Legal · GDPR notice and KVKK information

Privacy policy

Effective date: [YÜRÜRLÜK TARİHİ]

In short: Your routes and loops are visible only to you. Other players only see the colour and power of cells. We keep raw GPS points for 30 days, then reduce them to a list of cells. You can export your data and delete your account from the app. We don't sell your data or use it for advertising.

1. Data controller

The controller for personal data processed through the HexRun mobile app and the hexrun.co website ("HexRun", "we") under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the EU General Data Protection Regulation ("GDPR") is:

  • Company: [ŞİRKET UNVANI]
  • Address: [ŞİRKET ADRESİ]
  • MERSIS no.: [MERSİS NO]
  • Trade registry: [TİCARET SİCİL MÜDÜRLÜĞÜ VE NO]
  • VERBIS: [VERBİS KAYIT DURUMU]
  • Data protection requests: [KVKK_EMAIL]
  • EU representative: [AB TEMSİLCİSİ — GDPR Md. 27, gerekiyorsa]

2. Data we process

CategoryExamplesSource
Account and identityUsername, display name, email, profile colour, language, country, age confirmation, Sign in with Apple or Google identifierYou; Apple / Google sign-in
Location and runs (GPS tracks)Location points during a run, timestamps, distance, duration, pace, closed loopsYour phone; a watch or app you connect
Derived game dataCell lists, power, duels, league and team rankings, badges, streakComputed from your runs
Privacy settingsApproximate centre and radius (200–800 m) of your privacy zone, visibility preferencesYou
Device and notificationsPush notification token, device model, OS and app version, notification preferencesYour device
Optional watch / health importsRun records from a Garmin, Coros, Suunto, Polar, Apple Health (HealthKit), Health Connect / Wear OS or Strava account you connect; health data such as heart rate if the provider shares itThe third-party account you connect, only with your permission
Social interactionsFriendships, team membership, applause, invite codes, report and block recordsYou and other players
Support and contactSupport messages, notes you add to a loop under reviewYou
Technical logsIP address, request time, error logs, security eventsOur servers

We do not collect advertising identifiers (IDFA / AAID) and we do not track you across other apps.

3. Purposes and legal bases

PurposeDataGDPR Art. 6 / 9KVKK Art. 5–6
Running your account and the game: closing loops, computing cells and duels, rankingsAccount, location and runs, derived game dataPerformance of a contract (6(1)(b))5(2)(c)
Anti-cheat and fair play; loop reviewLocation and runs, technical logsLegitimate interests (6(1)(f))5(2)(f)
Game notifications (duels, decay, results)Push token, preferencesPerformance of a contract (6(1)(b))5(2)(c)
Watch and app importsImported run recordsPerformance of a contract (6(1)(b))5(2)(c)
Showing statistics from imported health data (e.g. heart rate)Health dataExplicit consent (9(2)(a))Explicit consent (6(2))
Answering support requestsSupport messages6(1)(b); 6(1)(f)5(2)(c); 5(2)(f)
Security, abuse prevention, keeping the service runningTechnical logs6(1)(f); legal obligation 6(1)(c)5(2)(f); 5(2)(ç)
Waitlist and launch announcementsEmail, languageConsent (6(1)(a))Explicit consent (5(1)); commercial e-message consent under Law No. 6563
Responding to legal requests, protecting rightsRelevant data6(1)(c); 6(1)(f)5(2)(ç); 5(2)(e)

Where we rely on consent you can withdraw it at any time; this does not affect processing that happened before.

4. Location, visibility and privacy zone

  • Location is processed only when you start a run or import a run from a watch or app. We do not collect location in the background outside runs.
  • Your loops and routes are visible only to you. Other players only see the colour and power of cells and the owner's username. Duel records are shown only to the area's owner and that attacker.
  • Privacy zone: You can set a zone with a 200–800 m radius around your home. The owner of cells in that zone is shown to others as "Hidden player", without your name or initials. The centre of the circle is randomly offset per account and the circle is never drawn for others.
  • Share cards contain no map, route, streets or rival names, and cells in your privacy zone are left out of the silhouette.
  • The friends feed is visible only to your friends and times are rounded.

