Türkçe

Privacy Policy

Last updated: 12 August 2026

This policy explains what data the Jukebox service at jukebox.net.tr processes. The service has two kinds of user: venue owners (the businesses running the jukebox) and guests (people who scan a QR code and request a song).

Data controller

Muhammedcan Pirinççi
Email: destek@jukebox.net.tr

The person named above is the data controller under Turkish Personal Data Protection Law no. 6698 (KVKK).

1. Signing in with Google

Signing in is only possible with a Google Account. Google passes us your identity details only: name, email address, profile picture and your Google account id. We never see or store your password.

We use this to create your account, keep you signed in, and attach your requests to your account.

2. Access to YouTube data (venue owners only)

When you sign in as a venue owner we additionally ask for the youtube.readonly permission. That permission is read-only: we cannot change or delete anything in your YouTube account, upload videos, or comment on your behalf.

What we access and store with it:

  • The title, cover image and video count of your playlists — so you can choose in the dashboard which ones to open to guests.
  • The title, channel name, thumbnail and duration of the videos in the playlists you selected — so guests can search them and so we can work out how long the queue will run.
  • The access and refresh tokens Google issues — so we can sync your playlists without you signing in again every time.

Guests are never asked for any YouTube permission. Guest sign-in is for identity only.

Video data is held in a cache belonging to your venue alone. Videos you delete on YouTube, or remove from a playlist, disappear from our records at the next sync.

As required by the YouTube API Services Developer Policies, YouTube data that has not been refreshed within 30 days is deleted automatically. A job runs daily to enforce it: if a venue stops syncing, its playlist and video records are permanently removed from the system at the end of those 30 days.

3. YouTube API Services

This application uses YouTube API Services. By using the service you agree to the YouTube Terms of Service. How Google processes your data is described in the Google Privacy Policy.

You can revoke the access you granted us at any time from the Google security settings page. Once revoked, our access to your YouTube account ends; the tokens and playlist cache we stored are deleted as soon as the revocation is detected, and in any case removed within the 30-day period the YouTube API policies require.

You can do the same from the dashboard with Disconnect YouTube, which also revokes the grant on Google's side.

4. Data created by using the service

  • Song requests: which guest requested which song and when. Needed to run the queue, apply the venue's rules (waiting time, how many songs at once) and show the venue its statistics.
  • Coin balance and movements: coins bought, spent and refunded.
  • Subscription records: the venue's plan, start and end date, and payment status.

The statistics shown to a venue are aggregate counts; a venue owner cannot see guests' email addresses.

5. Payments

Payments are taken through iyzico. Your card number, expiry date and CVC go directly to iyzico; they never reach our servers and are never stored by us. We keep only the amount, date and status of the payment and the transaction reference iyzico returns.

6. Cookies

We use only the cookies the service needs to work: the session cookie (which remembers that you are signed in) and your theme preference. We use no advertising or third-party tracking cookies.

7. Who we share data with

We do not sell your data. To run the service we work only with these providers: Google/YouTube (sign-in and playlist data, USA), iyzico (payments, Türkiye), Vercel (hosting; servers run in Frankfurt, the provider is US-based) and Neon (database, Frankfurt/Germany). We may share data with the authorities where a legal obligation arises.

Because some of these providers are located outside Türkiye, your personal data is transferred abroad within the meaning of KVKK art. 9.

8. What we never use your data for

We use the data we access through Google/YouTube only to provide the functions described above. We never use it for:

  • Serving targeted advertising or building advertising profiles,
  • Selling it to data brokers or any other third party,
  • Credit assessment, scoring or similar purposes,
  • Training, developing or improving artificial-intelligence or machine-learning models,
  • Any other purpose not required to operate the service.

Humans do not read your data. The only exceptions are resolving a support request with your explicit permission, investigating a security problem, or complying with a legal obligation.

9. How we protect sensitive data (security measures)

We treat the following as sensitive data and protect it with the measures set out below: Google user data (your name, email address and profile picture), the YouTube data obtained under the youtube.readonly scope (your playlist and video metadata), and the OAuth access and refresh tokens that grant access to it.

  • Encryption in transit. All traffic between your browser, our servers and Google's APIs is carried over HTTPS/TLS. Plain HTTP requests are redirected to HTTPS; we make no unencrypted call to any Google API.
  • Encryption at rest. The OAuth access and refresh tokens Google issues are encrypted with AES before they are written to the database, so they are not readable in the stored data. The encryption key is held as an environment secret in the application runtime, never in the database and never in source control. The database itself is also encrypted at rest by our hosting provider.
  • Access control. The database is not reachable from the public internet; only the application server may connect, over a TLS connection with credentials held as environment secrets. Those credentials are known only to the data controller named above. No employee, contractor or third party has access; there is no administrative interface that exposes another user's Google data.
  • Least privilege at the source. We request read-only YouTube access, so even a full compromise of our systems could not be used to modify or delete anything in your YouTube account.
  • Isolation between tenants. Every query for playlist or video data is scoped to the owning venue, so no venue can read another venue's data, and venue owners cannot see guests' email addresses — only aggregate counts.
  • No credentials of our own to leak. Authentication happens entirely on Google's side; we never see or store a password. Card details go directly to our payment provider and never reach our servers.
  • Minimisation and deletion. We store only the playlist and video metadata the features need, and delete YouTube data that has not been refreshed within 30 days automatically. Revoking access deletes the stored tokens and the cached playlist data.
  • Patching. Application dependencies are kept current and security updates are applied when published.

No system is 100% secure. Should a breach affect your personal data, we will inform you and the Turkish Personal Data Protection Board as required by KVKK art. 12.

10. Retention and deletion

Data is kept for the following periods, by category:

  • Account details — for as long as your account exists.
  • YouTube playlist and video cache — 30 days at most; deleted automatically if not refreshed within that time.
  • YouTube tokens — for as long as the authorisation lasts; deleted on revocation.
  • Song requests — detached from the person when your account is deleted; the record survives only as an anonymous count.
  • Payment and accounting records — for the statutory retention period required by law.

You can delete your account and its data yourself from the dashboard. You may instead write to destek@jukebox.net.tr; requests are carried out within 30 days. If you revoke your YouTube permission, the stored tokens become invalid and your playlist cache is deleted.

Accounting law requires payment records to be kept for the statutory period even after an account is deleted.

11. Your rights

Under KVKK art. 11 you have the right to:

  • Learn whether your personal data is being processed,
  • Request information about it if it has been processed,
  • Learn the purpose of processing and whether it is used in line with that purpose,
  • Know the third parties, in Türkiye or abroad, it has been transferred to,
  • Request correction if it has been processed incompletely or incorrectly,
  • Request its erasure or destruction under the conditions set out in the law,
  • Request that correction, erasure and destruction be notified to the third parties it was transferred to,
  • Object to a result against you produced solely by automated analysis,
  • Claim compensation for damage suffered as a result of unlawful processing.

To exercise these rights, write to destek@jukebox.net.tr.

12. Contact

For any questions: destek@jukebox.net.tr

13. Language

This is a translation provided for convenience. In the event of any discrepancy, the Turkish version of this policy prevails.