Skip to content

Privacy Policy

Last updated: September 30, 2026

This Privacy Policy explains how “KaiRank” (“we”, “us”) collects and uses personal data when you use the website at https://kairank.com, the free AI visibility check, the KaiRank application and the emails we send you, and which data we use when we reach out to potential business customers. We act as the data controller for this processing under the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and, where it applies, the EU and UK General Data Protection Regulation (“GDPR”). This policy is also available in Turkish.

1. Who we are

Brand
KaiRank

We have not yet appointed a representative in the EU or the UK under Article 27 of the GDPR or the UK GDPR. You can contact us directly at the address on our Contact page.

For data our customers enter about their own clients (for example the brands, questions and competitors an agency tracks), the customer is the controller and we act as its processor, on its behalf and instructions (KVKK Art. 12). Our Terms of Service contain the terms for this.

2. Data we collect

  • Identity and contact data: your name and email address when you create an account. If you use “Sign in with Google”, we receive these from Google, and our sign-in server also stores your Google account ID to link it to your account. We never see your password; only a hash of it is kept on our sign-in server (Keycloak).
  • Customer data: your plan, subscription and payment status, customer and subscription IDs at the payment provider, payment notifications and support correspondence.
  • Invoice details (payments in TRY): for individuals, first name, last name and Turkish ID number (TCKN); for companies, company name, tax office, tax number (VKN) and the name of the contact person; in both cases email address, mobile number, billing address, city and postcode if given. Your name, Turkish ID or tax number, email, phone and address are passed to iyzico to take the payment; all invoice details are kept by us to issue the invoice.
  • Contract acceptance records: that you accepted the Terms of Service and acknowledged this notice at sign-up; and, for TRY purchases, that you accepted the Pre-Contract Information Form and the Distance Sales Contract, asked for the service to start immediately and allowed your card to be stored for recurring payments. These records hold the versions of the documents, for purchases the document texts sent to you, the boxes you ticked, the date and time, your IP address, your browser user agent, your email address and the plan.
  • Cookie choice records: your choice in the cookie banner, a random ID created in your browser, the Cookie Policy version, the date and your browser user agent, plus your user account if you are signed in (see our Cookie Policy).
  • Service data: your organisation, projects, tracked brands, websites, competitors, questions (prompts), city/country settings, team memberships, AI engine answers and scan results. This is mostly business information, although a brand name can be personal data for sole traders.
  • Third-party names in AI answers: the answers and reports we store may contain the names of other businesses or professionals mentioned by AI engines. We keep these names, based on our legitimate interest, only as a natural part of the visibility analysis and show them only in reports; we do not use them for anything else.
  • Country: at your first sign-in we store the country code Cloudflare derives from your IP address and use it to preselect the currency on the billing page (TRY/iyzico or USD/Paddle); you can change it there. Our marketing pages also use this country, without storing it, to show prices in the right currency.
  • Free check data: the website, brand, industry and city you enter, the result, your email address if you ask for the report by email, and a keyed hash (keyed SHA-256) of your IP address and of the network it belongs to (IPv6 /48, IPv4 /24) to limit abuse. We never store your raw IP address, and we delete the hashes after 24 hours. Your IP address is sent to Cloudflare Turnstile for bot verification.
  • Security data: your last sign-in time; session records on our sign-in server (IP address, browser and device information, session start and last activity); failed sign-in data used to lock an account temporarily after repeated wrong passwords; server and application logs, including error logs (these may contain IP addresses); Cloudflare security logs; an email log (recipient, email type and date); and short-lived technical counters, used to prevent abuse, of how many requests were made in a given period per account, organization or IP address and of how many free trials were started from the same network or the same company email domain (these counters hold a keyed hash of the IP address or domain, not the address or domain itself).
  • Free trial record: so that the free trial is offered only once per person, a keyed hash (HMAC-SHA256) of the standard form of your email address (lowercased, with any “+” suffix and, for Gmail addresses, dots removed), the number of trials and their dates. This record does not contain your email address itself; without the key, which only we hold, the hash cannot be linked to you.
  • Marketing and measurement data: page visits and conversions, only with your consent and separately per tool: Google Analytics 4 with analytics consent, Meta Pixel with advertising consent.
  • Business contact data (B2B): publicly available contact details of businesses we may approach (see section 5).
  • Card details: handled directly by our payment providers (iyzico for payments in TRY, Paddle for payments in USD), which also store them for recurring payments. We never see or store your card number.

