Privacy Policy
Last updated: August 3, 2026
This Privacy Policy explains how Smoky collects, uses, discloses, retains, and protects personal data when you use the Smoky mobile application, website, support channels, and related services (collectively, the “Service”). It also explains the choices and rights available to you. It is an information notice and does not itself constitute consent.
1. Data Controller
Ali Yıldırım, an individual business operator established in Türkiye and operating under the Smoky and Roya Tech Studios brands, is the controller of personal data processed for the Service. You can contact us at [email protected].
2. Scope
Smoky helps users locate designated smoking areas and request walking directions. This Policy applies to data processed through the Service. It does not govern a third party’s independent processing under its own policy, including an app store, map provider, or advertising provider.
3. Data We Process
3.1 Location and map requests
- Your device location, if you grant permission and use a nearby-location or route feature.
- An approximate map area, selected spot identifier, route endpoints, and the search or route request needed to return nearby spots or directions.
Smoky does not require continuous background location access. You can deny or revoke location permission in device settings, but location-dependent features may not work. Depending on the requested feature, location or route coordinates may be transmitted to our systems and a map or routing provider; they are not only processed on your device.
3.2 App, device, and usage data
- A device-generated or app-install identifier used for route limits, subscription entitlement, rewards, security, and abuse prevention.
- App version, device and operating-system information, language, general region, IP address, request timestamps, and server or diagnostic logs.
- Feature interactions such as searches, selected places, route requests, reward events, sponsor-card impressions and clicks, and error events.
3.3 Purchases and subscriptions
We receive purchase and entitlement information such as product, store, subscription status, renewal or expiration status, and transaction or app-user identifiers from Apple, Google, and RevenueCat. We do not receive your full payment-card details from app-store purchases.
3.4 Advertising and consent data
Google AdMob and Google User Messaging Platform may process advertising identifiers, device and network information, ad interactions, reward verification, and privacy-consent signals. Personalized advertising or cross-app tracking is used only where allowed and after any consent or platform permission required by law. If you decline, you may still receive contextual or non-personalized ads.
3.5 Communications and submissions
If you contact us or submit a correction, suggestion, image, description, or other material, we process your contact details, message, attachments, related metadata, and the information you choose to provide.
3.6 Website data
When you visit our website, hosting and security providers may process IP address, browser and device information, requested pages, timestamps, referrer information, and security logs. We will provide any legally required cookie or tracking choices before using non-essential website technologies.
4. How and Why We Use Data
We process the data described above to:
- show nearby spots, place details, maps, and walking routes;
- operate route limits, subscriptions, purchase restoration, and rewards;
- remember settings and provide requested support;
- maintain, diagnose, secure, and improve the Service;
- detect fraud, abuse, outages, and violations of our Terms;
- measure feature, sponsor, promotion, and advertising performance;
- verify and improve place, map, search, and route information;
- comply with legal obligations and establish or defend legal claims.
We may create aggregated or de-identified information that does not reasonably identify you and use it for analytics, research, security, statistics, and product development. We do not attempt to re-identify properly de-identified data unless needed to test our safeguards or permitted by law.
5. Legal Bases
Where a legal basis is required, we rely on the following:
- Performance of a contract or steps you request: to provide maps, routes, accounts, support, subscriptions, and rewards.
- Legitimate interests: to secure and improve the Service, prevent abuse, measure basic performance, maintain records, and defend claims, where those interests are not overridden by your rights.
- Consent: for device location permission, personalized advertising, tracking, or another optional use where consent is legally required. Consent may be withdrawn without affecting earlier processing.
- Legal obligation: to meet tax, accounting, regulatory, consumer-protection, authority-request, and other legal requirements.
- Legal claims and vital interests: where processing is necessary to protect a person or establish, exercise, or defend a claim.
Under Türkiye’s Law No. 6698, these bases correspond, as applicable, to express legal authorization, contractual necessity, legal obligation, establishment or protection of a right, legitimate interests that do not harm fundamental rights, and explicit consent where no other condition applies. Any request for explicit consent is presented separately from this notice.
6. When We Disclose Data
We disclose only the data reasonably necessary to:
- Service providers: cloud hosting, database, security, analytics, customer support, email, map, routing, and technical vendors.
- Platform and commerce providers: Apple, Google, and RevenueCat for distribution, billing, subscription, entitlement, and purchase restoration.
- Advertising providers: Google AdMob and related consent tools for ad delivery, measurement, fraud prevention, and rewards, subject to your choices and applicable law.
- Authorities and legal recipients: when required by law or reasonably necessary to protect rights, safety, and the Service.
- Transaction parties: advisers and a buyer, investor, successor, or counterpart in a proposed or completed business transfer, subject to confidentiality and applicable law.
We require processors acting for us to handle personal data under our instructions, apply appropriate safeguards, and provide protection consistent with this Policy and applicable law.
