TapfleetLegal
Sign in
← All documents· updated 2026-09-06
Template — review with counsel before publishing

Privacy Policy

Last updated: 2026-09-06

This policy explains what Tapfleet does with personal data about the people who use our website and panel — account holders, the members of a customer organisation, and people who contact us. Here we are the controller.

Personal data that appears inside a customer's own test data, app builds, screenshots, logs or hierarchy dumps is different: there we are a processor acting for the customer, and our Data Processing Agreement governs it, not this policy.

Controller: Batuhan Ünverdi, Türkiye. Contact: batuhanunverdii@gmail.com. Data protection contact: batuhanunverdii@gmail.com. EU representative (Art. 27 GDPR): not appointed at this stage; use the contact address above.

1. What we collect

CategoryWhat it isWhere it comes from
AccountName, email address, password hash, two-factor enrolment and backup codes, linked GitHub or SSO identityYou, or your identity provider
OrganisationOrganisation name and slug, your role (owner, admin, member, viewer), invitations, SCIM-provisioned membershipYou and your organisation's admins
UsageProjects, tests, suites, runs, device minutes metered per job, issues, pull-request checks — and who triggered themGenerated as you use the Service
Audit logEvery admin, agent and system action: actor type and id, action, target, and a payload describing the changeGenerated automatically
BillingPlan, spend limit, invoices, and the customer identifier held by our payment processor. We never see or store full card numbersYou and the payment processor
TechnicalIP address, user agent and timestamps in server and security logsYour browser or client
SupportWhat you send us by email or in a support conversationYou

We do not run advertising or profiling, and we do not sell personal data.

2. Why we use it, and on what legal basis

PurposeLegal basis (GDPR Art. 6(1))
Creating your account, running the Service, providing support(b) performance of a contract with you, or steps before it
Billing, metering device minutes, collecting fees(b) contract; (c) legal obligation for invoices and tax records
Security: authentication, the audit log, abuse and fraud prevention, keeping tenants isolated(f) legitimate interest in a secure service, and (c) where a law requires it
Keeping the Service working and improving it — aggregate usage and reliability analysis(f) legitimate interest in a service that works
Service emails you cannot opt out of (security notices, billing, material changes)(b) contract
Marketing email, where we send it(a) consent, or (f) for existing business customers where local law allows, always with an unsubscribe link

Where we rely on legitimate interest we have weighed it against your rights, and you may object (section 7).

3. Cookies

The panel sets only strictly necessary cookies. There are no analytics, advertising or tracking cookies, and no third-party tracker is embedded in the panel.

CookiePurposeLifetime
Session cookie (set by our authentication layer, Better Auth)Keeps you signed in and identifies your active organisation. A second short-lived cookie is issued mid-sign-in when two-factor authentication is enabled, and is redeemed for the sessionSession, bounded by your organisation's configured session lifetime (default 7 days)
qa_themeRemembers your light or dark theme choice so the page renders correctly on the server1 year
qa_projectRead, if present, to preselect a project; the panel does not currently set itSet by your browser session; a convenience only

Because all of these are strictly necessary to deliver a service you asked for, or set only at your own request, no consent banner is used. If we ever add a non-essential cookie we will ask for consent first.

4. How long we keep it

Account and organisation records are kept while the account exists and for 90 days afterwards, except where a law (for example tax law on invoices) requires longer.

Data generated inside the Service follows the retention windows in docs/data-residency.md and the retention policy. The platform defaults are:

ClassDefault window
Artifacts (screenshots, design diffs, debug output)30 days
Logs and hierarchy dumps30 days
Video14 days
Run and test metadata400 days
Audit events400 days
Database backups14 days on the server, plus the off-box copy

An organisation's owners and admins can shorten these under Organization › Data & retention; every window is capped at 730 days. A retention job sweeps on a schedule and records each pass.

5. Who else sees it

We share personal data only with the subprocessors listed in subprocessors.md — today our EU infrastructure and device-cloud providers, our source hosting, and the notification and support tools an organisation chooses. Each acts under a contract that limits them to processing on our instructions.

We may also disclose data to professional advisers, to a successor of our business, or where a law or a valid legal request requires it — in which case we will tell you unless we are forbidden to.

Services you connect (your model provider, GitHub, Slack, PagerDuty, Jira, GitLab, BrowserStack) receive data because you configured them. They act for you, not for us.

6. Where it is processed

During the pilot the Service is hosted in Türkiye: the control plane, database and file storage for builds and artifacts run on a single server in Ankara (dehost). Devices are the customer's own machines and never leave the customer's network, so no device pool of ours processes your app. Cross-region replication is off. An EU region (Hetzner, Germany) is planned before general availability, and this notice will be updated when the move happens.

Two supporting services sit outside that: Stripe, which processes subscription billing, operates from Ireland, and Resend, which delivers our transactional email, processes in the United States under Standard Contractual Clauses. Neither receives your builds, artifacts, runs or audit records — Stripe gets billing and subscription records, Resend gets the address and content of mail we send you. Crash reporting is not enabled during the pilot. The full list, with data categories and regions, is in Subprocessors.

Support and administrative access happens from Türkiye. If that is outside the EU/EEA, or if you enable an optional subprocessor hosted outside it, the transfer is covered by the European Commission's Standard Contractual Clauses together with any additional measures needed — details on request at batuhanunverdii@gmail.com.

7. Your rights

Under the GDPR you may ask for access to your personal data, correction, deletion, restriction of processing, a portable copy, and you may object to processing based on legitimate interest. Where we rely on consent you may withdraw it at any time, without affecting what happened before.

How to exercise them:

  • Self-service. An organisation owner or admin can export the organisation's data at Organization › Data (a single JSON export with an artifact index), and an owner can request deletion there — typing the organisation slug to confirm. Deletion is scheduled 7 days out and can be cancelled until it runs; after that it is irreversible.
  • By email. Write to batuhanunverdii@gmail.com. We answer within one month; if a request is complex we may extend by two further months and will tell you why.

If you are a member of a customer organisation and your request concerns data that organisation controls, we will point you to them, since they decide what happens to it.

You may also complain to a supervisory authority — in Turkey, the Kişisel Verileri Koruma Kurumu; in the EU, the authority where you live or work.

8. Children

The Service is for businesses. It is not directed at children and we do not knowingly collect data about anyone under 16. If we learn we have, we delete it.

9. Changes

We will update this page when our processing changes and move the "Last updated" date. For a material change affecting account holders we will give notice by email or in the panel before it takes effect.

10. Contact

Batuhan Ünverdi — batuhanunverdii@gmail.com (also the data protection contact).