New: Buying requests are live — describe the stone you need, let suppliers come to you
StoneHub StoneHub

Privacy Policy

5 October 2026

This policy explains what StoneHub actually collects. The Application contains no advertising network, no analytics tracker and no third-party marketing tool.

It also serves as the disclosure required by Article 10 of Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"). Section (i) covers the GDPR position for users in the European Union.

a) Data Controller

Data controllers: Fazıl Eren Çiftdemir ve İsacan Çeliktaş. Both are joint controllers for the processing described here; addressing a request to either of them has the same effect.

Address: Acıbadem Mahallesi, Beyazleylaklı Sokak No: 6, Kadıköy / İstanbul

For requests: stoneaihub@gmail.com

b) Personal Data We Process

Identity and contact details:

Account and security data:

Membership and purchase data:

Content you publish:

Company profile and product information is visible to every user of the Application from the moment it is published. Buying requests are shown only to Premium members, and that includes the contact details you put in them. We recommend not uploading confidential information or information belonging to third parties.

Usage and interaction data:

Reports and blocks:

Device and notification data:

Location data — important note:

What we do not collect: StoneHub does not collect identity documents, national identity numbers, card details, advertising identifiers (IDFA), biometric data or special categories of personal data. The Application uses no cookies.

c) Purposes of Processing

Account and membership: creating your account, authenticating you, maintaining your session, granting permissions according to your account type.

Listing and promotion: publishing your company profile and products, showing them on the map and in search, operating the showcase service.

Paid services: tracking your plan and entitlements, calculating usage quotas, monitoring subscription start and end dates.

Communication and notifications: notifying you when a company you follow adds a product, when a product you favourited is updated, or when your showcase period is about to end; and delivering transactional messages such as account verification and password resets. These relate to the operation of the service and carry no promotional or marketing purpose.

Security and abuse prevention: assessing content reports, detecting fake listings and accounts, applying your blocking preferences, protecting system security.

Service improvement: reviewing aggregate view counts for product and company pages. This review is not carried out at individual level.

Legal obligations: meeting statutory retention and disclosure duties, responding to requests from competent authorities, and establishing or defending legal claims.

d) Recipients and Transfers

Your data is never sold, rented out, or transferred for marketing purposes to anyone other than the recipients listed below.

Other users: the information you publish in your company profile and product listings (name, contact person, phone, e-mail, address, location, photographs) is visible to other users of the Application. Buying requests you post, and the contact details inside them, are shown only to Premium members. That is inherent to the service, and the decision to publish is yours.

Hosting provider: data is hosted on Supabase infrastructure on servers located in Ireland (European Union).

Notification infrastructure: push notifications are delivered through the Expo notification service to Apple (APNs) and Google (FCM). Only the device notification identifier and the notification text are shared.

Apple: when you buy a paid service, the transaction takes place through the Apple App Store and payment data is processed by Apple.

Apps on your device: when you call a company, message it on WhatsApp, send an e-mail or request directions, your device's corresponding app (phone, WhatsApp, e-mail, maps) takes over. From that point the relevant provider's privacy policy applies.

Public authorities: competent public bodies and judicial authorities, where disclosure is required by law.

Transfers abroad: because the hosting and notification infrastructures are located outside Türkiye, your data is transferred abroad within the meaning of Article 9 of the KVKK. Each recipient, its role and the country its servers are in is listed individually above. Under Article 11 of the KVKK you may ask at any time which recipients your data has been transferred to.

e) Collection Method and Legal Basis

Personal data is collected electronically through the mobile application, from the information you enter and from records generated while the Application operates.

Legal bases (KVKK Art. 5/2):

Explicit consent: no data is currently processed for marketing and no commercial electronic messages are sent to you, so use of the service is not based on explicit consent.

Should commercial electronic messages be sent in future, separate explicit consent will be obtained for that purpose alone. You may withdraw it at any time, and neither opening an account nor using the service will ever depend on giving it.

Notification and location permissions are granted through your device's operating system and can be withdrawn at any time.

f) Retention Periods

When the period expires, data is deleted, destroyed or irreversibly anonymised.

g) Data Security

Principal technical measures:

Organisational measures: access to data is limited to people who need it for their role, and access rights are reviewed regularly.

In the event of a data breach, notification is made to the Turkish Data Protection Authority and to affected individuals as soon as possible, in line with Article 12/5 of the KVKK, and to the competent supervisory authority under Article 33 of the GDPR where applicable.

h) Your Rights and the Controls You Hold

Under Article 11 of the KVKK you may ask whether your data is processed, request information about it, learn the purposes and whether it is used accordingly, learn the recipients at home and abroad, request rectification, request erasure or destruction, request that such actions be communicated to recipients, object to adverse results produced solely by automated analysis, and claim compensation for damage caused by unlawful processing.

Controls available to you directly in the Application:

How to apply: send your request in Turkish by either of these routes:

Your request should state your name, identity number (nationality and passport number if you are not a Turkish citizen), an address for service, your phone and e-mail where available, and what you are asking for. A written request also needs your signature.

Requests are answered free of charge as soon as possible and within 30 days at the latest. Where the action requested carries a cost of its own, the fee set by the Board may apply.

You do not need to apply in order to delete your account and data — the "Delete my account" function in the Application does it immediately.

Complaint to the Board: if your request is refused, our answer is inadequate, or you receive no answer within 30 days, you may complain to the Turkish Data Protection Board within 30 days of learning the answer and in any case within 60 days of your request (KVKK Art. 14). You must apply to us before going to the Board.

i) Users in the European Union (GDPR)

For users resident in the EU, the legal bases for processing are: performance of a contract (GDPR Art. 6(1)(b)), compliance with a legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f) — platform security and abuse prevention).

Data is hosted on servers in Ireland (European Union), that is, within the EU. Limited transfers outside the EU as part of the notification infrastructure are made on the basis of standard contractual clauses.

Your rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and not to be subject to automated decision-making (Art. 22). StoneHub carries out no automated decision-making or profiling producing legal effects.

You may exercise these rights at stoneaihub@gmail.com. You also have the right to lodge a complaint with the data protection supervisory authority in your country.

j) Children's Data

StoneHub is not directed at persons under 18 and does not knowingly collect their data. If such data is found to have been processed, the account is closed and the data deleted.

k) Changes

This policy may be updated to reflect changes in the services and in applicable law. Material changes are announced by in-app notice. The current version is always published on this screen in the Application.

Effective date: 5 October 2026