You must give us your name and email address to create an account, and invoice details are required by Turkish tax law for payments in TRY. Without them we cannot open an account or complete a purchase. Everything else is optional. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

3. Why we use your data and our legal bases

  • To create your account and sign you in (including “Sign in with Google”), provide the service, run scans, send reports and service emails (such as trial ending, payment result and order confirmation), pass your invoice details to the payment provider to take payment, and send the free check report you ask for: performance of a contract (KVKK Art. 5(2)(c); GDPR Art. 6(1)(b)).
  • To issue invoices, keep invoice and accounting records and respond to lawful requests from authorities: legal obligation under Turkish law (KVKK Art. 5(2)(ç); where the GDPR applies, our legitimate interest in meeting these obligations, Art. 6(1)(f)).
  • To prove that a contract was made and consent was given (contract acceptance and cookie choice records) and to keep invoice records for possible disputes: establishing, exercising or defending legal claims (KVKK Art. 5(2)(e); GDPR Art. 6(1)(f)).
  • To keep the service and accounts secure (session records, protection against repeated failed sign-ins, bot protection, free check limits, request limits), make sure the free trial is used only once per person, fix errors, avoid sending the same email twice, preselect your currency by country, report the business names in AI answers, improve the product and introduce our service to businesses: legitimate interests (KVKK Art. 5(2)(f); GDPR Art. 6(1)(f)).
  • Optional analytics and advertising measurement cookies: your consent (KVKK Art. 5(1); GDPR Art. 6(1)(a)). You can withdraw it at any time with the “Cookie settings” link at the bottom of the page.

The free check report email contains only the report and a link to create an account if you wish. We do not send you any other promotional email without your consent.

4. Where the data comes from

We collect data through forms on our website and in the app (sign-up, checkout and free check), from Google LLC if you use “Sign in with Google”, from the country information Cloudflare adds to requests, through cookies and browser local storage, from payment notifications sent by our payment providers and from email correspondence. For businesses we may approach, we use the business’s own website and its business listing on Google Maps. Collection is fully or partly automated and electronic.

5. Business outreach (B2B)

To introduce our service, we email businesses we think may be interested in their AI visibility, under these rules:

  • Who: only merchants and tradespeople (tacir and esnaf) operating in Turkey that have a Google Maps business listing and a website. We do not send such emails to liberal professions (such as lawyers, doctors or accountants) or to businesses in the European Union or the United Kingdom.
  • Data we use: the business name, website and domain; the generic contact address the business publishes on its own website (such as info@, iletisim@ or hello@); the industry and city we searched for; send dates and status; and the result of the AI visibility check described below. We do not use personal email addresses and do not store anyone’s name.
  • Sources: the business’s website (contact address) and its listing in the Google Places service provided by Google LLC, from which we take only the business name and website address.
  • Purpose and content: one business email about our service and, if you do not reply, at most one reminder. The email shares the result of a short visibility check in which one AI engine is asked one sample question about your industry and city. Only the industry and city are sent to the AI provider for this check; the names of other businesses in the answer may be stored with the result.
  • Legal basis: our legitimate interest (KVKK Art. 5(2)(f)). Under Turkish Law No. 6563 on the Regulation of Electronic Commerce and its Regulation on Commercial Communication and Commercial Electronic Messages, commercial electronic messages to merchants and tradespeople do not require prior consent, but you can always opt out.
  • Transparency: our first email gives our company details, where we got your details, a link to this policy and how to opt out.
  • Opting out: click the link in any of our emails and your opt-out takes effect immediately. If you reply with something like “unsubscribe”, we detect it automatically and process it within 1 business day at the latest. An opt-out covers your business’s whole domain, so we will not email another address on it either. You can also opt out through Turkey’s Message Management System (İYS), which we check before sending. If you reply to us at all, we will not send a reminder.
  • Retention: the business record is kept for at most 12 months after our last contact. When you opt out, or an email bounces, the record is deleted immediately; we keep only a minimal suppression record (email address, domain, reason and date) indefinitely so that we never email you again.

6. Who we share data with

We do not sell personal data. We share it only as far as needed for the purposes above, with:

Infrastructure and communication

  • Hetzner Online GmbH (Germany/Finland): server hosting and backups (processor).
  • Cloudflare, Inc. (USA): network services, security, bot protection (Turnstile), secure tunnelling and country lookup from your IP address (processor).
  • Google LLC (USA), Google Workspace: email delivery, business email and the mailbox that receives replies to our business outreach (processor).
  • Google LLC (USA): “Sign in with Google” authentication (only if you use it).

Payments and invoicing

  • İyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. (iyzico, Turkey): payments in TRY and card storage; your name, Turkish ID or tax number, email, phone and address are passed to iyzico, which acts under its own obligations as a licensed payment institution.
  • Paddle.com Market Ltd (United Kingdom): merchant of record for payments in USD, handling payment, invoicing and tax; Paddle acts as an independent controller for these activities.
  • To issue your invoices: the e-Archive/e-Invoice systems of the Turkish Revenue Administration and the accountant or e-invoicing service provider we use for this (Turkey).

AI and data providers (processors)

  • OpenAI, L.L.C. (USA): ChatGPT answers.
  • Google LLC (USA): Gemini answers and Google Places business listings.
  • Perplexity AI, Inc. (USA): Perplexity answers.
  • Anthropic, PBC (USA): Claude answers, and suggesting brands, competitors and questions from your website’s public content.
  • DataForSEO (a service provider established outside Turkey): Google AI Overviews results.

