Privacy Policy
This policy explains what StoneHub actually collects. The Application contains no advertising network, no analytics tracker and no third-party marketing tool.
It also serves as the disclosure required by Article 10 of Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"). Section (i) covers the GDPR position for users in the European Union.
a) Data Controller
Data controllers: Fazıl Eren Çiftdemir ve İsacan Çeliktaş. Both are joint controllers for the processing described here; addressing a request to either of them has the same effect.
Address: Acıbadem Mahallesi, Beyazleylaklı Sokak No: 6, Kadıköy / İstanbul
For requests: stoneaihub@gmail.com
b) Personal Data We Process
Identity and contact details:
- Full name
- E-mail address (required to open an account)
- Phone number (optional)
- For Corporate Members: company name, contact person, company phone, company e-mail and website
Account and security data:
- Your password — stored only as an irreversible hash; StoneHub never sees it in plain text
- Account creation date, session and authentication records
- Account type (individual / corporate), interface language, notification preference
Membership and purchase data:
- Plan (Basic / Premium) and subscription start and end dates
- Showcase credits and product rights purchased, and records of their use
- Your payment details are NOT processed by StoneHub. Purchases run through the Apple App Store; your card details stay with Apple and StoneHub only learns that a purchase took place
Content you publish:
- Company profile: description, country, city, street address and map coordinates
- Quarry and facility locations: type, name, country, city, address and coordinates
- Product details: name, description, stone type, finish, dimensions, stock, price and currency
- Product and cover photographs
- Buying requests: title, description, stone type, quantity, delivery location and the phone number or e-mail you put in the request
Company profile and product information is visible to every user of the Application from the moment it is published. Buying requests are shown only to Premium members, and that includes the contact details you put in them. We recommend not uploading confidential information or information belonging to third parties.
Usage and interaction data:
- Products you favourite and companies you follow
- View counters for company profiles and products (we do NOT record who viewed what — only a total count is incremented)
- Your in-app notifications and their read status
Reports and blocks:
- Content reports you submit: the reported record, the reason you selected and any note you added
- Companies you have blocked
Device and notification data:
- Push notification identifier and platform (iOS/Android) — only if you have allowed notifications
Location data — important note:
- If you grant permission on the map screen, your device's current location is used only to place you on the map, build the "near you" list and calculate a trip route.
- That location is processed on your device; it is NOT sent to or stored on StoneHub servers. Every other feature of the Application works without granting location permission.
- Separately, the coordinates a Corporate Member enters for its own company or quarry are business information published deliberately, and these are stored.
What we do not collect: StoneHub does not collect identity documents, national identity numbers, card details, advertising identifiers (IDFA), biometric data or special categories of personal data. The Application uses no cookies.
c) Purposes of Processing
Account and membership: creating your account, authenticating you, maintaining your session, granting permissions according to your account type.
Listing and promotion: publishing your company profile and products, showing them on the map and in search, operating the showcase service.
Paid services: tracking your plan and entitlements, calculating usage quotas, monitoring subscription start and end dates.
Communication and notifications: notifying you when a company you follow adds a product, when a product you favourited is updated, or when your showcase period is about to end; and delivering transactional messages such as account verification and password resets. These relate to the operation of the service and carry no promotional or marketing purpose.
Security and abuse prevention: assessing content reports, detecting fake listings and accounts, applying your blocking preferences, protecting system security.
Service improvement: reviewing aggregate view counts for product and company pages. This review is not carried out at individual level.
Legal obligations: meeting statutory retention and disclosure duties, responding to requests from competent authorities, and establishing or defending legal claims.
d) Recipients and Transfers
Your data is never sold, rented out, or transferred for marketing purposes to anyone other than the recipients listed below.
Other users: the information you publish in your company profile and product listings (name, contact person, phone, e-mail, address, location, photographs) is visible to other users of the Application. Buying requests you post, and the contact details inside them, are shown only to Premium members. That is inherent to the service, and the decision to publish is yours.
Hosting provider: data is hosted on Supabase infrastructure on servers located in Ireland (European Union).
Notification infrastructure: push notifications are delivered through the Expo notification service to Apple (APNs) and Google (FCM). Only the device notification identifier and the notification text are shared.
Apple: when you buy a paid service, the transaction takes place through the Apple App Store and payment data is processed by Apple.
Apps on your device: when you call a company, message it on WhatsApp, send an e-mail or request directions, your device's corresponding app (phone, WhatsApp, e-mail, maps) takes over. From that point the relevant provider's privacy policy applies.
Public authorities: competent public bodies and judicial authorities, where disclosure is required by law.
