RanMatch Privacy Policy and Regional Privacy Notice
Draft — bracketed contact, transfer, and retention fields must be completed before publication.
Effective date: [EFFECTIVE DATE]
Last updated: [LAST UPDATED DATE]
1. Scope and controller
This Privacy Policy explains how personal data is collected, used, disclosed, retained, and deleted when you use the RanMatch mobile application and related services (the “Service”).
The controller of your personal data is:
Halil İbrahim Tayfur
Mailing address or P.O. box: [MAILING ADDRESS OR P.O. BOX]
Privacy email: support@ranmatch.com
Support email: support@ranmatch.com
Phone: [SUPPORT PHONE]
Website: ranmatch.com
The “Regional provisions” section describes additional rights that may apply based on where you live.
2. Personal data we collect
2.1 Account and authentication data
- full name or profile name;
- email address;
- date of birth and age-eligibility information;
- Firebase-generated user ID and account timestamps;
- session, authentication, and account-security information.
Your password is processed by Firebase Authentication. RanMatch does not see or store your plaintext password.
2.2 Profile and preference data
Depending on your choices, you may provide:
- profile photos and biography;
- gender and participation preferences;
- school/education, work, height, languages, and interests;
- lifestyle fields such as alcohol and smoking preferences;
- sport or activity type, skill level, weekly frequency, goals, and participation style;
- profile visibility and discovery preferences.
Parts of your profile may be visible to other RanMatch users. The “Who can see information?” section explains how visibility works.
2.3 Location data
If you grant permission, we may receive device location. This can include:
- location while using the app for proximity and distance features;
- a more precise but rounded last location, accuracy, and timestamp in the private account record;
- an approximate discovery location reduced to an area of roughly one kilometer;
- country, city, and district selected for an activity;
- exact meeting latitude/longitude that you share with activity members.
An exact meeting point is not added to the general discovery profile; it is shared with users authorized to access the relevant activity. You can disable location permission in device settings, but proximity, distance, or location-based features may then be unavailable.
2.4 Matching and interaction data
- likes, passes/decisions, and mutual matches;
- blocked accounts;
- messaging state and unread counts;
- matching and feature-usage quotas;
- discovery filters and preferences used to generate suggestions.
2.5 Messages and User Content
- direct and activity-group text messages;
- photos, GIFs, and audio recordings you send;
- sender/recipient IDs, timestamps, storage paths, content type, and audio duration;
- call invitations, call mode, and meet.jit.si meeting links;
- activity titles, descriptions, cover images, and other user-provided content.
Messages are not represented as end-to-end encrypted. Security controls are used in transit and within service-provider infrastructure, but you should send only information that needs to be shared.
2.6 Activity, participation, and reputation data
- activities you create or join;
- date, duration, capacity, category, city/district, participation mode, and gender preference;
- organizer/member records and join requests;
- declarations about whether an activity occurred and whether a user attended;
- user ratings, reliability statistics, and publication times;
- membership and change-audit records.
2.7 Safety, report, and support data
- blocking records;
- report reason, details, related user/match/activity, and status;
- moderation decision, reason, authorized reviewer, and timestamps;
- correspondence and attachments you provide in a support request;
- limited technical security information used to prevent fraud and unauthorized access, such as IP address, user agent, request records, and App Check/App Attest validation signals.
2.8 Profile-verification data
If you choose profile verification, we process:
- a selfie captured with the front-facing camera;
- the face-forward or turn-side instruction shown to you;
- verification method, submission date, and review date;
- pending, verified, or rejected status;
- authorized reviewer and, if applicable, rejection reason.
The current version uses Apple Vision tools on the device to check whether the image contains one face, along with face position, size, capture quality, and head direction. The check is not used to search for your face in another database or create a biometric template that uniquely identifies you. The submitted selfie may be reviewed by an authorized person, is not displayed on your profile, and is not made available to other users.
2.9 Purchase and subscription data
Payments are processed by Apple; RanMatch does not receive full payment-card details. RanMatch may process limited information such as:
- purchased product/subscription and membership tier;
- transaction and subscription IDs, environment, and expiration date;
- transaction evidence signed by Apple;
- an App Store account token derived one-way from the RanMatch user ID;
- active, canceled, refunded, revoked, or expired subscription status.
