Tecrübetecrube.com
Last updated: August 11, 2026

Privacy Policy

Tecrube Interactive’s global privacy commitment: what we collect, how we use, share and protect data.

1. Introduction and global scope

This Privacy Policy applies to tecrube.com, subdomains, dashboards, APIs, apps, plugins and marketing-automation / ad-management services (together the “Service”) operated by Tecrube Interactive (“Tecrube”, “we”, “us”).

It is drafted for users worldwide, including Türkiye, the EEA, UK, US, Middle East and Asia-Pacific. Where mandatory local law (KVKK, GDPR, UK GDPR, CCPA/CPRA, etc.) is stricter, that law prevails; otherwise this Policy applies.

By using the Service or providing personal data you confirm you have read and understood this Policy. If you disagree, do not use the Service.

2. Controller and contact

Controller: Tecrube Interactive. Official contact: info@tecrube.com.

Privacy requests, breach notices and privacy questions are accepted only at info@tecrube.com. Requests are not completed without identity verification.

For third-party data you upload (customers, leads, recipient lists), you may be controller and Tecrube a processor acting on your instructions, depending on the contract and factual control.

3. Definitions

“Personal data”: any information relating to an identified or identifiable natural person.

“Processing”: any operation on personal data, including collection, storage, alteration, transfer and deletion.

“Customer Data”: content and personal data you upload or pull into the Service from connected accounts.

“Account Data”: your subscription, billing, identity, support and usage records.

4. Categories of data we collect

Identity and contact: name, e-mail, phone, company, title, country/region, language.

Account and transaction: roles, sessions, plan, billing/tax data, payment status; full card numbers are handled by payment providers, not stored by Tecrube.

Service and integrations: across Setup, Analysis, Management, Ads, Growth, Outreach and Action hubs — campaign, spend, performance, audience, content, conversion, inventory, form, task, CRM, automation and workspace data from connected ad, social, analytics and messaging accounts.

Brand and assets: brand kit (logo, colours, fonts, tone, rules), creatives, briefs and media you upload.

Messaging channels: e-mail/SMS/WhatsApp/voice logs, call recordings and transcripts (if enabled), chat/DM content, lead and recipient lists.

Measurement: pixels, CAPI, UET, server-side tracking, UTM, consent signals and related events.

Support: forms, e-mail, chat and ticket content.

Technical and security: IP, device/browser, OS, referrer, session IDs, logs, cookies, error records, fraud/security signals.

Marketing preferences: consent, opt-out and commercial-message records where applicable.

5. Sources of data

We obtain data from you directly (registration, forms, support, brand kit), automatically from your device, from connected third-party platforms, payment providers, lawfully available public sources and lists you upload.

Competitor-analysis and similar tools rely only on lawful public sources or sources you authorise; unauthorised access or ToS violations are your responsibility.

Data from third-party platforms is subject to their terms and your authorisations. Tecrube is not liable for incomplete, inaccurate or unauthorised transfers from those platforms.

6. Purposes of processing

To provide, configure, secure and improve the Service; run campaign/automation/reporting/CRM/outreach/action features; support you; bill you; prevent abuse, spam and fraud; meet legal duties; and improve products via anonymised/aggregated analytics where possible.

Marketing communications occur only with consent or where law allows; you may opt out at any time.

We do not process personal data to guarantee outcomes (ROAS, sales, leads, etc.); performance metrics are informational.

7. Legal bases (KVKK / GDPR / similar)

Contract performance; legal obligation; legitimate interests (security, product improvement, network protection — without overriding your rights); and consent where required.

For EEA/UK users, GDPR Art. 6 / UK GDPR bases apply. Special-category data is not processed by default; if needed, explicit consent or a statutory exception is required.

For call recording, location or similarly sensitive features, additional notice/consent duties under local law are yours.

Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.

8. Automated processing, actions and AI

The Service may use automation and AI for creatives, targeting, optimisation, chat/voice agents and approved automated actions. Outputs are decision-support or automation you authorised; final responsibility is yours.

You may expose account data to external chat/AI connectors (e.g. ChatGPT/Claude-like tools) under your instruction; that transfer risk is yours.

We do not as a rule make solely automated decisions that produce legal or similarly significant effects. If we do, applicable rights to contest and obtain human review remain available.

9. Sharing, processors and disclosures

We do not sell personal data and do not “sell” or “share” it for cross-context behavioural advertising under CCPA/CPRA except as permitted for service providers / necessary disclosures.

Sharing occurs only with: (a) hosting, CDN, security, monitoring, payment, e-mail/SMS/WhatsApp/voice, analytics and auth vendors; (b) ad/social/measurement platforms you connect; (c) affiliates if any; (d) authorities when legally required; (e) corporate transactions; (f) protection of rights — and only as necessary.

