Legal
Privacy Policy
Explains in detail how Planfly collects, uses, shares, stores and protects personal data on its website, business dashboard and booking pages.
Contents · 25 sections
- Data Controller Information
- 1. Purpose and Scope
- 2. Data Controller and Division of Roles
- 3. Whose Personal Data Do We Process?
- 4. What Personal Data Do We Process?
- 4.1. Data of Website Visitors
- 4.2. Data Relating to Prospective Customer, Communication and Support Processes
- 4.3. Data of Business Accounts and Dashboard Users
- 4.4. Staff Member Data
- 4.5. Data of People Who Book Appointments and of Business Customers
- 4.6. Data Relating to Payment Processes
- 5. How Do We Collect Personal Data?
- 6. For What Purposes Do We Process Personal Data?
- 6.1. Providing and Managing the Service
- 6.2. Sales, Communication and Support Processes
- 6.3. Contractual and Commercial Processes
- 6.4. Information Security and System Administration
- 6.5. Product Development, Analytics and Improvement
- 6.6. Marketing and Commercial Communications
- 6.7. Fulfilling Legal and Administrative Obligations
- 7. On What Legal Grounds Do We Process Personal Data?
- 8. Special Categories of Personal Data
- 9. Who May We Share Personal Data With?
- 10. Transfers of Data Abroad
- 11. Cookies and Similar Technologies
- 12. How Long Do We Keep Personal Data?
- 12.1. Traffic, Security and System Logs
- 12.2. Communication, Request and Support Records
- 12.3. Account and Dashboard Data
- 12.4. Contract, Invoicing and Commercial Records
- 12.5. Payment Records
- 12.6. Consent and Permission Records
- 12.7. Businesses' Customer and Appointment Data
- 12.8. Analytics Data
- 13. Security of Personal Data
- 14. Businesses' Own Customer Data
- 15. Embeddable Widget and Third-Party Sites
- 16. Google Services: Sign in with Google, Google Calendar and Google Meet
- 16.1. Signing In and Signing Up with Google
- 16.2. Google Calendar and Google Meet Integration
- 16.3. Limited Use of Google User Data
- 16.4. Removing the Connection and Retention
- 17. Our Approach to Children
- 18. Data Subject Rights
- 19. Applications and Contact
- 20. Region-Specific Privacy Notices
- 21. Individuals in Other Countries
- 22. Language of This Policy
- 23. Changes to the Policy
- 24. Final Provision
This Policy is published in Turkish and English with the same content. If you are located outside Türkiye, this English version is the authoritative version for you (see Section 22).
Data Controller Information
- Data controller: Mobiza Teknoloji
- Brand / service: Planfly
- Email: legal@planfly.app
- Phone: +90 850 307 90 23
- Address: Ovaakça Santral Mah. Ovaakça Fatih Sultan Mehmet Cad. No: 86, 16335 Osmangazi, Bursa, Türkiye
- Tax number: 1280527561
- Tax office: Uludağ Tax Office
- DUNS number: 751143161
1. Purpose and Scope
This Privacy Policy (the "Policy") has been prepared with respect to personal data processed in connection with the Planfly-branded website operated by Mobiza Teknoloji, all of its subdomains, the business dashboard, web applications, online booking pages, the embeddable booking widget, appointment confirmation and reminder notifications, communication channels and digital services connected with Planfly.
This Policy applies:
- on planfly.app and all of its subdomains,
- in communication channels owned by Planfly or operated on Planfly's behalf,
- in customer, user and visitor interactions connected with Planfly.
This Policy does not cover other products, brands, services or platforms of Mobiza Teknoloji outside Planfly. The Policy should be read together with the KVKK Privacy Notice and the Cookie Policy. The privacy notices that apply depending on your region are listed in Section 20.
2. Data Controller and Division of Roles
Unless expressly stated otherwise, the data controller for the processing of personal data within Planfly is Mobiza Teknoloji.
However, businesses that use Planfly, such as hair salons, beauty centers, psychologists, dietitians, clinics, studios and similar businesses, are data controllers with respect to their own commercial and professional processes, such as collecting data belonging to their own customers, appointment management, customer communication, intake forms and reminders.
The roles of the parties in the Planfly ecosystem are therefore divided as follows:
- Mobiza Teknoloji is the data controller with respect to Planfly's own website, sales processes, business accounts and dashboard access, subscriptions, invoicing and payment confirmation, support, security, system administration, infrastructure, analytics and legal obligations.
- Businesses are data controllers with respect to the customer (client, patient, member, etc.) data they collect or enter through their booking pages, widgets and dashboards.
- Mobiza Teknoloji acts as a data processor, processing businesses' customer data only in line with the business's instructions and only to the extent necessary to provide the Planfly service. The provisions that apply to this relationship are set out in the data processing section of the Terms of Use and in the Data Processing Agreement.
