This notice informs users of the Runbay mobile app and visitors to its website under Turkish Personal Data Protection Law No. 6698 (the “Law”). The Runbay brand alone does not identify the legal data controller. The verified name or legal entity and contact details of the controller are shown in the identity section of this document.
Providing information is separate from accepting the terms, giving explicit consent for health data processing and granting device permissions. Viewing this notice or recording that it has been read does not constitute consent to every processing purpose or to international transfers.
The data processed depends on the features you use. Mobile app data is associated with your account. Visiting the website does not transfer your mobile profile or running records to the website.
Data processing flows in the current app
Category
Data covered
Account and authentication
User ID, authentication information from Apple or Google, name and email provided by the identity provider, session tokens and account timestamps.
Profile and preferences
Display name, birth year, gender preference including the option not to disclose, height, training level, goal, home/gym preference, training days per week and time zone.
Body measurements
Weight, measurement date and body fat percentage if entered by the user.
Workouts and performance
Program selection and calendar; exercise, sets, reps, weight, perceived effort, warm-up information, start/end times, duration and notes; training volume, active minutes, estimated one-rep maximum and personal bests.
Location and running
Latitude, longitude, location timestamp, accuracy, speed and altitude; route, start coordinates, distance, moving time, pace, kilometer splits and elevation gain.
Matching and transaction records
Candidate programs generated from goal, level, setting and day preferences, match scores, recommendation/selection records and program matching inputs.
Notifications and security
Push token, iOS/Android platform and device registration last-seen time; IP addresses, request/response records and errors generated during access.
Legal actions and requests
Type, version and time of terms acceptance, notice acknowledgement and health data consent; information necessary to handle and verify a request.
SECTION 03
Purposes and legal bases
The mapping below is limited to data necessary and proportionate to the stated activity. Listing a category does not permit every item in that category to be used for every purpose. Contractual necessity or legitimate interests for ordinary personal data are not, on their own, sufficient for information that constitutes health data.
Activities, purposes and legal bases
Activity and purpose
Legal basis
Creating accounts, managing sessions, accessing your records and applying basic program preferences
Article 5(2)(c): processing necessary and directly related to entering into or performing a contract.
Generating route, distance and pace for a GPS run started by the user
Article 5(2)(c) for location records that are not health data; explicit consent under Article 6(3)(a) is additionally required for processing that produces health information or assessments. Device permission does not replace a legal basis.
Storing body measurements and health-related activity data; generating personal progress indicators
Article 6(3)(a): specific, informed and freely given explicit consent. Use outside the scope of consent is not permitted.
Sending workout reminders enabled by the user
Article 5(2)(c) for the requested reminder service; if notification content reveals special-category data, the relevant additional processing condition is also required.
Preventing unauthorized access, rate limiting and investigating service errors
Article 5(2)(f): legitimate interests based on necessity and balancing assessments that do not harm fundamental rights and freedoms.
Handling data protection requests and binding official requests
Article 5(2)(ç), limited to the specific obligation; Article 5(2)(e) for records necessary to establish, exercise or protect a right. Article 6 conditions must also be assessed for special-category data.
SECTION 04
Collection methods and sources
Data is obtained electronically from profile and measurement entries, activities you start, location services you permit, Apple/Google authentication, notification registration and requests between the app and server. Personal performance indicators are derived by calculating existing records.
Offline workout and run data may first be stored on your device and synced to your account when connected. Local storage does not mean the data remains only on your device. Information you provide in a request or complaint is also processed.
SECTION 05
Health data and sensitive location information
Body measurements and activity assessments revealing physical condition may constitute health data depending on context. Runbay requests separate health data consent for these functions. Runbay does not provide diagnosis or treatment as a healthcare institution and does not assume that special conditions available to healthcare institutions apply.
Although precise location is not independently listed as a special category under the Law, it can reveal homes, workplaces and daily habits. Location use must be limited to the requested running function. Any use revealing health or other special-category data requires the relevant additional conditions.
