AppShiner
GDPR & KVKK Compliant Data Governance

Privacy Policy & Data Protection Statement

Last Updated: September 27, 2026 • Version 2.1

Zero Code Invasion

No SDK or source code access required. We only inspect publicly available store listings and web endpoints.

PCI-DSS Level 1

Payments are processed securely via Lemon Squeezy (Merchant of Record). AppShiner never stores card numbers.

Full Data Ownership

You retain 100% intellectual property rights over your application, metrics, and generated audit reports.

1. Overview & Scope of This Policy

This Privacy Policy explains how AppShiner ("we", "our", or "the Platform") collects, uses, and safeguards information when you visit appshiner.com, register an account, or order an application health audit. We are committed to upholding the highest standards of data integrity under the General Data Protection Regulation (GDPR - Regulation EU 2016/679) and Turkish Personal Data Protection Law (KVKK No. 6698).

2. Information We Collect

  • Account Data: Name, work email address, and encrypted credentials when registering an account.
  • Application Audit Metadata: Public App Store or Google Play URLs, application titles, categories, and client notes submitted for inspection.
  • Billing Information: Transaction identifiers, currency, and purchase timestamps. Actual cardholder details (PAN, CVV) are processed exclusively by our Merchant of Record, Lemon Squeezy Inc., in a secure PCI-DSS Level 1 environment.
  • Technical Session Telemetry: Anonymized browser type, IP address, and interface interactions used strictly for dashboard security and rate limiting.

3. Non-Invasive "Black-Box" Methodology

AppShiner operates strictly as an external, black-box diagnostic engine:

  • We never request access to your private GitHub/GitLab repositories, production databases, or confidential server credentials.
  • We do not require installing SDKs, tracking pixels, or diagnostic daemons in your production binary code.
  • All automated UI/UX and marketplace benchmarking is performed using public store metadata, headless browser rendering, and visual heuristics.

4. How We Use Your Data

We use collected information solely to:

  • Generate, verify, and deliver your comprehensive multi-module application health report.
  • Notify you via email when a senior specialist has finalized and approved your audit deliverable.
  • Facilitate customer support inquiries and quality re-inspection requests.
  • We never sell, lease, or monetize your data, contact info, or audit reports to third-party ad networks or brokers.

5. Your Legal Rights (GDPR & KVKK Compliance)

Under applicable data protection legislation, you possess the right to:

  • Access: Request a complete copy of all personal data and audit reports stored on your account.
  • Rectification: Request correction of inaccurate contact or company details.
  • Erasure ("Right to be Forgotten"): Request complete deletion of your account, past audit history, and associated records from our servers.

To exercise any of these rights, email our Data Protection Desk at privacy@appshiner.com. We respond within 3 business days.

6. Security & Infrastructure

AppShiner enforces industry-standard 256-bit TLS/SSL encryption for all web communications and REST API endpoints. Internal database files are safeguarded by strict file system web configurations preventing unauthorized directory traversal or public indexing.