Select Language ×
Türkçe English Deutsch Français Pусский Español Italiano Português Azərbaycan العربية

Membership Restaurant KVKK

RESTAURANT | Membership and Platform Users Information Text

MEMBERSHIP AND PLATFORM USERS INFORMATION TEXT

Membership, reservation, order, payment result, loyalty, social features, customer intelligence, mobile application and web usage

Data Controller Restaurant Electronic Communication Software Trade Inc.
Document Type KVKK m.10 Information Text
Version / Date 2.0 / 10.07.2026
Contact info@restaurant.com │ Suadiye Mah. Kazım Özalp Sk. C Block No: 60 Inner Door No: 2 Kadıköy / Istanbul
Important: This document applies according to the personal data processing activities in force. Before a new product, integration, artificial intelligence tool, foreign service provider, or data category is activated, the data processing inventory, legal reason, information, and transfer mechanism will also be updated.

Version 2.0 | Last Update: 10.07.2026

RESTAURANT | Membership and Platform Users Information Text

1. Data controller and scope of the text

Restaurant Electronic Communication Software Trade Inc. ("Restaurant" or "Company") is the data controller regarding the personal data processing activities described in this text.

This Information Text covers the operations carried out regarding individuals who open accounts or use services through the Restaurant mobile application and website, users who create reservations or orders, loyalty program participants, those using user-to-user sharing and social features, and guests included in the reservation/order.

The restaurant where you make a reservation or place an order may also be a data controller regarding its own service, customer relationship, financial obligations, and business activities. The restaurant's own information text is also valid for its processing activities.

2. What personal data do we process?

Category Processable data
Identity and profile First name, last name, username, profile photo, date of birth to the extent necessary; identity/tax information required by law for invoicing.
Contact Phone, email, delivery/invoice address, communication and notification preferences.
Membership and security Membership date, account status, linked account information, verification records, session, password reset, and security actions.
Reservation Restaurant, date-time, number of people, table/area preference, reservation channel, changes/cancellations, waiting list, no-show, prepayment, special requests, and notes related to the service by restaurant staff.
Order and delivery Ordered products and options, amount, discount, delivery/pick-up preference, address, delivery instructions, preparation/delivery status, courier, cancellation/refund, group or multiple restaurant cart.
Payment and finance Payment amount, date, transaction number, token, masked part of the card used, bank/payment institution, prepayment, refund, failed payment, and transaction risk information. Full card information is not recorded by Restaurant; payment is processed by a licensed bank or payment institution.
Loyalty Earned/used points, discounts, rewards, levels, benefits, participating restaurants, and abuse controls.
Customer relations Requests, complaints, support correspondence, call or message content, evaluation, and resolution information.
Social and user content Profile content, friends/connections, shared lists, group cart, messages, comments, and visibility preferences.
Location To show nearby restaurants or provide delivery, approximate or exact location if you use the feature and grant device permission; delivery address.
Technical and usage IP, device, operating system, browser, application version, device/ad identifiers used, cookies/SDK, logs, errors, performance, and in-app movement information.
Analysis and inference Visit frequency, preferences, segments, spending range, loyalty, recommendations, recovery, no-show, or abuse indicators.
Legal process Approval/rejection records, contract and request records, official correspondence, dispute and application information.
Special category data Only the allergy, health, or accessibility information you provide within the scope of your necessary service request. You should not write this type of information in free text fields if it is not necessary.

3. What methods and sources do we collect personal data from?

• Restaurant mobile application, www.restaurant.com, RezManager, and other digital interfaces belonging to Restaurant;

• The restaurant where you make a reservation or place an order, the restaurant's website/widget, restaurant staff, and call center;

• To the extent used, Google, Michelin/Mozrest, WhatsApp, and other reservation, order, or communication channels;

• POS, ERP, loyalty, delivery, and other integration systems;

• Limited payment result and transaction information from banks and payment institutions;

• Cookies, SDKs, system logs, device permissions, and in-app movements;

• Information you provide through email, phone, messaging, support, surveys, or social features;

• Authorized public institutions and other third parties in accordance with the legislation.

