUL, Turkey
Phone: +90 212 524 3240
KVKK complaints: Personal Data Protection Authority
GDPR complaints: Relevant Data Protection Authority