Last updated: 28 September 2026
Privacy Policy
What data is processed in CiroFly, for what purposes it is used, and your rights.
1. Introduction
This Privacy Policy explains the general framework regarding personal data processed while using the reporting and analytics panel offered under the CiroFly brand (the “Platform”).
The Platform is used by digital advertising agencies and brand teams to view advertising and store performance data on a single screen.
Data controller: Brand On Reklam Ajansı – Mehmet Buğra Kılıçarslan (CiroFly service). For questions: info@cirofly.com
2. Categories of data processed
The following types of data may be processed within the scope of the Platform:
- Account information: first name, last name, e-mail address, password (encrypted), company/agency name, role information.
- Usage data: session records, security and error logs of actions performed in the panel.
- Brand and performance data: advertising spend, clicks, impressions, reach, store revenue, order count, and similar business metrics.
- Integration information: technical credentials required to access the advertising and store accounts you connect (e.g. API access keys); these credentials are stored encrypted.
3. Purposes of processing
Your personal and business data are processed only for the following purposes:
- Creating your account, authenticating you, and providing access to the panel.
- Retrieving performance data from connected channels, storing it, and presenting it to you.
- Generating PDF/ZIP reports and providing in-panel analytics features.
- Service security, prevention of misuse, and technical support.
- Compliance with legal obligations.
4. Legal bases
Under KVKK (Turkish Personal Data Protection Law No. 6698), your data may be processed on the legal bases of the establishment or performance of a contract, legal obligation, legitimate interest, and — where required — your explicit consent.
Marketing communications are sent only if you have given your permission.
5. Third parties and international transfers
The Platform infrastructure runs on trusted cloud service providers (e.g. hosting, database, authentication). Advertising and store data are retrieved through the APIs of the platforms you connect.
Our service providers access data only to the extent necessary to deliver the service; your data is never sold to third parties or shared for advertising purposes.
There are two exceptions, both solely for measuring CiroFly's own ads: (1) Marketing cookies on our website — only if you allow them in the cookie window, Meta Pixel and the Meta Conversions API are used (details: Cookie Policy); without your consent no data about your visit is sent. (2) Purchases — when you make a paid purchase on CiroFly, under this condition accepted during payment, the purchase details (amount, currency and an irreversible SHA-256 hash of your email address and user ID) are sent to Meta Platforms Ireland Ltd. (outside Türkiye) via the Meta Conversions API. This notice is shown in the payment window before you pay.
Where data is transferred abroad, we act in accordance with the conditions set out in KVKK.
6. Meta (Facebook, Instagram, WhatsApp) data
CiroFly accesses the APIs of Meta Platforms, Inc. (“Meta”) only for the accounts that you or your agency connect, and only within the scope of the permissions you grant.
Data received from Meta is used solely to provide the service to you: reporting, advertising management actions that you approve, and WhatsApp messages sent on behalf of your brand. Meta data is never sold, is not used for ad targeting or profiling, is not transferred to data brokers, and is not shared with other customers.
To deliver the service, this data is processed only on our behalf and under our instructions by our infrastructure providers (Supabase, Vercel, Hetzner) and, when in-panel AI features are used, by our AI providers (Anthropic, Google).
Types of data accessed:
- Ad accounts: campaign, ad set and ad information; performance metrics such as spend, impressions, clicks, reach and conversions.
- Ad management: actions you approve in the panel (e.g. pausing/resuming an ad, changing a budget, creating campaigns and ads) are sent to Meta on your behalf. No change is ever made without your approval.
- Facebook Pages and Instagram business accounts: account name and ID, and the posts you choose to use in ads.
- WhatsApp Business: business account and phone number IDs, message templates, and the delivery status of messages sent on behalf of your brand.
- Access tokens: stored encrypted and used only for the brand they belong to.
7. Deletion of Meta data
You can remove your Meta connection at any time with the “Disconnect” button on the Integrations screen of the panel; the access token is deleted immediately and no further data is retrieved from Meta.
You can also revoke access on Meta's side: on Facebook, go to Settings & Privacy → Settings → Business Integrations (or Apps and Websites) and remove CiroFly.
You can request complete deletion of the data received from Meta and stored by us by writing to info@cirofly.com; requests are completed within 30 days at the latest. Detailed steps: cirofly.com/en/legal/meta-veri-silme
8. Retention period
Your account data may be retained for the duration of your membership and, after account closure, for as long as statutory retention obligations require.
Performance data is stored on a per-brand basis for service delivery and historical reporting; deletion requests are evaluated within a reasonable time.
9. Your rights
Under Article 11 of KVKK, you have the right to learn whether your data is being processed, to request information, to request correction or deletion, to know the third parties to whom your data has been transferred, and to object to processing.
You may submit your requests to info@cirofly.com. Requests are concluded within 30 days at the latest.
10. Policy updates
This policy may be updated when necessary. The current version is always published on this page; registered users are informed of material changes through reasonable means.
