DoorSynch Privacy Policy
Last updated: 18 July 2026 · Türkçe için tıklayın
DoorSynch ("the App") is a site entry/exit access-management application: site owners and
managers issue QR visitor passes, security guards verify them at the gate, and every entry and
exit is recorded in the site's log. This policy explains what data DoorSynch processes, why,
and what your rights are.
1. Who we are
DoorSynch is operated by the i-shim team. Contact for all privacy matters:
[email protected].
2. What data we process
a. Account data (all users)
- E-mail address — used to create and sign in to your account, and to let a
site owner add you to a site's team by e-mail.
- Push notification token — if you grant notification permission, a device
token is stored so entry-approval requests can reach the responsible host or manager.
- Language preference — stored on your device only.
b. Site and team data (owners, managers, guards)
- Site name, type and address, entered by the site owner.
- Team membership: which accounts are the owner, managers and guards of a site.
c. Visitor pass data (entered by hosts about their visitors)
- Visitor name, and optionally a phone number, a
note (e.g. a vendor's company name) and a host/unit label.
- Pass category (guest, courier, personnel, service visit), validity window and access mode.
Important: visitor details are entered by the host who creates the pass, not
by the visitor. The host is responsible for informing their visitor that their name (and any
optional details) will be processed by the site for access-control purposes. Visitors do not
need the App and no account is created for them.
d. Entry/exit log
- For each verified entry or exit: the visitor's name, pass category, direction (in/out),
the timestamp, which guard scanned, and how the entry was approved (QR scan or live
host/manager approval).
3. What we do NOT do
- We do not sell or rent any data.
- We do not show advertising and do not use advertising or
cross-app tracking SDKs.
- We do not collect precise location, contacts, photos or files. The camera
is used only while a guard actively scans a QR pass; no images are stored
or transmitted.
4. Where data is stored
Data is stored in Google Firebase (Firestore, Authentication and Cloud Functions), operated
by Google LLC, with the application backend running in Google Cloud's europe-west1
region. Google acts as a data processor; see
Firebase Privacy & Security.
5. Who can see what
- A site's data (passes, logs, team, settings) is visible only to that site's owner,
managers and guards, each within their role's permissions.
- Entry/exit log records are written only by the server after verification — guards cannot
create or edit log entries directly.
- No data is shared with third parties except the infrastructure providers above, or where
required by law.
6. Retention and deletion
- Passes and log entries are kept as long as the site keeps them; passes can be revoked at
any time by the site's owner or a manager.
- You may request deletion of your account and associated personal data at any time by
e-mailing [email protected] from your registered address. We respond within
30 days.
- Visitors may direct requests about their pass/log data either to the site that processed
their visit or to us at the same address.
7. Legal bases (GDPR) and KVKK
For users in the EU/EEA, processing rests on the performance of the service you request
(Art. 6(1)(b) GDPR) and the site operator's legitimate interest in securing its premises
(Art. 6(1)(f)). For processing subject to Turkish law, the Turkish-language section below also
serves as the disclosure required by KVKK (Law No. 6698) Article 10. Site owners/managers act
as data controllers for their site's visitor data; DoorSynch processes that data on their
behalf.
8. Children
DoorSynch is not directed at children under 13 and does not knowingly collect their data.
9. Changes
We will post any changes to this policy on this page and update the date above.
DoorSynch Gizlilik Politikası
Son güncelleme: 18 Temmuz 2026
DoorSynch ("Uygulama"), site giriş-çıkış erişim yönetimi uygulamasıdır: site sahipleri ve
yöneticileri QR ziyaretçi kartları oluşturur, güvenlik görevlileri bunları kapıda doğrular ve
her giriş-çıkış sitenin kayıt defterine işlenir. Bu politika, DoorSynch'in hangi verileri neden
işlediğini ve haklarınızı açıklar.
1. Veri sorumlusu ve iletişim
DoorSynch, i-shim ekibi tarafından işletilir. Gizlilikle ilgili tüm talepler için:
[email protected].
2. İşlenen veriler
a. Hesap verileri (tüm kullanıcılar)
- E-posta adresi — hesap oluşturma ve giriş için; ayrıca bir site sahibinin
sizi e-postayla ekibe ekleyebilmesi için kullanılır.