We only send these providers the tracked questions, brand and industry details, the chosen country/city and, where needed, your website’s public content. We never send your name, email or other account details.

Other recipients

  • Google LLC (USA), Google Analytics 4: only with your analytics consent.
  • Meta Platforms (Ireland/USA), Meta Pixel: only with your advertising consent.
  • Authorities and courts, where required by law.

7. International transfers

Most of these providers are established outside Turkey (in Germany, Finland, the USA, the United Kingdom, Ireland and the country where DataForSEO is established), so your data is transferred abroad on a regular basis to provide the service. Under Article 9 of the KVKK, for regular transfers to countries without an adequacy decision of the Turkish Personal Data Protection Board we use the standard contracts published by the Board, and we notify each signed contract to the Turkish Personal Data Protection Authority within 5 business days. We do not rely on the occasional-transfer exceptions in Article 9(6) for regular transfers.

8. How long we keep data

DataRetention
Account and service data (organisation, projects, questions, competitors, AI answers, team, invoice details, sign-in account)While your account is open. You can close your account under Settings → Close account (account owner only) or by writing to us at the address on our Contact page. When an account is closed, any active subscription is cancelled with the payment provider straight away, and all account data and your sign-in account (unless you are also a member of another organisation) are deleted immediately.
Archived projectsDeleted 90 days after archiving.
Inactive accountsAccounts whose trial or subscription has ended and whose members have not signed in for 12 months are deleted.
Contract acceptance records (document versions and texts, consents, date, IP address, user agent, email address)10 years (general limitation period); kept even if your account is deleted.
Invoice records10 years (the 5-year period under the Turkish Tax Procedure Law, plus evidence); kept even if your account is deleted.
Free check records12 months.
Keyed hash of your IP address for the free check24 hours (only for the usage limit).
Free trial record (keyed hash of the email address, number of trials and their dates)24 months after the last trial; kept even if your account is closed, to prevent the free trial from being used again.
Request counters used to prevent abuseAt most 8 days.
Email log (recipient, email type, date)13 months (to avoid sending the same email twice).
Cookie choice records3 years.
Payment notifications from payment providers13 months after processing.
Session records on our sign-in serverUntil the session ends: at most 10 hours (2 hours without activity); with “Remember me”, at most 14 days (7 days without activity).
Server and application logsA rotating log of at most 5 × 10 MB per service; the oldest entries are overwritten as new ones arrive (typically a few weeks).
BackupsAt most 14 days. Deleted data disappears from backups within 14 days at the latest.
Business outreach recordsAt most 12 months after our last contact; deleted immediately after an opt-out or a bounce.
Outreach suppression records (email address, domain, reason, date)Indefinitely, so that we can keep honouring your opt-out.

At the end of these periods the data is deleted or destroyed. Payment providers acting as independent controllers apply their own retention periods.

9. Cookies

We use strictly necessary cookies to keep you signed in, remember your language, and for security and bot protection. Google Analytics 4 loads only with your analytics consent and Meta Pixel only with your advertising consent. See our Cookie Policy for the full list and how to change your choice.

10. Your rights

Depending on where you live, you have the right to access your personal data, have it corrected or erased, restrict its processing, receive it in a portable format and withdraw your consent at any time without affecting processing carried out before the withdrawal. Users in Turkey have the rights listed in Article 11 of the KVKK; see the Turkish version of this policy for details.

Your right to object: where we rely on legitimate interests, you can object at any time on grounds relating to your particular situation. You can object to direct marketing, including our business outreach emails, at any time and without giving reasons; we will then stop. To do so, use the link in the email, reply to it, or contact us at the address on our Contact page.

You also have the right to lodge a complaint with the data protection supervisory authority in the country where you live or work, or where you think an infringement took place, and in Turkey with the Personal Data Protection Board.

To exercise your rights, email us at the address on our Contact page from the address registered to your account. We respond free of charge within 30 days. See our Contact page for what to include in an application under the KVKK.

11. Security

We protect your data with these technical and organisational measures: all connections are encrypted with TLS; our web services are not directly exposed to the internet; all web traffic reaches them through Cloudflare’s secure tunnel, and administrative access to the server is by SSH key only; passwords are stored only as hashes and accounts are temporarily locked after repeated failed sign-ins; the application session cookie is encrypted; server access is limited to authorised people on a least-privilege basis; and databases are backed up every night. We keep server and application logs for debugging and security; they are size-limited and rotate automatically, and we do not keep a separate long-term log of sign-in events. No system is completely risk-free; if a breach occurs, we will notify the authorities and affected people as the law requires.

12. Children

KaiRank is a business service and is not intended for anyone under 18.

13. Changes

We may update this policy from time to time. We will announce material changes on our website and, where appropriate, by email. The current version is always available on this page.

14. Contact

For any privacy questions, contact us at the address on our Contact page. See also our Terms of Service.