Unless expressly stated otherwise, Mobiza Teknoloji is not a party to appointments made through Planfly or to the services that are the subject of those appointments. The service relationship is formed between the person who books the appointment and the relevant business.
Orders paid in currencies other than Turkish lira: Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all orders paid in currencies other than Turkish lira on our website. Paddle provides customer service for payment and billing inquiries and handles returns and refunds for these orders. In this Policy, "Paddle" means Paddle.com Market Limited (company number 08172165, 30 Old Bailey, London EC4M 7AU, United Kingdom) and the Paddle group companies named in Paddle's buyer terms (e.g., Paddle.com Inc. for buyers in the United States and Paddle.com (Canada) Ltd. for buyers in Canada).
Paddle is an independent controller for the payment data it collects on its checkout (card and other payment method details, billing address and tax information) under its own privacy notice. To open the checkout, Mobiza Teknoloji sends Paddle your billing email address, your billing name or business name, your country and billing address, your tax number (if provided), your language preference and the identifier of your business account in Planfly. To activate and manage your subscription, Mobiza Teknoloji receives from Paddle only order data (order and subscription ID, plan, amount, currency, country, tax status, name, email, payment status and refund or chargeback status); it does not receive your card details. For these orders too, Mobiza Teknoloji is the controller for account, dashboard, support, security and marketing processes.
In-app purchases: For subscriptions purchased through the App Store or Google Play, the seller is Apple or Google, and payment data is processed under those companies' own responsibility as controllers. To activate your subscription, Mobiza Teknoloji receives from them only transaction information about the purchase, renewal and refund status.
Payment institutions: While providing payment services on our behalf, iyzico also processes certain data under its own responsibility as a controller (e.g., for fraud prevention and its own legal obligations).
3. Whose Personal Data Do We Process?
Planfly may process personal data belonging to the following groups of people:
- website visitors,
- prospective customers and people who request information or a quote,
- business owners, managers and authorized users who use the Planfly dashboard,
- staff members added by businesses or invited to their team,
- people who book appointments through a business's booking page or widget,
- customers registered in the dashboard by businesses (clients, patients, members, students, etc.),
- people who pay for a subscription or are involved in the invoicing process,
- people who contact Planfly in connection with support, communication, sales or complaint processes.
4. What Personal Data Do We Process?
The data processed may vary depending on the module and flow used.
4.1. Data of Website Visitors
- IP address,
- device and browser information,
- operating system and technical usage data,
- page navigation records and usage logs,
- referring page and campaign / UTM data,
- cookie data and similar online identifiers,
- if you give consent, measurement data collected through Google Analytics 4 relating to navigation and interactions on marketing pages and to successful sign-up, sign-in and business setup events (Google Analytics cookie ID, device and browser information, approximate location, the domain of the referring site and campaign / UTM tags; no name, email, phone number or form content is sent),
- if a contact form is filled in, first name, last name, phone number, email address, business name, message content and similar information provided by the user.
4.2. Data Relating to Prospective Customer, Communication and Support Processes
- first name, last name,
- phone,
- email,
- business name and industry,
- the content of requests, questions and support tickets, together with their attachments,
- campaign or referral source information,
- communication and support history.
4.3. Data of Business Accounts and Dashboard Users
- first name, last name,
- email,
- phone,
- account identification details,
- hashed password records and two-factor authentication configuration,
- if Sign in with Google is used, the Google account ID, the email address of the Google account and the date it was linked (details in Section 16),
- if the Google Calendar / Google Meet integration is used, the email address and ID of the connected Google account, encrypted access and refresh tokens, the permissions granted, the selected calendar and connection status records (details in Section 16),
- business name, industry, address, contact details, social media account, logo and cover image,
- billing information (full name or trade name, Turkish national ID number (T.C. kimlik numarası) or tax number, tax office, billing address),
- subscription, plan, payment and invoice records,
- role, permission and team invitation records,
- session, transaction and security logs,
- support and communication records,
- device, browser, IP and dashboard usage data.
4.4. Staff Member Data
The following data relating to staff members that businesses add to Planfly may be processed:
- first name, last name and title,
- photo and bio,
- calendar color and the services they provide,
- working hours, time off and holidays,
- user account details, if invited to the dashboard.
Depending on the business's preference, a staff member's name, title, photo and bio may be shown publicly on the booking page.
4.5. Data of People Who Book Appointments and of Business Customers
- first name, last name,
- phone number and/or email address,
- selected service, service options, staff member, date and time,
- appointment note,
- answers given to intake form questions,
- appointment status, cancellation, rescheduling and no-show records,
- recurring appointment and group class attendance records,
- online meeting links and, if the business has connected its Google account, records of the event created in Google Calendar,
- date of birth, tags, private notes and appointment history added by the business through the dashboard,
- records of the display of the privacy notice, explicit consent and consent to commercial electronic messages (date, IP address, browser information, text version),
- records of appointment confirmation and reminder emails / messages sent,
- technical records relating to the use of the appointment management link.