2.10 Device permissions and local information
- Camera: profile verification and taking photos.
- Microphone: recording audio messages.
- Photo picker: accessing only the photo or GIF you choose to upload.
- Location: proximity, distance, and meeting features.
- Local device preferences: app settings such as selected language and last known membership status.
The current RanMatch version does not use an advertising network, a cross-app tracking SDK, contact-book access, or HealthKit health data. If this changes, this Policy and the relevant consent and store disclosures will be updated before the new processing begins.
3. Sources of personal data
We may receive personal data:
- directly from you through account, profile, message, activity, report, and support fields;
- from your device and permissions you grant;
- from other users, for example when they add you to an activity, rate you, or report you;
- from Apple in limited subscription-validation and App Store records;
- from infrastructure providers such as Google Firebase, Apple, and 8x8/Jitsi through service and security records.
4. Why we process data and our legal bases
Depending on applicable law, we rely on one or more of the following bases:
| Purpose | Main data | Main legal basis |
|---|---|---|
| Create accounts, authenticate users, and provide the Service | Account, profile, user ID | Performance of a contract |
| Operate discovery, proximity, matching, and filters | Preferences, approximate location, interactions | Contract; consent where location permission/consent is required |
| Provide messages, media, calls, and activities | User Content, communications, memberships, meeting location | Contract; consent for sensitive permissions where required |
| Perform requested profile verification | Selfie, verification outcome and records | User request/consent; legitimate interests in safety and fraud prevention; any special condition required by local law |
| Provide safety, reporting, blocking, and moderation | Reports, content, account and technical security records | Legitimate interests; contract; legal obligation |
| Validate subscriptions and provide entitlements | Transaction evidence, product and membership status | Contract; legal obligation |
| Debug, maintain reliability, and prevent abuse | Limited technical and usage records | Legitimate interests; security obligations |
| Respond to legal requests and defend rights | Necessary account, communication, and safety records | Legal obligation; establishment, exercise, or defense of legal claims |
Where we rely on legitimate interests, we balance the safety of the Service and its users, fraud prevention, and system integrity against your rights. Where processing is based on consent, you may withdraw consent for the future. Withdrawal does not affect processing already performed lawfully.
For users in Türkiye, the processing conditions under Law No. 6698 are explained separately under “Türkiye — KVKK notice.”
5. Who can see information?
Other RanMatch users
Depending on visibility settings and the context of interaction, other users may see:
- profile name, age, profile photos, biography, sport/activity information, interests, languages, and selected profile fields;
- approximate location or calculated distance;
- verification badge and activity-reliability/rating summary;
- direct messages and media after a mutual match;
- activity membership information, group messages, and the exact meeting point if they are authorized members of the same activity.
Your private account record, email address, verification selfie, and sensitive administration records are not added to the public profile.
Service providers
We may disclose data, only as needed to provide the Service, to categories including:
- Google Firebase: authentication, databases, file storage, server functions, and app-integrity checks;
- Apple: App Store distribution, StoreKit payments/subscriptions, App Attest, device permissions, and Apple Maps/MapKit;
- 8x8 / meet.jit.si: audio/video meeting infrastructure when a user opens a meeting link;
- legal, security, advisory, or technical-support providers where necessary and subject to appropriate confidentiality obligations.
A meet.jit.si call opens outside RanMatch. 8x8 may process meeting URLs, meeting communications, and technical service data under its own privacy notice.
Legal requests and organizational changes
We may disclose data to competent authorities where required by law, to protect rights and safety, investigate fraud, or respond to a valid legal request. If the Service is involved in a merger, financing, reorganization, or transfer, personal data may be transferred to a relevant party with appropriate confidentiality and notice measures.
6. Do we sell data or share it for advertising?
RanMatch does not sell personal data for money. The current version does not use a third-party targeted-advertising network and does not “share” personal data for cross-context behavioral advertising across apps or websites owned by different companies. If this practice changes, required notices and choice mechanisms will be provided before it takes effect.
7. International data transfers
RanMatch is provided from Türkiye, but providers such as Google Firebase, Apple, and 8x8/Jitsi may process data in Türkiye, the European Economic Area, the United States, and other countries where they maintain facilities. Data-protection rules in those countries may differ from those in your location.
