PRIVACY POLICY
Last updated: April 2026
This Privacy Policy explains how personal data of individuals using the TrainProCoach mobile application ("App") is collected, processed, stored, and protected. Our company, acting as the data controller under the Law on Protection of Personal Data No. 6698 ("KVKK"), processes your personal data for the purposes and methods specified in this policy.
11. DATA CONTROLLER
22. COLLECTED PERSONAL DATA
👤2.1 Identity and Contact Information
- •Name, surname, username
- •E-mail address, phone number
- •Google or Apple account information used for login (for authentication purposes only)
⚖️2.2 Physical and Health Information
- •Age, gender, height, weight, goals
- •Health issues, disability status, hormonal problems, harmful habits
- •Training, nutrition, and cardio program results
- •Progress photos
💳2.3 Payment Information
- •First and last name, billing address, tax information
- •Card information (card number, expiration date, CVV) — this information is transmitted only to the Iyzico infrastructure during the payment process and is not stored on our servers
- •Package purchased and transaction history
💻2.4 Usage and Technical Data
- •IP address, device type, operating system
- •In-app messaging content
- •Firebase Cloud Messaging (FCM) token (for sending push notifications)
- •Offline mode usage data (temporarily stored on the device)
33. PURPOSES AND LEGAL BASIS FOR DATA PROCESSING
- Account creation and authentication — Performance of the contract
- Providing personalized training and nutrition programs — Performance of the contract
- Trainer-user matching — Performance of the contract
- Execution of payment transactions — Performance of the contract / Legal obligation
- Progress tracking and photo archive — Explicit consent
- Sending push notifications — Explicit consent
- Application security and error detection — Legitimate interest
- Fulfillment of legal obligations — Legal obligation
44. THIRD PARTIES WITH WHOM DATA IS SHARED
Your personal data is shared with the following parties only for the specified purposes.
Iyzico Payment Services Inc.
Card and billing information are transmitted for the purpose of executing payment transactions. Iyzico is a PCI-DSS certified payment infrastructure.
Google LLC (Firebase)
Used for push notification delivery (FCM) and application analytical data. You can access Google's privacy policy at firebase.google.com.
Google LLC (Google Sign-In)
Used for optional Google account login option. Identity information is obtained only for authentication purposes.
Apple Inc. (Sign in with Apple)
Used for optional Apple account login option. Apple transmits only the minimum necessary identity information.
CDN / File Storage Service
Progress photos and uploaded files are stored over an encrypted connection.
Trainers
The trainer selected by the user by purchasing a package can access relevant profile and program data to prepare training, nutrition, or cardio programs. This access is limited only to the duration of the service relationship.
Your data is not sold, rented, or shared for commercial purposes with third parties other than those listed above.
55. DATA RETENTION PERIOD
- Account and profile information — Until the account is deleted
- Program results and progress data — Until the account is deleted
- Payment and transaction records — 10 years due to legal obligation
- Messaging content — Until the account is deleted
- FCM token — Until it becomes invalid or the account is deleted
- Offline queue data — On the device, until synchronization is complete
If you delete your account, all your data for which there is no legal storage obligation will be permanently deleted within 30 days.
66. YOUR RIGHTS UNDER KVKK
Pursuant to Article 11 of Law No. 6698, you have the following rights:
- To learn whether your personal data is processed
- To request information if it has been processed
- To learn the purpose of processing and whether it is used in accordance with its purpose
- To know the third parties to whom it is transferred at home or abroad
- To request correction if it is incomplete or incorrectly processed
- To request its deletion or destruction within the framework of the conditions provided for in the Law
- To object to the occurrence of a result against you by analyzing the processed data exclusively through automated systems
- To request compensation for damages in case of loss due to unlawful processing
To exercise your rights, you can send an e-mail to fithubapps@gmail.com or make a request from the Support section within the application. Requests are responded to within 30 days.
77. DATA SECURITY
Your personal data is protected by the following technical and administrative measures:
- 🔒All data communication is carried out with HTTPS/TLS encryption
- 🔒Passwords are stored with a one-way (hash) algorithm
- 🔒Access rights are organized according to the principle of least privilege
- 🔒Session management is provided by the access token and refresh token mechanism; tokens are kept in a timed and encrypted form
- 🔒Payment information is not stored on our servers, it is transmitted directly to the PCI-DSS compliant Iyzico infrastructure