5. Retention

DataPeriod
Raw GPS points (location + time)30 days. After that a run is reduced to its cell list and summary statistics (distance, duration, pace); raw points are deleted.
Cell lists, run summaries, game dataAs long as your account exists
Account dataUntil the account is deleted; deleted or anonymised within 30 days of your deletion request. Removed from backups within [BACKUP RETENTION PERIOD].
Push tokensUntil you sign out, uninstall the app or the token becomes invalid
Import connectionsUntil you disconnect; access tokens are then deleted
Waitlist emailUntil you leave the list or [WAITLIST RETENTION PERIOD] after the launch announcement
Technical logs and security events[LOG RETENTION PERIOD], subject to statutory periods

6. Recipients and service providers

We don't sell your data. We share it only as far as needed to run the service, with providers bound by contract:

RecipientPurposeData
Hosting / cloud: [CLOUD PROVIDER AND REGION]Servers and databaseAll service data
Map tiles: [MAP TILE PROVIDER]Drawing the mapIP address, map area being viewed (your route is not sent)
Expo (push service), Apple APNs, Google FCMDelivering push notificationsPush token, notification content
Sign in with Apple and GoogleAuthenticationSign-in identifier, email (if you share it)
Strava, Garmin, Coros, Suunto, Polar, Apple Health, Health ConnectImporting runs only if you connect them (and posting to Strava if you turn it on)Access token, run records
Email delivery: [EMAIL PROVIDER]Waitlist and account emailsEmail, language
Error monitoring: [ERROR MONITORING PROVIDER, if any]Crash and error detectionTechnical logs, device information
Competent authoritiesLegal obligationsRequested data

Data from health platforms (Apple Health, Health Connect) is never used for advertising or marketing and is not shared with third parties.

7. International transfers

Some of the providers above may process data outside Türkiye and the European Economic Area. Transfers from Türkiye follow KVKK Art. 9 (an adequacy decision, the standard contracts published by the Turkish Data Protection Board, notified to the Authority within 5 business days of signing, or other statutory safeguards). Transfers from the EEA follow GDPR Art. 45–46 (an adequacy decision or the European Commission's Standard Contractual Clauses). You can request a copy of the safeguards at [KVKK_EMAIL].

8. Your rights and how to use them

Under the GDPR you have the right to access, rectification, erasure, restriction, data portability, to object to processing based on legitimate interests, to withdraw consent, and to complain to the supervisory authority where you live. Under KVKK Art. 11 you may also learn whether your data is processed, request information, learn the purpose and the third parties it is shared with, request correction or deletion and notification of these to recipients, object to an adverse outcome produced solely by automated analysis, and claim compensation for unlawful processing.

How to use them

  • In the app: Profile › Settings › Download my data gives you your runs, cells and account data as a machine-readable file. Profile › Settings › Delete account deletes your account (details).
  • By email: write to [KVKK_EMAIL] from the email address on your account. We may ask for extra information to verify your identity.
  • In writing: to [ŞİRKET ADRESİ].

We answer free of charge within 30 days at the latest. If we reject your request, you find the answer insufficient, or we don't answer in time, you can complain to the Turkish Personal Data Protection Board or your local supervisory authority.

9. Children

HexRun is not for children under 13. If the age of digital consent in your country is higher (between 13 and 16 in EU member states), you may use the app below that age only with the consent of a parent or guardian. If we learn that a child under 13 has created an account, we delete the account and its data. You can reach us about this at [KVKK_EMAIL].

10. Anti-cheat and automated checks

Every loop is automatically checked for pace and GPS consistency (for example stretches far beyond running pace, GPS jumps or long GPS gaps). A flagged loop is not punished: it is marked "under review", your run and streak are saved, and the map doesn't change until a result comes in. A person makes any decision to reject a loop. To contest it or add context, use "Add info" in the app or our support channels.

11. Website and cookies

hexrun.co sets no cookies, runs no analytics or ad tracking and loads no third-party scripts or fonts. Our server may keep standard access logs (IP address, time, page requested) for security and operations. Your email is only sent to our API if you submit the waitlist form.

12. Waitlist

We process the email address and language you enter on the waitlist only to tell you about HexRun's launch and early access invitations, based on your consent. You can leave the list via the link in every email or by writing to [KVKK_EMAIL].

13. Security

Data is encrypted in transit with TLS; access is limited to staff who need it for their role and is logged. Reducing raw location data to cell lists after 30 days also limits the impact of any breach. If a breach occurs, we notify the authorities and you within the periods required by the GDPR and KVKK.

14. Changes and contact

We may update this policy and will announce significant changes in the app before they take effect. Questions: [KVKK_EMAIL].

This English version is provided for convenience; if it conflicts with the Turkish text, the Turkish text prevails. Türkçe oku.