Where applicable law requires it, we use adequacy decisions, contractual safeguards, binding corporate rules, or another lawful transfer mechanism. For transfers covered by European data-protection law, European Commission Standard Contractual Clauses and supplementary safeguards may be used where appropriate.
The KVKK mechanism and provider agreements for regular transfers from Türkiye must be completed before publication: [TRANSFER SAFEGUARD AND, IF APPLICABLE, KVKK NOTIFICATION DATE].
You may request a copy of applicable safeguards by contacting support@ranmatch.com.
8. Retention and deletion
We aim to retain data only for as long as needed for the purpose of collection, safety, dispute resolution, and legal obligations. The following criteria reflect the current system behavior:
| Data | Retention criterion |
|---|---|
| Account and private profile | While the account is active; removed from active systems through account deletion |
| Public profile and profile photos | Until removed or replaced, profile visibility is disabled, or the account is deleted |
| Silent match | If neither participant replies, the match and associated media may be deleted after approximately 48 hours |
| Active match and direct messages | Until the match is removed, one participant blocks the other, or a relevant account is deleted, subject to safety/legal-record exceptions |
| Activity and group content | While needed for activity history, membership, disputes, ratings, and safety; account/activity deletion and legal exceptions apply |
| Profile-verification selfie | Until replaced by a new verification image or the account is deleted; a shorter post-review rule must be finalized before publication: [VERIFICATION SELFIE RETENTION PERIOD] |
| Safety reports and moderation records | For the period needed to protect safety, prevent repeated violations, and handle legal requests: [SAFETY RECORD RETENTION PERIOD] |
| Subscription and transaction-validation records | As needed to provide entitlements and meet accounting/legal obligations: [TRANSACTION RECORD RETENTION PERIOD] |
| Technical security records | For a limited period needed for security and error investigation: [TECHNICAL LOG RETENTION PERIOD] |
| Support correspondence | As needed to resolve the request and protect quality and legal rights: [SUPPORT RECORD RETENTION PERIOD] |
You can delete your account through application settings. The process is designed to remove the authentication account, private/public profile records, account-linked files, and relevant social/activity data from active systems. Limited records strictly necessary for another person’s safety, a valid legal obligation, fraud prevention, or the establishment or defense of a claim may be retained in anonymized or access-restricted form. Service-provider backups may be cleared according to their ordinary deletion cycles.
Deleting a RanMatch account does not cancel a subscription managed by Apple.
9. Automated processing and recommendations
RanMatch may filter or order candidate profiles based on preferences, approximate location, activity interests, prior likes/passes, blocks, and profile visibility. These operations provide connection suggestions and do not make decisions that produce legal or similarly significant effects.
The on-device face/pose quality check for profile verification only assists with obtaining a suitable selfie. Final verification or moderation outcomes may include authorized human review. To contest an outcome, contact support@ranmatch.com.
10. Security
We use technical and organizational controls such as access restrictions, authentication, App Check/App Attest, server-side authorization, encryption in transit, provider-side storage encryption, and separation between private and public data.
No system is completely secure. If you believe your account or data is at risk, contact support@ranmatch.com.
If a personal-data breach requires notice under applicable law, we will notify affected individuals and competent authorities within the legally required period.
11. Your choices and rights
Depending on your location and applicable law, you may have the right to:
- access personal data and obtain a copy;
- correct inaccurate or incomplete data;
- request deletion;
- restrict or object to processing;
- receive data you provided in a portable format;
- withdraw consent;
- request human review of certain automated processing or moderation outcomes;
- opt out of sale, targeted advertising, or certain forms of sharing;
- complain to a data-protection authority;
- exercise privacy rights without discrimination.
You can edit many profile fields in the app, change permissions in device settings, block users, and delete your account in application settings. For other requests, contact support@ranmatch.com.
We may need to verify your identity for security. We will request only the information needed for the request. If an authorized agent submits a request, we may ask for evidence of authority. We respond within the period required by applicable law and explain any permitted extension.
12. Children’s privacy
RanMatch is only for users aged 18 and over. We do not intend to knowingly collect account data from anyone under 18. If we learn that a minor created an account, we will take reasonable steps to delete the account and associated data or take another protective action. Contact support@ranmatch.com to report a concern.
