rando

Privacy Policy — English summary

Effective date: 5 September 2026 · Last updated: 5 September 2026
Published at: https://rando.vu/gizlilik-en

This is a courtesy summary of the Turkish original. In case of any conflict, the Turkish text prevails: Gizlilik Politikası.

1. Who we are

Rando is an appointment-management app for small businesses. The app is used by the business owner and their staff; the business stores its own customer records in it.

We carry the whole operational burden for customer data — the business is not asked to do anything about it:

Whose dataControllerOur role
Business owner and staff (login phone number, session, device id, usage events) Us — Melih Ünal Data controller
The business's own customers (name, phone, appointments, notes, tickets) Us, jointly with the business Joint controller. Requests, erasure, security, breach notification, retention and deletion are all handled by us

If you are a customer of a business using Rando: contact us directly at melihunal79@gmail.com · Rumelihisarı Mah. 5. Sokak No: 29 Daire: 2, 34470 Sarıyer / İstanbul. You do not need to contact the business as well; we accept and answer requests on the business's behalf too.

For customer data we are a joint controller together with the business and we take on performance of the obligations: we answer Article 11 requests within thirty days free of charge, we carry out erasure, we implement the security measures under Article 12, we make breach notifications, and we apply the retention and deletion periods. This text does not claim that we are the sole controller — Turkish law assigns that status on the facts, and the business collects the customer's number itself. KVKK Article 3(1)(ı) defines the controller as the party that determines the purposes and means of processing personal data and is responsible for the establishment and management of the data filing system.

Developer named in the Google Play store listing: Melih Ünal · App: Rando · Privacy contact: melihunal79@gmail.com · Address: Rumelihisarı Mah. 5. Sokak No: 29 Daire: 2, 34470 Sarıyer / İstanbul · Web: https://rando.vu

2. Data we collect

As controller (owner and staff): phone number (used as the login identity), one-time login code (only a hash is stored, valid for 3 minutes), recovery code (hash only), session token (30 days, stored in the device's encrypted storage), an app-generated random device identifier, name and role, and server-side product-usage events.

Usage events never contain a raw phone number, a name, a message body or free text. A person is represented by an irreversible, per-business code.

As joint controller (the business's customers): customer name, phone number, birthday, free-text note, marketing consent flag, appointment history, and ticket / cash-register / commission records. No card or bank details are processed.

Voice: captured only while you hold the assistant's microphone button; see section 5.

3. What we never collect

Location/GPS, camera, photo gallery, contacts, SMS content, call logs, advertising ID (AAID). The app contains no advertising network, no analytics SDK, no crash reporting SDK and no third-party trackers. It requests only two permissions: Internet and Microphone (microphone only for the voice assistant, asked at first use). No SMS-reading permission is requested — login codes are typed in manually.

4. Who we share data with

PartyWhat is sentWhyWhere
Hosting provider (DigitalOcean)All stored data resides on the server Running the serviceFrankfurt, Germany
SMS provider (İletiMerkezi)Recipient's phone number and the message text Delivering login codes and appointment messages Türkiye
AI provider (via OpenRouter)See section 5 Understanding and answering assistant questions USA
The device's speech-recognition serviceYour voice (section 5) Converting speech to textDetermined by the device / OS vendor
Competent public authoritiesRequested data Where required by lawTürkiye

We do not sell personal data and do not use it for advertising.

5. Voice assistant and AI

Your speech is transcribed by the device's own speech-recognition service. No audio is sent to our servers and no audio is stored by us or sent to the AI provider. However, Android's own documentation states that this API "is likely to stream audio to remote servers to perform speech recognition" — in that case the audio is governed by the device/OS vendor's privacy policy, not ours. If you deny the microphone permission, the assistant still works in text mode.

Sent to the AI provider: your typed (or transcribed) sentence; the business name, branch names, service list, staff names and your role; and, if your question concerns a customer, that customer's name, masked phone number, visit counts, first/last visit dates, favourite service, no-show count and a summary of recent appointments; money figures only if your role is allowed to see them.

Never sent: any raw phone number, the text of a customer note (the assistant only learns that a note exists), passwords, login codes, session tokens or provider keys.

Chat text is not written to persistent storage or to the event log. The assistant cannot change data on its own: every write requires an explicit on-screen confirmation.

6. Security

HTTPS for all traffic; login and recovery codes stored only as hashes; session token and device id kept in the device's encrypted storage; secrets, phone numbers and message bodies never written to logs; strict per-business data isolation (including the event log's person code); role-based access (staff cannot see revenue or commission, in the UI or via the assistant); temporary lockout after repeated failed logins. Backup frequency, location and encryption: daily automatic backups; kept on the same server in a directory accessible only to the server administrator; backups older than 14 days are deleted

7. Retention and deletion

Login code hash: 3 minutes. Session token: 30 days. Account and business data: until the account is deleted. Event log: 24 months. Backups: 14 days.

Delete your account in the app: Data screen → "Hesabı sil" (Delete account), with a two-step confirmation listing what will be deleted.

Delete without installing the app: https://rando.vu/hesap-silme.

Today no separate set of data is retained for security, fraud prevention or legal compliance. Copies inside backups taken before the deletion fall away when the backup retention period ends.

If a business deletes its account, its customers' records are deleted with it. Customers do not have to wait for that: a customer may ask us directly to delete their data (melihunal79@gmail.com or https://rando.vu/hesap-silme). We handle the request ourselves and tell the customer the outcome; we do not send them back to the business.

8. Your rights

This section applies to everyone — business owners and staff who use the app, and customers who book an appointment with a business using it. Because we are a joint controller for customer data (§1), customers may exercise all of these rights directly against us; contacting the business as well is not required.

Under Turkish Law No. 6698 (KVKK) Article 11 you may ask whether your data is processed, request information about the processing and its purpose, learn the third parties the data is transferred to in Türkiye or abroad, request correction or erasure, request that corrections be notified to those third parties, object to decisions produced solely by automated analysis, and claim compensation for damage caused by unlawful processing.

Requests are answered free of charge within 30 days at the latest. Submit them in writing to Rumelihisarı Mah. 5. Sokak No: 29 Daire: 2, 34470 Sarıyer / İstanbul, via registered electronic mail (KEP) none, with a secure or mobile electronic signature, or from the e-mail address already registered with us to melihunal79@gmail.com.

9. International transfers

Our server is in Germany, and the AI provider may be outside Türkiye. Under KVKK Article 9 (as amended by Law No. 7499) this is an international transfer. The Turkish DPA has not issued an adequacy decision for any country to date, so the transfer must rest on an appropriate safeguard — for example the Board's standard contractual clauses, which must be notified to the Authority within five business days of signature.

Safeguard relied on for this transfer: the standard contract published by the Turkish Personal Data Protection Board under Article 9 of the KVKK; the contract and the notification to the Authority are in preparation

10. Children

The app is intended for business owners and staff aged 18 and over. It is not directed at children and does not knowingly collect children's data.

11. Changes and contact

We update the "last updated" date above whenever this policy changes. Material changes are additionally announced via an in-app notice.

Developer / controller: Melih Ünal · E-mail: melihunal79@gmail.com · Address: Rumelihisarı Mah. 5. Sokak No: 29 Daire: 2, 34470 Sarıyer / İstanbul · Web: https://rando.vu · Account deletion: https://rando.vu/hesap-silme

© 2026 Rando