Miles Coffee Privacy Policy
This policy explains how Miles Coffee handles your personal data when you use the Miles Coffee iOS app. You can browse coffees, store information, and public events without an account. We collect only the data that we need to run your account, your event reservations, and your Milesport passport. We do not sell your data, show third-party advertising, or track you across apps or websites.
Who we are
The data controller for the Miles Coffee app is UCB GIDA İMALATI İTHALAT İHRACAT TURİZM SANAYİ VE TİCARET ANONİM ŞİRKETİ. This company operates the Miles Coffee brand. In this policy, "Miles Coffee", "we", "us", and "our" mean this company.
- MERSIS number: 0883103620600001
- Tax office: Alemdar. Tax number: 8831036206
- Registered address: İstasyon Mah. Çilem Sk. Kartepe Sanayi Sitesi K Blok No:1 K/147 Kartepe/Kocaeli, Türkiye
- Data protection e-mail: [email protected]
"You" means a person who uses the app, as a guest or with a Miles Coffee account.
What this policy covers
This policy covers the Miles Coffee iOS app (bundle ID co.milescoffee.app) and its application programming interface (API) at https://api.miles.coffee. It also covers the organizer dashboard that authorized Miles staff use to run events.
The Miles website shop at milescoffee.co has its own policies. The app only links to the shop. The policies of the website apply to the data that the website collects.
You can browse coffees, store information, and public events as a guest, without an account. You need an account to reserve an event place and to use member features, such as the member QR code and the Milesport passport.
We process personal data under Turkish Law No. 6698 on the Protection of Personal Data (KVKK). Our KVKK information notice gives the details that this law requires. You can read it at https://miles.coffee/legal/kvkk.
Personal data we collect
We collect the personal data below when you create an account and use the app. We collect it through the forms in the app and your actions in the app. Authorized Miles staff also record event check-ins in the organizer dashboard.
- Identity and contact data: your full name, e-mail address, and phone number. The phone number is optional when you register. You must give it only if you want to reserve an event place.
- Customer transaction data (events): your event reservations and waiting-list entries, with their status, position, and timestamps. This data also includes the check-in that Miles staff record when you attend an event, with the check-in time. For accountability, we also record internally which staff member recorded the check-in.
- Customer transaction data (membership): your Milesport passport stamps, membership tier, Status Miles total, achievements, saved reward goal, and private inbox notices about your reservations and events. The Milesport passport has an account seal with your membership start date. You get an event stamp after a staff check-in.
- Preference data: your preferred coffee style and your notification preferences.
- Device data: a push notification token and the platform of your device. We get these only if you allow notifications on your device.
The app shows your Status Miles total as Miles points. Earning Status Miles from purchases is not active yet.
Some data stays only on your device. The app does not send this data to our server:
- Your language choice
- Your saved coffees (favorites)
- Cached details of public events
The app keeps your session tokens in the iOS secure storage (Keychain) on your device.
Transaction security data
We process the data below to keep your account and our service secure.
- Password: we store your password only as an Argon2 hash. We never store it in plain text.
- Sessions: we store session refresh tokens only as hashes. An access token is valid for 15 minutes. A refresh session is valid for 30 days. Each time the app uses a refresh token, we replace it with a new token.
- Member QR code: the server signs each code, and each code is valid for 90 seconds. The server keeps only a reference hash of the code.
- Sign-in attempts: our gateway limits sign-in attempts for each IP address. The gateway keeps these counts only in memory and does not store them.
- Error logs: our server keeps error logs, and these logs rotate automatically. We do not keep access logs.
Data we do not collect
- Precise or approximate location. The app does not ask for location permission. Store directions open in Google Maps, outside the app.
- Camera, photos, or contacts
- Health data
- Payment or card data. The app has no in-app purchases. Shop links open the Miles website.
- Advertising identifiers
We do not track you across apps or websites. We do not use third-party advertising or analytics software development kits (SDKs). We do not sell personal data.
We do not process special categories of personal data, such as health or biometric data. We do not use profiling that has a legal effect on you.
How we use your data and why
We use your personal data only for the purposes below. For each purpose, we give the legal ground under Article 5 of Law No. 6698.
- To create and manage your account, let you sign in, contact you about a reservation, and send you service notices. Legal ground: the processing is necessary for the establishment or performance of a contract with you, Article 5(2)(c).
- To run your membership, event reservations, event capacity, waiting lists, attendance records, Milesport passport stamps, and achievements. Legal ground: Article 5(2)(c).
- To plan event capacity and to keep staff accountable for attendance records. Legal ground: our legitimate interest, Article 5(2)(f).
- To apply your coffee style and notification preferences. Legal ground: Article 5(2)(c).
- To keep your account secure, to prevent fraud and abuse, and to protect the integrity of the service. Legal grounds: Article 5(2)(c), our legal obligations under Article 5(2)(ç) where they apply, and our legitimate interest under Article 5(2)(f).
- To send push notifications to your device. Legal grounds: Article 5(2)(c) and the notification permission that you give on your device.
- To meet our legal obligations and to answer lawful requests from public authorities and courts. Legal ground: our legal obligation, Article 5(2)(ç).
- To establish, use, or protect a right if a legal claim arises. Legal ground: Article 5(2)(e).
- To send you offer messages. Legal ground: your explicit consent. The section about notifications and messages gives the details.