4.6. Data Relating to Payment Processes
Planfly does not store full card numbers, CVV/CVC codes or unmasked payment card data in its own systems; for payments made with iyzico, the card's expiration date is not stored either. Card details entered on the Planfly payment page are transmitted over an encrypted connection (TLS) to the infrastructure of iyzico Ödeme Hizmetleri A.Ş. ("iyzico"); Planfly processes this information only for the duration of the transmission and does not write it to any database, log or session. If the iyzico payment form is chosen, card details are entered directly on the iyzico page. Saved cards are kept in iyzico's card storage infrastructure.
For orders paid in currencies other than Turkish lira on our website, payment is made on Paddle's checkout. Card and other payment method details are entered directly with Paddle and never reach Planfly's servers; Paddle processes them as the seller and an independent controller under its own privacy notice. The data Planfly sends to and receives from Paddle is described in Section 2.
The following limited payment data may be processed by Planfly:
- payment status,
- transaction number and reference number,
- payment date, amount and the period it covers,
- payment method,
- card type or card scheme (e.g., Visa, Mastercard, Troy),
- the masked last four digits of the card,
- if card storage is chosen, card and customer reference keys (tokens) generated by iyzico,
- limited transaction data provided by iyzico for payment confirmation, automatic renewal, refunds and payment disputes,
- for orders paid in currencies other than Turkish lira, the order data received from Paddle (Section 2).
5. How Do We Collect Personal Data?
Your personal data may be collected by automated, partially automated or non-automated means through the following channels:
- website visits,
- cookies and similar technologies,
- sign-up, sign-in, contact and support forms,
- information received from Google, upon your approval in your Google account, when you sign in or sign up with Google or link a Google account,
- use of the business dashboard and session records,
- online booking pages and appointment management links,
- the booking widget or iframe that businesses embed on their own websites,
- customer, staff member or appointment data entered by businesses through the dashboard,
- team invitations,
- transaction and order notifications from the payment institution, Paddle and other service providers,
- delivery reports from messaging and email service providers,
- email, phone and other communication channels.
6. For What Purposes Do We Process Personal Data?
Planfly may process personal data for the following purposes:
6.1. Providing and Managing the Service
- operating the Planfly website and the business dashboard,
- creating and managing user and business accounts, and offering the option to sign in and sign up with Google,
- publishing online booking pages and the widget,
- performing calendar, staff, service, working hours and availability calculations,
- creating, confirming, canceling and rescheduling appointments, and enabling them to be added to calendars,
- at the business's request, creating, updating and deleting Google Calendar events and Google Meet links for online appointments,
- sending appointment confirmation and reminder emails and messages,
- keeping intake forms and customer records on behalf of the business,
- managing team, role and permission structures,
- providing reports and statistics to the business.
6.2. Sales, Communication and Support Processes
- receiving requests for information and quotes,
- communicating with prospective customers,
- providing product, plan and pricing information,
- responding to support tickets, questions, suggestions and complaints.
6.3. Contractual and Commercial Processes
- carrying out free trial, subscription, plan change and automatic renewal processes,
- collecting payments, card storage and payment confirmation,
- for orders paid in currencies other than Turkish lira, opening Paddle's checkout and activating and managing the subscription with the order data received from Paddle,
- managing invoicing, accounting and finance processes,
- entering into, performing and terminating the contract.
6.4. Information Security and System Administration
- authentication and authorization,
- when signing in with Google, checking that the email address has been verified by Google and preventing the misuse of accounts opened with an email address belonging to someone else,
- session security,
- logging,
- detecting fake appointments, spam, bots, misuse and unauthorized access,
- operating rate limiting and similar protection mechanisms,
- system performance, error management, maintenance and auditing,
- backups and protecting data integrity.
6.5. Product Development, Analytics and Improvement
- analyzing the user experience,
- producing aggregated usage statistics,
- identifying errors and bottlenecks,
- developing features and improving the service.
6.6. Marketing and Commercial Communications
- if consent is given, sending campaigns, news and announcements about Planfly,
- measuring campaign and conversion performance,
- managing communication preferences.
Planfly does not use businesses' customer data for its own marketing activities, and does not sell or rent it.
6.7. Fulfilling Legal and Administrative Obligations
- fulfilling obligations arising from legislation,
- responding to requests from competent authorities,
- resolving disputes,
- establishing, exercising and protecting rights,
- fulfilling retention, evidentiary and audit obligations.
