Your context, not your commodity.
This Privacy Policy explains what personal data MeetWho collects, why we process it, who we share it with, how long we keep it, and the rights you have under the GDPR, the Turkish KVKK, the UK GDPR, and the CCPA/CPRA.
Data controller
ROLF 360 Dijital Pazarlama ve Yazılım Ajansı Limited Şirketi (“ROLF 360”, “MeetWho”, “we”, “us”), Levent, Karanfil Sokağı No:13, 34330 Beşiktaş / Istanbul, Türkiye — Beşiktaş V.D. 7352015577 — is the data controller for personal data processed through meetwho.app and related domains.
Privacy contact: hello@meetwho.app. Legal counsel: Genç Partners — bahadir@genc.partners — genc.partners.
Personal data we collect
- Account & identity. Email, sign-in provider (Google / Apple / email + password), password hash (never the plain password), display name, username, optional phone number in E.164 format, preferred language and country/city.
- Profile you author. Headline, bio, what you're working on, what you're looking for, what you can help with, expertise tags, projects, external links, avatar and banner images.
- Event context. Events you host or attend, RSVPs, per-event intent, event group chats, event QR check-ins, availability windows, meeting bookings.
- Relationship memory. Connection requests, accepted connections, disconnections, blocks and reports, saved people, private notes, tags, follow-up reminders, encounters logged via QR.
- Messaging. One-to-one messages, event group chat messages, reactions, replies, and attachments you upload (stored in a private bucket accessible only to the conversation participants).
- Support & feedback. Support tickets, replies, and any content you paste into them.
- Device & technical data. IP address, user-agent, approximate location derived from IP (country/city only), device type, timezone, screen size, browser language, session identifiers, error logs.
- Push tokens. Web-Push subscription (endpoint + keys) if you opt in to browser or PWA notifications; APNs/FCM tokens on mobile.
- Payment metadata. Subscription tier, renewal status, invoice history and Polar/Stripe customer identifier. Full card numbers never touch our servers — they are handled by our PCI-DSS certified payment processor.
- Analytics events. Non-identifying product analytics (page views, feature usage) via Google Analytics 4 and Hotjar, subject to your cookie preferences.
Data we do not collect
- Your address book, phone contacts, or calendar events — we never scrape or import them.
- Precise GPS location or background location tracking.
- Sensitive category data (racial or ethnic origin, political opinions, religious beliefs, health, sexual orientation, biometric identifiers) unless you voluntarily place it in a free-text field, in which case you are asked not to.
- Behavioural advertising profiles built for third-party ad networks.
Why we process data (purposes & legal bases)
Under GDPR / UK GDPR Art. 6 and KVKK Art. 5 we rely on the following legal bases:
- Contract (Art. 6(1)(b) / KVKK Art. 5(2)(c)). Creating your account, authenticating you, delivering messages, recommending people to meet, running events you host or attend, providing paid features you purchased.
- Legitimate interests (Art. 6(1)(f) / KVKK Art. 5(2)(f)). Product security, fraud and abuse prevention, service analytics, product improvement, low-volume transactional email. We balance these against your rights and you can object at any time.
- Consent (Art. 6(1)(a) / KVKK Art. 5(1)). Optional cookies (Google Analytics, Hotjar), Web-Push notifications, marketing emails, and any voluntary sensitive data you share.
- Legal obligation (Art. 6(1)(c) / KVKK Art. 5(2)(a)). Tax and accounting retention, responding to lawful requests from competent authorities.
Public vs private surfaces
- Public profile at
meetwho.app/@username— fields you choose to publish. You can hide the profile entirely from Settings. - Private by default — email, phone, private notes, saved-people lists, follow-ups, drafts, messages, encounters, and your full attendance history are never rendered on a public page.
- Per-event visibility — for each event you can appear publicly, only to other attendees, or stay hidden. Event-specific intent lives with the event, not on your profile.
Sharing & recipients
We do not sell personal data. We share it only with the following categories of recipients, under written agreements that require confidentiality and equivalent safeguards:
- Infrastructure & backend — Supabase (managed Postgres, auth, storage, realtime) and Cloudflare (edge compute, CDN, DDoS protection).
- Email delivery — Resend, for transactional email from
hello@meetwho.app. - Push delivery — Google (FCM / Web Push) and Apple (APNs) for browser and mobile notifications.
- Payments — Polar and Stripe for subscription billing and invoicing.
- Federated sign-in — Google and Apple when you use “Continue with Google” or “Continue with Apple”.
- Analytics & product research — Google Analytics 4 and Hotjar, only if you accept analytics cookies.
- Other users — the parts of your profile, intents and messages you choose to share with them.
- Event organisers — for events you attend, the organiser can see your name, avatar and attendance status.
- Authorities — where legally required, and only to the minimum extent necessary, after reviewing the request.
