Miles Coffee

Miles Coffee Information Notice on the Processing of Personal Data (KVKK)

Version 1.1 · Effective 9 October 2026

We prepared this notice under Article 10 of Law No. 6698 on the Protection of Personal Data. It explains which personal data we process through the Miles Coffee app, its API, and the organizer dashboard. It also gives our purposes and legal grounds. Finally, it shows who receives your data, how long we keep it, and how you can use your rights under Article 11 of the Law.

Data controller

The data controller for your personal data is UCB GIDA İMALATI İTHALAT İHRACAT TURİZM SANAYİ VE TİCARET ANONİM ŞİRKETİ ("Miles Coffee" or "we"). This role comes from Law No. 6698 on the Protection of Personal Data (the Law). This company operates the Miles Coffee brand.

We do not publish a phone number. You can contact us by e-mail or by post.

Purpose and scope of this notice

We prepared this notice to inform you under Article 10 of the Law. The notice also meets the Communiqué on Procedures and Principles to be Followed in Fulfilment of the Obligation to Inform.

This notice covers the Miles Coffee iOS app (bundle ID co.milescoffee.app) and the application programming interface (API) at https://api.miles.coffee. It also covers the organizer dashboard that authorized Miles staff use. The website shop at milescoffee.co has its own policies. The app only links to the shop.

You can browse coffees, store information, and public events without an account. This notice is mainly for persons who create an account in the app and use its member features.

Our Privacy Policy explains the same processing in simpler words. You can read the Privacy Policy at https://miles.coffee/legal/privacy.

Categories of personal data that we process

When you use the app and create an account, we process these categories of personal data:

For accountability, we record internally which staff member recorded each event check-in. Earning Status Miles from purchases is not active yet.

We process no special categories of personal data. Thus, we carry out no processing under Article 6 of the Law.

We do not collect location data, camera or photo data, contacts from your address book, health data, payment or card data, or advertising identifiers. We do not track you across apps or websites. We do not use third-party advertising or analytics software development kits (SDKs). We do not sell personal data.

Your language choice, saved coffees (favorites), and cached details of public events stay only on your device. The app does not send this data to our server. The app keeps session tokens in the iOS secure storage (Keychain) on your device.

Purposes of processing

We process your personal data for these purposes:

We do not use your personal data for profiling that has a legal effect on you.

How we collect personal data

We collect your personal data electronically, by fully or partly automated means, through these channels:

We collect this data on the legal grounds in the section about legal grounds for processing.

Recipients and purposes of transfer

In line with Articles 8 and 9 of the Law, we transfer your personal data only to these recipients and for these purposes:

We use no other processors, and we do not sell your personal data.

The links in the app to Google Maps, Instagram, and the Miles website open third-party services. The policies of those services apply to the data that they collect.

Transfers of personal data abroad

Article 9 of the Law, as amended by Law No. 7499 in 2024, sets the rules for transfers abroad. A transfer needs one of the conditions in Article 5 or Article 6 of the Law. It also needs an adequacy decision for the country, the sector in that country, or the international organization.

If no adequacy decision exists, a transfer can rely on one of the appropriate safeguards in the Law. You must also be able to use your rights and apply to effective legal remedies in the destination country. Examples are a standard contract that the Personal Data Protection Board announces, binding corporate rules, and a written undertaking that the Board permits.

The data controller or the data processor notifies a standard contract to the Personal Data Protection Authority within five business days after signature.

If no adequacy decision and no appropriate safeguard exist, only an occasional transfer is possible. It must fit one of the exceptional cases that the Law lists.

Your requests to the API pass through the global network of Cloudflare, Inc. We carry out this transfer under Article 9 of the Law, with the appropriate safeguards that the Law requires. The safeguard for this transfer is a standard contract. The transfer relies on the legal grounds for the data in the requests, as the section about legal grounds for processing shows.

When we turn on remote notifications, notification data will go to Expo and Apple in the United States. We will announce this change in the app before it takes effect. We will carry out that transfer under Article 9 of the Law.

Retention periods

We keep your personal data for these periods:

You can delete your account in the app. Open Account > Delete account and confirm with your current password. We then remove this data from the active database immediately:

If a step fails, the system tries the cleanup again automatically within minutes. A freed reservation place goes to the next member on the waiting list. Deleted data leaves the backups within 7 days.

You can also request the deletion of your account by e-mail to [email protected].

When the retention period ends or the reasons for processing no longer exist, we erase, destroy, or anonymize the personal data. We do this under Article 7 of the Law and the related legislation.

Your rights under Article 11 of the Law

Under Article 11 of the Law, you can apply to the data controller and use these rights:

How to apply and how we answer

The Communiqué on Procedures and Principles of Application to the Data Controller sets the application methods. You can send a request about your rights in one of these ways:

Your application must include this information:

Attach the information and documents about the subject to your application.

We conclude your application as soon as possible, based on the nature of the request, and within 30 days at the latest. We do this free of charge. If the action has an extra cost, we can charge the fee in the tariff of the Personal Data Protection Board. If the application results from our error, we refund the fee.

We accept your application, or we reject it and give our reasons. We send our answer to you in writing or electronically.

Right to complain to the Personal Data Protection Board

Under Article 14 of the Law, you can complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) in these cases: we reject your application, you find our answer insufficient, or we do not answer in time.

You must complain within 30 days after you learn our answer, and in all cases within 60 days after the date of your application. Under the Law, you must apply to us first, before you complain to the Board.

Version, changes, and language

This is version 1.1 of this notice. It is effective from 9 October 2026. Each version shows its version number and effective date.

We announce material changes in the app before they take effect.

The Turkish version of this notice is at https://miles.coffee/legal/kvkk. The English version is at https://miles.coffee/legal/kvkk?lang=en.

The English version is a translation of the Turkish text. If the Turkish and English versions differ, the Turkish version prevails.