7. On What Legal Grounds Do We Process Personal Data?
Planfly processes personal data in accordance with Articles 5 and 6 of Law No. 6698 on the Protection of Personal Data (KVKK), relying on different legal grounds depending on the nature of the relevant processing activity. In this context, your personal data may be processed on one or more of the following legal grounds:
- processing personal data of the parties to a contract is necessary, provided that it is directly related to the establishment or performance of that contract,
- it is expressly provided for by law,
- processing is mandatory for the data controller to fulfill its legal obligation,
- the data has been made public by the data subject,
- processing is mandatory for the establishment, exercise or protection of a right,
- processing is mandatory for the legitimate interests of the data controller, provided that it does not harm your fundamental rights and freedoms,
- your explicit consent, where required by legislation.
For processing activities based on explicit consent, you may withdraw your explicit consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
8. Special Categories of Personal Data
Planfly does not set up any structure intended to process special categories of personal data. However, businesses providing health services (e.g., psychologists, dietitians, dental clinics, private medical practices, physiotherapists) may process special categories of personal data, such as health data, through the intake questions they add to booking forms, appointment notes or notes they add to the customer card.
With respect to such data:
- the data controller is the relevant business; the business decides which questions to ask, on which legal ground the data will be processed and whether explicit consent must be obtained where necessary, and the business is responsible for these decisions,
- businesses may obtain a separate and optional explicit consent for the processing of health data on the booking form; Planfly records this consent together with the date, IP address and text version,
- businesses are expected not to request special categories of data that are not required to book an appointment and to prepare their questions in line with the principle of data minimization,
- private notes added to the customer card are stored encrypted in the database and shown only to the business's authorized users,
- by using the discreet message option, which does not show the service name in reminder messages, businesses can reduce the risk of third parties learning health information from message content,
- Planfly processes this data only as a data processor, to the extent necessary to provide the service and having regard to the adequate measures prescribed by the Personal Data Protection Board (KVKK Board) for special categories of personal data.
9. Who May We Share Personal Data With?
Depending on the purpose of processing and the legal ground, and only to the extent necessary, your personal data may be shared with the following groups of recipients:
| Recipient group | Purpose of sharing |
|---|---|
| The business you book with or contact | Creating and carrying out the appointment and managing the business's customer relationship |
| Hosting, server, database and backup providers | Running the service, storing and backing up data |
| Cloudflare (CDN, R2 file storage, DNS, network security) | Storing and serving images and files, performance, preventing attacks and misuse |
| Netgsm İletişim ve Bilgi Teknolojileri A.Ş. and other authorized messaging providers | Sending appointment confirmation and reminder messages |
| Email delivery service providers | Delivering account, appointment, invoice and support emails |
| Google LLC (if used) | Transmitting the Sign in with Google request; if enabled by the business, creating events and Google Meet links in the business's Google Calendar for online appointments (Section 16) |
| Apple Inc. (if used) | Transmitting the Sign in with Apple request; verifying subscription purchases made through the App Store |
| Google LLC (Google Play, if used) | Verifying subscription purchases made through Google Play |
| Google LLC (Firebase Cloud Messaging) | Delivering push notifications (e.g., a new appointment) to business users in the Planfly mobile app |
| Google LLC (Google Drive) | Storing encrypted database backups |
| Artificial intelligence model providers (e.g., OpenAI, L.L.C.) | Answering your questions in the chat assistant on our website and summarizing conversations for the support team |
| iyzico Ödeme Hizmetleri A.Ş. and banks | Subscription payments, card storage, automatic renewal and refunds |
| Paddle (the seller and an independent controller for orders paid in currencies other than Turkish lira on our website, Section 2) | Opening the checkout, collecting payment, calculating taxes, issuing invoices or receipts, refunds, payment disputes and answering payment and billing inquiries |
| Persons and organizations providing accounting, e-invoicing, legal, audit and consulting services | Legal obligations, invoicing, audits and protecting rights |
| Google Analytics 4 (Google LLC) and other analytics and measurement service providers (if consent is given) | Usage statistics for marketing pages, sign-up and campaign measurement |
| Competent public institutions and organizations, courts and enforcement offices | Fulfilling legal requests and obligations |
The information you provide for an appointment you make as a customer of a business is shared with the relevant business, because the appointment and service relationship is essentially formed between that business and you.
Planfly's policy is to engage service providers under contracts that include data security and confidentiality obligations, and it never sells personal data to third parties under any circumstances.
10. Transfers of Data Abroad
Planfly's service infrastructure may include services that use servers located abroad or service providers with connections abroad. As a result, your personal data or technical records that qualify as personal data may be transferred abroad.
