Privacy Policy — Social Media Login

Effective Date: April 13, 2026  |  Last Updated: April 13, 2026

This Privacy Policy explains how Eyexapp (operated by Eyexapp Teknoloji A.Ş.) and Weblapp (a subsidiary brand of Eyexapp) collect, use, store, share, and protect your personal information when you use social media login features across our applications, websites, and services. This policy applies to authentication via Facebook, Instagram (Meta Platforms), X (formerly Twitter), LinkedIn, TikTok, Google, and any other supported social media platform.

By using any social login feature provided by Eyexapp or Weblapp, you acknowledge that you have read, understood, and agree to the terms described in this Privacy Policy. If you do not agree, please do not use social login — you may use alternative sign-in methods where available.

1. Definitions

2. Data Controller

The data controller for information collected through social login is:

Eyexapp Teknoloji A.Ş.
Fenerbahçe Mah. İğrip Sk. No: 13
34726 Kadıköy, İstanbul, TÜRKİYE
Email: privacy@eyexapp.com
Website: eyexapp.com

3. Information We Collect Through Social Login

When you choose to sign in using a social media account, we receive specific information from the Platform. The exact data depends on which platform you use and what permissions you grant.

3.1 Facebook & Instagram (Meta Platforms)

Data Category Details
Basic Profile Name, profile picture, email address, Facebook/Instagram user ID
Public Profile Gender, age range, locale, timezone (if publicly available)
Email Primary email address associated with your Meta account
Pages & Business (if applicable) Page access tokens, page metadata (only when explicitly authorized for business integrations)
Instagram Business (if applicable) Instagram Business/Creator account info, media insights (only when explicitly authorized)

We comply with Meta Platform Terms and Meta Privacy Policy.

3.2 X (formerly Twitter)

Data Category Details
Basic Profile Display name, username (@handle), profile image URL, X user ID
Email Email address associated with your X account (if permission granted)
Public Metrics Follower/following count (public data only, not stored unless required)

We comply with X Developer Policy and X Privacy Policy.

3.3 LinkedIn

Data Category Details
Basic Profile First name, last name, profile picture URL, LinkedIn member ID
Email Primary email address associated with your LinkedIn account
Lite Profile (OpenID) Locale, headline (if using Sign In with LinkedIn via OpenID Connect)

We comply with LinkedIn API Terms of Use and LinkedIn Privacy Policy.

3.4 TikTok

Data Category Details
Basic Profile Display name, username, avatar URL, TikTok open ID
Email Email address (if permission granted and available)
Public Videos (if applicable) Video metadata for authorized integrations only (not collected during basic login)

We comply with TikTok Developer Terms and TikTok Privacy Policy.

3.5 Google

Data Category Details
Basic Profile Full name, profile picture URL, Google account ID
Email Primary email address, email verification status
OpenID Claims Locale, hosted domain (for Google Workspace users)

We comply with Google API Services User Data Policy and Google Privacy Policy.

3.6 Other Platforms

If we introduce social login support for additional platforms (e.g., Apple, GitHub, Discord, Snapchat), we will update this policy to include the specific data categories collected. In all cases, we follow the principle of data minimization — we only request the permissions strictly necessary for authentication and core service functionality.

4. How We Use Your Information

We use the information collected through social login for the following purposes:

  1. Account Creation & Authentication: To create your user account, verify your identity, and enable secure sign-in across sessions and devices.
  2. Profile Setup: To pre-populate your profile with your name and profile picture, reducing manual data entry.
  3. Communication: To send account-related notifications (e.g., security alerts, password resets, service updates) using your email address.
  4. Service Improvement: To analyze aggregated, anonymized usage patterns and improve authentication flows and user experience.
  5. Security & Fraud Prevention: To detect, prevent, and respond to security incidents, fraud, or unauthorized access.
  6. Legal Compliance: To comply with applicable laws, regulations, and legal processes.
  7. Customer Support: To assist you with account-related inquiries and technical issues.
We do NOT use your social login data to post on your behalf, access your contacts or friend lists, read your private messages, or perform any actions on your social media accounts without your explicit consent.