We apply data-processing terms with vendors. Third-party platform policies also apply; Tecrube does not control them.

The sub-processors below access data for the stated purpose and no other. Those marked “only if you connect” receive nothing unless you connect that account. This list is updated whenever a provider is added, and changes are announced by in-product notice.

OpenAI, L.L.C. — Text and content generation, classification. Processing region: ABD. Data transferred: Prompt text; brand profile and campaign context. Customer lists and contact details are not sent.

Anthropic PBC — Text and content generation, decision explanations. Processing region: ABD. Data transferred: Prompt text; brand profile and campaign context.

Google LLC (Gemini API) — Text generation and summarisation. Processing region: ABD / AB. Data transferred: Prompt text; brand profile and campaign context.

Groq, Inc. — Low-latency text generation. Processing region: ABD. Data transferred: Prompt text; brand profile and campaign context.

OpenRouter, Inc. — Model routing (only if an administrator selects it). Processing region: ABD. Data transferred: Prompt text, forwarded to the selected model.

İyzico Ödeme Hizmetleri A.Ş. — Payment collection and refunds. Processing region: Türkiye. Data transferred: Name, e-mail, phone, billing address, card details (card details never reach Tecrübe). This transfer is necessary for the service to function.

Google Ireland Ltd. (Google Ads, Analytics) — Ad delivery and measurement — only if you connect your account. Processing region: AB / ABD. Data transferred: Ad account ID, campaign and conversion data, through the account you connect.

Meta Platforms Ireland Ltd. — Ad delivery, Instagram/Messenger messaging — only if you connect. Processing region: AB / ABD. Data transferred: Ad account ID, campaign data, message contents.

WhatsApp Business Platform (Meta) — Customer messaging — only if you connect. Processing region: AB / ABD. Data transferred: Phone number and message content.

TikTok Technology Ltd. — Ad delivery — only if you connect. Processing region: AB / Singapur. Data transferred: Ad account ID and campaign data.

Kimlik sağlayıcılar (Google, Apple, Meta, LinkedIn, X) — Single sign-on — only if you use it. Processing region: ABD / AB. Data transferred: Name, e-mail and provider user ID.

E-posta gönderim sağlayıcısı (SMTP) — Transactional e-mail: verification, invoices, alerts. Processing region: Yönetici ayarına göre. Data transferred: E-mail address and message content. This transfer is necessary for the service to function.

Barındırma sağlayıcısı (sunucu ve yedekler) — Running the application and database backups. Processing region: Türkiye / AB. Data transferred: All data processed by the service, encrypted. This transfer is necessary for the service to function.

10. International transfers

Data may be processed in Türkiye, the EEA, the US or other countries where infrastructure is located. Where no adequacy decision exists, we use GDPR Standard Contractual Clauses, UK IDTA/Addendum, KVKK Art. 9 safeguards and supplementary measures as needed.

Transfers may be inherent to a global SaaS and integrated platforms. By using the Service you acknowledge such transfers, subject to mandatory local consent rules.

11. Retention

We retain data while your account and contract are active; for statutory billing/tax periods; and as needed for disputes and security logging.

When the purpose ends, data is deleted, destroyed, anonymised or legally archived. Deletion from backups completes within a reasonable technical cycle.

12. Security

We apply TLS, access control, authorisation, logging, encryption where appropriate, environment segregation and monitoring. No system is 100% secure.

We notify incidents as required by law. You remain responsible for account security (password, 2FA, API keys).

13. Your rights (global)

Depending on applicable law: access, rectification, erasure, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority (e.g. Turkish Board, EEA DPA, ICO).

Under US state laws such as CCPA/CPRA (if applicable): know, delete, correct, opt out of sale/share and non-discrimination. Requests: info@tecrube.com.

We may verify identity. Unfounded, repetitive or excessive requests may be refused or charged. Response times follow applicable law (typically 30 days / CCPA statutory period).

14. Children

The Service is not directed to anyone under 18. We do not knowingly collect children’s data. If collected in error we will delete it. Parents/guardians should contact info@tecrube.com.

15. Third-party sites and Do Not Track

External links are governed by their own privacy practices; Tecrube is not responsible for them.

There is no uniform industry response to browser Do Not Track signals; we do not guarantee a uniform response unless required by law.

16. Changes

We may update this Policy. The current version is published with an “Updated” date. Material changes may be notified by e-mail or in-product notice.

Continued use after a change constitutes acceptance. If you disagree, close your account and stop using the Service.

17. Contact

Privacy and data requests: info@tecrube.com. This is also the primary channel for formal privacy notices.