Turkish version: Gizlilik Politikası.
This policy describes how we process personal data when you use the Drip Coffee app and the related loyalty service. The app is a white-label loyalty product for a specific café; your account belongs only to that café.
Data we collect
| Data | Examples | Purpose |
|---|---|---|
| Account | Email, first/last name, password hash (never stored in plain text) | Sign-up, login, verification |
| Loyalty | Star/point balance, reward balance, transaction history | Running the loyalty program |
| Session | QR sessions, access/refresh tokens | Staff earn/redeem |
| Notifications | Expo / FCM / APNs device token, OS | Campaign and café messages |
| Business content | Menu/campaign images uploaded by staff | Display menu and offers |
| Security logs | Login attempts, deletion requests | Abuse prevention |
| Support | Emails you send us | Customer support |
We do not collect location, contacts, payment cards, or advertising IDs for tracking. We do not use third-party ad SDKs.
Camera and photo library are used by staff (QR scan, menu/campaign photos). Customers display a QR on screen; customer camera is not required.
How we use data
- Perform the service: account, balances, QR earn/redeem
- Security and fraud prevention
- Email verification, password reset, deletion confirmation (Brevo)
- Push notifications if you allow them (you can disable in system settings)
Retention
Active accounts: for the life of the service. After deletion we erase or anonymize identity fields. Loyalty ledger rows may be kept for accounting/dispute/fraud and are detached from your identity. Device tokens and sessions are removed.
Your rights / deletion
Email support@diveqatech.com for access, correction, or deletion requests.
Self-service deletion:
- In-app: Profile → Delete my account
- Web: https://diveqatech.com/hesap-sil (choose café + email; app install not required)
Deletion applies only to the selected café. You may register again with the same email.
Children
Not directed at children under 13.
Security & transfers
Passwords are hashed; API uses HTTPS. Servers or email providers may be outside Türkiye. We take reasonable technical measures; no method is 100% secure.
Contact
DIVEQA Technologies — support@diveqatech.com — https://diveqatech.com