5. Legal Basis for Processing (GDPR / KVKK)

We process your personal data under the following legal bases:

Legal Basis Application
Consent You give explicit consent when you click "Sign in with [Platform]" and authorize data sharing on the Platform's consent screen.
Contractual Necessity Processing is necessary to provide the services you requested (account creation, authentication).
Legitimate Interest Security monitoring, fraud prevention, and service improvement where these interests do not override your fundamental rights.
Legal Obligation Compliance with Turkish KVKK, EU GDPR, and other applicable data protection laws.

6. Data Sharing & Third Parties

We may share your personal data with the following categories of recipients:

We do NOT sell, rent, or trade your personal data to any third party for marketing or advertising purposes.

7. Data Retention

We retain your personal data as follows:

8. Data Security

We implement industry-standard technical and organizational measures to protect your personal data:

9. Your Rights

Under applicable data protection laws (including GDPR and Turkish KVKK Law No. 6698), you have the right to:

  1. Access: Request a copy of the personal data we hold about you.
  2. Rectification: Request correction of inaccurate or incomplete personal data.
  3. Erasure: Request deletion of your personal data ("right to be forgotten").
  4. Restriction: Request restriction of processing of your personal data in certain circumstances.
  5. Data Portability: Request your data in a structured, commonly used, machine-readable format.
  6. Object: Object to processing based on legitimate interests, including profiling.
  7. Withdraw Consent: Withdraw previously given consent at any time without affecting the lawfulness of processing prior to withdrawal.
  8. Complaint: Lodge a complaint with the Turkish Personal Data Protection Authority (KVKK) or your local supervisory authority.

To exercise any of these rights, contact us at privacy@eyexapp.com. We will respond within 30 days of receiving your request.

10. Managing Social Login Connections

You can manage or revoke social login connections at any time:

Revoking access will prevent future logins via that platform but will not automatically delete data already collected. To delete previously collected data, please submit a separate deletion request.

11. Cookies & Tracking Technologies

When you use social login, the following cookies and similar technologies may be used:

We do not use social login data for cross-site tracking or targeted advertising.

12. Children's Privacy

Our services are not directed to individuals under the age of 13 (or the minimum digital consent age in your jurisdiction, e.g., 16 in certain EU member states). We do not knowingly collect personal data from children through social login or any other means.

If we become aware that we have inadvertently collected personal data from a child below the applicable age, we will take immediate steps to delete such information. If you believe a child has provided us with personal data, please contact us at privacy@eyexapp.com.

13. International Data Transfers

Your personal data may be transferred to and processed in countries outside of your country of residence, including but not limited to:

Where data is transferred outside the EEA or Türkiye, we ensure appropriate safeguards are in place, including:

14. Platform-Specific Disclosures

14.1 Meta (Facebook / Instagram) — Data Deletion Callback

In compliance with Meta Platform Terms, we provide a Data Deletion Request Callback URL. When you remove our app from your Facebook or Instagram settings, Meta notifies us, and we initiate deletion of all data associated with your Meta account within 30 days.

You may also submit a manual deletion request at privacy@eyexapp.com with the subject line "Meta Data Deletion Request."

14.2 X (Twitter) — Limited Use

We adhere to the X Developer Agreement and Policy. Data obtained via X login is used solely for authentication and is not used for surveillance, monitoring, or any purpose that violates the X Developer Policy.

14.3 LinkedIn — Restricted API Use

We access LinkedIn data only through officially approved API products. We do not scrape LinkedIn data, and we do not use LinkedIn data for any purpose other than user authentication and profile setup.

14.4 TikTok — Developer Terms Compliance

We comply with TikTok's Developer Terms of Service. Login data obtained from TikTok is not used for content scraping, automated posting, or any purpose beyond authentication.

14.5 Google — Limited Use Disclosure

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

We encourage you to review this policy periodically. Your continued use of social login after changes are posted constitutes acceptance of the updated policy.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Eyexapp Teknoloji A.Ş. (operating Eyexapp & Weblapp brands)
Fenerbahçe Mah. İğrip Sk. No: 13, 34726 Kadıköy, İstanbul, TÜRKİYE
Email: privacy@eyexapp.com
General: hello@eyexapp.com
Phone: +90 553 597 4412
Website: eyexapp.com

For data protection inquiries in the European Union, you may also contact your local Data Protection Authority. For Türkiye, you may contact the Kişisel Verileri Koruma Kurumu (KVKK).

Related Documents

← Back to Home