13. Regional provisions
13.1 Türkiye — KVKK notice
For purposes of Turkish Personal Data Protection Law No. 6698, the controller is Halil İbrahim Tayfur. Data is collected wholly or partly by automated means through app forms and content uploads, device permissions, automatic technical records, other-user interactions, and Apple/Firebase/Jitsi services.
Data is processed on grounds that may include formation or performance of the Service contract, legal obligations, establishment/exercise/defense of rights, legitimate interests that do not override your fundamental rights, and explicit consent where necessary. If processing creates special-category data, the specific conditions and adequate safeguards in Article 6 of Law No. 6698 apply.
For the purposes described in this Policy, data may be transferred to authorized RanMatch personnel, other users, providers such as Google/Firebase, Apple, and 8x8/Jitsi, advisers, and legally authorized public bodies. Transfers abroad must use an applicable mechanism under Article 9 of Law No. 6698: [KVKK INTERNATIONAL TRANSFER MECHANISM].
Under Article 11, you may ask whether your data is processed; request information; learn the purpose and whether data is used accordingly; learn recipients in Türkiye or abroad; request correction and notice to recipients; request deletion/destruction where conditions apply and notice to recipients; object to a result produced exclusively by automated analysis that is against you; and claim compensation for unlawful processing.
Submit a request to support@ranmatch.com or [MAILING ADDRESS OR P.O. BOX]. Current KVKK identity-verification and application procedures apply.
13.2 European Economic Area, United Kingdom, and Switzerland
Where the GDPR or equivalent law applies, the legal bases in “Why we process data” apply. You may have rights of access, correction, erasure, restriction, objection, portability, withdrawal of consent, and complaint to a competent supervisory authority.
If RanMatch offers services to people in these regions and must appoint a local representative, the details must be added before launch:
- EU representative: [EU REPRESENTATIVE, IF REQUIRED]
- UK representative: [UK REPRESENTATIVE, IF REQUIRED]
International transfers may rely on an adequacy decision, Standard Contractual Clauses, and supplementary safeguards where needed. Contact support@ranmatch.com for a copy of applicable safeguards.
13.3 United States and California
Where applicable U.S. state privacy law applies, you may have rights to access/know, correct, delete, obtain a portable copy, opt out of targeted advertising or sale/sharing, limit certain uses of sensitive data, and receive equal service when exercising a right.
Categories we may process in the preceding 12 months include identifiers and contact information, online identifiers, approximate/precise location, profile characteristics, User Content, purchase/subscription information, internet/app activity, inferences, and safety records. These categories are disclosed as described above to users, infrastructure providers, and competent authorities for the stated purposes.
RanMatch does not sell personal information and, in its current version, does not share it for cross-context behavioral advertising or process it for targeted advertising as those terms are defined by relevant state laws. RanMatch does not knowingly serve people under 16; every account is 18+.
Submit a request or appeal through support@ranmatch.com. You may use an authorized agent where applicable law permits.
13.4 Brazil
Where Brazil’s General Data Protection Law (LGPD) applies, processing may rely on performance of a contract, legal obligations, the exercise of rights, legitimate interests, and consent where required. You may request confirmation, access, correction, anonymization/blocking/deletion, portability, information about sharing, consent-related rights, and review through support@ranmatch.com. You may also contact Brazil’s National Data Protection Authority (ANPD).
13.5 Canada, Australia, and other regions
Local law may grant additional rights such as access, correction, deletion, withdrawal of consent, and complaint to a privacy regulator. RanMatch will handle verifiable requests under applicable local law. If a country requires a local representative, registration, data localization, or a separate notice, it must be completed before that storefront is enabled.
14. Changes to this Policy
We may update this Policy when the product, data practices, or law changes. We will revise the “Last updated” date. For material changes, we will provide advance notice by in-app message, email, or another appropriate method and request renewed consent/acceptance where required.
15. Contact and complaints
For privacy questions, requests, or complaints:
Controller: Halil İbrahim Tayfur
Privacy email: support@ranmatch.com
Support email: support@ranmatch.com
Mailing address or P.O. box: [MAILING ADDRESS OR P.O. BOX]
Phone: [SUPPORT PHONE]
You may also have the right to complain to the competent data-protection or consumer authority where you live.