- Bildirim token'ı — bildirim izni verirseniz, giriş-onay taleplerinin
sorumlu ev sahibine/yöneticiye ulaşabilmesi için cihaz token'ı saklanır.
- Dil tercihi — yalnızca cihazınızda saklanır.
b. Site ve ekip verileri (sahip, yönetici, güvenlikçi)
- Site adı, türü ve adresi (site sahibi girer).
- Ekip üyeliği: hangi hesapların sahip, yönetici ve güvenlikçi olduğu.
c. Ziyaretçi kartı verileri (ev sahibi tarafından girilir)
- Ziyaretçi adı; isteğe bağlı olarak telefon,
not (örn. firma adı) ve daire/ev sahibi etiketi.
- Kart kategorisi (misafir, kurye, personel, hizmet ziyareti), geçerlilik penceresi ve
erişim modu.
Önemli: Ziyaretçi bilgilerini ziyaretçinin kendisi değil, kartı oluşturan ev
sahibi girer. Ev sahibi, ziyaretçisini adının (ve girilen diğer bilgilerin) erişim kontrolü
amacıyla işleneceği konusunda bilgilendirmekle yükümlüdür. Ziyaretçilerin Uygulamayı kurması
gerekmez; adlarına hesap açılmaz.
d. Giriş-çıkış kaydı
- Doğrulanan her giriş/çıkış için: ziyaretçi adı, kart kategorisi, yön (giriş/çıkış), zaman
damgası, hangi güvenlikçinin okuttuğu ve onay yöntemi (QR ya da canlı onay).
3. Yapmadıklarımız
- Hiçbir veri satılmaz veya kiralanmaz.
- Reklam gösterilmez; reklam/izleme SDK'sı kullanılmaz.
- Hassas konum, rehber, fotoğraf veya dosyalara erişilmez. Kamera yalnızca
güvenlikçi QR okuturken çalışır; görüntü kaydedilmez ve iletilmez.
4. Verilerin saklandığı yer
Veriler, Google LLC tarafından işletilen Google Firebase altyapısında (Firestore,
Authentication, Cloud Functions) saklanır; uygulama sunucuları Google Cloud
europe-west1 bölgesinde çalışır. Google, veri işleyen sıfatıyla hareket eder:
Firebase Gizlilik ve Güvenlik.
5. Verileri kimler görebilir
- Bir sitenin verileri (kartlar, kayıtlar, ekip, ayarlar) yalnızca o sitenin sahibi,
yöneticileri ve güvenlikçileri tarafından, rollerinin izin verdiği ölçüde görülür.
- Giriş-çıkış kayıtları yalnızca sunucu tarafından, doğrulama sonrasında yazılır —
güvenlikçiler kayıt oluşturamaz veya değiştiremez.
- Yukarıdaki altyapı sağlayıcıları ve yasal zorunluluklar dışında üçüncü kişilerle veri
paylaşılmaz.
6. Saklama süresi ve silme
- Kartlar ve kayıtlar, site sildikçe/sakladıkça tutulur; kartlar sahip veya yönetici
tarafından her an iptal edilebilir.
- Hesabınızın ve kişisel verilerinizin silinmesini, kayıtlı e-posta adresinizden
[email protected]'a yazarak her zaman talep edebilirsiniz; 30 gün içinde
yanıtlanır.
- Ziyaretçiler, kart/kayıt verilerine ilişkin taleplerini ziyaret ettikleri siteye veya
aynı adrese iletebilir.
7. KVKK aydınlatması
6698 sayılı KVKK kapsamında: yukarıda sayılan veriler, sözleşmenin kurulması/ifası
(m.5/2-c) ve site işleticisinin meşru menfaati (m.5/2-f) hukuki sebeplerine dayanılarak,
erişim kontrolü ve güvenlik amacıyla işlenir. Site sahipleri/yöneticileri, sitelerinin
ziyaretçi verileri bakımından veri sorumlusudur; DoorSynch bu verileri onlar adına işler.
KVKK m.11'deki haklarınızı (bilgi talep etme, düzeltme, silme vb.) [email protected] adresi
üzerinden kullanabilirsiniz.
8. Çocuklar
DoorSynch 13 yaş altı çocuklara yönelik değildir ve bilerek onlardan veri toplamaz.
9. Değişiklikler
Bu politikadaki değişiklikler bu sayfada yayımlanır ve üstteki tarih güncellenir.