Miles Coffee Information Notice on the Processing of Personal Data (KVKK)
We prepared this notice under Article 10 of Law No. 6698 on the Protection of Personal Data. It explains which personal data we process through the Miles Coffee app, its API, and the organizer dashboard. It also gives our purposes and legal grounds. Finally, it shows who receives your data, how long we keep it, and how you can use your rights under Article 11 of the Law.
Data controller
The data controller for your personal data is UCB GIDA İMALATI İTHALAT İHRACAT TURİZM SANAYİ VE TİCARET ANONİM ŞİRKETİ ("Miles Coffee" or "we"). This role comes from Law No. 6698 on the Protection of Personal Data (the Law). This company operates the Miles Coffee brand.
- Trade name: UCB GIDA İMALATI İTHALAT İHRACAT TURİZM SANAYİ VE TİCARET ANONİM ŞİRKETİ
- MERSIS number: 0883103620600001
- Tax office and tax number: Alemdar Tax Office, 8831036206
- Address: İstasyon Mah. Çilem Sk. Kartepe Sanayi Sitesi K Blok No:1 K/147 Kartepe/Kocaeli, Türkiye
- Data protection e-mail: [email protected]
- Cafe and customer contact: [email protected]
We do not publish a phone number. You can contact us by e-mail or by post.
Purpose and scope of this notice
We prepared this notice to inform you under Article 10 of the Law. The notice also meets the Communiqué on Procedures and Principles to be Followed in Fulfilment of the Obligation to Inform.
This notice covers the Miles Coffee iOS app (bundle ID co.milescoffee.app) and the application programming interface (API) at https://api.miles.coffee. It also covers the organizer dashboard that authorized Miles staff use. The website shop at milescoffee.co has its own policies. The app only links to the shop.
You can browse coffees, store information, and public events without an account. This notice is mainly for persons who create an account in the app and use its member features.
Our Privacy Policy explains the same processing in simpler words. You can read the Privacy Policy at https://miles.coffee/legal/privacy.
Categories of personal data that we process
When you use the app and create an account, we process these categories of personal data:
- Identity and contact data: full name, e-mail address, and phone number. The phone number is optional at registration. You must give it only to reserve an event place.
- Customer transaction data: event reservations and waiting-list entries, with status, position, and timestamps. Event check-ins that Miles staff record, with the check-in time. Milesport passport stamps, which are an account seal with your membership start date and event stamps after a staff check-in. Membership tier, Status Miles total, achievements, and saved reward goal. Private inbox notices about reservations and events.
- Preference data: preferred coffee style and notification preferences.
- Transaction security data: the password, stored only as an Argon2 hash. Session refresh tokens, stored only as hashes. Short-lived access tokens and refresh sessions. A reference hash of the member QR code that the server signs. The IP address, which the gateway processes only in memory to limit sign-in attempts. Server error logs.
- Device data: a push notification token and the device platform, only if you allow notifications on your device.
For accountability, we record internally which staff member recorded each event check-in. Earning Status Miles from purchases is not active yet.
We process no special categories of personal data. Thus, we carry out no processing under Article 6 of the Law.
We do not collect location data, camera or photo data, contacts from your address book, health data, payment or card data, or advertising identifiers. We do not track you across apps or websites. We do not use third-party advertising or analytics software development kits (SDKs). We do not sell personal data.
Your language choice, saved coffees (favorites), and cached details of public events stay only on your device. The app does not send this data to our server. The app keeps session tokens in the iOS secure storage (Keychain) on your device.
Purposes of processing
We process your personal data for these purposes:
- To create and manage your account and to let you sign in
- To contact you about reservations and to send service notices
- To manage membership, event reservations, capacity, and waiting lists
- To keep event attendance records and to give Milesport passport stamps and achievements
- To plan event capacity and to keep attendance records accountable
- To apply your coffee style and notification preferences, and to send push notifications to your device if you allow them
- To send offer messages if you give your explicit consent
- To keep your account secure, to prevent fraud and abuse, and to protect the integrity of the service
- To meet legal obligations and to give the information that authorized public authorities and courts request
- To establish, use, or protect a right if a legal claim arises
We do not use your personal data for profiling that has a legal effect on you.