Notifications and messages
You control notifications in Notification settings (Account > Notifications). Event updates and new coffee notices are on by default. Offers are off by default.
Offer messages are commercial electronic messages under Law No. 6563 on the Regulation of Electronic Commerce. We send them only with your explicit consent and approval. You do not need to give this consent to use the app.
You can withdraw your consent at any time in Notification settings. You do not need to give a reason, and the withdrawal costs nothing.
Remote push delivery is not active yet. Updates about your reservations and events appear in the inbox in the app. When we turn on remote push delivery, your consent will control whether you get offer messages.
The app also has e-mail verification and password reset. E-mail delivery is off at this time. When we turn it on, we will send these e-mails from a verified sender address.
International transfers
We store your data on a server in Türkiye. Your requests to our API pass through the global network of Cloudflare, Inc., a company in the United States. Thus, this is a transfer of personal data abroad.
We carry out this transfer under Article 9 of Law No. 6698, with the appropriate safeguards that the law requires. The safeguard for this transfer is a standard contract.
When we turn on remote notifications, the data for each notification will go to Expo and Apple in the United States. We will announce this change in the app before it takes effect. We will also carry out that transfer under Article 9.
How long we keep data
- Account data: we keep it while your account exists.
- Backups: we make encrypted daily backups. We keep each backup for 7 days and then delete it automatically.
- Deletion record: after you delete your account, we keep a deletion record for 30 days. The section about account deletion explains this record.
- Error logs: these logs rotate automatically. We do not keep access logs.
- Sign-in attempt counts: our gateway keeps them only in memory and does not store them.
- Legal claims and obligations: we can keep the data that a legal claim or a legal obligation needs, for the period that the law requires.
When the reasons for processing no longer exist, we erase, destroy, or anonymize the personal data under Article 7 of Law No. 6698.
How to delete your account
You can delete your account in the app. Open Account > Delete account, then confirm with your current password.
We then remove the data below from the active database immediately. If a step fails, the system tries the cleanup again automatically within minutes.
- Your account and profile
- Your sessions and member codes
- Your reservations and waiting-list entries
- Your attendance records and Milesport stamps
- Your inbox notices and device tokens
If you held an event place, that place goes to the next member on the waiting list.
Your deleted data leaves our backups within 7 days, because we delete each backup after 7 days.
We keep a deletion record for 30 days. It contains only a random account ID and the deletion time. It contains no name, e-mail address, phone number, or other profile data. This record stops a deleted account from returning if we restore a backup.
You can also ask us to delete your account. Send an e-mail to [email protected].
How we protect your data
We use these measures to protect your personal data:
- TLS encryption for all connections
- Argon2 hashing for passwords
- Hashes instead of plain session tokens
- A database account with only the privileges that it needs
- Encrypted backups
- Role checks for each staff action
- No caching of private responses
No system is fully secure. If you think that someone else has access to your account, contact us at [email protected].
If other persons obtain processed personal data by unlawful means, we notify you and the Personal Data Protection Board as soon as possible. Article 12 of Law No. 6698 requires this.
Your rights
Under Article 11 of Law No. 6698, you have the right to:
- Learn whether we process your personal data
- Request information about the processing, if we process your personal data
- Learn the purpose of the processing and whether we use your data for that purpose
- Know the third parties in Türkiye or abroad that receive your personal data
- Ask us to correct your personal data if it is incomplete or wrong
- Ask us to erase or destroy your personal data under the conditions in Article 7 of Law No. 6698
- Ask us to notify the third parties that received your personal data about a correction, erasure, or destruction
- Object to a result against you that comes from an analysis of your data by automated systems only
- Claim compensation if you suffer damage because of unlawful processing of your personal data
To use these rights, apply in writing to our registered address or by e-mail to [email protected]. Our KVKK information notice explains the application methods. We conclude your application within 30 days at the latest, free of charge. If the action has an extra cost, we can charge the fee in the tariff of the Personal Data Protection Board.
You can withdraw your consent for offer messages at any time in Notification settings. You can also delete your account at any time in the app.
You can complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) in these cases: we reject your application, you find our answer insufficient, or we do not answer in time.
Children
The app is not directed to children under 13. If you are under 18, use the app only with the permission of a parent or guardian.
If you are a parent or guardian and you learn that a child under 13 created an account, contact us at [email protected]. We will delete the account.
Changes to this policy
Each version of this policy shows its version number and effective date. This is version 1.1. It is effective from 9 October 2026.
If we make a material change, we announce it in the app before the change takes effect.
The Turkish version of this policy is at https://miles.coffee/legal/privacy. The English version is at https://miles.coffee/legal/privacy?lang=en.
Contact us
For questions about your personal data or this policy, contact us at [email protected].
- Data protection e-mail: [email protected]
- Cafe and customer contact: [email protected]
- Registered address: İstasyon Mah. Çilem Sk. Kartepe Sanayi Sitesi K Blok No:1 K/147 Kartepe/Kocaeli, Türkiye
- Cafe address: Alikahya Fatih Mah. Horasan Cad. No:30 İzmit/Kocaeli, Türkiye
We do not publish a phone number.
Our KVKK information notice is at https://miles.coffee/legal/kvkk. The English version is at https://miles.coffee/legal/kvkk?lang=en.