Join do Privacy Policy
Last updated: 4 October 2026 Effective date: 3 October 2026
1. Data Controller and Contact
This Privacy Policy is issued by Join do Application Yazılım ve Sanayi Limited Şirketi ("Join do", "Company", "we", "us", "our") to inform you about how we collect, use, store and protect personal data through the Join do mobile application (the "App") and the website at joindo.app (the "Website", together the "Platform").
Company information:
- Legal name: Join do Application Yazılım ve Sanayi Limited Şirketi
- Address: Organize Sanayi Bölgesi Mevkii, 2. Cad. No: 4/2040, Tüney Köyü, Merkez/ÇANKIRI, Türkiye
- Trade registry (Mersis): 0484224355100001
- Tax number: 4842243551
- Data protection contact: support@joindo.app
- Registered electronic mail (KEP): joindoapplicationyazilim@hs01.kep.tr
Join do acts as a data controller under Turkish Law on the Protection of Personal Data No. 6698 ("KVKK") and as a controller under the EU/UK General Data Protection Regulation ("GDPR") for users in the European Economic Area and the United Kingdom.
2. Personal Data We Collect
When you use the Platform, we process the following categories of personal data:
2.1 Data you provide directly
- Account data: email address, username, first and last name, profile picture, optional gallery images
- Profile data: date of birth, gender, height and weight (see Section 2.5), biography, language preference, favourite sports, sport skill levels, availability schedule
- Sign-up survey: your optional answer to how you heard about Join do
- Location data: precise device location (with your permission)
- Communication content: direct messages, event and group chat messages and the content you share in chats (photos from your camera or gallery, voice messages, GIFs and stickers, polls and votes, message reactions and replies, a place you pick on the map and share, group and event cards), the optional message you add to a friend request (up to 200 characters), event and group descriptions
- Voice messages: the audio you record in a chat (up to 2 minutes) and a waveform summary shown in the player. The microphone is used only while you press the record button; if you do not grant microphone permission you cannot send voice messages, and no other feature is affected.
- Your own stickers: photos from your gallery that you turn into stickers
- Match (Play) preferences: the sport, level and time preferences you choose and your responses to matches (accept / skip)
- Highlight (DoStatus) posts: text and an optional photo; the reactions (like or emoji) you give to other users' posts
- Reviews and reports: the partner review you give after an event, match or friendship (good / bad / no-show / didn't play, plus an optional reason) and the reports you file
- Support requests: messages you send to support@joindo.app
2.2 Data we collect automatically
- Usage data: feature usage counters (
daily_feature_usage_limits), last seen timestamp, online status, profiles you visit, Highlight posts you view - Device data: device type, operating system version, app version, locale, the device's light/dark appearance setting (iOS only, for analytics), Firebase App Check device integrity token (Google Play Integrity on Android, Apple App Attest / DeviceCheck on iOS)
- Connection data: IP address (kept transiently in Redis cache for security and rate-limiting purposes only; not retained in persistent logs)
- Push notification ID: device token issued by Firebase Cloud Messaging (FCM) for your device; in older versions of the app, the OneSignal subscriber ID
- Product metrics: key usage events linked to your account, used to improve the service (sign-up, profile completion, creating or joining an event or group, friend requests, Premium purchase), and a record of the days on which you use the app; message content is never included in these records
- Data kept only on your device: session data, app preferences and the list of your own stickers are stored on your device; deleting the app also deletes this list (for the sticker images themselves, see Section 6)
2.3 Data from third parties
- Authentication provider data: limited profile data (email, name, user identifier) from Apple Sign In or Google Sign In when you sign in with those providers
- Subscription data: subscription status and purchase history from RevenueCat
2.4 Data we do NOT collect
Join do does not collect:
- Advertising identifiers (IDFA / GAID) — Join do does not currently show advertisements
- Cross-app or cross-website tracking data — on iOS, Apple's App Tracking Transparency prompt may be shown, but even if you allow it your advertising identifier is not read or passed to any service, and we do not track you across other companies' apps or websites
- Device contacts — the feature has not been activated
- Biometric data, religious beliefs, sexual orientation, political opinions or similar special category personal data (the only exception is height and weight, which may qualify as health data; see Section 2.5)
2.5 Height and weight
Because height and weight may qualify as special category data concerning health under KVKK Article 6 and GDPR Article 9, we handle them with extra care:
- When they are requested: Entering your height (cm) and weight (kg) is mandatory when you create your profile. Existing accounts without these values complete them on the Edit Profile screen before they can continue using the app. You can change the values at any time in Edit Profile.
