Privacy Policy
Board & Pieces is operated by Mathome Yazılım Ltd. Şti. (“Mathome,” “we,” “us”). This policy explains what personal data we collect when you use the Board & Pieces mobile app or visit boardandpieces.com, why we collect it, who we share it with, and the rights you have over it.
Effective date: 1 June 2026.
1. Who we are
The data controller responsible for your personal data is:
Mathome Yazılım Eğitim Danışmanlık Sanayi ve Ticaret Limited Şirketi
Gebze OSB Mah. Kemal Nehrozoğlu Cad. No: 507/9 İç Kapı No: Z01
Gebze / Kocaeli, Türkiye
İlyasbey Vergi Dairesi — VKN 6131907545
Contact: support@boardandpieces.com
Mathome is registered with the Turkish Data Controllers' Registry (VERBİS) as required under Law No. 6698 on the Protection of Personal Data (“KVKK”).
2. Scope
This policy applies to the Board & Pieces iOS and Android apps, the boardandpieces.com website, and any related services we provide. It does not apply to third-party services we link to (for example, Apple App Store or Google Play product pages), which are governed by their own privacy policies.
3. What we collect
We collect only what we need to make Board & Pieces work. The categories below are exhaustive — if it is not on this list, we do not collect it.
3.1 Account data
- Identifiers from your sign-in provider — when you sign in with Apple or Google, we receive a unique user ID, your display name (if provided), and an e-mail address (which may be a relay address you control, e.g. an Apple private relay). We do not receive your sign-in password.
- Profile fields you choose to add — display name, profile photo, country flag.
3.2 Game activity
- Games you create, join, accept, decline, forfeit, or finish; the moves you make; chat consent state; ELO and win/loss counters per game type.
- Group and venue memberships, role (member / admin / sponsor), and credit-ledger entries (no payment card data — see §3.6).
- Tutorial progress per game (which lessons you have completed).
3.3 Approximate location (opt-in)
To show you nearby venues and players, Board & Pieces requests location permission when you open the “Near me” section. When granted:
- We compute your approximate position only — a 75-metre presence check against venue coordinates. We do not store your precise GPS coordinates and we do not build a location history.
- Location is read only while the app is in the foreground; we do not run a background location service.
- Your presence at a venue auto-expires after 15 minutes of inactivity. There is no historical record of where you have been once that window passes.
- We never sell location data and never share it with advertisers.
You can revoke location permission at any time in iOS Settings → Privacy → Location Services, or Android Settings → Apps → Board & Pieces → Permissions.
3.4 In-game chat messages
When you and your opponent both opt in to chat during a game, the messages you send are stored on our servers only for the duration of that game. When the game ends (finished, forfeited, or abandoned), every message in that game is permanently deleted, including from the post-game result screen. There is no chat history, no archive, and no way for you, your opponent, or Mathome to retrieve the messages afterwards.
The one exception: if a message is reported for moderation (harassment, hate speech, etc.) before the game ends, a snapshot of that specific message and the report metadata is kept in a separate moderation queue accessible only to Mathome staff under §6, until the report is reviewed and acted upon (at most 90 days), then deleted.
3.5 Device + technical data
- Push notification token — issued by Apple (APNs) or Google (FCM) so we can deliver invites, game-turn alerts, and re-engagement pings you have opted in to. You can revoke per-category in Settings → Notifications.
- Device type, OS version, app version, language — used to deliver the correct build, debug crashes, and localise the UI.
- IP address (server-side only) — automatically logged on incoming HTTPS requests to boardandpieces.com and our Cloud Functions for abuse triage. Not linked to your account in long-term storage; rotated out after 30 days.
3.6 Purchase data
All in-app purchases are processed by Apple App Store or Google Play. We never see your credit card or banking details. We receive a receipt from Apple or Google (via our subscription provider RevenueCat — see §6) which tells us which product you bought, the amount and currency, and whether the subscription is active. We use this to grant Premium features and venue / group credit balances.
3.7 Analytics + diagnostics
- Firebase Analytics — anonymised event counts (e.g. “onboarding finished,” “game created”). We do not enable advertising-ID collection; the iOS App Tracking Transparency prompt is not shown because we do not track you across apps or websites.
