🔒

Privacy Policy

Last updated: May 28, 2026

MinSahib takes your privacy seriously. This policy explains what we collect, how we use it, and your rights.

1. Data We Collect

Required (for account):

  • Phone number (for login)
  • Password (stored as bcrypt hash — even we can't see the original)
  • Full name

Optional:

  • Email (for password reset, notifications)
  • Profile photo
  • Preferred language

From listings:

  • Title, description, category, price, images
  • Location (map coordinates if provided)

Auto-collected:

  • IP address (for security, anonymized after 30 days)
  • Browser, device type (for stats, anonymized)

2. What We Don't Collect

  • Credit card info (we accept no payments)
  • Sensitive categories (health, religion, ethnicity, political opinion)
  • Children's data (under-18 use prohibited)

3. How We Use It

  • Account management (login, session, password reset)
  • Listing publication and display
  • Buyer-seller messaging
  • Notifications
  • Fraud detection and security
  • Service improvement (anonymized analytics)

4. Storage Location

All data is stored on Supabase's Frankfurt (EU) servers. GDPR-compliant infrastructure.

5. Sharing

We never sell your data. We share with third parties only when:

  • Legally required (court order, terror/fraud investigation)
  • Necessary for service providers (Supabase: hosting, Vercel: deploy, Resend: email) — all under contract and GDPR-compliant
  • With your explicit consent (e.g., for analytics)

6. Cookies

Essential cookies (session, language) are on by default. Analytics cookies (Yandex Metrica, Google Analytics) run only after your explicit consent. Details: Cookie Policy.

7. Your Rights (GDPR)

  • Access: view your data from your account
  • Correction: update your profile
  • Deletion: account deletion request (via email) → permanently deleted within 30 days
  • Portability: download all your data as JSON
  • Objection: right to object to specific processing

Requests: sedatkeskin@gmail.com

8. Children

Under-18 use is prohibited. Any detected child account is immediately deleted.

9. Data Breach

We have had no breach so far. In case of one, affected users will be notified within 72 hours.

10. Changes

When the policy is updated, the date changes. Material changes are emailed.

Contact

Privacy questions: sedatkeskin@gmail.com