- Purpose: to show them on your profile (as long as you keep them visible) and to let Premium users search by height and weight range in the Partner filter. They are not used for Match or "For You" suggestions, advertising, marketing or analytics, and are not passed to any third party.
- Legal basis: your explicit consent. Because height and weight are mandatory for a profile, if you wish to withdraw your consent you can delete your account or contact support@joindo.app.
- Visibility: Visible on your profile by default. When you turn off Account Settings → Show Height and Weight, your height and weight are no longer sent to other users or shown on your profile.
- Protection in filters: The Premium height/weight filter does not exclude users who hide or have not entered these values, so a hidden value cannot be inferred from filter results.
- Access and retention: Stored on our servers; within Join do, only authorised personnel can access them for support and moderation. Kept while your account is active and deleted when your account is permanently deleted.
3. Purposes of Processing
| Purpose | Data processed | Legal basis |
|---|---|---|
| Account creation and authentication | Email, name, date of birth, authentication-provider data | Performance of the contract |
| Height and weight on your profile and the Premium height/weight filter | Height, weight, visibility preference | Explicit consent (see Section 2.5) |
| Discovery of nearby users and events (Around, Join; list and map) | Precise location, favourite sports, gender, language | Performance of the contract |
| Activity check-in (proximity verification within 100 m of the venue) | Precise location at check-in time | Performance of the contract |
| Messaging (text, photos, voice messages, GIFs and stickers, polls, reactions, replies, place and card sharing), matching, social interaction | Profile data, message and media content, interaction history | Performance of the contract |
| GIF and sticker search in chats (GIPHY) | Search text and app language; your device's IP address and technical information reach GIPHY directly | Performance of the contract (you choose to use the feature) |
| Content moderation (NSFW analysis, reporting, manual review) | Uploaded images, reported content and conversation context | Legitimate interest (platform safety) |
| App and device integrity verification (Firebase App Check) | Device integrity token | Legitimate interest (platform safety) |
| Push notifications | FCM device token (OneSignal subscriber ID in older versions), language preference | Consent (notification permission) |
| Reminder and suggestion notifications (common ground with a profile you viewed, weekly profile-visitor summary, a reminder when you have not opened the app for a while) | Profile visit records, last active time, notification preferences | Legitimate interest; can be turned off in notification settings |
| Subscription and billing | RevenueCat purchase records | Performance of contract; legal obligation |
| Premium offer and campaign notifications | Subscription status, discount eligibility, language, usage segment | Legitimate interest; can be turned off with the "Premium offers" option in notification settings. No marketing emails are currently sent; if they are, your explicit consent will be obtained separately |
| Location-based sport partner matching (Match / Play), mutual acceptance and match history | Precise location, favourite sports, skill level and time preferences, match responses | Performance of the contract |
| "For You" profile suggestions | Location (up to 40 km), favourite sports, available days and times, gender (used only to balance the gender mix of each set of suggestions); users previously suggested, visited, already friends or blocked are excluded | Performance of the contract |
| Common ground and shared sports history on profiles | Date the friendship started, past events attended together and their sports, number of different people you have played sports with | Performance of the contract |
| Profile visitors | Visit record (visitor, visited user, time) | Performance of the contract |
| Highlight views and reactions | Viewing user, reaction given | Performance of the contract |
| Partner reviews between users and the trusted-partner badge | Review answer and optional reason, reviewer and reviewed user IDs | Legitimate interest (community trust) |
| Sign-up survey | "How did you hear about us" answer | Legitimate interest (measuring how the service is discovered) |
| Abuse prevention, rate-limiting, fraud detection | IP, user-action counters | Legitimate interest |
| Analytics (Firebase Analytics) and product metrics | Anonymous usage events, session data, the device's light/dark appearance setting; key usage events linked to your account (see Section 2.2) | Legitimate interest |
| Legal obligations and lawful authority requests | Data within the scope of the request | Legal obligation |
4. Protection of Your Location Data
Location is the most sensitive data category Join do handles, and we apply specific safeguards:
- Display on the Partner (Around) screen: In the list and on profiles, other users see your approximate distance (in kilometres; under 1 km is shown as "< 1 km") and your city. On the map your real location is not shown: your marker is pseudo-randomly displaced within an approximately 1 km radius of your real location (jitter). The displacement is fixed for you, so your real location cannot be narrowed down by looking at the map repeatedly.
