Privacy Policy

Last updated August 8, 2026 · v2

Privacy Policy

Last updated: 30 June 2026

This Privacy Policy explains how rategale ("rategale", "we", "us") collects, uses, shares and protects your personal data when you use our websites, mobile apps and related services (together, the "Platform"). It applies to everyone who uses rategale, anywhere in the world.

rategale is a hybrid platform with three connected worlds: business reviews (rating and reviewing businesses), a social network (posts, reels, stories, polls, comments, direct messages, following) and user-to-user ratings. Because the Platform combines these functions, this policy covers a broad range of data.

We act as the data controller for your personal data. Our identity and contact details are in the [Imprint](/legal/imprint). For data-protection questions you can reach our Data Protection contact at [dpo@rategale.com].

> This document is written to reflect how the Platform actually works. It is a > baseline and should be reviewed by qualified legal counsel before you rely on it.


1. Data we collect

1.1 Data you provide when you sign up and use your account

  • Identifiers: email address (and a normalized form used to detect duplicate

accounts and resolve logins), optional phone number, an auto-generated username (which you may later change), and your password (stored only as an Argon2id hash — we never store your password in plain text).

  • Date of birth and age class: we derive whether you are a minor (13–17) or an

adult (18+). You must be at least 13 to use rategale (see §9).

  • Parental contact (minors only): if you are 13–17 you may provide a

parent/guardian email for awareness. It is deleted automatically when you turn 18.

  • Sign-up intent: whether you joined as a consumer, business owner or creator —

used to tailor onboarding. It does not restrict what you can do.

  • Authentication choices: Google or Apple sign-in, magic links, passkeys

(WebAuthn), QR login, and optional two-factor authentication (TOTP) with backup recovery codes.

1.2 Profile data

Anything you add to your profile: display name, bio, avatar and cover images, gender, pronouns, birthday (with your chosen visibility), city and country, external links (website, Instagram, X, LinkedIn, TikTok, YouTube), spoken languages, and optional rich sections such as work history, education, life events, relationships and family links. Relationship and family links between accounts are only shown with the mutual consent of both people.

1.3 Content you create

Reviews, posts, reels, stories, polls, comments, reactions, reposts, bookmarks, direct messages, review conversations with businesses, and the media (images, video, audio) you upload. Your content may be public, limited to followers/friends/close friends, or private, depending on the settings you choose.

1.4 Media and metadata

When you upload an image or video we keep the original on our storage and generate resized/optimized versions to serve. The publicly served versions have location and camera EXIF metadata stripped. We retain the original metadata (which may include GPS coordinates, device model and timestamps) on our backend, encrypted at rest, for safety, fraud prevention and legal/moderation purposes. You can view the EXIF of your own uploads; staff access to it is logged and audited. If you delete your data, the retained metadata is deleted too.

All uploaded images and videos are automatically checked against child sexual abuse material (CSAM) hash databases (PhotoDNA / NCMEC). Matches are quarantined and reported as required by law.

1.5 Device, technical and security data

  • Session and login data: access/refresh tokens, device information (user agent,

operating system, browser), IP address, approximate location from IP (country and city via MaxMind GeoLite2), and timestamps. You can view and revoke your active sessions and login history at any time.

  • Security signals: a hashed device fingerprint and behavioural signals

(e.g. typing and form-completion patterns) collected at sign-up. These are used only to prevent bots, fake accounts and multi-account abuse — never for advertising or personalization. The device fingerprint hash is purged 30 days after account deletion.

  • Impossible-travel detection: we may flag logins from distant locations in a

short time as a security event and ask you to re-authenticate.

1.6 Location data

  • Approximate location (from IP): used to show relevant local content and for

security. Roughly city-level accuracy.

  • Precise location (GPS): collected only if you explicitly opt in through a

browser or device permission, for features such as "discover nearby". You can withdraw this permission and delete the stored location at any time.

  • Smart locale: by default the feed, search and suggestions are tuned to your

location and language. You can turn this off in settings.

1.7 Contacts (only if you choose to upload them)

If you use contact-based friend suggestions, we match contacts using one-way hashes of emails and phone numbers (SHA-256) rather than storing the raw contacts. This feature is rate-limited and entirely optional.

1.8 Advertising and interaction data

rategale shows ads. Ad targeting is computed server-side from your account attributes (such as age range, language, country/city, interests and on-platform activity). We do not use third-party advertising cookies or cross-site trackers, and we do not sell your personal data. We record ad impressions and clicks, and you can see "why am I seeing this ad". See §6 for your ad controls.

1.9 Derived data

We compute aggregates and signals such as your customer-rating average (how businesses rated you as a customer), user-to-user rating aggregates, personalization signals, and content/engagement statistics.