4. Purposes of processing and legal reasons

Purpose of processing Legal reason
Creating the account, phone/email verification, login, account settings, and execution of the membership agreement KVKK m.5/2(c): directly related and necessary for the establishment or performance of the contract.
Creating, communicating, modifying, canceling reservations, waiting list, reminders, and managing service requests m.5/2(c); legal obligations m.5/2(a)/(ç); in disputes m.5/2(e).
Managing order, delivery/pick-up, group cart, courier, cancellation, and refund processes m.5/2(c); financial/legal transactions m.5/2(a)/(ç); protecting rights m.5/2(e).
Managing prepayment, payment result, refund, and transaction security m.5/2(c), m.5/2(a)/(ç), m.5/2(e) and for security m.5/2(f).
Calculating and using loyalty points, discounts, levels, rewards, and benefits m.5/2(c); preventing abuse m.5/2(f).
Managing customer support, complaints, applications, refunds, and disputes m.5/2(e), m.5/2(ç) and according to the relevant service m.5/2(c).
Account and platform security, preventing fake accounts, unauthorized transactions, fraud, and abuse Without harming your fundamental rights and freedoms m.5/2(f); when rights need to be protected m.5/2(e).
Technical performance, capacity, error analysis, anonymous/aggregate statistics, and service development Without harming fundamental rights and freedoms m.5/2(f); where possible, anonymous/aggregate data is used.
Creating the search, sorting, and restaurant/product recommendation you requested To provide the requested service m.5/2(c) and in personalized product measurement m.5/2(f).
Personalized campaigns, behavioral profiling, targeted advertising, and marketing analysis Based on your separate and voluntary explicit consent (m.5/1). For commercial electronic communication, approval is also obtained in accordance with the relevant legislation.
Providing social features such as friends, messaging, list sharing, and group cart To provide the requested service m.5/2(c). If there is additional use for contact synchronization or marketing purposes, explicit consent is also obtained.
Showing nearby restaurants or providing delivery If you request the feature m.5/2(c). Separate explicit consent is required for marketing, background, or continuous location tracking.
Invoice, tax, accounting, official authority requests, and legal obligations m.5/2(a) and m.5/2(ç).

Your permission granted through your device's operating system is not considered explicit consent under KVKK alone. There is also a legal reason specified in this text for the relevant transaction, or separate explicit consent is obtained when necessary.

5. Data processing regarding restaurants and third-party guests

Your necessary data will be transferred to the relevant restaurant for your reservation or order to be fulfilled. The restaurant may process your personal data on its behalf regarding its own business service, customer communication, financial and legal obligations. Restaurant does not disclose a restaurant's customer data to another restaurant on a person basis; such a feature can only be activated with explicit notification and appropriate legal reason.

If you make a reservation on behalf of others, create a group cart, or share a third party's contact information, you must be authorized to share this information and provide the relevant person access to this information text. Restaurant will inform the relevant person additionally during the first communication when necessary.

6. Special category personal data

Reservation or order notes may contain special category personal data such as allergies, health status, disability, or accessibility needs. Please share this data only if it is genuinely necessary for the safe and appropriate provision of the service.

• Necessary special category data is processed based on the appropriate processing condition in Article 6 of the Law and with additional security measures.

• This data is not used for marketing, advertising, or general customer segmentation purposes.

• Data is only shown to authorized Restaurant and restaurant staff for the execution of the service.

• When necessary, explicit consent is obtained separately during the relevant field or transaction; it is not made a general condition of membership.

• When the special request ends, this data is deleted or access is removed within a shorter period than operational records unless there is a legal or security necessity.

7. Customer intelligence, profiling, and automated processes

Restaurant may produce analyses from reservation, order, usage, and technical data for preventing duplicate accounts, service security, capacity and product development, providing the recommendations you requested, and loyalty processes.

• Records can be combined in a necessary and measurable way to accurately match transactions created by the same user from different channels.

• Visit frequency, preferences, spending range, loyalty, recovery, no-show, or abuse indicators can be produced.

• Personalized campaigns, targeted advertising, and behavioral marketing profiles are only used if you have separate explicit consent.