Categories of providers with connections abroad may include:
- content delivery network, file storage (Cloudflare R2), DNS and network security services,
- cloud and hosting providers,
- email delivery services,
- if used, Sign in with Google and the Google Calendar and Google Meet integration (Google LLC),
- for orders paid in currencies other than Turkish lira on our website, Paddle (Paddle.com Market Limited, established in the United Kingdom, and, for buyers in the United States, Paddle.com Inc., established in the USA),
- Apple Inc. for Sign in with Apple and App Store purchases; Google LLC for Google Play purchases, mobile app push notifications (Firebase Cloud Messaging) and encrypted database backups (Google Drive),
- artificial intelligence model providers for the chat assistant on our website,
- error monitoring and performance tools,
- if consent is given, Google Analytics 4 (Google LLC) and other analytics and measurement tools.
Mobiza Teknoloji bases transfers of data abroad on Article 9 of the KVKK and the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad (Kişisel Verilerin Yurt Dışına Aktarılmasına İlişkin Usul ve Esaslar Hakkında Yönetmelik). Depending on the nature of the transfer, the following are relied on:
- an adequacy decision regarding the country, international organization or sector to which the transfer is made,
- in the absence of an adequacy decision, appropriate safeguards: in particular the standard contract announced by the Personal Data Protection Board (notified to the Personal Data Protection Authority (KVKK Authority) within five business days of signing), binding corporate rules, or a written undertaking with the Board's permission,
- where these options are not available, and only provided that the transfer is incidental, the exceptional cases listed in the sixth paragraph of Article 9 of the KVKK, including explicit consent.
Transfers to Paddle for orders paid in currencies other than Turkish lira on our website are based on the standard contract announced by the Personal Data Protection Board. The transfer safeguards for individuals located in the European Economic Area, Switzerland and the United Kingdom are described in the regional privacy notices listed in Section 20.
11. Cookies and Similar Technologies
Planfly uses cookies and similar technologies on the website, the business dashboard and booking pages. These technologies may be used for the following purposes:
- operating the site, the dashboard and booking pages,
- session management and form security,
- remembering theme and interface preferences,
- security and preventing misuse,
- if consent is given, traffic and usage analysis and campaign measurement.
If you give consent, Planfly uses Google Analytics 4 on marketing pages, legal documents and the account acquisition flow (sign-up, sign-in, email verification and business setup). The business dashboard, booking pages, the widget and appointment management pages are not measured (after sign-in, only the successful sign-in / sign-up event is sent, without the dashboard address); ad and personalization permissions and Google signals are turned off, and no name, email, phone number or form content is added to measurement events. You can withdraw your consent at any time using the "Cookie preferences" link on the page.
For cookies and similar technologies that are not strictly necessary, prior consent / explicit consent is obtained where required by applicable legislation. For more information, see the Cookie Policy.
12. How Long Do We Keep Personal Data?
Planfly keeps personal data only for as long as necessary for the purpose for which it is processed and to the extent required or permitted by applicable legislation. The retention period may vary depending on the nature of the data, the purpose of processing, the contractual relationship, technical requirements and legal obligations.
12.1. Traffic, Security and System Logs
Traffic records, access logs and security records are kept for the periods set out in Law No. 5651 on Regulating Internet Publications and Combating Crimes Committed Through Such Publications and the related secondary regulations, and for as long as necessary for information security, incident investigation and legal proceedings.
12.2. Communication, Request and Support Records
Contact form records, support tickets and correspondence are kept for a reasonable period depending on the nature of the relationship. They may be kept longer if there is an ongoing customer relationship, a dispute, an evidentiary need or a legal requirement.
12.3. Account and Dashboard Data
Data relating to business and user accounts is kept for as long as the account is active. Information relating to Sign in with Google and the Google Calendar connection is kept for as long as the connection remains in place and is deleted when the connection is removed (Section 16.4). After an account or business is deleted, this data may be kept for as long as necessary due to legal obligations, disputes, evidentiary needs, security and the backup cycle, and is deleted, destroyed or anonymized at the end of that period.
12.4. Contract, Invoicing and Commercial Records
Invoicing, accounting, contract and commercial transaction records are kept for the periods set out in applicable legislation, in particular Tax Procedure Law No. 213 (Vergi Usul Kanunu) and Turkish Commercial Code No. 6102 (Türk Ticaret Kanunu) (as a rule, up to 10 years).
12.5. Payment Records
Payment transaction references, masked card information and transaction confirmation records are kept for as long as necessary for accounting, evidentiary, fraud prevention and legal obligation purposes. When you remove your saved card from the dashboard, the card is no longer used for subsequent payments and deletion of the card storage token held by iyzico is requested. For orders placed through Paddle, payment methods are stored by Paddle and can be managed at paddle.net; the order records received from Paddle are kept for the purposes described in this section. The retention periods of the payment and billing records kept by Paddle itself are governed by Paddle's privacy notice.
12.6. Consent and Permission Records
Records relating to privacy notices, explicit consent and consent to commercial electronic messages may be kept, because of the burden of proof, for the duration of the relevant relationship and thereafter for the statutory limitation periods. If you withdraw your consent to commercial electronic messages, your opt-out notice is recorded and sending messages is stopped.
