Privacy notice (GDPR and KVKK)
Last updated: 4 October 2026
This notice explains how the bus processes personal data under the EU General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law No. 6698 (KVKK).
1. Data controller
Gümüş Labs — H. Kaan Gümüş. Contact for data protection: the-bus@gumuslabs.com.
Operators (schools, companies, drivers) decide which riders they add. For rider data entered by an operator, the operator is the data controller and we process the data on the operator's behalf as a processor.
2. Data we process
Account data: name, email address, optional phone number, language.
Rider data entered by the operator: name, rider type (adult or student), route and stop.
Location data: the vehicle's position from the driver's phone during active trips only.
Service data: boarding events, absences, proximity alarms, announcements, notifications and device tokens for push messages.
Subscription data: store transaction identifiers and status. We never receive card details; payments are handled by Apple and Google.
Technical data: security logs. The web panel sets a sign-in session cookie and, on sign-up, a Google reCAPTCHA cookie without consent, because the service and its protection need them; analytics cookies only with your consent. This website sets no cookies. The mobile app also reports device security signals (for example signs of root/jailbreak, hooking tools, an emulator or an installation outside the app stores) and, unless you turn it off, crash reports (stack trace, device model, operating system, app version, installation id and the device security signals).
Collection method: electronically, through the app and the web panel, from you, from your organisation (operator) and, during trips, automatically from the driver's phone (KVKK Art. 10).
3. Purposes and legal bases
Providing the service (accounts, routes, live location, alarms, boarding confirmation, notifications): performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
A child's location and boarding data: explicit consent of the guardian, given in the app before a student account is linked (GDPR Art. 6(1)(a) and Art. 8; KVKK Art. 5(1)). Consent can be withdrawn at any time in the app.
Accounting, tax and settlement records: legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)).
Security, fraud and abuse prevention: legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
Crash reports and device security signals in the mobile app: legitimate interest in the stability and security of the app and in triaging abuse (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)). Crash reports are on by default; you can turn them off at any time in the app under Settings → Send crash reports.
Bot protection with Google reCAPTCHA on web panel sign-up: legitimate interest in preventing fraud and abuse (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
Analytics cookies (Google Analytics): consent (GDPR Art. 6(1)(a)), only after you accept the cookie banner.
4. Children
Student accounts are linked only after a guardian has given explicit consent. The guardian can withdraw consent in the app; location sharing for that child then stops.
5. Retention
Location pings: 30 days, then deleted automatically.
Notifications: deleted 90 days after they were read.
Notification delivery log: 30 days after delivery.
Crash reports: 90 days in Firebase Crashlytics, then deleted automatically.
Device security signals: cleared 90 days after the device last reported them.
Account data: while the account is active; on account deletion it is deleted or anonymised at once (see the account deletion page). Encrypted backups expire after at most 12 months.
Settlement and billing records: as long as tax law requires (10 years).
Audit logs of administrative actions in an organisation: as long as the organisation exists.
6. Recipients and processors
Hosting provider in the EU (Germany): servers, database and authentication.
Cloudflare: network protection and traffic routing for the service, and hosting of this website.
Firebase Cloud Messaging (Google): delivery of push notifications.
Firebase Crashlytics (Google): crash reports, covering stack trace, device model, OS, app version, installation id and device security signals.
Apple App Store and Google Play: sale and billing of subscriptions.
Resend: transactional email.
Google Maps (maps and address search), Google Sign-In (optional) and Google Analytics (web admin panel only, with consent).
Google reCAPTCHA (web panel sign-up only): bot protection.
Where a provider processes data outside the EU or Türkiye, transfers rely on standard contractual clauses (GDPR Art. 46; KVKK Art. 9).
7. Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection, and to withdraw consent at any time (GDPR Art. 15–22; KVKK Art. 11).
You can lodge a complaint with a supervisory authority: in Türkiye the Personal Data Protection Authority (KVKK), in the EU the authority of your country of residence.
To exercise your rights, contact the-bus@gumuslabs.com.
8. Changes
We will announce material changes to this notice in the app and on this page.