• Restaurant bases its principle on not making a definitive decision that has legal or similar significant negative consequences about you solely based on automated evaluation. In case such a result occurs, you can request human review and appeal.

• Analyses provided to restaurants are as collective or anonymous as possible. Information on a person basis is limited to the restaurant's own customers, services, and legal authority.

8. AI-supported features

If you use AI Concierge, natural language-supported search, automatic suggestions, support, or similar AI features; the messages you write, conversation context, restaurant/product preferences, and necessary account data for the transaction may be processed.

• The purpose of the AI feature, the categories of data used, and the necessary information for foreign transfer may be presented layer by layer on the screen where the feature is used.

• Personal data is not used to train the external provider's general model without a contract and technical measures.

• Unnecessary identity and special category data are not included in AI requests; pseudonymization and data minimization are applied where possible.

• AI outputs may be incorrect; transactions such as reservations, payments, account closures, or significant restrictions are not completed solely based on the output without necessary verifications.

9. To whom and for what purposes are your personal data transferred?

Recipient group Purpose and scope of transfer
The restaurant where the reservation is made/ordered and authorized personnel Reservation, order, special requests, prepayment, service, cancellation, refund, and customer support processes.
Banks and licensed payment institutions Payment, prepayment, refund, transaction security, and financial obligations. Full card data is processed by the relevant institutions.
Couriers and delivery providers To deliver, name, phone, address, location, and necessary limited information related to the order.
Reservation/order channels and integration providers Establishing, synchronizing, updating, and troubleshooting the transaction through your selected channel.
POS, ERP, CRM, and loyalty integrations Restaurant operation, order/reservation matching, and application of loyalty benefits.
Cloud, hosting, security, authentication, email, SMS, push, support, analytics, and error tracking providers Operation, security, communication, and technical services of the platform.
Advertising, media, campaign, survey, and research providers Only personalized marketing within the scope of your relevant explicit consent and commercial communication preferences.
Lawyers, financial advisors, auditors, insurance, and consultants Protection of legal rights, financial and corporate obligations.
Authorized public institutions and judicial authorities Legal obligations, official requests, and legal processes.
Parties in merger, investment, or restructuring processes Under confidentiality and data protection obligations, necessary and measurable review and transfer for the transaction.

10. Data transfer abroad

If the cloud, hosting, security, email, notification, analytics, customer support, communication, or AI services we use are located abroad or if foreign subprocessors access the data, your personal data may be transferred abroad.

Regular transfers are made using one of the appropriate safeguards, including adequacy decisions or standard contracts, in accordance with Article 9 of the Law. Notification to the Authority is made within five business days from the completion of the signatures of the standard contracts. Provisions for occasional transfers are not used as a general basis for regular technology use.

Current foreign recipient groups and the transfer mechanism used will be disclosed on Restaurant's relevant privacy/transfer information page or upon your request.

11. Cookies, SDKs, and push notifications

Mandatory cookies and SDKs may be used for session, security, preference, and providing the service you explicitly requested. A separate preference mechanism is provided for non-mandatory tracking technologies for analytics, advertising, and marketing purposes.

• Non-mandatory cookies and SDKs are not activated without your acceptance; the option to reject is made as accessible as acceptance.

• Marketing push notifications are separate from mandatory service notifications such as reservation/order confirmation and security.

• You can turn off marketing notifications from application settings and device settings. Turning off does not affect membership and mandatory service notifications.

• The technology used, provider, purpose, duration, and information on foreign transfer are explained in the Cookies and Mobile Tracking Technologies Policy.

12. Retention periods

Your data is retained for the period prescribed by the relevant legislation or necessary for the purposes mentioned above. When your active membership ends, your account is closed; however, necessary limited records for financial records, transaction security, proof of explicit consent/rejection, disputes, and legal obligations may be retained separately and with restricted access until the end of the relevant period.

Data group Retention criteria
Account and membership Membership duration; after closure, only necessary records for legal, security, and protection of rights.
Reservation and order Necessary duration for service, support, financial records, and possible disputes; unnecessary operational notes are kept shorter.
Finance/accounting Mandatory periods of tax, trade, and financial legislation.
Marketing and commercial communication Active use until the date of withdrawal/rejection; proof of consent/approval and rejection for the necessary duration.
Technical/security logs Limited duration for risk proportional, security, and incident investigation.
Special category request The shortest duration necessary for the service; if there is no legal or security reason, it is deleted/restricted before the general transaction history.