Transfers abroad: because the hosting and notification infrastructures are located outside Türkiye, your data is transferred abroad within the meaning of Article 9 of the KVKK. Each recipient, its role and the country its servers are in is listed individually above. Under Article 11 of the KVKK you may ask at any time which recipients your data has been transferred to.
e) Collection Method and Legal Basis
Personal data is collected electronically through the mobile application, from the information you enter and from records generated while the Application operates.
Legal bases (KVKK Art. 5/2):
- Performance of a contract (Art. 5/2-c): creating an account, publishing listings, providing paid services, sending notifications
- Compliance with a legal obligation (Art. 5/2-ç): statutory retention and disclosure duties
- Establishment, exercise or protection of a right (Art. 5/2-e): keeping records that may serve as evidence in disputes
- Legitimate interests (Art. 5/2-f): platform security, combating fake listings and abuse, improving the service
Explicit consent: no data is currently processed for marketing and no commercial electronic messages are sent to you, so use of the service is not based on explicit consent.
Should commercial electronic messages be sent in future, separate explicit consent will be obtained for that purpose alone. You may withdraw it at any time, and neither opening an account nor using the service will ever depend on giving it.
Notification and location permissions are granted through your device's operating system and can be withdrawn at any time.
f) Retention Periods
- Account data: for as long as your account is open
- Company profile, products and photographs: until taken down or the account is deleted
- Push notification identifier: until you turn notifications off or delete the account
- Content reports and blocking records: 2 years after assessment, for abuse prevention
- Purchase and membership records: 10 years, under tax and commercial legislation
- Records subject to a dispute: for the applicable limitation period
When the period expires, data is deleted, destroyed or irreversibly anonymised.
g) Data Security
Principal technical measures:
- All traffic is encrypted with TLS
- Row-level security is enforced in the database; each user can reach only the records they are authorised for
- Session data is stored encrypted on the device, in the operating system's secure storage
- Server-side operations pass through authentication and ownership checks
- Access to uploaded images is restricted by path-based authorisation rules
- Passwords are stored as irreversible hashes
Organisational measures: access to data is limited to people who need it for their role, and access rights are reviewed regularly.
In the event of a data breach, notification is made to the Turkish Data Protection Authority and to affected individuals as soon as possible, in line with Article 12/5 of the KVKK, and to the competent supervisory authority under Article 33 of the GDPR where applicable.
h) Your Rights and the Controls You Hold
Under Article 11 of the KVKK you may ask whether your data is processed, request information about it, learn the purposes and whether it is used accordingly, learn the recipients at home and abroad, request rectification, request erasure or destruction, request that such actions be communicated to recipients, object to adverse results produced solely by automated analysis, and claim compensation for damage caused by unlawful processing.
Controls available to you directly in the Application:
- Update your profile details from Profile > Edit profile
- Turn notifications off in profile settings
- Withdraw location permission at any time in device settings
- Take your products and company profile down at any time
- Permanently delete your account and data from Profile > Delete my account
How to apply: send your request in Turkish by either of these routes:
- In writing, signed, to Acıbadem Mahallesi, Beyazleylaklı Sokak No: 6, Kadıköy / İstanbul
- By e-mail to stoneaihub@gmail.com, from an address registered in our system
Your request should state your name, identity number (nationality and passport number if you are not a Turkish citizen), an address for service, your phone and e-mail where available, and what you are asking for. A written request also needs your signature.
Requests are answered free of charge as soon as possible and within 30 days at the latest. Where the action requested carries a cost of its own, the fee set by the Board may apply.
You do not need to apply in order to delete your account and data — the "Delete my account" function in the Application does it immediately.
Complaint to the Board: if your request is refused, our answer is inadequate, or you receive no answer within 30 days, you may complain to the Turkish Data Protection Board within 30 days of learning the answer and in any case within 60 days of your request (KVKK Art. 14). You must apply to us before going to the Board.
i) Users in the European Union (GDPR)
For users resident in the EU, the legal bases for processing are: performance of a contract (GDPR Art. 6(1)(b)), compliance with a legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f) — platform security and abuse prevention).
Data is hosted on servers in Ireland (European Union), that is, within the EU. Limited transfers outside the EU as part of the notification infrastructure are made on the basis of standard contractual clauses.
Your rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and not to be subject to automated decision-making (Art. 22). StoneHub carries out no automated decision-making or profiling producing legal effects.
You may exercise these rights at stoneaihub@gmail.com. You also have the right to lodge a complaint with the data protection supervisory authority in your country.
j) Children's Data
StoneHub is not directed at persons under 18 and does not knowingly collect their data. If such data is found to have been processed, the account is closed and the data deleted.
k) Changes
This policy may be updated to reflect changes in the services and in applicable law. Material changes are announced by in-app notice. The current version is always published on this screen in the Application.
Effective date: 5 October 2026