12.7. Businesses' Customer and Appointment Data
Appointment, customer, intake form answer, customer note and notification records are kept in line with the instructions and preferences of the business, which is the data controller. The business can export or delete customer records from the dashboard. If the business account is closed, this data is deleted or anonymized, subject to the backup cycle and legal obligations.
12.8. Analytics Data
Measurement data sent to Google Analytics is kept for the retention period selected in Planfly's Google Analytics account (at most 14 months for standard accounts); Google Analytics cookies are valid for at most 12 months and are deleted when you withdraw your consent.
Data whose retention period has expired is deleted, destroyed or anonymized in accordance with the Regulation on the Erasure, Destruction or Anonymization of Personal Data (Kişisel Verilerin Silinmesi, Yok Edilmesi veya Anonim Hale Getirilmesi Hakkında Yönetmelik) and as part of periodic destruction processes.
13. Security of Personal Data
In accordance with Article 12 of the KVKK, Mobiza Teknoloji implements appropriate technical and administrative measures to ensure the security of personal data. In this context, the following measures may be applied depending on the risk:
- encrypted transmission with TLS (HTTPS) on all connections,
- separating business data on a per-business basis and role-based access control (owner, manager, staff member),
- not keeping passwords in plain text, and the option of two-factor authentication,
- encrypting Google Calendar access and refresh tokens in the database; using request-specific, single-use verification values for Sign in with Google and not storing the Google access token issued for sign-in,
- encrypting private notes on the customer card in the database,
- rate limiting, bot traps and misuse detection,
- logging and incident tracking,
- regular backups,
- limiting employee access on a need-to-know basis, and confidentiality obligations,
- assessing the security configurations and contracts of service providers.
If we become aware of a data breach, the necessary notifications are made in accordance with Article 12 of the KVKK and the Board's decisions; for breaches affecting businesses' customer data, the relevant business is informed without delay.
Nevertheless, no data transmission over the internet and no technical infrastructure can be guaranteed to be completely free of risk.
14. Businesses' Own Customer Data
Since Planfly is a platform that provides technical infrastructure to businesses, businesses may collect data relating to their own customers through Planfly or enter it into Planfly.
In this context, data such as first name, last name, phone, email, appointment details, intake form answers, appointment notes, customer tags and private notes is processed for the relevant business's own processes.
With respect to this data:
- the relevant business is responsible for its own obligation to inform; Planfly provides each business with a privacy notice template generated with the business's details and allows the business to link to its own notice,
- where necessary, carrying out explicit consent and commercial electronic message consent processes is the responsibility of the relevant business,
- if the business sends commercial electronic messages to its own customers, the obligations under Law No. 6563 on the Regulation of Electronic Commerce, the related regulation and the Message Management System (İleti Yönetim Sistemi, İYS: Türkiye's national registry of consents for commercial messages) belong to the business,
- Planfly processes this data only as a data processor, for the purposes of providing the service, security, technical maintenance, support and fulfilling contractual obligations.
15. Embeddable Widget and Third-Party Sites
Businesses may embed the Planfly booking widget or booking page (iframe) on their own websites. In that case, the information you enter in the booking form is transmitted directly to Planfly's infrastructure and processed according to the principles described above.
The website on which the widget appears, however, is under the control of the relevant business or third party. The privacy and cookie policies of that site apply to the cookies, analytics tools and other data processing activities used on it.
Online meetings take place on Google Meet; if the business connects its Google account, the event created in Google Calendar for your online appointment is described in Section 16. If you move on to third-party services through the Google Meet link or the social media and map links that the business includes on its booking page, the terms and privacy policies of the relevant service provider (e.g., Google) apply.
16. Google Services: Sign in with Google, Google Calendar and Google Meet
Planfly integrates with services provided by Google LLC ("Google") in two ways: allowing users to sign in to Planfly with their Google account, and allowing businesses to create events with Google Meet links in Google Calendar for their online appointments. Both integrations are optional; even if you don't use them, you can use Planfly with your email address and password. The consent-based use of Google Analytics is covered by Section 11 and the Cookie Policy, not by this section.
16.1. Signing In and Signing Up with Google
When you use the "Continue with Google" option, you are redirected to Google's sign-in page; your Google account password is not transmitted to Planfly. If you sign in with your Google account and give your approval, Planfly receives only basic identity information from Google (the openid, email and profile scopes):
- Google account ID (the permanent number Google assigns to your account),
- the email address of your Google account and whether that address has been verified by Google,
- your name in your Google account.
