Legal Document

RestoTrack Privacy Policy

Effective: September 13, 2025
Version 2.0

PRIVACY POLICY

RESTO TRACK MOBILE APPLICATION


Effective Date: September 13, 2025
Last Revised: June 11, 2026
Document Version: 2.0


1. INTRODUCTION AND SCOPE OF APPLICATION

1.1 General Provisions

This Privacy Policy (hereinafter referred to as "the Policy") is issued by RESTO TRACK ("the Company," "we," "us," or "our") and governs the collection, use, processing, storage, disclosure, and protection of personal information obtained through the RESTO TRACK mobile application (hereinafter referred to as "the Application" or "the Service").

1.2 Applicability

This Policy applies to all users of the Application and sets forth the Company's practices concerning the handling of personal information in accordance with applicable privacy laws, data protection regulations, and industry standards. All users are required to read, understand, and acknowledge the provisions contained herein prior to accessing or utilizing the Application.

1.3 User Eligibility and Access Restrictions

The Application is designed and intended exclusively for use by authorized courier delivery personnel who are eighteen (18) years of age or older. Access to the Application is restricted to individuals who have received proper business authorization. The Application is not available for public access or download.

1.4 Acknowledgment of Consent

By accessing, installing, or using the Application, users expressly acknowledge that they have read this Policy in its entirety, understand its provisions, and consent to the collection, processing, and disclosure of their personal information as described herein.

1.5 Definitions

For the purposes of this Policy, the following terms shall have the meanings set forth below:

  • "Application" or "Service" means the RESTO TRACK mobile application and all related features, functionality, and services made available by the Company.
  • "Company," "we," "us," or "our" means NEVA TECH LTD, acting as the data controller in respect of personal information processed through the Application.
  • "User" or "you" means any authorized individual who accesses, installs, or uses the Application, including courier and driver delivery personnel.
  • "Personal Information" or "Personal Data" means any information relating to an identified or identifiable natural person, as further described in Section 2 of this Policy.
  • "Location Data" means precise and approximate geographic location information collected from a User's device, including data collected while the Application operates in the foreground or background.
  • "Processing" means any operation performed on Personal Information, whether or not by automated means, including collection, recording, storage, use, disclosure, transmission, and deletion.
  • "Business Partner" means a restaurant establishment, customer, logistics partner, or other authorized party with whom the Company shares information for operational purposes, as described in Section 4.

2. INFORMATION COLLECTION PRACTICES

2.1 Categories of Information Collected

The Company collects various categories of information necessary for the provision of delivery services and the operation of the Application, as detailed in the subsections below.

2.1.1 Location Information

Location Data for Driver and Courier Tracking

The Application accesses your mobile device's location data in order to perform the core functions of our driver and courier tracking services. This data may be collected even when the Application is running in the background (that is, when the app is closed or not actively in use).

  • Purpose of Data Collection: Location data is used to ensure operational efficiency, optimize delivery routes, track courier and driver locations in real time, and provide users with up-to-date information about delivery status.
  • Data Sharing: Your location data is never sold or shared with third parties for advertising, marketing, or user-profiling purposes. It may be shared only to carry out the core functions described above and, where required by law, with authorized authorities as part of legal processes.
  • User Control: You may manage or restrict location permissions at any time through your device settings. Withdrawing these permissions may disable location-based features such as driver and courier tracking.

The Application collects comprehensive location data, which constitutes a fundamental component of its core functionality. Location data collection includes:

(a) Precise Geographic Location Data

The Application continuously collects precise GPS coordinates through the ACCESS_FINE_LOCATION permission protocol. Such precise location information enables:

  • Accurate real-time tracking of delivery personnel
  • Route optimization and efficiency analysis
  • Precise navigation to customer delivery addresses
  • Verification of delivery completion at designated locations

Precise location data collection occurs throughout the duration of active delivery assignments and during all periods of Application usage.

(b) Approximate Location Information

Through the ACCESS_COARSE_LOCATION permission protocol, the Application obtains general area location information derived from cellular network tower data and Wi-Fi network positioning systems. Approximate location data serves as a supplementary positioning method and maintains location awareness when precise GPS signals are temporarily unavailable or degraded.

