Legal
Privacy Policy
Last updated: June 29, 2026
This Privacy Policy explains how GoldMath ("GoldMath", "we") collects, uses, and protects your personal data when you use our jewelry accounting and workshop management software (desktop, mobile, and web/cloud versions — together, the "Service"). By using the Service, you accept this Policy.
1. Data Controller and Contact
Your data is processed by GoldMath, as the data controller operating the Service. You can reach us with any privacy-related question, request, or data-deletion application:
- Email: [email protected]
- Phone / WhatsApp: +90 553 093 59 48
- Web: https://goldmath.net
2. Data We Collect
We collect the following data to provide the Service:
- Account information: your full name, email address, phone number, and business (company) details, as provided at registration.
- Google Sign-In information: when you use "Sign in with Google", we receive only your email address, name, Google account ID (a unique identifier), and email-verification status via Google's OpenID Connect service. We do not receive your Google password.
- Business and accounting data: accounts, transactions, gold/cash records, workshop movements, and other data you enter within the Service. This data belongs to you and is stored to provide the Service.
- Technical data: session/security logs, device and app information, and automatically generated data such as IP address, for security purposes.
3. Purposes of Processing
- Providing the Service, creating your account, and verifying your identity,
- Operating accounting, account, workshop, and reporting features,
- Performing backup and export operations at your request,
- Providing support, sending notifications, and communicating with you,
- Maintaining security, preventing misuse, and meeting legal obligations.
4. Google User Data and Limited Use
GoldMath's use and transfer of information received from Google accounts fully complies with the Google API Services User Data Policy (including the Limited Use requirements).
- We use data received from Google only to provide user-facing features of the Service to you.
- We do not use or sell Google user data for advertising purposes.
- We share this data only with your explicit consent, where legally required, or with processors necessary for the Service to function; we transfer it to no other party.
- Humans read this data only with your explicit consent, during a security/breach review, or where legally required.
5. Legal Basis (Turkey's KVKK)
Your personal data is processed under Turkey's Law on the Protection of Personal Data No. 6698 ("KVKK"), on the legal bases of: necessity for the establishment or performance of a contract, compliance with a legal obligation, legitimate interest, and — where required — your explicit consent.
6. Data Sharing and Service Providers
We do not sell your data. To provide the Service, we share it only with processors bound by confidentiality obligations, in the following categories:
- Server and hosting infrastructure providers (the cloud/infrastructure the app runs on),
- Google, for authentication (Sign in with Google),
- An email delivery provider, for transactional/verification emails,
- Push notification services (e.g. Apple/Google push services), for mobile notifications.
7. Retention Period
We retain your data for as long as your account is active and for as long as necessary to provide the Service and meet legal obligations. When you delete your account, we delete or anonymize your personal data, subject to legal retention obligations. Deleted data is also purged from rotating system backups within 30 days at the latest. See the Account Deletion page for details.
8. Security
We apply technical and administrative measures to protect your data, including encryption in transit (HTTPS/TLS), access controls, authentication and authorization layers, and multi-tenant isolation. No method is 100% secure, but we take our responsibility to protect your data seriously.
9. International Transfers
Some of the infrastructure and service providers we use may have servers located outside Turkey. In that case, transfers are carried out in accordance with the conditions and safeguards required under the KVKK.
10. Your Rights
Under Article 11 of the KVKK, you have the right to:
- Learn whether your personal data is being processed, and access it,
- Request correction of incomplete or inaccurate data,
- Request deletion or destruction of your data,
- Object to processing, and learn the parties your data has been transferred to.
To exercise these rights, contact us at [email protected].
11. Account and Data Deletion
As the business owner, you can delete your account from within the app yourself: in the mobile app, Settings → Company → Delete Account; on desktop, Settings → Company. Deletion becomes permanent 30 days after the request, so you can cancel an accidental request from the same screen within that window. The business owner creates staff, craftsman, and branch user accounts and removes them from Settings → Users.
If you are the business owner but no longer have access to the app, you can send a request to [email protected]; after verifying your identity, we complete the request within 30 days at the latest.
For which data is deleted, which is retained for legal reasons, and the applicable timelines, see the Account Deletion page.
12. Children's Privacy
The Service is intended for businesses and is not directed at individuals under 18. We do not knowingly collect personal data from children.
13. Changes to This Policy
We may update this policy from time to time. We announce material changes through the Service or on this page. The "Last updated" date at the top of the page indicates the current version.
14. Contact
For questions about this policy or your personal data: [email protected] · +90 553 093 59 48