This policy explains how personal data is processed when you use Revue Pass, the loyalty app of Revue Coffee, developed and operated by DIVEQA Technologies.
Turkish: Gizlilik Politikası · KVKK Aydınlatma.
1. Data we collect
| Data | Examples | Purpose |
|---|---|---|
| Account | Email, full name | Sign-up and sign-in (no password; a one-time code is emailed) |
| Optional profile | Form of address (female / male / unspecified), birthday (day and month only) | Royal title wording, birthday treat |
| Loyalty | Crown and reward balance, visit count, transaction history | Running the loyalty program |
| Referral | Your referral code, who invited whom | Bring-a-friend campaign |
| Polls | Your vote in in-app polls | Showing results |
| Session and QR | Session key in the device's secure storage, QR code valid for 45 seconds | Staying signed in, earning and redeeming at the till |
| Notifications | Expo / Apple / Google push token, platform, marketing consent | Campaign notifications (only with consent) |
| Security logs | Sign-in code requests (hashed), staff management actions | Security and abuse prevention |
| Support | Emails you send us | Support |
We do not collect: location, contacts, microphone, advertising identifiers for tracking, payment card data, or third-party advertising / analytics SDKs.
Camera and photo library access is used only by cafe staff (scanning a customer's QR code at the till, uploading menu photos). Customers are never asked for camera access.
2. Purposes and legal bases
- Contract: account, crowns and rewards, QR transactions, referral rewards
- Legitimate interest: security, abuse prevention, operating and improving the service
- Consent: campaign notifications (separate opt-in; can be turned off in Profile or system settings)
- Legal obligation: transaction records that must be retained
4. Retention
- Active account: for as long as you use the service
- Sign-in codes: expire within minutes; only a hash is stored
- After deletion: email, name, form of address and birthday are erased; push tokens and sessions are removed. Transaction rows remain without any link to you so the cafe's reports stay consistent
5. Your rights and account deletion
You may request access, correction or deletion of your data, or object to processing: support@diveqatech.com
- In the app: Profile → Hesabımı sil (Delete my account)
- On the web: diveqatech.com/revuecoffee/hesap-sil — we email you a confirmation link; the app does not need to be installed
6. Children
The service is not directed to children under 13. We delete accounts we learn belong to a child under 13.
7. Security
No passwords are used; one-time sign-in codes are stored hashed. The API is HTTPS-only, session keys expire and are kept in the device's secure storage, and QR codes are signed and valid for 45 seconds.
8. Contact
DIVEQA Technologies
Email: support@diveqatech.com
Web: https://diveqatech.com