(c) Background Location Tracking

The Application maintains continuous location monitoring through the ACCESS_BACKGROUND_LOCATION permission protocol, even when the Application is not actively displayed on the user's device screen or interface. Background location collection is essential for:

  • Maintaining uninterrupted delivery tracking throughout service periods
  • Ensuring accurate delivery time records and documentation
  • Monitoring delivery route adherence and compliance
  • Providing real-time status updates to restaurant partners and customers
  • Maintaining operational continuity during extended delivery periods

(d) Foreground Location Services

The FOREGROUND_SERVICE_LOCATION permission enables the Application to maintain active location services while operating in the foreground state, ensuring consistent location tracking during active delivery operations and maintaining service continuity.

2.1.2 Delivery and Operational Information

The Application collects operational information necessary for service functionality, including:

  • Courier identification credentials and authentication data
  • Delivery assignment details and order specifications
  • Order information associated with specific delivery tasks
  • Delivery completion status and verification data
  • Route information and historical delivery records
  • Time-stamped activity logs and performance metrics
  • Communication data necessary for operational coordination

2.1.3 Device and Technical Information

The Application may collect technical information required for proper functionality, including:

  • Device identifiers and unique equipment identifiers
  • Operating system version and device specifications
  • Application version and configuration data
  • Application usage analytics and performance metrics
  • Network connectivity information and signal strength data
  • Error logs and diagnostic information

2.2 Methods of Collection

Information is collected through various methods, including:

  • Direct input by users through the Application interface
  • Automatic collection through device sensors and system permissions
  • Collection through third-party integrated services and APIs
  • Collection through background processes and foreground services

3. PURPOSES OF INFORMATION PROCESSING

3.1 Primary Business Purposes

The Company processes collected information exclusively for legitimate business purposes directly related to delivery operations and service provision, including:

(a) Delivery Operations and Navigation

  • Facilitating accurate navigation to customer delivery addresses
  • Monitoring real-time delivery progress and completion status
  • Optimizing delivery routes for operational efficiency
  • Maintaining comprehensive delivery records and timing documentation

(b) Service Quality and Performance

  • Ensuring compliance with service level agreements
  • Monitoring adherence to operational standards and protocols
  • Providing accurate delivery estimates and status updates
  • Verifying successful delivery completion

3.2 Operational Management Functions

Collected information supports critical operational functions, including:

  • Assignment and distribution of delivery orders to appropriate courier personnel
  • Facilitation of efficient completion of delivery processes and workflows
  • Maintenance of real-time delivery status updates across all system components
  • Integration with mapping, navigation, and routing services
  • Coordination of communication between delivery personnel, restaurant partners, and customers

3.3 Quality Assurance and Compliance

Information processing supports quality assurance and compliance initiatives, including:

  • Verification of delivery accuracy and completion standards
  • Monitoring of delivery performance metrics and key performance indicators
  • Maintenance of regulatory compliance and business agreement obligations
  • Analysis of delivery patterns for service improvement initiatives
  • Documentation for dispute resolution and quality control purposes

3.4 System Maintenance and Improvement

Information may be processed for:

  • Technical troubleshooting and system optimization
  • Application performance monitoring and enhancement
  • Security monitoring and threat detection
  • Service development and feature improvement

4. INFORMATION SHARING AND DISCLOSURE

4.1 Disclosure to Business Partners

The Company may disclose relevant information to authorized business partners, including:

(a) Restaurant Establishments: Information necessary for order coordination, fulfillment verification, and service delivery may be shared with restaurant establishments that originate delivery orders.

(b) Customers: Delivery status information, estimated arrival times, and courier identification may be shared with customers who are recipients of delivery services.

(c) Third-Party Logistics Partners: Operational information may be shared with third-party logistics partners who collaborate in delivery operations and service provision.

All information shared with business partners is limited strictly to data necessary for delivery coordination, order fulfillment, customer service, and operational purposes.

4.2 Disclosure to Service Providers

The Company may disclose information to third-party service providers who assist in Application functionality and business operations, including:

  • Mapping and navigation service providers
  • Cloud hosting and data storage infrastructure providers
  • Customer communication and notification platforms
  • Technical support, maintenance, and development providers
  • Analytics and performance monitoring services

All service providers are contractually required to maintain appropriate data protection standards and are authorized to use disclosed information solely for specified business purposes.

4.3 Legal and Regulatory Disclosure

The Company reserves the right to disclose information when:

  • Required by applicable law, statute, regulation, or legal process
  • Requested through valid legal process, including subpoenas, court orders, or governmental requests
  • Necessary to protect the Company's legal rights, property, or interests
  • Required to ensure user safety and security
  • Necessary to prevent, investigate, or address fraudulent or unauthorized activities
  • Required to comply with law enforcement requests and judicial proceedings
  • Necessary to enforce this Policy or other applicable terms and conditions

4.4 Business Transaction Disclosure

In the event of a merger, acquisition, consolidation, restructuring, sale of assets, financing, bankruptcy, or other business transaction, user information may be disclosed to prospective or actual acquirers, investors, or successors as part of the business assets transferred, subject to appropriate confidentiality obligations and data protection commitments.