This information is used to create your account or match it with your existing account that has the same email address, to recognize you on subsequent sign-ins and to keep your account secure. For an account opened with Google, your email address is considered verified without a separate verification email, since it has been verified by Google. The name on your account is taken from your Google account; you can change it at any time. If Google has not verified the address, no account is opened with Google and no matching is performed. Your profile photo, contacts, emails, files or calendar are not obtained this way; the access token issued by Google during sign-in is not stored.
You can later link your Google account, replace it with another Google account or remove the link on the Settings › Security page. The address of the Google account you link may be different from your Planfly email address. For actions that require you to verify your identity again (e.g., accessing security settings, deleting your account), you can also verify with your Google account instead of your password. For account linking, identity verification and email verification, your email address is sent to Google so that the correct Google account is preselected. If you have turned on two-factor authentication, a verification code is also requested when you sign in with Google.
16.2. Google Calendar and Google Meet Integration
A business owner or manager can connect a Google account to Planfly on behalf of the business, and a staff member can do so on their own behalf. During the connection, Google asks for your approval of the permissions Planfly requests:
- basic identity (openid, email): to learn the email address and ID of the connected Google account,
- Google Calendar events (calendar.events): to create events with Google Meet links for online appointments, update them when the appointment changes and delete them when it is canceled,
- calendar list (calendar.calendarlist.readonly, optional): to list the names of your calendars so that you can choose the calendar to which events are added.
Planfly uses these permissions only for the appointment events it creates itself; it does not read, change or delete other events in your calendar. Access and refresh tokens are stored encrypted in the database.
An event created for an online appointment contains the appointment date and time, the service name (only "Online meeting" if the business uses the discreet message option), the name of the person who booked the appointment, the staff member's name, the business name and a link to the appointment in the Planfly dashboard (which only the business's authorized users can open). Depending on the business's preference, the email address of the person who booked the appointment and, if the event is created in the business account, the staff member's email address are also added to the event as guests; guests cannot see each other. Google's invitation and update emails are sent only if the business has turned this option on. The Meet link generated by Google is saved to the appointment in Planfly and sent to the person who booked the appointment with the appointment notifications.
The data controller for this data relating to people who book appointments is the relevant business; Planfly transmits this data to the business's own Google account on the business's instructions and as a data processor. The video call itself takes place on Google Meet; Planfly does not access the content of the call and does not record it. Google's own terms and privacy policy apply to the use of Google Calendar and Google Meet.
16.3. Limited Use of Google User Data
Planfly's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Accordingly, data received from Google:
- is used only to provide and improve the user-requested features described in this section (Sign in with Google, creating Google Calendar events and Google Meet links),
- is not used for advertising, personalized advertising, retargeting or building profiles for advertising purposes,
- is not sold, and is not transferred to third parties except where necessary for these features, for security purposes or as required by a legal obligation,
- is not used to develop or train artificial intelligence or machine learning models,
- is not read by Planfly employees unless you give your express approval, it is required for security purposes (e.g., investigating abuse) or it is required by law.
16.4. Removing the Connection and Retention
- You can remove the Sign in with Google link on the Settings › Security page; your Google account ID and Google email address are deleted from your account. If you opened your account with Google, you will first be asked to set a password so that you don't lose access to your account.
- When the Google Calendar / Google Meet connection is disconnected from the dashboard, the access and refresh tokens are deleted and, if the same Google account is not used in another connection on Planfly, Google is asked to revoke the access permission. Previously created events and Meet links remain in the business's Google Calendar and are under the business's control.
- You can also remove Planfly's access to your Google account at any time on the third-party apps and services page of your Google account.
- Sign in with Google information is deleted together with your account; the Google Calendar connection is deleted when the connection is disconnected or when the relevant staff member record or the business is deleted, according to the principles in Section 12.
17. Our Approach to Children
Planfly services are primarily intended for businesses, business representatives and businesses' customers; they are not designed as a service specifically for children.
However, some businesses (e.g., child and adolescent therapy, children's haircuts, education and course centers) may accept appointments for services intended for children. In such cases, the appointment is expected to be made by a parent or legal guardian, and data relating to the child is expected to be shared only to the extent necessary for the service. The privacy notice and, where necessary, consent processes for processing children's data are the responsibility of the business, which is the data controller.
Planfly does not engage in profiling or behavioral advertising targeted at children. If it becomes apparent that a child's data has been processed unlawfully, the necessary assessment is made within the framework of applicable legislation and the circumstances of the specific case.
18. Data Subject Rights
Under Article 11 of the KVKK, data subjects have the following rights:
- to learn whether their personal data is processed,
- to request information about it if it has been processed,
- to learn the purpose of processing and whether the data is used in line with that purpose,
- to know the third parties to whom the data is transferred in Türkiye or abroad,
- to request correction if the data is incomplete or inaccurately processed,
- to request erasure or destruction if the conditions in Article 7 of the KVKK are met,
- to request that the correction, erasure or destruction be notified to the third parties to whom the data has been transferred,
- to object to a result against them arising from analysis exclusively by automated systems,
- to request compensation for damages if they suffer damage due to unlawful processing.
