Privacy Policy
Privacy Policy
Tourist City Itinerary Planner (also shown on the device as Trip Plan, localized in the device language)
Last updated: 13 August 2026
This policy: https://tripplan.morrowline.app/en/privacy/
Terms of Use: https://tripplan.morrowline.app/en/terms/
1. Introduction
This Privacy Policy describes how Seyfi Can Zeyrek (“we”, “us”) processes personal data when you use the Tourist City Itinerary Planner mobile application on Android and iOS.
2. Data controller
Controller: Seyfi Can Zeyrek
Address: Esenyalı Mahallesi, 35140, Karabağlar/İzmir, Türkiye
Privacy and support email: sczgamesinfo@gmail.com
Telephone: not published; contact by email.
No data protection officer is appointed. Use the email above.
EU Digital Services Act trader contact (we offer the app to consumers in the EU):
Seyfi Can Zeyrek, Esenyalı Mahallesi, 35140, Karabağlar/İzmir, Türkiye, sczgamesinfo@gmail.com.
Google Play seller name: Morrowline Apps. Apple App Store seller name: Seyfi Can Zeyrek.
Turkish users: a separate KVKK information notice is published with this policy.
3. Scope
This policy covers the Android and iOS apps version 1.0.0 and later, including onboarding, itinerary planning, city guides, ads on the free tier, and the lifetime in-app purchase. It does not cover third-party websites or maps you open from the app.
4. Data we collect
| Category | Examples | Purpose | Location | Retention | Shared with |
|---|---|---|---|---|---|
| Account identifier | Firebase anonymous UID | Run the app; attach analytics, crash reports, and purchases | Google Firebase (United States); a copy of the UID may be stored on device | Until you ask us to delete the identifier, or you uninstall (device copy) | Google; RevenueCat |
| Settings and preferences | Destination, trip length, companion type, interests, budget; saved places; completed days; onboarding/paywall flags; 3-day trial start time | Remember your plan and unlock state | On your device | Until uninstall or you clear app data | Not uploaded to our Firestore |
| Diagnostics | Crash logs, device model, OS version | Fix crashes | Google Crashlytics | Google’s Firebase default | |
| Analytics | App instance ID; anonymous login event | Understand use of the app | Google Analytics | Google’s Firebase default | |
| Advertising data | Advertising ID (GAID/IDFA) after required consent; ad events | Ads on the free tier | Google AdMob | Google Ads retention | |
| Purchase history | RevenueCat user ID; lifetime entitlement; store transaction IDs | Unlock premium; restore | RevenueCat; Apple; Google Play | Store and RevenueCat records | RevenueCat; Apple; Google |
| Security | Firebase App Check attestation | Reduce abuse | Session / Firebase default | ||
| Push token | FCM token | Deliver notifications if you allow them | On the device | Until you revoke permission or uninstall | Google issues the token; this app version does not save it in Firestore |
| Fonts | IP address when fonts load | Display typefaces | Google Fonts | Per Google Fonts | |
| Onboarding notes | Optional free text (for example mobility or diet) | Shown only on that screen | Memory only | Not saved after you leave the step | Not shared |
We do not currently read, store, or send GPS coordinates. We do not collect your name, email (unless you email us), payment card numbers, contacts, photos, or HealthKit data.
City guides, destination lists, and images hosted on Firebase are publisher content, not your personal trip file.
5. How we collect
- Automatically: anonymous sign-in, analytics, crash reporting, App Check, ads SDKs, font download, FCM token if notifications are allowed, purchase receipts through the stores and RevenueCat.
- From you: onboarding choices and saved places stored on the device; optional location permission (not coordinates).
- From Apple or Google: purchase validation.
6. Why we use data
To provide itineraries and guides, remember local preferences, secure the backend, measure stability and usage, show ads to non-premium users, and restore the lifetime purchase.
7. Legal bases (EEA / UK)
Contract: providing the app and restoring purchases.
Legitimate interests: App Check, security, some analytics.
Consent: personalized advertising (UMP in the EEA/UK; App Tracking Transparency on iOS).
Legal obligation: when the law requires us to keep or disclose information.
You may withdraw consent for personalized ads in the consent form, iOS Tracking settings, or Android advertising settings without losing the core planner.
8. Sensitive permissions
Location (when in use)
We may ask for location so nearby-place features can work in a later version. We do not currently access GPS, verify visits, calculate live travel times from your position, or send coordinates to our servers. You may skip or revoke the permission and still use plans, guides, and saved places.
Notifications
Optional. Used for Firebase Cloud Messaging. Not required for planning.
Tracking (iOS)
Used to deliver personalized ads if you allow tracking.
We do not use Accessibility, Usage Access, camera, microphone, or HealthKit.
9. Sharing and processors
We share data with processors who help us run the app:
- Google — Firebase Authentication, Cloud Firestore, Cloud Storage, Analytics, Crashlytics, Cloud Messaging, App Check, AdMob, Google Fonts
- RevenueCat — purchase entitlements
- Apple and Google Play — billing
We do not sell your data for money. Advertising on the free tier may share identifiers with Google for ads (see California section).
10. International transfers
The Firebase project touristictripcityplan uses Firestore in region nam5 (United States). RevenueCat and Google also process data in the United States. Transfers from the EEA/UK use the safeguards in those vendors’ terms (including Standard Contractual Clauses where applicable).
11. Retention
On-device preferences last until uninstall or data clear. The app-granted trial timestamp is on device only. Cloud identifiers last until you request deletion or the vendor’s default period. Store purchase records follow Apple and Google.
12. Your rights
EEA / UK: access, correction, erasure, restriction, objection, portability, withdraw consent, complain to a supervisory authority (or the ICO in the UK).
Türkiye: rights under KVKK Art. 11, as described in the Turkish information notice.
California: know, delete, correct, and opt out of sharing for cross-context advertising. We do not sell personal information for money. We may share advertising identifiers with Google on the free tier. Email sczgamesinfo@gmail.com with the subject “Do Not Share” or use device ad/tracking settings. We will not discriminate against you for exercising these rights.
To exercise rights, email sczgamesinfo@gmail.com. If you know your anonymous UID, include it to help us find records.
13. Account and deletion
The app signs you in anonymously. That creates an identifier. It is not a named login. The app is not identifier-free.
Delete: email sczgamesinfo@gmail.com from a mailbox we can reply to, ask us to delete your anonymous identifier, and include the UID if you have it. We will delete or unlink Firebase Auth, Analytics, Crashlytics, and RevenueCat identifiers we control. Uninstalling the app deletes on-device preferences. Store purchase history remains with Apple or Google. There is no in-app delete button in this version.
14. Children
The app is for users 13 or older. We do not direct the app at children under 13. If you believe a child under 13 used the app, contact us and we will delete identifiers we hold.
15. Security
We use HTTPS, Firebase App Check, and store SDKs. No method is perfectly secure.
16. Automated decisions
We do not make solely automated decisions with legal or similarly significant effects. Suggested walking routes are informational.
17. Changes
We will update this page and the last_updated date. Material changes will be highlighted in the app or on the website when practical.
18. Contact
Seyfi Can Zeyrek
Esenyalı Mahallesi, 35140, Karabağlar/İzmir, Türkiye
sczgamesinfo@gmail.com
EU trader contact: same name, address, and email.
Related: Terms of Use