International transfers
MeetWho operates globally. Personal data may be processed in the European Union, the United Kingdom, Türkiye and the United States. When we transfer data outside your jurisdiction we rely on: (i) European Commission adequacy decisions where available; (ii) the EU Standard Contractual Clauses (2021/914) and the UK IDTA; and (iii) KVKB explicit consent or the safeguards permitted under KVKK Art. 9. A copy of the relevant SCCs is available on request to hello@meetwho.app.
Retention
- Account & profile — while your account is active. On deletion, identifying fields are erased or anonymised within 30 days.
- Messages — retained until you or your counterpart delete them, or until account deletion.
- Event data — for six months after the event ends, then anonymised except where you continue to reference it.
- Support tickets — 24 months from resolution.
- Billing records — 10 years (Turkish Tax Procedure Law) / 6 years (UK) / 10 years (EU average) as required.
- Security logs — up to 12 months.
- Backups — encrypted backups may hold residual copies for up to 35 days after deletion, then rotate out.
Security
Encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access to production, row-level security on all user data, audit-logged admin access, hashed API keys, signed webhooks, HttpOnly session cookies, hardened Content-Security-Policy, and continuous vulnerability scanning. See the Security page for details. No system is perfectly secure; if you find a vulnerability, contact hello@meetwho.app.
Your rights
Depending on where you live you have some or all of the following rights. We honour them regardless of jurisdiction where feasible:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data (most fields are editable directly in Profile & Settings).
- Erasure / “right to be forgotten” — delete your account and associated personal data.
- Restriction — ask us to pause certain processing while a dispute is resolved.
- Portability — export your profile, connections, notes and follow-ups in a machine-readable format from Settings.
- Objection — object to processing based on legitimate interests, including profiling for recommendations.
- Withdraw consent — for cookies, notifications and marketing at any time, without affecting past lawful processing.
- Complaint — lodge a complaint with your supervisory authority: the Turkish KVKK (Kişisel Verileri Koruma Kurumu, kvkk.gov.tr), your EU/EEA DPA, the UK ICO, or the California Privacy Protection Agency.
Exercise any right at hello@meetwho.app. We respond within 30 days (extendable by 60 days for complex requests) and never charge a fee for reasonable requests.
Automated decision-making
MeetWho generates match recommendations (“people you should meet”) using rule-based logic and text similarity — not opaque scoring. These recommendations are informational. They do not produce legal or similarly significant effects concerning you and are not automated decision-making within the meaning of GDPR Art. 22. You can hide, downvote or ignore any recommendation.
Google user data & Limited Use
MeetWho’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
- What we access. With your explicit consent, MeetWho requests exactly four Google scopes and nothing else:
openid,userinfo.emailanduserinfo.profile(to identify the connected account),calendar.calendarlist.readonly(to let you choose which of your calendars to sync) andcalendar.events(to read your events for busy-time detection and to create, update or delete only the MeetWho events and bookings you generate). We do not request full-calendar access, and nothing from Gmail, Drive, Photos or Contacts. - What we use it for. Google Calendar data is used only to show your agenda inside MeetWho, block busy hours on your booking page, send you reminders for your own events, and keep your calendar in sync. Nothing else.
- No AI training, no AI transfer. Google Workspace data — raw, aggregated, anonymised or derived — is never used to develop, train, improve or fine-tune any foundational or generalised AI/ML model, and is never sent to any third-party AI or ML service. MeetWho’s AI features (matching explanations, translations, categorisation) operate on a separate data path that reads only MeetWho-native profile, event and intent data; the Google Calendar store is isolated from every AI code path.
- No humans reading it. No MeetWho employee reads your Google Calendar data except with your explicit written permission for a support request, for security investigations, or where required by law.
- No sale, no ads. We never sell, rent or transfer Google user data, and never use it for advertising, retargeting or credit purposes.
- Revoke any time. Disconnect Google Calendar from Calendar → Integrations in MeetWho, or from your Google Account permissions. On disconnect we delete stored Google tokens and imported calendar rows.
Cookies & analytics
We use strictly necessary cookies for authentication and security, and — with your consent — Google Analytics 4 and Hotjar for aggregated product analytics. See the Cookie Policy for the full list, purposes and durations, and how to change your choices.
Children
MeetWho is intended for people aged 16 or older. We do not knowingly process personal data of anyone under 16. If you believe a minor has created an account, email hello@meetwho.app and we will remove it.
Changes to this Policy
When we materially change this Policy, we update the “Last updated” date and notify affected users in-product or by email at least 15 days before it takes effect. Previous versions are available on request.
Contact
General privacy questions: hello@meetwho.app. Turkish data subjects also see the Data Processing Notice for the KVKK-aligned disclosure. Postal address: ROLF 360 Dijital Pazarlama ve Yazılım Ajansı Ltd. Şti., Levent, Karanfil Sokağı No:13, 34330 Beşiktaş / Istanbul, Türkiye.