- Search radius and changing location: The Partner map and "For You" suggestions cover users within a radius of about 40 km. When you pick another area with "Change Location", the Partner search runs in that area; the area you pick does not change the location stored on your profile.
- Sharing a place in chat: A place you pick on the map and send to a chat is shown only to the participants of that chat. Join do does not offer live location sharing.
- Activity check-in: When you confirm attendance at an event, you must be located within 100 metres of the event coordinate. This check is performed only at the moment of check-in; your location is not continuously tracked outside this moment.
- Permission control: You can revoke location permission at any time via your device settings; this limits location-based features such as Partner, Join, Match, "For You" and check-in.
5. Recipients of Your Data
5.1 What other users can see
Join do is a social platform; by its nature, the following information is shown to other users:
- Your profile: name, age, profile photos, biography, favourite sports and levels, availability, city and approximate distance (your exact location is never shown, see Section 4), height and weight (unless you hide them in Account Settings, see Section 2.5), a Premium badge if you are a Premium member, and the number of different people you have played sports with ("Played with N people").
- Online status and last active: other users may see when you are "Online" and when you were last active (e.g. "active 2 hours ago"); you can turn off the online indicator in Account Settings.
- Your chats: messages, photos, voice messages, GIFs and stickers, poll votes and reactions you send are shown to the participants of that chat; when you react to a message, your name and profile photo appear with the reaction. The sender sees a "seen" indicator once you have viewed their messages.
- Shared sports history: when you view a friend's profile, how long you have been friends and the number and sports of past events you attended together are shown only to the two of you.
- Match (Play): when a match is found, the other person sees your profile and the sport you chose; if you both accept, you become friends and a one-to-one chat opens.
- Your profile visits: when you visit a profile, the visit is recorded and the visited user may receive a notification. Premium users see everyone who visited them. Free users see visits from friends and the first visit from a non-friend each day openly; other visits are shown hidden.
- Your Highlight interactions: when you view or react to a Highlight post, its owner can see you and your reaction.
- Your friend request message: shown to the user you send the request to.
- Partner reviews: your identity is not shown to the person you review; users who reach enough positive reviews may get a "Good Sport" badge on their profile.
5.2 Service providers and authorities
We share personal data only with the following categories of recipients and only to the extent necessary to operate the service:
| Recipient | Service | Location | Legal basis for transfer |
|---|---|---|---|
| Google Firebase (Authentication, Realtime Database, App Check, Analytics, Cloud Messaging) | Authentication, chat, app integrity, analytics, push notifications | Realtime Database: europe-west1 (EU); other services: Google's global infrastructure (including the United States) | Appropriate safeguards / SCCs |
| OneSignal | Only for users of older versions of the app, push notification delivery during the transition period (user ID, subscriber ID and email address; username, city, gender and age as targeting tags). The current version does not send any data to OneSignal | United States | Standard Contractual Clauses (SCCs) |
| Uploadcare | Upload and CDN delivery of photos and audio files (profile and gallery photos, Highlight and chat photos, voice messages, your own stickers) | EU / United States | SCCs |
| Amazon Web Services (Rekognition) | Automated image moderation, provided through Uploadcare, applied only to images flagged by our own filter | United States | Standard Contractual Clauses (SCCs) |
| Strato (Germany) | Auxiliary image hosting | Germany | Adequacy decision |
| RevenueCat | Subscription verification and management (user ID, email, name, where the purchase screen was opened from) | United States | SCCs |
| GIPHY | GIF and sticker search and display in chats. Your search text and app language are sent directly to GIPHY together with your device's IP address and technical information; GIFs in chats are loaded onto recipients' devices from GIPHY's servers. Your account data is not sent to GIPHY | United States | You choose to use the feature; GIPHY's own privacy policy applies |
| Apple Maps / Google Maps and Google Maps Platform | Map display (Apple on iOS, Google on Android); for address search, address lookup and elevation, our server sends Google only coordinates or search text, never your identity | United States / global | SCCs; Apple's and Google's own privacy policies |
| Expo (650 Industries) | Delivery of app updates (IP address, platform and app version when checking for updates) | United States | SCCs |
| Apple App Store / Google Play | App distribution and payment processing | EU / United States | Apple's and Google's own privacy policies |
| Public authorities | Legal request, court order | Turkey or requesting jurisdiction | Legal obligation |
Join do does not sell or share personal data with advertisers. Join do does not currently use any third-party advertising network. If this changes, this Policy will be amended and separate explicit consent will be obtained.
