taht.app

Privacy notice

We collect the minimum data needed to sell and operate the board. We do not use third-party advertising analytics and we never sell personal data.

Last updated: 21 August 2026

CONTROLLER

taht.appOwner: Harun Tekdal · Hannover, Almanya · hi@creativefactory.tr

DATA WE PROCESS

When you bid: name, email, submitted URL and listing copy, bid amount, and payment records. Card details are handled by Stripe Payments Europe, Ltd. and never reach TAHT.

When you visit: a random browser identifier, first and last seen times, and page-view count. Raw IP addresses are not stored with visitor records.

When a listing is clicked: listing and timestamp, without attaching the click to an identity. IP addresses may be processed briefly for security and rate limiting.

WHY WE PROCESS IT

  • To form and perform the placement contract.
  • To meet accounting, tax, and legal duties.
  • To prevent fraud and abuse and keep the service secure.
  • To measure aggregate visitors and genuine listing clicks.

SERVICE PROVIDERS

Data is shared only as needed with Stripe Payments Europe, Ltd. for payments, Cloudflare for hosting and CDN, Hetzner for database hosting, and Resend when email notices are enabled. These providers may process data outside Türkiye. Authorities receive data only where lawfully required.

RETENTION

  • Payment and invoice records: 10 years where required by financial law.
  • Listing records: while the listing is live; refunded or removed bids leave the board.
  • Visitor identifiers and click records: up to 24 months.
  • Rate-limit records: a few hours.

COOKIES AND STORAGE

There are no advertising cookies and no Google Analytics-style tracker. A random browser identifier in local storage prevents counting the same visitor repeatedly; clearing browser data removes it.

YOUR RIGHTS

You may ask what we hold, request correction or deletion where applicable, object to processing, and ask whom data was shared with. Send requests through Contact; we respond within 30 days and may verify your identity.

SECURITY

  • Site and API traffic is encrypted with TLS.
  • The database is not exposed on a public port.
  • Card data never enters our systems.
  • The admin area requires authentication.