- Firebase Crashlytics + Performance — crash stack traces and performance traces tied to a per-install ID (not your account). Used to fix bugs.
4. How we use your data
We use the data above for these purposes and no others:
- Provide the service — sign you in, match you with opponents, run games, deliver in-app notifications, grant Premium and credit balances after a verified purchase.
- Localise the experience — show content in your preferred language, surface nearby venues.
- Keep the service safe — detect abuse, enforce the Terms of Service, respond to moderation reports.
- Improve the app — aggregated analytics, crash and performance diagnostics.
- Comply with the law — respond to lawful requests from competent authorities; preserve records we are required to keep under Turkish tax and commercial law.
We do not sell your personal data, share it with advertising networks, or use it to train AI models.
5. Legal basis (EEA / UK / Türkiye)
For users in the European Economic Area and the United Kingdom, our legal basis under Articles 6 and 9 of the GDPR / UK GDPR is:
- Performance of a contract (Art. 6(1)(b)) — for account, game activity, chat, push tokens, purchases.
- Consent (Art. 6(1)(a)) — for approximate location, push notifications, optional analytics. You can withdraw consent at any time from the OS settings or from in-app Settings.
- Legitimate interests (Art. 6(1)(f)) — for abuse prevention, security logging, and product diagnostics (where this does not override your rights).
- Legal obligation (Art. 6(1)(c)) — for tax, accounting, and lawful authority requests.
For users in Türkiye, processing is carried out under KVKK Art. 5 on the same grounds (explicit consent for location and optional analytics; performance of contract, legitimate interest, and legal obligation for the rest).
6. Who we share data with
We engage the following service providers as data processors. Each is contractually bound to process your data only on our instructions and to keep it secure. We do not share data with anyone else for marketing or analytics purposes.
| Provider | Purpose | Data categories | Location |
|---|---|---|---|
| Google LLC / Google Ireland Ltd Firebase Authentication, Firestore, Cloud Functions, Cloud Storage, Cloud Messaging (FCM), Firebase Analytics, Crashlytics, Performance Monitoring | Backend hosting, sign-in, push delivery, analytics, diagnostics | Account, game activity, chat (during a game), push tokens, device data, anonymised analytics | EU + US (Google Cloud regions; transfers covered by EU Standard Contractual Clauses and the EU–US Data Privacy Framework) |
| RevenueCat, Inc. | Subscription receipt validation and entitlement state | Anonymised user ID, store-issued receipt, entitlement state. No card data. | United States |
| Apple Inc. (App Store) Google LLC (Google Play) | Process in-app purchases, deliver app updates | Whatever Apple / Google collect to process the transaction; see their respective privacy policies. | Per Apple / Google policies |
We may also disclose personal data to legal counsel, auditors, or competent authorities where required by law, court order, or to enforce our Terms.
7. How long we keep your data
- Account + profile — until you delete your account. After deletion, residual backups expire within 30 days.
- Game history (moves, results, ELO) — kept while your account is active so you can review past games. Deleted with your account.
- In-game chat messages — deleted when the game ends. See §3.4 for the moderation-snapshot exception.
- Approximate location — not stored as history; only a live 15-minute presence record. See §3.3.
- IP / server access logs — 30 days, then deleted.
- Purchase records — kept for ten (10) years from the date of the transaction to comply with Turkish tax and commercial law.
- Moderation snapshots — up to 90 days from the report, then deleted unless legal proceedings require longer retention.
8. Children
Board & Pieces is not directed at children under the age of sixteen (16). You must be at least 16 years old to create an account. If you are under 16, please do not use the service. If we become aware that we have collected personal data from a child under 16, we will delete that data and close the account. Parents and guardians who believe their child has created an account can contact us at support@boardandpieces.com.
9. Security
We protect your data with TLS in transit, encryption at rest on Google Cloud infrastructure, server-side access rules (Firestore Security Rules) that prevent users from reading other users' private data, and least-privilege access for our own staff. No system is perfectly secure; we encourage you to use a strong sign-in method and keep your device's OS up to date.
10. Your rights
Wherever you are based, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data (edit your profile in-app, or contact us).
