Cookie and SDK Policy
Çerez ve SDK Politikası
Last updated: 10 September 2026
Complements the Personal Data Processing Notice and the Explicit Consent text.
This English text is provided so that the document can be read by people who do not read Turkish, including App Store reviewers. The Turkish original is the version that governs; in the event of any discrepancy, the Turkish text prevails.
1. What this policy covers
In order to provide its services, analyse the user experience and send notifications, the 28 mobile application uses third-party software development kits (SDKs) and similar technologies in addition to its own infrastructure.
The mobile equivalent of the web concept of a "cookie" is the set of device identifiers (Advertising ID, Instance ID), the usage and event data collected through SDKs, and local storage records. This policy complements the Personal Data Processing Notice and the Explicit Consent text; it does not replace them.
2. SDKs and technologies used
The table below shows the technologies actually used in the App. Listing an SDK that is not used is as wrong as leaving out one that is; both amount to a breach of the duty to inform under Article 10 of the Personal Data Protection Law. When a new SDK is integrated into the App, this table is updated before that integration goes live.
2.1 Strictly necessary technologies — no explicit consent required
This category is technically necessary for the App to function and rests on the legal grounds of performance of a contract (Art. 5/2-c) and the legitimate interests of the data controller (Art. 5/2-f).
| Technology | Provider | Data processed | Purpose | Legal ground |
|---|---|---|---|---|
| Authentication and session management | Google Cloud [full legal name to be confirmed] | Session ID, authentication token | Signing you securely into your account and maintaining the session | Performance of a contract (Art. 5/2-c) |
| Local storage | The app developer (28) | App settings, interface preferences, draft content | Preserving app functionality and preferences | Performance of a contract (Art. 5/2-c) |
| Push notification infrastructure [integration to be confirmed] | Apple Push Notification service (APNs) and/or Firebase Cloud Messaging (FCM) | Device notification identifier (push token) | Delivering functional notifications to your device | Performance of a contract (Art. 5/2-c) |
| Security and log records | The app developer (28) / Google Cloud | IP address, device data, sign-in and sign-out records | Providing security, detecting fake accounts, statutory record keeping | Legitimate interest (Art. 5/2-f); expressly provided for by law (Art. 5/2-a) |
2.2 Analytics and performance SDKs — subject to explicit consent
| SDK | Provider | Data processed | Purpose | Legal ground |
|---|---|---|---|---|
| Firebase Analytics | Screen views, event records, session duration, app usage statistics, device identifiers | Measuring app performance, analysing usage patterns and improving service quality | Explicit consent (Art. 5/1) |
Your chat content and your location data are not transferred to this SDK.
2.3 Marketing and advertising SDKs
As at the date this text was prepared, the App contains no advertising or marketing measurement SDK whatsoever (Meta SDK, TikTok SDK, AppsFlyer, Adjust or similar). No consent box is therefore presented in this category.
If such an SDK is integrated in future: (i) this section will be completed with the SDK's name, provider, the data processed and the purpose, (ii) a consent box separate from the analytics consent will be added — the current analytics consent does not cover advertising SDKs —, and (iii) on iOS, Apple's App Tracking Transparency (ATT) system permission will also be shown. ATT permission does not replace explicit consent under the Personal Data Protection Law; the two are obtained together.
3. Transfers abroad
The SDK providers listed above process data on their servers outside Türkiye. The Google Cloud infrastructure is in Ireland; Firebase Analytics and the push notification infrastructure may run on the provider's global infrastructure, including the United States.
The legal position of these transfers, their risks and the safeguards in place or planned are explained in detail in Section 7 of the Personal Data Processing Notice and Section 5 of the Explicit Consent text. The analytics SDK transfer happens only if you give the explicit consent in 2.2.
4. Third-party processors
The providers listed above act as processors under their own service and privacy terms. We recommend that you review their own privacy policies for their data processing practices. The data controller is obliged to conclude a data processing agreement with these providers and is jointly responsible with them, under Article 12/2 of the Personal Data Protection Law, for ensuring that data security measures are taken.
5. Retention periods
| Data | Retention period |
|---|---|
| Analytics SDK data (Firebase Analytics) | 14 months — this period is set in the provider's console. At the end of the period the data is automatically deleted or aggregated |
| Session and authentication tokens | For the duration of the session; invalidated on sign-out or when the session ends |
| Local storage records | Until the app is removed from the device or its data is cleared (kept on your device) |
| Push notification identifier (token) | For as long as the account is active; deleted when the account is deleted or notification permission is withdrawn |
| Log and security records | 1 year |
6. Managing your preferences
- You can change your analytics SDK consent at any time from the in-app "Settings → Privacy → Data and Analytics Preferences" section. Withdrawing your consent does not affect the App's core functions.
- On iOS devices you can also exercise system-level control from "Settings → Privacy & Security → Tracking" and "Settings → Privacy & Security → Apple Advertising".
- On Android devices you can reset or delete your advertising identifier from "Settings → Google → Ads".
- You can manage notification permissions from "Device Settings → 28 → Notifications". Turning off functional notifications may mean you are not made aware of the App's time-bound features.
7. Updates
This policy is updated on every change to the SDK integrations, before that change goes live. Where an SDK requiring fresh consent is added, that consent is obtained separately.
Last updated: 10 September 2026 · Contact: hello@28istanbul.com
Last updated: 10 September 2026