6. Retention Periods
| Data category | Retention |
|---|---|
| Profile data (email, name, photo, location etc.) | For the duration the account is active |
| Height and weight | For as long as the account is active; deleted when the account is permanently deleted |
| One-to-one chat messages (Firebase Realtime Database) | For as long as the chat exists; you can delete your own messages at any time (a note that the message was deleted remains in its place) |
| Friend (Do) request records and the message added to the request | Automatically deleted after 90 days |
| Activity group chat (Firebase Realtime Database) | Until the activity is deleted |
| Highlight (DoStatus) posts | Removed from discovery feeds 24 hours after publication; the text and post record remain in the owner's archive ("Highlights") until deleted by the user or upon account deletion |
| Highlight photos | Automatically deleted from our servers 24 hours after publication; reported photos are kept for up to 7 more days for review. In the archive, the photo is shown only from the copy stored on your own device |
| Highlight views and reactions | Until the related post or the account is deleted |
| Photos and voice messages shared in chats | Automatically deleted from our servers 3 days after sending; a note remains in the chat in place of the message |
| Your own stickers | The sticker image is uploaded to our servers (Uploadcare) so it can be sent in chats and is not deleted automatically; your sticker list is kept only on your device. You can request deletion of the image via support@joindo.app |
| GIPHY GIFs and stickers | Only the GIPHY link is stored in the chat; Join do does not store your GIF and sticker searches |
| In-app notifications | Automatically deleted after 90 days; profile-visit notifications are kept for as long as the account is active to power the Profile Visitors list |
| Profile visit records | For as long as the account is active |
| Group membership and group chat data | Retained for the duration of group membership; removed when the user leaves the group or the group is deleted |
| Match (Play) requests and matches | A search request stays open for up to 1 week; both sides have 48 hours to accept a match. Match history shows pending and unsuccessful matches from the last 30 days; records are kept for as long as the account is active |
| Partner reviews and report records | Retained for as long as the account is active |
| Product metric records | Usage events are deleted automatically after 180 days, the record of days you used the app after 400 days |
| Account deletion grace period | 7 days (during which the user may sign in again to restore the account) |
| After 7-day grace expires | Personal data linked to your account is irreversibly deleted; no archival copy is retained. One-to-one chats and their messages are deleted; messages you sent in group and event chats may remain in those chats' history (see Section 14); product metric records may remain, no longer linkable to you, until the periods above expire |
| Financial / subscription records subject to legal retention | Retained for the period mandated by Turkish Commercial Code and tax legislation (up to 10 years), limited to financial records only |
| IP address (rate-limiting) | Transient (Redis TTL — seconds to minutes); no persistent log |
7. Your Rights under KVKK and GDPR
Pursuant to KVKK Article 11 and GDPR Articles 15–22, you have the following rights:
- To learn whether personal data concerning you is being processed;
- To request information about the processing of your data;
- To learn the purposes of processing and whether the data is used in line with those purposes;
- To know the third parties (in Turkey or abroad) to whom your data has been disclosed;
- To request the correction of incomplete or inaccurate data;
- To request the deletion or destruction of your data ("right to be forgotten");
- To request that correction, deletion and destruction be communicated to third parties to whom data has been transferred;
- To object to a decision concerning you made solely on the basis of automated processing;
- To request compensation for damage resulting from unlawful processing.
Additional rights under GDPR: data portability, the right to restrict processing, the right to withdraw consent, and the right to lodge a complaint with a supervisory authority.
How to exercise your rights: Send a request to support@joindo.app together with information that allows us to verify your identity. We will respond within 30 days. Written requests may also be submitted to our KEP address.
8. CCPA / CPRA — California Residents
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), California residents have the right to:
- Know what categories of personal information are collected;
- Request deletion of certain personal information;
- Opt out of the sale or sharing of personal information ("Do Not Sell or Share My Personal Information").
Join do does not sell personal information. Marketing communications are sent only with explicit consent. To exercise your rights, contact support@joindo.app.
