Privacy Notice

Last updated 11 September 2026

DATA CONTROLLER

Spotreach, a trading name of legal name of the sole proprietorship, registered address, Türkiye (tax number tax number). For anything on this page write to info@spotreach.net. We answer within 30 days.

What this notice covers

Spotreach is software sold to businesses. A seller describes what they sell; we surface the businesses whose public customer reviews show the problem that product solves, and hand over the evidence. This notice explains the personal data involved in that, for three groups of people: our customers and their staff, people connected to the businesses we scan (for example a sole trader whose name is the business name), and people who write reviews. It applies to this site, the panel at app.spotreach.net and our e-mails.

1. Our customers

What we hold: company name; the contact e-mail or phone number you give us; the product and buyer descriptions, catalogue and preferences you enter; your account key; your plan, subscription period and payment status; which leads you unlocked and when; the date and version of the terms you accepted; and technical records needed to keep the service secure, such as the IP address of sign-up and log-in attempts, used for rate limiting.

Why, and on what legal basis:

  • To open and run your account and deliver the service: performance of our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
  • To keep accounting and tax records: our legal obligations (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)).
  • To secure the service, prevent abuse of free trials, keep evidence that the terms were accepted, and defend legal claims: our legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(e) and (f)).
  • To send you service messages about your account, scans and billing. We do not send you marketing e-mail unless you ask for it.

2. Payments

Paid plans are sold through Paddle.com, which acts as Merchant of Record. Paddle collects your payment details directly and is an independent controller for them under its own privacy notice, available on paddle.com. We never see or store card numbers. Paddle tells us what we need to run your subscription: the buyer's name and e-mail, country, plan, amounts, and payment and refund status.

3. The businesses we scan

You may be reading this because Spotreach surfaced your business to one of our customers. Here is exactly what that involves.

What we hold: the business listing as published on the source: its name, category, city or address, and the phone number and website where the business has published them, together with our own automated verdict, meaning which complaint category matched, how strongly, and when. Business information is mostly not personal data. It becomes personal data where it identifies a person, for example a sole trader trading under their own name or a personal mobile number used as the business line.

Where it comes from: public listings and reviews made available through Google Maps Platform and the Apple App Store.

Why, and on what legal basis: to let businesses that sell a relevant product find and contact businesses that may need it. We rely on legitimate interests (GDPR Art. 6(1)(f)) and, for Türkiye, on the data having been made public and on legitimate interests (KVKK Art. 5(2)(d) and (f)). We have assessed this interest against the rights of the people involved and keep that assessment on file; you can ask for a summary. The safeguards that assessment depends on are the ones listed on this page: we keep only business-level information, never reviewer identities, never Google review text, and we honour objections permanently.

How we tell you: we do not contact the businesses we scan ourselves, and writing to every listed business would mean processing far more data about them than the service does. This public notice is how we inform you, as GDPR Art. 14(5)(b) allows.

What you can do: ask what we hold about your business, have it corrected, object to it being processed, or have it removed. Write to info@spotreach.net with the business name and city, or the link to its listing. You do not need to give a reason for an objection to direct-marketing use, and we do not ask you to prove which law you rely on.

  • Removal is permanent. We add your listing to a suppression list: it is skipped in every later scan and is not offered to any customer again. Leads about your business that no customer has received are deleted.
  • If a customer already received it, that customer holds its own copy as an independent controller. We tell each customer who received the record that you have objected, so they stop using it.
  • We keep only the listing identifier on the suppression list, so that the removal stays in force.

4. People who write reviews

  • Reviewer identity is never recorded. The name, profile, photo or handle of the person who wrote a review is not stored, shown, or passed to customers, in any source.
  • Google review text is not stored. For Google Maps sources the wording of a review is analysed when the scan runs and is not written to our database. We keep our verdict and a pointer back to the listing.
  • App Store reviews: a short excerpt of the review, without the author's name, is kept and shown next to the lead as evidence. It is refreshed when the business is scanned again, so a review that is removed at the source drops out.

Our customers may not try to identify or contact reviewers; our Acceptable Use Policy prohibits it.

5. Who processes data for us

  • Google Maps Platform (Google LLC / Google Ireland Ltd). Search and listing lookups. We send search terms built from customers' product descriptions.
  • Apple App Store feeds (Apple Inc.). Read-only public review feed. Nothing about you is sent.
  • Google Gemini API (Google LLC / Google Ireland Ltd). Receives the product and buyer descriptions customers write, to generate signal profiles and search terms. No lead data, contact details or account keys are included. We use the paid API tier, under which Google does not use prompts to improve its products.
  • Paddle.com. Payments, invoicing, tax and refunds, as an independent controller (see section 2).
  • Our e-mail delivery provider, e-mail provider. Receives the recipient address and the content of service e-mails.
  • Our hosting provider, hosting provider and region. Stores the database and backups described on this page.

We do not sell customer data, and we do not share it with anyone else except where the law requires it, for example on a valid order from a court or authority. If this list changes we update it here before the change takes effect.

6. International transfers

Spotreach is run from Türkiye and some processors are in the United States. When personal data from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (with the UK addendum where needed) or on the processor's certification under the EU-US Data Privacy Framework. Transfers out of Türkiye are made under Article 9 of the KVKK, using the standard contracts it provides for.

7. How long we keep data

  • Customer accounts: for as long as the account is open. If you close your account we delete the account, product profiles and contact details within 30 days.
  • Sign-ups that never became an account: deleted after 180 days.
  • Billing and tax records: for the period Turkish commercial and tax law requires, currently up to 10 years. Paddle keeps its own records under its notice.
  • Evidence that you accepted the terms: for as long as the account exists and afterwards for the limitation period for claims.
  • Business records: for as long as they are used in scans and in customers' leads. Records you have asked us to remove are deleted as described in section 3, except the suppression entry.

8. Security

Connections to the site and the panel are encrypted. The session cookie never contains your account key. The operator console is separate from customer accounts and uses its own credentials. Access to the database is limited to the people who run the service. No system is perfectly secure; if a breach affects your personal data we tell you and the competent authority as the law requires.

9. Automated decisions

Scoring a business is automated, but it produces no legal or similarly significant effect on any individual: it ranks businesses as sales prospects. Our customers may not use results for decisions about individuals such as employment, credit, insurance or housing.

10. Your rights

Depending on where you are, you can ask for access to your data, a copy in a portable format, correction, erasure, restriction, or object to processing, and withdraw any consent you gave. These rights come from the GDPR (EEA), the UK GDPR, Article 11 of the KVKK (Türkiye), the CCPA/CPRA (California) or comparable local law. We apply the same process to all of them. We do not sell or "share" personal information for cross-context behavioural advertising as the CCPA defines those terms.

Write to info@spotreach.net. We may ask you to confirm you control the account or the business concerned, and we answer within 30 days. You can also complain to a data protection authority: in the EU the authority in your country, in the UK the Information Commissioner's Office, and in Türkiye the Personal Data Protection Authority (KVKK). We would appreciate the chance to resolve it with you first.

11. Cookies

We set one session cookie for the panel and, if you switch themes, store that choice in your browser. There are no analytics, advertising pixels or third-party trackers. Details are on the cookies page.

12. Children

The service is for businesses and is not directed at anyone under 18. We do not knowingly collect children's data.

13. Changes

If we change this notice in a way that affects you, we say so in the panel, and for customers by e-mail, before the change takes effect. The date at the top shows the current version.