2. Why we use your data (purposes)

  • To create and operate your account and provide the Platform's features.
  • To display your content and the reviews/conversations you take part in.
  • To personalize your feed, search and suggestions (you can opt out).
  • To show and measure advertising (with the controls in §6).
  • To keep the Platform safe: prevent spam, bots, fake accounts, fraud, harassment and

abuse; moderate content; and run CSAM detection.

  • To communicate with you (service messages, security alerts, and — if you opt in —

digests and notifications).

  • To comply with legal obligations and respond to lawful requests.
  • To analyze and improve the Platform using aggregated/de-identified data.

3. Legal bases

Where data-protection law (such as the EU/UK GDPR and Türkiye's KVKK) applies, we rely on:

  • Performance of a contract — to provide the service you signed up for.
  • Consent — for precise GPS location, contact upload, personalized advertising,

optional analytics and certain notifications. You can withdraw consent at any time.

  • Legitimate interests — for security, fraud/abuse prevention, basic analytics

and improving the Platform, balanced against your rights.

  • Legal obligation — for example CSAM detection/reporting, tax and record-keeping,

and responding to lawful requests.

4. How long we keep data

We keep personal data only as long as needed for the purposes above:

  • Active account: for the life of your account.
  • Deactivation: profile and content are hidden; you can reactivate within 180 days.
  • Deletion: after a 30-day grace period (which you can cancel by email link), we

permanently delete or anonymize your personal data. The hashed device fingerprint is purged within 30 days of deletion.

  • Published reviews are permanent. To keep the public review record honest and

complete, reviews and reposts are not deleted when an account is removed; they remain shown as authored by a "Deleted account". Other content (posts, reels, stories, polls, comments) is deleted with the account.

  • Direct messages: when you delete your account, your copies are removed; the

other participant still sees the conversation, attributed to a "Deleted account".

  • Security, audit and moderation logs are retained for defined periods (some up to

5 years) where required for safety and legal compliance.

5. Who we share data with

We do not sell your personal data. We share it only as follows:

  • Other users / the public, according to your visibility settings (your public

profile, public posts, public reviews and aggregates).

  • Businesses you interact with — when you review a business, a private

conversation opens; the business sees your review and your messages in it. Ad targeting is anonymous in aggregate — businesses never see who their audience is.

  • Service providers (processors) acting on our instructions, such as: cloud and

object storage, IP-geolocation (MaxMind), CSAM detection (PhotoDNA/NCMEC), email and SMS delivery, push-notification delivery, and payment processing for advertisers.

  • Authorities and legal — when required by law, court order, or to protect rights,

safety and the integrity of the Platform.

  • Corporate transactions — in a merger, acquisition or restructuring, with

safeguards and notice where required.

6. Advertising controls

  • Personalized ads: you can turn off ad personalization in settings; you will then

see non-targeted ads. For minors (13–17) personalized ads are always off.

  • Category opt-out: you can block ad categories you do not want to see

(e.g. alcohol, gambling, diet).

  • Transparency: every ad lets you see "why am I seeing this ad", and your ad

targeting profile is included in your data export.

7. Your rights

Depending on where you live, you have rights to access, rectify, erase, restrict and object to processing, to data portability, and to withdraw consent. You can exercise most of these directly in the app, and request a full data export or account deletion in settings. For details and how to submit a request, see [Your Data Rights](/legal/data-rights). You also have the right to lodge a complaint with your local data-protection authority (in Türkiye, the KVKK Authority).

8. Security

We use industry-standard measures including encryption in transit, encryption at rest for sensitive stored data, Argon2id password hashing, refresh-token rotation with leak detection, account-lockout and step-up authentication for sensitive actions, optional two-factor authentication, and audited staff access. No system is perfectly secure, but we work continuously to protect your data.

9. Children

rategale is not for children under 13, and sign-ups under 13 are rejected. Users aged 13–17 have additional protections by default: personalized ads are off, sensitive content is hidden, certain messaging and rating features are restricted, and appearance-related ratings cannot be made about them.

10. International transfers

rategale is an international platform. Your data may be processed in countries other than your own. Where required, we use appropriate safeguards (such as standard contractual clauses) for international transfers.

11. Changes to this policy

We may update this policy. We will change the "Last updated" date and, for material changes, provide additional notice. Continued use after changes means you accept the updated policy.

12. Contact

For privacy questions or to exercise your rights, contact [privacy@rategale.com] or our Data Protection contact at [dpo@rategale.com]. Our legal entity and postal address are in the [Imprint](/legal/imprint).

© 2026 rategale

Privacy Policy | rategale