- Delete your account and associated data (Settings → Account → Delete account, or e-mail us).
- Object to or restrict certain processing (such as analytics).
- Portability — receive a copy of the data you provided in a structured, machine-readable format.
- Withdraw consent for optional processing (location, push, analytics) at any time.
- Complain to a supervisory authority — in Türkiye, the Kişisel Verileri Koruma Kurumu (KVKK); in the EEA, your national data protection authority; in the UK, the Information Commissioner's Office (ICO).
To exercise any of these rights, e-mail us at support@boardandpieces.com. We respond within 30 days, sooner where the law requires.
11. International transfers
We are based in Türkiye. Some of our service providers (Google, RevenueCat) process data in the European Union and the United States. Where data is transferred outside the EEA / UK / Türkiye, we rely on adequacy decisions where available, or on Standard Contractual Clauses (or their KVKK equivalents) to ensure your data is protected to the same standard wherever it is processed.
12. Regional addenda
12.1 European Economic Area + United Kingdom
Our EU representative for matters relating to the GDPR is currently not appointed because our offering to EU data subjects is below the threshold that triggers Art. 27 GDPR. If you are in the EEA and wish to exercise your rights, contact us directly at support@boardandpieces.com. You also have the right to lodge a complaint with your local supervisory authority. UK residents may complain to the ICO (ico.org.uk).
12.2 Türkiye (KVKK)
Bu uygulama 6698 sayılı Kişisel Verilerin Korunması Kanunu (“KVKK”) kapsamında geliştirilmiştir. Veri Sorumlusu: Mathome Yazılım Eğitim Danışmanlık Sanayi ve Ticaret Limited Şirketi, yukarıda belirtilen adresinde mukim. Kişisel verileriniz KVKK madde 4 ışığında hukuka uygun, doğru, sınırlı ve ölçülü olarak işlenir. KVKK madde 11 kapsamındaki haklarınızı kullanmak için support@boardandpieces.com adresine veya kvkk.gov.tr üzerinden Veri Sorumlusuna Başvuru Tebliği'ne uygun şekilde başvurabilirsiniz.
12.3 California (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the CPRA:
- The right to know what categories of personal information we collected about you in the past 12 months (listed in §3 above) and the categories of sources (you, the app, your sign-in provider) and recipients (listed in §6 above).
- The right to delete personal information.
- The right to correct inaccurate personal information.
- The right to opt out of sale or sharing of personal information. Mathome does not sell or “share” personal information as those terms are defined in the CCPA.
- The right to limit the use of sensitive personal information. We do not use sensitive personal information beyond the purposes listed in §4.
- The right to non-discrimination for exercising your rights.
To exercise these rights, e-mail us at support@boardandpieces.com. An authorised agent may submit a request on your behalf with written proof of authorisation.
12.4 Brazil (LGPD)
If you are in Brazil, the Lei Geral de Proteção de Dados (Lei nº 13.709/2018) applies. You have the rights set out in LGPD Art. 18, including access, correction, anonymisation, portability, deletion, and information about sharing. Our legal bases under LGPD Art. 7 mirror those listed in §5 above. Contact us at support@boardandpieces.com to exercise these rights. You may also lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).
12.5 Japan (APPI)
For users in Japan, we comply with the Act on the Protection of Personal Information (個人情報の保護に関する法律). You have the right to request disclosure, correction, and cessation of use of your personal information. The personal information protection manager can be reached at support@boardandpieces.com.
12.6 Korea (PIPA)
For users in the Republic of Korea, we comply with the Personal Information Protection Act (개인정보 보호법). The Personal Information Protection Officer (개인정보 보호책임자) is reachable at support@boardandpieces.com. You have the right to access, correct, delete, and suspend processing of your personal information, and to lodge a complaint with the Personal Information Protection Commission (PIPC).
13. Changes to this policy
We may update this policy to reflect changes in the law, in our service, or in the providers we use. When we make a material change, we will notify you in-app and update the “Effective date” at the top of this page. Continued use of Board & Pieces after the update means you accept the revised policy. Previous versions are available on request.
14. Contact us
Questions about this policy, your data, or how we handle it? Write to support@boardandpieces.com or by post to the address in §1.