13. Your rights

You have the following rights under Article 11 of the Law:

1. Learn whether your personal data is processed;

2. Request information regarding processed data;

3. Learn the purpose of processing and whether it is used appropriately;

4. Know the third parties to whom data is transferred within the country or abroad;

5. Request correction of incomplete or incorrect data;

6. Request deletion or destruction within the framework of the conditions in the Law;

7. Request notification of correction, deletion, or destruction to third parties to whom data is transferred;

8. Object to the emergence of a result against you due to analysis exclusively through automated systems;

9. Request compensation for damages in case of damage due to unlawful processing.

14. Application methods

You can submit your requests in Turkish; in person or by notary/post to the address Suadiye Mah. Kazım Özalp Sk. C Block No: 60 Inner Door No: 2 Kadıköy / Istanbul, using your previously notified and registered email address in the system from info@restaurant.com, or through the software/application provided for application.

The application must include your name-surname, signature if written, T.C. identity number or passport/identity number for foreigners, address for notification, email/phone if any, and subject of the request. Additional information may be requested to verify your identity based on the nature of the request. Your application will be concluded free of charge within a maximum of 30 days; if the process requires additional costs, the fee in the Authority's tariff may apply.

15. Changes and validity

This text came into effect on 10.07.2026. The text will be updated and announced through appropriate channels in case of substantial changes in data processing purposes, products, integrations, recipient groups, or legal grounds.

APPENDIX-1 — Explicit Consent Text for Personalized Marketing and Profiling

This appendix is an independent and optional explicit consent text from the above Information Text. Not giving or later withdrawing the consent below does not affect your Restaurant membership, reservation, order, payment result, loyalty account, and mandatory service notifications.

If you give explicit consent, Restaurant may process your reservation, order, loyalty, application and web usage movements, preferences, campaign interactions, approximate location usage, and customer relations data; to analyze your interests and preferences, create customer segments, offer you special restaurant/product/campaign and advantages, personalize application screens and advertisements, measure marketing performance, and create similar user groups.

In this context, your data may be transferred to advertising, media, analytics, survey, and campaign providers serving as data processors only to the extent necessary for campaign and marketing services. If there is regular foreign transfer, the appropriate transfer mechanism in Article 9 of the Law is used; this consent is not the general basis for regular foreign transfer.

You can withdraw your consent at any time by applying through the application settings or to info@restaurant.com. Withdrawal will take effect for the future; it does not affect the lawful transactions made until the consent is withdrawn.

☐ I AGREE — I give explicit consent for the processing of my personal data mentioned above for personalized marketing, behavioral profiling, and targeted campaign purposes.
☐ I DO NOT AGREE — I do not want my personal data to be processed for these purposes.

Date / Time: ______________________ User / Account: ______________________

APPENDIX-2 — Commercial Electronic Communication Approval

This approval is for commercial electronic communications within the scope of Law No. 6563 on the Regulation of Electronic Commerce and related legislation; it is not an acceptance of KVKK information or membership. Not giving consent does not prevent you from benefiting from Restaurant services.

You can approve Restaurant to send commercial electronic communications containing campaigns, offers, promotions, surveys, events, loyalty advantages, and marketing content through the following channels:

☐ SMS / phone

☐ Email

☐ Mobile application marketing notification (push)

☐ If WhatsApp or similar messaging channel is used

You can withdraw this approval at any time from the Restaurant application settings, from the rejection mechanism in the messages, through the Message Management System, or by applying to Restaurant. Notifications necessary for reservation/order confirmation, security, payment, and execution of the service are separate from commercial marketing messages.

☐ I AGREE — I approve the sending of commercial electronic communication from the channels I have marked.
☐ I DO NOT AGREE — I do not want to receive commercial electronic communication.

Date / Time: ______________________ User / Account: ______________________

Version 2.0 | Last Update: 10.07.2026

WhatsApp store