4.5 Aggregate and De-identified Information

The Company may disclose aggregate, de-identified, or anonymized information that does not identify individual users for business, research, or analytical purposes without restriction.


5. DATA SECURITY AND PROTECTION MEASURES

5.1 Security Framework

The Company implements and maintains administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, acquisition, alteration, disclosure, destruction, and other forms of unlawful or unauthorized processing.

5.2 Administrative Safeguards

Administrative security measures include:

  • Access controls limiting information access to authorized personnel on a need-to-know basis
  • Employee training and awareness programs regarding data protection and privacy practices
  • Background verification procedures for personnel with access to personal information
  • Incident response procedures and breach notification protocols
  • Regular review and updating of security policies and procedures
  • Designation of responsible personnel for data protection oversight

5.3 Technical Safeguards

Technical security measures include:

  • User authentication and authorization mechanisms
  • Secure data storage practices and backup procedures
  • Regular security assessments, vulnerability testing, and system monitoring
  • Intrusion detection and prevention systems
  • Logging and monitoring of system access and activities
  • Security patch management and system update procedures

5.4 Physical Safeguards

Physical security measures include:

  • Restricted access to facilities housing servers and data storage systems
  • Environmental controls and disaster recovery capabilities
  • Secure disposal procedures for equipment containing personal information

5.5 Encryption and Data Transmission

IMPORTANT SECURITY DISCLOSURE: The Company hereby notifies users that data transmitted through the Application is not currently protected by encryption protocols during transmission between user devices and Company servers. The Company acknowledges this security limitation and is actively engaged in development efforts to implement comprehensive end-to-end encryption protocols to enhance data security during transmission.

Users are advised to consider this current limitation when utilizing the Application. Notwithstanding this limitation, the Company maintains robust security measures for stored information and implements strict access controls to prevent unauthorized access to user data.

5.6 Security Incident Response

The Company maintains documented procedures for responding to actual or suspected security incidents, including:

  • Prompt investigation and assessment of security events
  • Containment and remediation of security breaches
  • Notification to affected users as required by applicable law
  • Implementation of corrective and preventive measures
  • Cooperation with law enforcement and regulatory authorities
  • Documentation and reporting of security incidents

5.7 Limitations of Security Measures

Users acknowledge that no method of electronic transmission or storage is completely secure, and the Company cannot guarantee absolute security of personal information. Users utilize the Application at their own risk with full awareness of inherent security limitations.


6. DATA RETENTION AND DELETION

6.1 Retention Principles

The Company retains personal information for the duration necessary to fulfill the purposes outlined in this Policy, subject to applicable legal, regulatory, and business requirements.

6.2 Retention Periods

Specific retention periods are determined based on:

  • The nature and sensitivity of the information
  • Legal and regulatory retention requirements
  • Business operational requirements
  • Dispute resolution and litigation needs
  • Contractual obligations with business partners

6.3 Data Deletion Procedures

Users may submit requests for deletion of their account and associated personal information through the Company's designated data subject request portal accessible at:

https://rsmanager.restopos.com.tr

IMPORTANT NOTICE: Automated data deletion functionality is not currently supported within the Application interface. All deletion requests are processed manually by authorized Company personnel in accordance with established internal procedures, verification protocols, and applicable legal requirements. The Company will endeavor to process deletion requests within a reasonable timeframe following verification of the requestor's identity.

6.4 Post-Deletion Retention

Notwithstanding deletion requests, certain information may be retained following account deletion when required for:

  • Compliance with legal obligations, including tax, accounting, and regulatory requirements
  • Resolution of outstanding disputes, claims, or litigation
  • Enforcement of agreements and protection of legal rights
  • Maintenance of business records as required by applicable law
  • Fraud prevention and security purposes
  • Backup systems (until such backups are purged in the ordinary course of business)

Users will be informed of any specific retention requirements applicable to their deletion request.