Legal grounds for processing
We process your personal data on these legal grounds in Article 5 of the Law:
- The processing of the personal data of the parties is necessary, and directly related to the establishment or performance of a contract, Article 5(2)(c). This ground covers identity and contact data, customer transaction data, preference data, transaction security data, and device data. We process this data for your account, sign-in, reservations, waiting lists, attendance records, Milesport stamps, and achievements. We also process it for preferences, service notices, and push notifications if you allow them.
- The processing is mandatory for us to meet a legal obligation, Article 5(2)(ç). This ground covers obligations about account and transaction security where they apply, and requests from authorized public authorities and courts.
- The processing is mandatory to establish, use, or protect a right, Article 5(2)(e). This ground covers keeping and using the data that a legal claim needs, if a legal claim arises.
- The processing is mandatory for our legitimate interests, Article 5(2)(f), provided that it does not harm your fundamental rights and freedoms. This ground covers event capacity planning, accountability for attendance records, prevention of fraud and abuse, and the integrity of the service.
- Explicit consent, Article 5(1). This ground covers offer messages. These messages are commercial electronic messages under Law No. 6563 on the Regulation of Electronic Commerce. We send them only with your approval.
Offer notifications are off by default. You do not need to give explicit consent to use the app. You can withdraw your explicit consent and approval at any time in Notification settings (Account > Notifications). You do not need to give a reason, and the withdrawal costs nothing. A withdrawal does not affect the lawfulness of earlier processing.
Remote push delivery is not active yet. When it becomes active, offer messages will depend on this explicit consent and approval. Event updates and new coffee notices are on by default. You can change these preferences on the same screen.
We process no special categories of personal data. Thus, we rely on no legal ground in Article 6 of the Law.
How we collect personal data
We collect your personal data electronically, by fully or partly automated means, through these channels:
- The forms in the app, such as the registration and reservation forms, and your actions in the app
- The API that the app connects to
- Event check-ins that authorized Miles staff record in the organizer dashboard
- The push notification token that your device supplies, if you allow notifications on your device
We collect this data on the legal grounds in the section about legal grounds for processing.
Recipients and purposes of transfer
In line with Articles 8 and 9 of the Law, we transfer your personal data only to these recipients and for these purposes:
- Hosting: the API and the database run on a server that the Miles technical team operates in Türkiye. We store your data in Türkiye.
- Cloudflare, Inc. (United States): network security, TLS, and traffic routing in front of the API. The personal data in requests passes through the global network of Cloudflare. The section about transfers abroad explains this transfer.
- Apple Inc.: distribution of the app through the App Store and TestFlight, and the device push service when notifications become active. The Apple policy applies to the data that Apple collects.
- Expo (650 Industries, Inc., United States): push notification relay. We will use this service only when we turn on remote notifications in a later version. This service is not active now.
- Authorized Miles staff: access to the reservations, attendance records, and contact details that they need to run events.
- Authorized public authorities and courts: only when the law requires it, and only to meet the related legal obligation.
We use no other processors, and we do not sell your personal data.
The links in the app to Google Maps, Instagram, and the Miles website open third-party services. The policies of those services apply to the data that they collect.
Transfers of personal data abroad
Article 9 of the Law, as amended by Law No. 7499 in 2024, sets the rules for transfers abroad. A transfer needs one of the conditions in Article 5 or Article 6 of the Law. It also needs an adequacy decision for the country, the sector in that country, or the international organization.
If no adequacy decision exists, a transfer can rely on one of the appropriate safeguards in the Law. You must also be able to use your rights and apply to effective legal remedies in the destination country. Examples are a standard contract that the Personal Data Protection Board announces, binding corporate rules, and a written undertaking that the Board permits.
The data controller or the data processor notifies a standard contract to the Personal Data Protection Authority within five business days after signature.
If no adequacy decision and no appropriate safeguard exist, only an occasional transfer is possible. It must fit one of the exceptional cases that the Law lists.
Your requests to the API pass through the global network of Cloudflare, Inc. We carry out this transfer under Article 9 of the Law, with the appropriate safeguards that the Law requires. The safeguard for this transfer is a standard contract. The transfer relies on the legal grounds for the data in the requests, as the section about legal grounds for processing shows.
