1. Data We Collect
- Account data: name, email and profile photo when you sign in with Google.
- Location data: only with your permission, from your device GPS, for Compass, Footprint and beach check-ins.
- Usage data: favorites, visited regions, badges, beach check-ins.
- Technical data: IP address, browser/device info, language preference and (if you consent) analytics cookies.
2. Purposes of Processing
- Deliver personalized AI recommendations (weather, wind, time, location context).
- Operate account features such as favorites, footprint and badges.
- Keep the Platform secure and prevent abuse and fraud.
- Collect anonymous usage statistics, subject to your consent.
3. Legal Basis
We process your data on the basis of contract performance (account features), your explicit consent (location and analytics cookies) and legitimate interest (security, service improvement).
4. Cookies
Necessary cookies are always active for session and security. Analytics cookies (Google Analytics) load only if you consent in the cookie banner. You may withdraw consent at any time.
5. Third Parties
- Supabase — database and authentication (hosting; servers in the EU/Paris).
- Vercel — web hosting and infrastructure (EU/Frankfurt).
- Sentry — error monitoring (IP and technical error context, only on errors).
- Contact-form data (business name, name, email, phone) is processed only to respond to your enquiry; never for marketing.
- Google — OAuth sign-in and (with consent) Google Analytics.
- OpenWeatherMap — weather/wind data (no personal data shared).
- Anthropic / OpenAI — your preferences are processed to generate recommendations; no identifying data is sent.
6. Retention
Your personal data is kept for the following periods, after which it is deleted or anonymized:
- Account data (name, email, avatar): while your account is active + up to 30 days after deletion.
- Location-derived data (visited regions, badges, beach check-ins): the life of your account (deletable anytime).
- Analytics events (incl. IP): up to 14 months.
- Contact / enquiry records: up to 24 months after the request is resolved.
- Server / security logs: up to 90 days.
7. Security Measures
We apply appropriate technical and organizational measures: encryption in transit (HTTPS), access control via row-level security (RLS), mandatory two-factor authentication (MFA) on admin accounts, and least-privilege access.
8. Breach Notification
In the event of a security breach affecting your personal data, we notify the competent authority and, where required, you without undue delay (within 72 hours under the GDPR), in accordance with applicable law.
9. Children's Data
The service is not directed to children under 16 and we do not knowingly collect personal data from them. If we learn we have processed data of a child under 16, we delete it.
10. Your Rights
You have the rights of access, rectification, erasure, restriction, portability and objection. For requests: contact@sezgin.co.
You can download your data as JSON directly from your Account page (bodrumgo.app/en/account), and delete your account and all data in one click.
11. International Transfers
Hosting is in the EU (Supabase — Paris, Vercel — Frankfurt). Some services such as Google (OAuth/Analytics) may process data in the US; such transfers rely on appropriate safeguards (e.g. standard contractual clauses).
12. Contact
For privacy questions, contact us at contact@sezgin.co.