6.5 Deletion Limitations and Exceptions

The Company may decline or limit data deletion requests when:

  • Retention is required by applicable law or regulation
  • Information is necessary for the establishment, exercise, or defense of legal claims
  • Retention is necessary to protect the rights, property, or safety of the Company or others
  • Processing is necessary for compelling legitimate interests that override the user's rights

7. USER RIGHTS AND CONTROLS

7.1 Location Permission Management

Users maintain control over location permission settings through their mobile device operating system settings interface. However, users must understand that:

  • Disabling location services will significantly impair Application functionality
  • Core delivery tracking features require active location permissions
  • Background location access is essential for continuous delivery operations
  • Disabling required location permissions may result in inability to perform assigned delivery duties and may affect employment or contractual obligations

7.2 Data Subject Rights

Subject to applicable law and verification of identity, users may exercise the following rights:

(a) Right of Access: Users may request confirmation of whether personal information is being processed and may obtain access to such information.

(b) Right to Rectification: Users may request correction of inaccurate or incomplete personal information.

(c) Right to Deletion: Users may request deletion of personal information under circumstances specified in Section 6 of this Policy.

(d) Right to Restrict Processing: Users may request restriction of processing under certain circumstances as provided by applicable law.

(e) Right to Data Portability: Where applicable, users may request receipt of personal information in a structured, commonly used format.

(f) Right to Object: Users may object to certain types of processing as provided by applicable law.

(g) Right to Withdraw Consent: Where processing is based on consent, users may withdraw such consent, subject to legal or contractual restrictions.

7.3 Exercise of Rights

To exercise any of the rights described above, users must submit a written request through the designated contact channels specified in Section 13 of this Policy. The Company will respond to verified requests in accordance with applicable legal timeframes.

7.4 Verification Procedures

The Company reserves the right to verify the identity of individuals making data subject requests prior to fulfilling such requests. Users may be required to provide additional information to confirm their identity.

7.5 Communication Preferences

Users may manage preferences regarding non-essential Application notifications through device settings or Application interface options where such controls are available.


8. ACCESS RESTRICTIONS AND ELIGIBILITY

8.1 Authorized User Requirements

Access to the Application is strictly limited to authorized courier delivery personnel who meet specific business qualification requirements established by the Company or its business partners. The Application is not available for public download, access, or use. All users must possess proper business authorization prior to obtaining access to Application functionality.

8.2 Age Restrictions and Verification

The Application is designed and intended exclusively for use by individuals who are eighteen (18) years of age or older. The Company does not knowingly collect, process, or maintain personal information from individuals under the age of eighteen (18).

Any individual who does not meet the minimum age requirement must immediately discontinue use of the Application. If the Company becomes aware that personal information has been collected from an individual under eighteen (18) years of age, such information will be deleted promptly.

8.3 Geographic Restrictions

The Company reserves the right to restrict access to the Application based on geographic location or jurisdiction as required for compliance with applicable laws or operational requirements.


9. THIRD-PARTY SERVICES AND INTEGRATIONS

9.1 Advertising Policy

The Application does not display third-party advertisements and does not utilize advertising identifiers or similar technologies for marketing or advertising purposes. The Company does not collect, process, or disclose personal information for third-party advertising activities.

9.2 Third-Party Service Integration

The Application integrates with certain third-party services, including but not limited to mapping services, navigation providers, and communication platforms. Such third-party services operate under their own privacy policies and terms of service, which are independent of this Policy.

9.3 Third-Party Responsibility

The Company is not responsible for the privacy practices, data handling procedures, or content of third-party services. Users are encouraged to review the privacy policies and terms of service of any third-party services accessed through or integrated with the Application.

9.4 Third-Party Links

The Application may contain links to third-party websites, applications, or services. The Company does not endorse, control, or assume responsibility for any third-party content or services. Access to third-party resources is at the user's own risk.


10. INTERNATIONAL DATA TRANSFERS

10.1 Cross-Border Transfers

In the course of business operations, personal information may be transferred to, processed in, or accessed from countries other than the country in which the user is located. Such transfers may involve transmission to jurisdictions that may not provide the same level of data protection as the user's country of residence.

10.2 Transfer Safeguards

When personal information is transferred internationally, the Company ensures that appropriate safeguards are implemented to protect such information in accordance with this Policy and applicable data protection laws. Such safeguards may include:

  • Standard contractual clauses approved by relevant regulatory authorities
  • Adequacy determinations by competent data protection authorities
  • Binding corporate rules or similar internal policies
  • Other legally recognized transfer mechanisms

10.3 Consent to Transfer

By using the Application, users consent to the transfer of their personal information to countries outside their country of residence, including countries that may not provide equivalent data protection laws.


11. POLICY MODIFICATIONS AND UPDATES

11.1 Right to Modify

The Company reserves the right to modify, amend, supplement, or replace this Policy at any time, in its sole discretion, to reflect changes in business practices, legal requirements, regulatory guidance, service functionality, or other operational considerations.