When we turn on remote notifications, notification data will go to Expo and Apple in the United States. We will announce this change in the app before it takes effect. We will carry out that transfer under Article 9 of the Law.
Retention periods
We keep your personal data for these periods:
- Account data: while your account exists.
- Access tokens: valid for 15 minutes. Refresh sessions: valid for 30 days. Each time the app uses a refresh token, we replace it with a new token.
- Member QR code: valid for 90 seconds. The server keeps only a reference hash of the code.
- IP address for sign-in limits: the gateway processes it only in memory and does not store it.
- Server error logs: these logs rotate automatically. We keep no access logs.
- Encrypted daily backups: we keep each backup for 7 days and then delete it automatically.
- Deletion record: we keep it for 30 days. It contains only a random account ID and the deletion time. It stops a deleted account from returning after a backup restore. It contains no name, e-mail address, phone number, or other profile data.
- Data that a legal claim or a legal obligation needs: for the period that the related legislation requires.
You can delete your account in the app. Open Account > Delete account and confirm with your current password. We then remove this data from the active database immediately:
- Account and profile
- Sessions and member codes
- Reservations and waiting-list entries
- Attendance records and Milesport stamps
- Inbox notices and device tokens
If a step fails, the system tries the cleanup again automatically within minutes. A freed reservation place goes to the next member on the waiting list. Deleted data leaves the backups within 7 days.
You can also request the deletion of your account by e-mail to [email protected].
When the retention period ends or the reasons for processing no longer exist, we erase, destroy, or anonymize the personal data. We do this under Article 7 of the Law and the related legislation.
Your rights under Article 11 of the Law
Under Article 11 of the Law, you can apply to the data controller and use these rights:
- Learn whether we process your personal data
- Request information about the processing, if we process your personal data
- Learn the purpose of the processing and whether we use your data for that purpose
- Know the third parties in Türkiye or abroad that receive your personal data
- Ask us to correct your personal data if it is incomplete or wrong
- Ask us to erase or destroy your personal data under the conditions in Article 7 of the Law
- Ask us to notify the third parties that received your personal data about a correction, erasure, or destruction
- Object to a result against you that comes from an analysis of your data by automated systems only
- Claim compensation if you suffer damage because of unlawful processing of your personal data
How to apply and how we answer
The Communiqué on Procedures and Principles of Application to the Data Controller sets the application methods. You can send a request about your rights in one of these ways:
- In writing, with your wet signature, to İstasyon Mah. Çilem Sk. Kartepe Sanayi Sitesi K Blok No:1 K/147 Kartepe/Kocaeli, Türkiye
- To [email protected], with your registered electronic mail (KEP) address, your secure electronic signature, or your mobile signature
- To [email protected], from the e-mail address that you gave us before and that is registered in our system. An example is the e-mail address of your Miles Coffee account.
Your application must include this information:
- Your name, your surname, and your signature if the application is in writing
- For citizens of the Republic of Türkiye, the Turkish identity number. For foreign nationals, the nationality, the passport number, or the identity number if any.
- Your residential address or business address for notifications
- Your e-mail address, phone number, and fax number for notifications, if any
- The subject of your request
Attach the information and documents about the subject to your application.
We conclude your application as soon as possible, based on the nature of the request, and within 30 days at the latest. We do this free of charge. If the action has an extra cost, we can charge the fee in the tariff of the Personal Data Protection Board. If the application results from our error, we refund the fee.
We accept your application, or we reject it and give our reasons. We send our answer to you in writing or electronically.
Right to complain to the Personal Data Protection Board
Under Article 14 of the Law, you can complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) in these cases: we reject your application, you find our answer insufficient, or we do not answer in time.
You must complain within 30 days after you learn our answer, and in all cases within 60 days after the date of your application. Under the Law, you must apply to us first, before you complain to the Board.
Version, changes, and language
This is version 1.1 of this notice. It is effective from 9 October 2026. Each version shows its version number and effective date.
We announce material changes in the app before they take effect.
The Turkish version of this notice is at https://miles.coffee/legal/kvkk. The English version is at https://miles.coffee/legal/kvkk?lang=en.
The English version is a translation of the Turkish text. If the Turkish and English versions differ, the Turkish version prevails.