Last updated: 2026-09-06
This policy explains what Tapfleet does with personal data about the people who use our website and panel — account holders, the members of a customer organisation, and people who contact us. Here we are the controller.
Personal data that appears inside a customer's own test data, app builds, screenshots, logs or hierarchy dumps is different: there we are a processor acting for the customer, and our Data Processing Agreement governs it, not this policy.
Controller: Batuhan Ünverdi, Türkiye. Contact: batuhanunverdii@gmail.com. Data protection contact: batuhanunverdii@gmail.com. EU representative (Art. 27 GDPR): not appointed at this stage; use the contact address above.
| Category | What it is | Where it comes from |
|---|---|---|
| Account | Name, email address, password hash, two-factor enrolment and backup codes, linked GitHub or SSO identity | You, or your identity provider |
| Organisation | Organisation name and slug, your role (owner, admin, member, viewer), invitations, SCIM-provisioned membership | You and your organisation's admins |
| Usage | Projects, tests, suites, runs, device minutes metered per job, issues, pull-request checks — and who triggered them | Generated as you use the Service |
| Audit log | Every admin, agent and system action: actor type and id, action, target, and a payload describing the change | Generated automatically |
| Billing | Plan, spend limit, invoices, and the customer identifier held by our payment processor. We never see or store full card numbers | You and the payment processor |
| Technical | IP address, user agent and timestamps in server and security logs | Your browser or client |
| Support | What you send us by email or in a support conversation | You |
We do not run advertising or profiling, and we do not sell personal data.
| Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|
| Creating your account, running the Service, providing support | (b) performance of a contract with you, or steps before it |
| Billing, metering device minutes, collecting fees | (b) contract; (c) legal obligation for invoices and tax records |
| Security: authentication, the audit log, abuse and fraud prevention, keeping tenants isolated | (f) legitimate interest in a secure service, and (c) where a law requires it |
| Keeping the Service working and improving it — aggregate usage and reliability analysis | (f) legitimate interest in a service that works |
| Service emails you cannot opt out of (security notices, billing, material changes) | (b) contract |
| Marketing email, where we send it | (a) consent, or (f) for existing business customers where local law allows, always with an unsubscribe link |
Where we rely on legitimate interest we have weighed it against your rights, and you may object (section 7).
The panel sets only strictly necessary cookies. There are no analytics, advertising or tracking cookies, and no third-party tracker is embedded in the panel.
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session cookie (set by our authentication layer, Better Auth) | Keeps you signed in and identifies your active organisation. A second short-lived cookie is issued mid-sign-in when two-factor authentication is enabled, and is redeemed for the session | Session, bounded by your organisation's configured session lifetime (default 7 days) |
qa_theme | Remembers your light or dark theme choice so the page renders correctly on the server | 1 year |
qa_project | Read, if present, to preselect a project; the panel does not currently set it | Set by your browser session; a convenience only |
Because all of these are strictly necessary to deliver a service you asked for, or set only at your own request, no consent banner is used. If we ever add a non-essential cookie we will ask for consent first.
Account and organisation records are kept while the account exists and for 90 days afterwards, except where a law (for example tax law on invoices) requires longer.
Data generated inside the Service follows the retention windows in docs/data-residency.md and the retention policy. The platform defaults are:
| Class | Default window |
|---|---|
| Artifacts (screenshots, design diffs, debug output) | 30 days |
| Logs and hierarchy dumps | 30 days |
| Video | 14 days |
| Run and test metadata | 400 days |
| Audit events | 400 days |
| Database backups | 14 days on the server, plus the off-box copy |
An organisation's owners and admins can shorten these under Organization › Data & retention; every window is capped at 730 days. A retention job sweeps on a schedule and records each pass.
We share personal data only with the subprocessors listed in subprocessors.md — today our EU infrastructure and device-cloud providers, our source hosting, and the notification and support tools an organisation chooses. Each acts under a contract that limits them to processing on our instructions.
We may also disclose data to professional advisers, to a successor of our business, or where a law or a valid legal request requires it — in which case we will tell you unless we are forbidden to.
Services you connect (your model provider, GitHub, Slack, PagerDuty, Jira, GitLab, BrowserStack) receive data because you configured them. They act for you, not for us.
During the pilot the Service is hosted in Türkiye: the control plane, database and file storage for builds and artifacts run on a single server in Ankara (dehost). Devices are the customer's own machines and never leave the customer's network, so no device pool of ours processes your app. Cross-region replication is off. An EU region (Hetzner, Germany) is planned before general availability, and this notice will be updated when the move happens.
Two supporting services sit outside that: Stripe, which processes subscription billing, operates from Ireland, and Resend, which delivers our transactional email, processes in the United States under Standard Contractual Clauses. Neither receives your builds, artifacts, runs or audit records — Stripe gets billing and subscription records, Resend gets the address and content of mail we send you. Crash reporting is not enabled during the pilot. The full list, with data categories and regions, is in Subprocessors.
Support and administrative access happens from Türkiye. If that is outside the EU/EEA, or if you enable an optional subprocessor hosted outside it, the transfer is covered by the European Commission's Standard Contractual Clauses together with any additional measures needed — details on request at batuhanunverdii@gmail.com.
Under the GDPR you may ask for access to your personal data, correction, deletion, restriction of processing, a portable copy, and you may object to processing based on legitimate interest. Where we rely on consent you may withdraw it at any time, without affecting what happened before.
How to exercise them:
If you are a member of a customer organisation and your request concerns data that organisation controls, we will point you to them, since they decide what happens to it.
You may also complain to a supervisory authority — in Turkey, the Kişisel Verileri Koruma Kurumu; in the EU, the authority where you live or work.
The Service is for businesses. It is not directed at children and we do not knowingly collect data about anyone under 16. If we learn we have, we delete it.
We will update this page when our processing changes and move the "Last updated" date. For a material change affecting account holders we will give notice by email or in the panel before it takes effect.
Batuhan Ünverdi — batuhanunverdii@gmail.com (also the data protection contact).