Privacy Policy
What we collect and why, who we share it with and how long we keep it.
This policy explains how your personal data is processed when you use the CoffeeMeet mobile app (the "App"). Data controllers: Onur Sercan Yılmaz and Serkan Taşlıçay (SOS Tech Labs) · Email: sostechlabs@gmail.com.
In short: we do not sell your data, we do not track you for advertising and we never show your exact location to anyone. We keep the least data the App needs, for the shortest time.
1. Data we collect
| Data | Source | Why |
|---|---|---|
| Apple / Google account ID, email address | Apple or Google when you sign in | Creating your account and recognising you |
| Name, age, gender, bio | You | Showing your profile to people at the same café, enforcing the age limit |
| Profile photos | You | Showing your profile |
| "Here for", status (Available etc.) | You | Helping people at the café understand you |
| Favourite drinks and what you are having | You | Calculating the taste match percentage |
| History of what you order at cafés (which café, when) | Your actions in the App | Making the match more reliable; showing your 3 most frequent items as "Usually" on your card |
| Who you want to see / who can see you (gender, age, purpose) | You | Filtering the list to your preferences |
| Location (while the App is open) | Your device, with your permission | Finding cafés near you and checking that a check-in is really at the café |
| Check-ins (café, time, hidden mode) | Your actions in the App | Showing you to people at that café |
| Cafés you have been to (how often, when last) | Automatically from your check-ins | Showing you your "Cafés you have been to" list |
| Your café ratings and comments | You, optionally, when leaving | Calculating the café average and showing you your own ratings |
| Likes, requests, matches, messages | Your actions in the App | Meeting and chatting |
| Reports, blocks, messages attached to reports | You or other users | Safety and moderation |
| Blocked-content attempts (field and time only, never the text) | Automatic | Preventing abuse |
| Subscription status | App Store / Google Play and RevenueCat | Unlocking Plus / Pro features |
| Push token, language, platform | Your device | Sending notifications |
We do not collect ID numbers, phone numbers, contacts, card details or background location. Payments are taken by Apple / Google; we never see card details.
2. How your location is protected
- Location is used only while the App is open and only with your permission. No background location is collected.
- Only your latest location is stored, overwritten on every update; no history is kept.
- Your exact location is never shown to other users. They only see the café you checked in to, and only if they are at the same café.
- With a "hidden" check-in you do not appear in the café list.
- When you leave the café or the check-in expires, you drop off the list immediately.
- To find cafés near you, your device sends only coordinates to OpenStreetMap’s Overpass servers. No account data is attached, but like any internet request those servers can see your IP address.
3. Your photos
- Location and device metadata (EXIF) are stripped from uploaded photos on our servers.
- People you have not matched with see your photo blurred. Matches and Plus / Pro members with photo access can see it clearly.
- Your photos are deleted from storage when you delete your account.
4. What other users see
People checked in at the same café who pass your filters see: your name, age, (blurred) photo, bio, "here for", status, when you arrived, what you are having, your favourite drinks, your 3 most frequent orders ("Usually") and your taste match. Nobody sees the rest of your order history, which cafés you went to or when. Your café ratings only count anonymously towards the café average; other users cannot see your comments. Only your match can read your messages.
5. Who we share data with (processors)
| Service | Purpose | Location |
|---|---|---|
| Supabase | Database, sign-in, file storage, server functions | Servers in Frankfurt, Germany (EU) |
| Apple, Google | Sign-in and in-app purchases | US / EU |
| RevenueCat | Verifying subscriptions (user ID and purchase data only) | US |
| Expo (650 Industries) | Relaying push notifications to Apple / Google | US |
| OpenStreetMap / Overpass | Café list (coordinates only) | Germany (EU) |
| Apple Maps / Google Maps | Displaying the map | US / EU |
These services process data only on our behalf and on our instructions. We do not sell or rent your data or share it with ad networks. We may share data with authorities when legally required (e.g. a court order).
International transfers: our servers are in the EU and some providers are in the US. These transfers rely on appropriate safeguards such as the standard contracts published by the Turkish Personal Data Protection Board, the EU Standard Contractual Clauses and the providers’ data processing agreements.
6. How long we keep data
| Data | Retention |
|---|---|
| Account and profile data, photos | Until you delete your account |
| Latest location | Overwritten on every update; deleted with the account |
| Check-ins | Deleted 30 days after the check-in ends |
| Order history | Deleted after 1 year; clear it any time in Settings |
| Cafés you have been to | Deleted 1 year after your last visit |
| Your café ratings and comments | Until you delete your account; delete any rating in "Cafés you have been to" |
| Messages | Deleted 1 hour after the chat ends |
| Matches | Deleted 7 days after they end |
| Likes and requests | Deleted after at most 90 days |
| Push token | Deleted after 60 days unused |
| Reports and attached message evidence | As long as needed for review and possible legal claims, at most 2 years |
| Consent records (which text you accepted and when) | For the life of your account |
7. Security
Data is encrypted in transit (TLS) and at rest. Every table is protected by row-level access rules: nobody can read another user’s private data directly, and limits and rules are enforced on the server. No system is 100% secure; if a breach happens we will inform you and the authorities within the legal deadlines.
8. Your rights
Under the Turkish KVKK (art. 11) and, if you live in the EU, the GDPR, you can access, correct, delete, restrict or object to the processing of your data, receive it in a portable format and withdraw consent. If you are in the EU you can also complain to your local supervisory authority.
- Edit your profile at any time in Settings and Profile.
- Delete your account instantly in Settings → Account → Delete account. Your profile, photos, check-ins, likes and messages are permanently deleted.
- Other requests: sostechlabs@gmail.com
9. Age
CoffeeMeet is only for people aged 18 and over. We delete accounts we learn belong to minors.
10. Changes
We may update this policy. For significant changes we show you the new text when you open the App and ask for your acceptance before you continue.
Last updated: 2026-10-04
Last updated: 2026-10-04