Data Controller
In accordance with KVKK, the data controller responsible for the processing of your personal data is Rankora. As data controller, Rankora determines the purposes and means of processing personal data collected through the website and services.
| Company Name | Rankora |
| Website | https://reviewshield.app |
| kvkk@reviewshield.app |
Purposes of Processing Personal Data
Your personal data may be processed for the following purposes:
Service Delivery
To create and manage your account, provide subscription services, and deliver the features you request.
Google Reviews Management
To connect your Google Business Profile, import reviews, and generate AI-powered responses on your behalf.
Billing & Payments
To process subscription payments, issue invoices, and manage billing information in compliance with financial regulations.
Customer Support
To respond to your support requests, resolve issues, and improve the quality of our services.
Security & Fraud Prevention
To detect and prevent unauthorized access, fraud, and other security threats to our platform.
Legal Obligations
To fulfill our obligations under applicable laws including tax legislation, e-commerce regulations, and data protection law.
Analytics & Service Improvement
To analyze usage patterns and improve the performance, functionality, and user experience of our platform.
Marketing Communications
To send product updates, newsletters, and promotional communications where you have given your consent.
Legal Basis & Collection Methods
Your personal data is collected through the following methods and processed on the legal bases listed below in accordance with KVKK Articles 5 and 6:
Collection Methods
Digital Channels
Via our website, web application, API integrations, and email communications.
Third-Party Integrations
Through Google OAuth when you connect your Google Business Profile account.
Cookies & Tracking Technologies
Through cookies and similar technologies as described in our Cookie Policy.
Legal Bases (KVKK Art. 5)
| Legal Basis | Application |
|---|---|
| Explicit Consent | For marketing communications and non-essential cookies (KVKK Art. 5/1). |
| Contractual Necessity | For service delivery and account management as required to perform our contract with you (KVKK Art. 5/2-c). |
| Legal Obligation | For tax records, invoicing, and compliance with applicable legislation (KVKK Art. 5/2-ç). |
| Legitimate Interest | For security, fraud prevention, and anonymous analytics where your rights are not overridden (KVKK Art. 5/2-f). |
Categories of Personal Data Processed
The following categories of personal data may be processed depending on your use of our services:
| Category | Examples |
|---|---|
| Identity Identity Data | Name, surname, username |
| Contact Contact Data | E-mail address, phone number (if provided) |
| Account Account & Authentication Data | Password (hashed), OAuth tokens, session identifiers |
| Business Business Data | Company name, Google Business Profile ID, review content |
| Billing Billing Data | Billing address, tax ID, payment method token (via Stripe — card details are never stored by us) |
| Technical Usage & Log Data | IP address, browser type, pages visited, feature usage |
| Communication Communication Data | Support tickets, email correspondence |
Transfer of Personal Data to Third Parties
Your personal data may be shared with the following third parties solely for the purposes described in this text, under data processing agreements and with appropriate safeguards:
| Recipient | Purpose | Location |
|---|---|---|
| Stripe | Payment processing and billing management | United States (SCCs applied) |
| Google LLC | Google Business Profile integration and OAuth authentication | United States (SCCs applied) |
| Vercel | Cloud infrastructure and application hosting | United States / EU (data residency options) |
| Neon / PostgreSQL | Database hosting for application data | EU Region |
| OpenAI | AI-generated review response suggestions | United States (SCCs applied) |
| Resend | Transactional and marketing email delivery | United States (SCCs applied) |
Personal data may be transferred to public authorities or judicial bodies where required by law. Cross-border transfers are carried out in accordance with KVKK Article 9 using Standard Contractual Clauses (SCCs) or adequacy decisions where applicable.
Retention Periods
Personal data is retained only as long as necessary for the purpose for which it was collected, or as required by applicable law:
| Data Category | Retention Period |
|---|---|
| Account Data | Duration of account + 3 years after account deletion |
| Billing & Invoice Data | 10 years (Turkish Tax Procedure Law) |
| Usage & Log Data | Up to 2 years |
| Support Communications | 3 years after ticket closure |
| Marketing Consent Records | 3 years after consent withdrawal |
| Google Review Data | Duration of service subscription |
At the end of the applicable retention period, personal data is securely deleted, anonymized, or destroyed in accordance with KVKK regulations and the Data Destruction Regulation.
Rights of Data Subjects (KVKK Article 11)
As a data subject under KVKK, you have the following rights regarding your personal data:
Right to be Informed
To learn whether your personal data is being processed.
Right of Access
To request information about the processing of your personal data.
Right to Rectification
To request correction of incomplete or inaccurate personal data.
Right to Erasure
To request deletion or destruction of your personal data where processing is no longer necessary.
Right to Notification
To request that corrections or deletions be notified to third parties to whom data was transferred.
Right to Object to Automated Decisions
To object to decisions made solely through automated processing that produce legal or similarly significant effects.
Right to Object to Processing
To object to the processing of your personal data in cases where processing is based on legitimate interest.
Right to Compensation
To request compensation for damages arising from unlawful processing of your personal data.
How to Exercise Your Rights
To exercise any of the rights listed above, you may submit a request to us using the contact details below. We will respond to your request within 30 days in accordance with KVKK. There is no fee for submitting a request; however, if the request requires additional cost, we may charge a fee in line with the tariff set by the Personal Data Protection Board.
Send your signed request to kvkk@reviewshield.app
kvkk@reviewshield.app
Online Application
Use our secure data subject request form available in your account settings.
Account Settings → Privacy → Submit KVKK Request
When submitting a request, please include your full name, contact information, the right you wish to exercise, and a copy of your identity document (required under the KVKK Application Communiqué).