Foreground location permission is used for pre-run signal checks and recording. Background permission allows a run you started to continue with the screen off. Revoking permission does not delete previously recorded routes.
The following recipient groups participate in delivering the service. Transfers are limited by the feature used and the provider’s technical role. A provider acting as a processor for one service may independently act as a controller for its own account or platform services.
Recipient groups identified from technical integrations
Recipient / service
Purpose and scope
Supabase and app server hosting
Authentication, account/database operations and serving app records. Exact legal entities, subprocessors and regions must be confirmed through contracts and production settings.
Apple and Google authentication
Signing in with your selected provider and delivering the authentication response; this does not mean your entire workout history is sent to them.
Expo, Apple and Google notification infrastructure
Delivering enabled reminders. Current message content includes the workout title and your display name where available.
Device platform map service
Displaying the map around a route. Map requests may disclose the geographic area and technical connection information.
Your selected sharing app and recipient
The run card you send through the system share menu, including visible route and performance information.
Authorized public bodies, courts and necessary legal service recipients
Information necessary and proportionate to meet valid requests or protect a specific right.
SECTION 07
International transfers
Supabase, authentication, notification, map and hosting services may involve international processing. The reviewed source code does not establish the selected production region, all recipient legal entities or signed transfer safeguards. This notice does not claim any particular country, adequacy decision or standard contract applies.
Regular transfers must be assessed under Article 9 of the Law using the relevant processing condition plus an adequacy decision or applicable appropriate safeguard. Exceptions for occasional transfers cannot legitimize ongoing cloud use through a general consent checkbox. The final notice must describe actual recipients, countries/regions and transfer mechanisms.
Once account deletion completes successfully, your account and related app records are removed from the primary database. While the account is active, data is retained as long as necessary for the relevant service. Backups and provider logs are outside deletion from the primary database; this notice does not guarantee deletion of those copies within 30 days.
Delete my account starts deletion of the authentication account and related application records. These include the profile, measurements, workouts, routes, program/matching records, personal bests, push tokens and consent records. Device records also enter the cleanup flow. Backups, provider logs and copies shared externally by the user are not simultaneously deleted everywhere by this action.
Canceling a single workout currently removes it from the history view; it is not physical database deletion. A statutory erasure request is separate. When processing conditions cease, deletion, destruction or anonymization obligations apply. Reasons and periods for any exceptional retention must be explained in the response to the request.
You may send a written request to the controller identified in this document, or use registered electronic mail (KEP), a secure electronic or mobile signature, or an email address previously provided to and registered with the controller. The account deletion screen is not presented as a channel for all data protection requests.
A request must include your name and surname; signature for written requests; Turkish identity number for Turkish citizens, or nationality and passport/identity number for foreign nationals; address for notices; contact email, phone or fax where available; and the subject of the request. Supporting information and documents may be attached. Identity checks must use only necessary information; passwords or session tokens must not be requested.
Requests must be resolved as soon as possible and within thirty days at the latest, depending on their nature. They are generally free; where additional costs arise, only the Board’s tariff may apply. Fees must be refunded if the request results from the controller’s error.
If a request is rejected, answered inadequately or not answered on time, a complaint may be made to the Board within thirty days of learning of the response and in all cases within sixty days of the request. The controller must be approached before the Board.
Explicit consent may be withdrawn prospectively; withdrawal does not invalidate processing previously carried out lawfully. Processing based solely on consent must stop, and disposal must be assessed where no other valid condition exists. A consent-dependent feature being unavailable without data is distinct from making the entire service conditional on consent.
The current app does not have a separate screen for withdrawing health data consent independently of account deletion. Account deletion must not be treated as the only way to exercise this right. Making the request channel operational and implementing withdrawal technically are part of preparing for final publication.
The notice must be updated when purposes or recipients change. A change requiring fresh explicit consent cannot take effect solely by editing this page.