Privacy Policy
Last updated: [EFFECTIVE DATE]
This Privacy Policy explains how [QUABYTE LEGAL ENTITY NAME] ("Quabyte," "we," "us," or "our"), operating the Konumla platform available at [https://konumla.co] (the "Service"), collects, uses, stores, shares, and protects information when you use the Service.
We act as a data controller for account and billing information you provide directly to us, and as a data processor for the business data you connect to or generate through the Service on behalf of the businesses you manage. If you connect a third party's Google Business Profile that you manage as an agency, you are responsible for having the right to do so.
If you have questions about this Policy, contact us at destek@konumla.co.
1. Who this Policy applies to
This Policy applies to:
- Account holders — agencies, agency team members, and individual business owners who register for and use the Service.
- Business locations — the businesses and Google Business Profile listings managed through the Service.
It does not apply to third-party websites or services we link to, which have their own privacy policies.
2. Information we collect
Information you provide to us:
- Account information: name, email address, password (stored hashed), company name, and role.
- Billing information: billing name, address, tax identifiers, and payment details. Card data is processed by our payment provider and is not stored on our servers.
- Content you submit: business locations you add, competitors you track, review reply templates, campaign settings, and support communications.
Information we collect automatically:
- Usage data: pages visited, features used, actions taken, and timestamps.
- Device and log data: IP address, browser type, operating system, and access times.
- Cookies and similar technologies (see Section 9).
Information we collect from Google Business Profile (Google user data):
When you connect a Google account, we access Google Business Profile data on your behalf. This is described in detail in Section 3.
Information from public sources:
Search engine results and map results used to measure local ranking and visibility (for example, Local Pack and organic positions). This data is gathered from public search results and is not connected to any individual's personal Google account.
3. Google user data
This section describes how the Service accesses, uses, stores, and shares data from Google APIs, in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
What we access. When you authorize the Service, you grant access using the Google OAuth scope https://www.googleapis.com/auth/business.manage. Through this scope we may access and manage, on your behalf, data associated with the Google Business Profile accounts and locations you manage, including:
- Business account and location information (name, address, hours, categories, attributes, phone, website).
- Reviews and review replies.
- Posts, photos, and other media.
- Questions and answers.
- Performance and insight metrics (for example, profile views, searches, calls, and direction requests).
- Verification status.
How we use it. We use Google user data solely to provide the features you request, including: displaying and editing your business information; reading and replying to reviews (including AI-assisted reply drafting that you review and approve); publishing posts; uploading media; managing questions and answers; reporting performance insights; and producing reports.
Limited Use. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
- use Google user data for serving advertisements;
- sell Google user data;
- transfer or use Google user data for purposes unrelated to providing the user-facing features of the Service;
- allow humans to read Google user data unless (a) you have given affirmative consent for specific data, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data is aggregated and anonymized and used for internal operations.
AI processing. Where the Service offers AI-assisted features (such as drafting review replies), the relevant content may be processed by a third-party AI provider strictly to generate the requested output. We do not permit such providers to use your Google user data to train their models, and we configure these integrations to prohibit such use where the provider offers that option.
Storage and retention. We store OAuth refresh tokens in encrypted form and only the Google user data needed to provide the Service. You may disconnect at any time (see Section 8), which revokes our access and triggers deletion of the associated stored data and tokens.
4. How we use your information
We use information to:
- provide, operate, and maintain the Service;
- authenticate you and secure your account;
- process subscriptions and payments;
- generate reports, insights, and white-label deliverables;
- provide AI-assisted features you request;
- communicate with you about your account, updates, and support;
- monitor, prevent, and investigate fraud, abuse, and security incidents;
- comply with legal obligations.
5. Legal bases for processing
Where KVKK (Law No. 6698 on the Protection of Personal Data) and, where applicable, the GDPR apply, we rely on the following legal bases:
- Performance of a contract — to provide the Service you signed up for.
- Consent — for connecting your Google account and for optional communications. You may withdraw consent at any time.
- Legitimate interests — to secure, improve, and operate the Service, balanced against your rights.
- Legal obligation — to comply with tax, accounting, and other laws.
6. How we share information
We do not sell your personal data. We share information only as follows:
- Service providers (sub-processors) — hosting, payment processing, email delivery, error monitoring, and AI processing, each bound by confidentiality and data protection obligations. A current list is available on request at destek@konumla.co.
- Within your agency account — data is visible to authorized members of your account according to the roles and permissions you configure.
- Legal and safety — when required by law, legal process, or to protect rights, safety, and the integrity of the Service.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
7. Data retention
We retain personal data for as long as your account is active and as needed to provide the Service, then delete or anonymize it within a reasonable period unless a longer retention is required by law (for example, billing records). Google user data is deleted following disconnection or account closure as described in Section 8.
8. Disconnecting Google and deleting data
You can disconnect your Google account at any time from Settings → Integrations in the Service. Disconnecting will:
- revoke the Service's access via Google's token revocation endpoint;
- delete the stored OAuth tokens; and
- delete the associated Google user data we hold, except where retention is required by law.
You may also revoke access directly from your Google Account permissions page. To delete your entire account and associated data, contact destek@konumla.co.
9. Cookies
We use strictly necessary cookies to operate the Service (for example, to keep you logged in) and, where permitted, analytics cookies to understand usage. You can control cookies through your browser settings.
10. Security
We use technical and organizational measures to protect your data, including encryption of credentials and tokens at rest, encrypted transport (TLS), access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. International transfers
The Service may process and store data on servers located in [COUNTRY/REGION — e.g., the European Union / Türkiye]. Where data is transferred across borders, we apply appropriate safeguards consistent with KVKK and, where applicable, the GDPR.
12. Your rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data;
- object to or restrict certain processing;
- request a copy of your data in a portable format;
- withdraw consent at any time;
- lodge a complaint with a supervisory authority (in Türkiye, the Kişisel Verileri Koruma Kurumu (KVKK)).
To exercise these rights, contact destek@konumla.co. We will respond within the timeframes required by applicable law.
13. Children
The Service is not directed to individuals under 18, and we do not knowingly collect their personal data.
14. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, notify you through the Service or by email.
15. Contact
[QUABYTE LEGAL ENTITY NAME]
[Registered address]
Email: destek@konumla.co
Data protection contact: [name / title, if appointed]