9. Security Measures
- TLS encryption in transit
- Firebase App Check for app and device integrity verification (Google Play Integrity on Android, Apple App Attest / DeviceCheck on iOS); on devices that fail this check, features such as sign-in and chat may not work
- IP- and user-based rate limiting
- Automated content moderation (server-side NSFW analysis, message risk scoring)
- Access control and role-based admin authorisation with audit logging
- Regular security updates
10. Children's Privacy
Join do is not intended for use by individuals under the age of 18. You must declare that you are 18 or older when registering. If we discover an account belonging to a person under 18, the account will be suspended and the data deleted promptly. If you believe a child has provided personal data to us, please contact support@joindo.app.
11. Automated Decision-Making and Profiling
Join do does not make decisions concerning you that are based solely on automated processing within the meaning of GDPR Article 22. The ranking applied on the Around feed (distance, recency, engagement, common sports, skill match, gender/city balance) only affects display order; it does not hide a user from the platform or restrict service access.
The gender/city balancing on the Around feed is applied to provide a diverse profile mix in the feed; it is not used to disadvantage individual users.
"For You" suggestions and Match (Play) pairing are also prepared automatically: they decide who is suggested based on proximity, shared sports and availability. Age is not used for For You suggestions; gender is used only to balance the gender mix of each set of suggestions. A match found in Match is not completed without mutual acceptance: unless both sides accept, no friendship is created and no chat opens. These suggestions only affect which profiles are shown to you; they do not restrict any user's access to the service.
The Premium height/weight filter does not exclude users who hide or have not entered these values (see Section 2.5).
The "Good Sport" badge may be shown automatically once the number of positive reviews from other users reaches a set threshold; not having the badge does not restrict use of the service.
12. Content Moderation and Administrative Access
- Visual content: All uploaded images, including chat photos and your own stickers, are passed through automated NSFW (adult content) classification on our servers at upload time. Analysis results are not stored; images flagged as inappropriate are rejected. Images flagged by this filter may additionally be re-verified by Amazon Rekognition's moderation service (provided through Uploadcare); only the flagged image is processed for this check, and the result is not retained.
- Highlight photos: A reported Highlight photo is kept for up to 7 days so authorised personnel can review it, and is then deleted.
- Partner reviews: When a review reports harassment or non-sport intent, a report is created automatically and reviewed by authorised personnel.
- Voice messages and GIFs: Voice messages are not analysed automatically; if reported, they may be reviewed by authorised personnel. GIFs and stickers from GIPHY are filtered by GIPHY's content rating (up to PG-13).
- Chat reports: When you report a user, authorised Join do personnel may access content only within the context of the conversation related to the report. Personnel cannot read random user conversations.
- Administrative actions: All administrative actions (suspension, ban etc.) are recorded in audit logs and may be disclosed to the affected user upon request.
13. Cookies
The mobile app does not use cookies.
Our website uses only essential cookies (session, language, theme preference). There are currently no analytics or marketing cookies. See our Cookie Policy for details.
14. Account Deletion
You can delete your account at any time from Profile → Settings → Account Settings → Freeze / Delete My Account in the app. The flow is:
- Soft delete: Your account is hidden from other users immediately; upcoming events you created are cancelled and you are removed from upcoming events you joined.
- 7-day grace period: If you sign in again within 7 days, your account is automatically restored.
- Permanent deletion (day 8): Personal data linked to your account (including height and weight) is irreversibly deleted from our systems; no archival copy is retained. This includes your photos, your one-to-one chats and their messages, your Match records and partner reviews. Messages you sent in group and event chats remain because they are part of those chats' history, and they show the name and photo you had when you sent them; you can request their deletion via support@joindo.app. If a group you created still has members, its ownership passes to the longest-standing admin, or otherwise to the longest-standing member. Only financial records subject to legal retention obligations (where applicable) are kept for the statutory period.
Instead of deleting your account, you can freeze it from the same menu: a frozen account is hidden from other users until you sign in again; events you created are cancelled and you are removed from events you joined.
15. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you by email or in-app notification. The most current version is always published on this page; the effective date is updated when changes are released.
16. Contact
For all privacy questions and requests: support@joindo.app For legal notices (KEP): joindoapplicationyazilim@hs01.kep.tr By post: Organize Sanayi Bölgesi Mevkii, 2. Cad. No: 4/2040, Tüney Köyü, Merkez/ÇANKIRI, Türkiye
Turkish residents have the right to file a complaint with the Personal Data Protection Authority: https://www.kvkk.gov.tr. EU residents have the right to lodge a complaint with the supervisory authority of their country of residence.