7. International Transfers
We are based in Türkiye, while providers such as Apple, Google, RevenueCat, map providers, and cloud vendors may process data in Japan, the European Economic Area, the United States, Türkiye, or other countries. These countries may have different privacy laws.
Where required, we use a legally recognized transfer mechanism, such as an adequacy decision, approved standard contractual clauses or contracts, binding corporate rules, another statutory safeguard, or explicit consent for a specific transfer when no other lawful mechanism is available. We also assess providers and apply technical and organizational safeguards appropriate to the transfer.
8. Retention
We keep personal data only as long as reasonably necessary for the purpose collected, including to provide the Service, maintain security, resolve disputes, and meet legal obligations. Retention is determined by data type, sensitivity, risk, user expectations, and applicable limitation, tax, accounting, and consumer-protection periods.
- Transient location and route inputs are kept only as needed to fulfill the request and maintain short-term security and diagnostic logs, unless a longer period is required for an investigation or by law.
- Install, usage, reward, and diagnostic records are kept while needed for the feature and ordinarily no longer than 24 months after collection.
- Subscription and transaction-related records may be retained for the subscription and the applicable legal, audit, refund, and dispute period.
- Support messages and submissions are kept while the request remains relevant and ordinarily no longer than three years after closure.
We may retain a record longer where law, fraud prevention, an active dispute, or a valid preservation request requires it. When retention ends, data is deleted, anonymized, or securely isolated until deletion from backups under the normal backup cycle.
9. Your Choices
- Disable or change location access in your device settings.
- Change advertising and consent choices through the in-app consent tool and applicable iOS or Android privacy settings.
- Reset or limit the platform advertising identifier where supported.
- Cancel subscriptions through Apple or Google Play settings.
- Request access, correction, deletion, or another applicable privacy action by emailing [email protected].
Deleting the app does not cancel a subscription and may not delete records held by an app store or another independent controller.
10. Your Privacy Rights
Depending on where you live, you may have rights to know whether and how we process your data; access it; correct it; delete it; restrict or object to processing; withdraw consent; receive portable data; learn the recipients of disclosures; object to certain automated decisions; and complain to a competent privacy authority.
Residents of Türkiye may exercise the rights in Article 11 of Law No. 6698, including learning the purpose of processing and whether data is used accordingly, learning recipients in Türkiye or abroad, requesting correction or deletion where conditions are met, and seeking compensation for damage caused by unlawful processing.
We may verify your identity and request information needed to locate your records. Authorized-agent requests require proof of authority. We will respond within the period required by applicable law and will explain any lawful refusal. You will not be discriminated against for exercising a privacy right.
11. Advertising Disclosures
We do not sell personal data for money. Advertising-provider disclosures for personalized advertising or cross-context behavioral advertising may be treated as a “sale,” “sharing,” or targeted advertising under some laws. Where those laws apply, you may opt out using the in-app consent controls, platform privacy settings, or by contacting us. We do not knowingly sell or share personal data of users under 16 for those purposes.
12. Children
The Service is not directed to children, and we do not knowingly collect personal data from anyone under 13 or the higher minimum age required in their jurisdiction without legally valid parental authorization. If you believe a child has provided personal data, contact us so we can review and delete it where required. The Service does not promote tobacco or nicotine use to minors.
13. Security
We use reasonable technical and organizational safeguards appropriate to the nature and risk of the data, including access controls, data minimization, transport encryption where supported, provider review, logging, and incident response measures. No system is completely secure, and we cannot guarantee absolute security. If a breach requires notice, we will notify affected users and authorities as required by law.
14. Automated Decisions
Automated systems may apply route quotas, detect suspected abuse, verify ad rewards, or determine subscription access. These routine decisions are not intended to produce legal or similarly significant effects. Contact us if you believe an automated result is incorrect. We will provide any additional rights required by applicable law.
15. Japan and Other Regions
Because Smoky is initially focused on Japan, Japan’s Act on the Protection of Personal Information may apply to relevant processing. We handle requests and disclosures required by that law, including requests concerning retained personal data, subject to its conditions and exceptions. Additional local terms apply only to the extent required and do not reduce rights granted by mandatory law.
16. Changes to This Policy
We may update this Policy to reflect changes in the Service, providers, law, or our practices. We will post the revised date and, where required, give additional notice or obtain consent before materially different processing. We encourage you to review this page periodically.
17. Contact and Complaints
Smoky / Roya Tech StudiosData controller: Ali Yıldırım
Country: Türkiye
Email: [email protected]
Website: https://smoky.royatech.co
Please use the subject line “Privacy Request” and describe your request and jurisdiction. You may also complain to the competent data protection authority, including Türkiye’s Personal Data Protection Authority, Japan’s Personal Information Protection Commission, or the authority where you live, where applicable.