In addition, for processing based on explicit consent you can withdraw your consent, and you can opt out of commercial electronic messages at any time free of charge.
If you are located in the European Economic Area, Switzerland, the United Kingdom or the United States, you also have the rights described in the regional privacy notice listed in Section 20; if you are located in another country, Section 21 also applies. You do not need to meet the formal requirements specific to KVKK applications to exercise these rights.
19. Applications and Contact
You can send us your requests regarding your personal data and requests to exercise your rights through the following channels:
- Legal name: Mobiza Teknoloji
- Email: legal@planfly.app
- Phone: +90 850 307 90 23
- Address: Ovaakça Santral Mah. Ovaakça Fatih Sultan Mehmet Cad. No: 86, 16335 Osmangazi, Bursa, Türkiye
Applications are concluded in accordance with the Communiqué on the Procedures and Principles of Applications to the Data Controller (Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ) as soon as possible depending on the nature of the request, and within thirty days at the latest. Additional information may be requested for identity verification, security and the scope of the application.
Applications from individuals located outside Türkiye are answered within the period set by the law of the place where they are located (one month for the European Economic Area and the United Kingdom, 30 days for Switzerland and 45 days for the United States); details are given in the regional privacy notices listed in Section 20.
For requests relating to an appointment you made with a business, you must first apply to the relevant business, which is the data controller. If your application reaches us, we will forward it to the relevant business and provide the technical support necessary for the business to respond to the request.
20. Region-Specific Privacy Notices
This Policy applies to you wherever you are located. Depending on your region, the following privacy notice also applies to you; it contains the information required by the law of that region (such as legal bases, international transfers, your rights and how to make a request or a complaint):
- Türkiye: KVKK Privacy Notice
- European Economic Area and Switzerland: GDPR Privacy Notice
- United Kingdom: UK Privacy Notice
- United States: US Privacy Notice
The regional privacy notice complements this Policy. If this Policy and the regional notice conflict, the regional notice prevails for individuals located in that region. You can exercise the rights described in the notices for the European Economic Area and Switzerland, the United Kingdom and the United States without meeting the formal requirements specific to KVKK applications. If you are located outside the regions above, Section 21 applies.
21. Individuals in Other Countries
If you are located in a country other than Türkiye, the European Economic Area, the United Kingdom, Switzerland or the United States, the principles in this Policy and the rights in Section 18 also apply to you. If the law of your country gives you additional rights, you can exercise them by writing to legal@planfly.app; we respond to your request within the period set by that law. Your personal data may be transferred to Türkiye and other countries with the safeguards described in Section 10.
22. Language of This Policy
This Policy is published in Turkish and English with the same content. For individuals located in Türkiye, the Turkish version is authoritative; for individuals located outside Türkiye, the English version is authoritative.
23. Changes to the Policy
Mobiza Teknoloji may update this Privacy Policy due to legislative changes, developments in the product structure, new modules, new integrations, new service providers or operational requirements.
The current text takes effect on the date it is published on planfly.app. For significant changes, additional notice may be given to business users by email or dashboard notification.
24. Final Provision
In processing personal data, Planfly is guided by the principles of transparency, lawfulness, proportionality, data minimization, security and user control. Since businesses also act as data controllers in the flows Planfly offers, the relevant businesses' own privacy notice and privacy obligations are separately reserved.
This Policy explains the general framework of Planfly's approach to data processing. Additional privacy notices, explicit consent texts, cookie preferences and contractual documents may also apply to specific modules, campaigns or integrations.
Other legal documents
- KVKK Privacy NoticeOctober 10, 2026
- GDPR Privacy Notice (European Economic Area and Switzerland)October 10, 2026
- UK Privacy NoticeOctober 10, 2026
- US Privacy NoticeOctober 10, 2026
- Terms of UseOctober 10, 2026
- Cookie PolicyOctober 11, 2026
- Data Processing AgreementOctober 10, 2026
- Distance Sales AgreementOctober 10, 2026
- Refund and Delivery PolicyOctober 10, 2026
- Partner (Sales Brokerage) AgreementOctober 11, 2026
- Partner Privacy NoticeOctober 10, 2026
- Account and Data DeletionOctober 11, 2026
Company information
Planfly is a product developed and operated by Mobiza Teknoloji.
- Title
- Mobiza Teknoloji
- Address
- Ovaakça Santral Mah. Ovaakça Fatih Sultan Mehmet Cad. No: 86, 16335 Osmangazi, Bursa, Türkiye
- Tax office (vergi dairesi)
- Uludağ Tax Office
- Tax ID
- 1280527561
- DUNS number
- 751143161
- Corporate website
- mobiza.com.tr