11.2 Notification of Changes

Material changes to this Policy will be communicated to users through one or more of the following methods:

  • In-application notifications or alerts
  • Email notification to registered email addresses
  • Prominent notice on the Company's website
  • Push notifications through the Application
  • Other appropriate communication channels

11.3 Effective Date of Modifications

Modifications to this Policy shall become effective upon posting of the revised Policy or on the date specified in the notification of changes, whichever is later. The "Last Revised" date at the beginning of this Policy indicates the date of the most recent modifications.

11.4 Continued Use and Acceptance

Continued access to or use of the Application following notification of Policy modifications constitutes acceptance of and agreement to the revised terms. Users who do not agree to revised terms must immediately discontinue use of the Application and may request account deletion in accordance with Section 6.3 of this Policy.

11.5 Prior Versions

The Company may maintain records of prior versions of this Policy for reference purposes but is under no obligation to maintain or provide access to superseded versions.


12. REGULATORY COMPLIANCE FRAMEWORK

12.1 Compliance Commitment

This Policy has been developed and is maintained in accordance with applicable privacy laws, data protection regulations, and industry standards, including but not limited to:

  • Requirements established by mobile application distribution platforms
  • Data protection regulations in jurisdictions where the Service operates
  • Industry-specific privacy requirements applicable to delivery and logistics services
  • Applicable consumer protection laws and regulations

12.2 Regulatory Cooperation

The Company cooperates with data protection authorities, regulatory agencies, and law enforcement authorities in accordance with applicable legal requirements and established procedures.

12.3 Regulatory Changes

The Company monitors changes in applicable privacy laws and regulations and updates its practices and this Policy accordingly to maintain compliance with evolving legal requirements.


13. CONTACT INFORMATION AND INQUIRIES

13.1 Data Controller and Contact Details

The data controller responsible for the Personal Information processed through the Application is:

NEVA TECH LTD
Registered Address: 170 Crescent Road, Barnet, EN4 9RS, United Kingdom Company Registration Number: 12004677
Email: info@nevatech.co.uk

For questions, concerns, requests, or complaints related to this Policy or the Company's data protection practices, users may contact the Company through the channels set out above.

13.2 Response Procedures

The Company will acknowledge receipt of privacy-related inquiries and will respond in accordance with applicable legal requirements and timeframes. Complex inquiries may require additional time for thorough investigation and response.

13.3 Regulatory Authority Contact

Users have the right to lodge a complaint with a competent data protection authority if they believe their privacy rights have been violated or if they are dissatisfied with the Company's handling of their personal information. In the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO), which may be contacted at ico.org.uk. Users located in other jurisdictions may also have the right to contact their local data protection authority.


14. GOVERNING LAW AND DISPUTE RESOLUTION

14.1 Governing Law

This Policy and all matters arising out of or relating to this Policy shall be governed by and construed in accordance with the laws of England and Wales, without regard to its conflict of law principles.

14.2 Dispute Resolution

Any disputes, controversies, or claims arising out of or relating to this Policy, including disputes regarding its interpretation, validity, enforceability, or breach, shall be resolved in accordance with the dispute resolution procedures specified in the Application's Terms of Service.

14.3 Severability

If any provision of this Policy is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, such provision shall be modified to the minimum extent necessary to make it valid and enforceable, or if such modification is not possible, such provision shall be severed from this Policy. The remaining provisions shall continue in full force and effect.

14.4 Waiver

No waiver of any provision of this Policy shall be deemed or shall constitute a waiver of any other provision, nor shall any waiver constitute a continuing waiver unless otherwise expressly provided in writing.


15. ACKNOWLEDGMENT AND ACCEPTANCE

BY ACCESSING, INSTALLING, DOWNLOADING, OR USING THE RESTO TRACK APPLICATION, YOU EXPRESSLY ACKNOWLEDGE AND CONFIRM THAT:

(a) You have read this Privacy Policy in its entirety;

(b) You understand the provisions, terms, and conditions contained herein;

(c) You consent to the collection, use, processing, storage, disclosure, and transfer of your personal information as described in this Policy;

(d) You meet all eligibility requirements specified in Section 8;

(e) You agree to be bound by the terms of this Policy; and

(f) You understand that your continued use of the Application constitutes ongoing acceptance of this Policy and any modifications thereto.


END OF PRIVACY POLICY

Document Control: Version 2.0 | Effective September 13, 2025