İçeriğe geç
Commı

Privacy Policy

This policy explains what information is processed when you use the Commi website and its Google scorecard, how it is used and who it is shared with.

1. Scope

This policy covers the Commi website and the Google scorecard on it. Section 9 describes the rules that apply if a business connects the Commi panel to its Google account.

When the Commi panel is provided to businesses under an agreement, separate information is given about the data processed in the panel.

The legal grounds for processing personal data and your rights under Turkish data protection law (KVKK, Law No. 6698) are described in the KVKK Privacy Notice (in Turkish).

2. Who we are

Emir Apaydın, owner of the venture operating under the Commi brand.

Contact: bilgi@commisoft.co

3. What information is processed

There are no forms on this website, and you are not asked for personal information such as your name, phone number or email address.

Technical records

  • Requests to the website appear in the hosting provider's server logs together with your IP address and browser information.
  • When you use the Google scorecard, a one-way, salted hash of your IP address, the time of searches and scans, and the step at which a scan was left are recorded. Your raw IP address is not stored.
  • An approximate location derived from your connection is used to rank nearby businesses higher and is not stored.

Businesses searched in the Google scorecard

  • The text you type into the search box is sent to Google and is not stored.
  • When you request the detailed scorecard on WhatsApp, our team prepares it as a link. The scorecard code in the message is the business's Google place ID; the link contains none of your personal information.
  • The selected business's public Google information and reviews (including the reviewer's public Google name, profile photo and profile link, and each review's Google Maps link and report link) are retrieved from Google Maps Platform, shown in the scorecard and cached for a limited time.

If you contact us directly

  • The WhatsApp and email buttons on the website only open the relevant app; you send the message from your own account. What you write is used only to reply to you.

4. How we use information

Information is not sold and is not used for advertising.

  • To prepare and show the scorecard you request.
  • To run the website and prevent abuse and automated requests.
  • To improve the service by counting searches and scans. These counts come from our own database; no third-party analytics tool is used.
  • To reply to you when you contact us.

5. Cookies and browser storage

  • The website does not use cookies and does not write data to your browser's storage. There are no advertising pixels or tracking codes. Fonts are served from the website's own address.
  • Cloudflare Turnstile, used for bot protection, is loaded from Cloudflare's servers and collects technical signals from your browser.

6. Who we share information with

Information is shared with the following providers only as far as needed to run the website. These providers are located outside Turkey, so information is transferred to the countries listed:

  • Vercel Inc. (USA): website hosting. Every request to the website passes through this infrastructure together with your IP address and browser information.
  • Supabase Inc. (USA; database servers in Ireland, EU): the website's database. The IP hash, search and scan records and the cache of business data received from Google are kept here.
  • Google LLC (USA): Google Maps Platform. The search text, the selected business's place ID and an approximate location are sent.
  • Cloudflare Inc. (USA): Turnstile bot protection. When a scorecard scan is started, your IP address and technical signals from your browser are processed.

Competent public authorities

Where required by law, information may be shared with competent public authorities to the extent requested.

7. Retention

  • Search and scan records (including the IP hash): 90 days, then deleted automatically.
  • Content received from Google (business name, address, rating, reviews with the reviewers' names, profile photos and profile links, the reviews' Google Maps and report links, Google's raw response and the scorecard score calculated from them): 30 days from the date it was retrieved from Google, then deleted automatically.
  • Detailed scorecard links prepared by our team: the Google content in them is deleted after 30 days as above and the link then shows that it has expired; the link record (including the business's place ID) is deleted entirely 90 days after it was created.
  • Server logs (IP address and browser information): subject to the hosting provider's own log retention.
  • Messages you send us by WhatsApp, email or phone: deleted within 1 year after the conversation ends if they do not lead to a business relationship.

8. Security

We take reasonable technical measures to protect information. For example: connections are encrypted with HTTPS; IP addresses are stored only as one-way hashes; the website connects to the database with a separate role that can access only its own tables.

No transmission over the internet and no storage method is completely secure. If we become aware of a breach affecting information, we will notify the people concerned and the Turkish Personal Data Protection Authority as required by law.

9. Google User Data

At the business owner's request, the Commi panel can connect to the business's Google Business Profile account. This section applies only to businesses that set up this connection.

The connection is made only with the business owner's permission, in one of two ways: the business owner explicitly grants permission on Google's consent screen (OAuth), or adds Commi's Google account as a manager of their Google Business Profile. In both cases Commi uses the Google Business Profile API with the business.manage scope (https://www.googleapis.com/auth/business.manage).

Data accessed

  • The list of locations in the business account and basic profile information (business name, address, category).
  • Reviews of the business: the reviewer's public Google name and profile photo, rating, review text and date.
  • The business's replies to those reviews.

How it is used

Data received from Google is used only to track reviews and notify the business of new ones, analyse reviews, prepare reports for the business, draft replies, and publish on Google the replies the business explicitly approves in the panel.

Commi never replies to a review without the business's prior authorization. Replies are not published automatically: each reply is published on Google only after the business, or the Commi team authorized by the business, explicitly approves it in the panel.

This data is not sold and is not used for advertising, user profiling, credit assessment or training general-purpose AI models. It is shared only with service providers needed to deliver these features (database hosting; when enabled in the panel, Google Gemini API and Anthropic Claude API for review analysis and reply drafts; email and WhatsApp delivery providers for new-review notifications and reports) or where required by law.

Human access

Data received from Google is shown to the business's own users whom it authorizes in the panel. The Commi team does not read this data, except:

  • With the business's permission: tasks the business assigns to the Commi team under its agreement or on request, such as monitoring reviews, preparing replies or filing removal requests on the business's behalf.
  • For security: investigating abuse or a bug.
  • To comply with the law: where required by legislation or a competent authority.

Security

Data received from Google is transferred over encrypted connections (HTTPS/TLS). Google access tokens are stored encrypted and used only to operate the connection. In the panel, permission to see Google data is given only to users the business authorizes.

Changes to your account

If Commi makes a change to the business's Google account (for example, adding a new manager to the profile), it notifies the business separately within 48 hours of the change.

Retention and deletion

Data received from Google is kept while the connection is active.

When the business removes the connection in the panel, revokes Commi's access from its Google account, removes Commi as a manager of its profile, or the service ends, the Google access tokens are deleted. Data received from Google is deleted from live systems within 30 days and from backups within the following 14 days. You can ask for earlier deletion by writing to bilgi@commisoft.co.

Revoking access and leaving the service

You can revoke Commi's access at any time from your Google account: go to Google Account › Security › Third-party apps & services, select Commi and remove access. Once access is revoked, the panel stops retrieving your reviews from Google and stops publishing replies.

If you added Commi as a manager of your Google Business Profile, you can remove it at any time from the People and access section of your profile.

When you tell us, at bilgi@commisoft.co or in the panel, that you want to stop using the service, within 7 business days your connection is removed, Commi relinquishes its manager role and any other permissions on your account, and you regain exclusive control of your account.

The public Google Maps information shown in the Google scorecard is outside the scope of this section; it is not obtained through a Google account connection.

Commi's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

10. Your rights

You can exercise your rights to access, correct or delete your information by writing to bilgi@commisoft.co. The full list of your rights and how to apply is in the KVKK Privacy Notice.

11. Changes

When the practices described in this policy change, the policy is updated and the date below changes.

12. Contact

Questions: bilgi@commisoft.co

Last updated: October 7, 2026