Account Deletion
How to delete your iştebu! yemek account from inside the app or without the app installed, and what data is retained for how long after deletion.
This page explains how to delete your account in the iştebu! yemek app (published by POİEX TEKNOLOJİ LİMİTED ŞİRKETİ) and what happens to your data afterwards. The detailed legal framework is in Section 5 of the Privacy Policy.
1. Delete your account in the app
- Sign in to the iştebu! yemek app.
- Open the Profile tab and go to Privacy & Data.
- Follow and confirm the steps on the Delete my account card.
Once lifecycle guards pass and deletion is confirmed, access to your account closes immediately and your upcoming meal selections are cancelled. If you are the sole guardian of an active student, in-app deletion cannot complete until the school links another guardian or ends the student.
2. Request deletion without the app
If you no longer have the app installed, you can have your account deleted without reinstalling it:
- Send a deletion request on WhatsApp. If you message from the phone number registered with iştebu! yemek, no further identity verification is usually needed.
- Or email privacy@istebuyemek.com, stating the phone number registered with iştebu! yemek and that you want your account deleted.
Whichever channel you use, your request is handled as a KVKK Article 7 application and completed within 30 days at the latest. Your registered phone number is used to verify your identity; additional verification may be requested if needed.
3. What happens to your data after deletion?
When you report missing, substituted, or wrong food for an order, a verified link to your own order and the issue type are added to the support record and included in your data export. Only you and authorized POİEX operators can access the record. It does not itself create a refund, additional charge, or payout approval. When personal-data erasure is processed, the order link is removed along with the user link; the platform does not embed that link in retained message text.
As detailed in Section 5 of the Privacy Policy:
- Immediately: access to your account closes and the account no longer appears in the direct-recipient search for operations notifications; your upcoming selections are cancelled; the server-side native push registration token and account-installation association are deleted even if you previously disabled notification permission on the device. Pending rating reminders, feedback-action notices, and operator-confirmed service announcements therefore cannot be delivered; terminal push-outbox records remain subject to the Privacy Policy’s 90-day technical retention period.
- Within 6 months at the latest (periodic destruction cycle): your name, phone number, profile photo, technical data in consent records (IP address, device information), SMS content records sent to you, personal operational-notification copies, and their read times are erased or anonymized. If you want earlier destruction, a KVKK Article 7 request to privacy@istebuyemek.com is completed within 30 days at the latest.
- For the statutory retention period (anonymized): past meal selections and order records subject to billing are kept anonymized, with the link to your identity removed, under Turkish Tax Procedure Law Article 253 and Turkish Code of Obligations Article 146; they appear as “Anonymous User” in historical per-person views.
- De-identified: user messages and staff replies in your in-app support requests are kept; the request’s link to your account and your own messages’ author links are removed. Private internal staff notes are not exposed to the user. Image-attachment records and their files in private object storage are erased. Dish and service notes are cleared and the review-submitting account link is cut, while the star rating and fixed service issues remain anonymized. The Seller action and selected rating/label/service-issue links remain as a service-quality checkpoint without your personal notification copy or free-text notes.
Guardian accounts: a guardian cannot remove the child, and an active student’s last guardian relationship cannot end. If you are the sole guardian, the school must link another guardian or end the student. This in-app safeguard does not remove your written KVKK Article 7 right; a WhatsApp or email request is processed separately within 30 days with school coordination. See Section 5 of the Privacy Policy for records kept on behalf of your child and the child’s data-protection rights.
If you are the only active admin of an organization, your deletion request may be refused until another admin is appointed for that organization. This is not a refusal of your KVKK Article 7 right; it is a safeguard protecting other users’ access to the service.
Menu announcements are covered too: a pending menu push is deliverable only while at least one announced meal still needs selection; account closure removes the native push registration, so pending pushes cannot be delivered. Personal in-app menu announcements, meal links and read times are removed in the personal-data erasure process described above. Terminal push delivery records follow the Privacy Policy’s 90-day technical retention period.
Opening a notification or explicitly marking it read, individually or in bulk, records its first read time. Choosing or editing one of the announced meals in the app also acknowledges the corresponding menu announcement for the acting account only; automatic and operator-entered orders do not do this. Cancelling the meal later does not make the announcement unread again. In-app announcements do not expire with age; read entries remain in notification history and follow the same account-data erasure process.
4. Delete data without deleting your account
Without closing your account, you can request the deletion, correction or restriction of specific data under KVKK Article 11: privacy@istebuyemek.com. Requests are answered within 30 days at the latest.
Related documents: Privacy Policy · KVKK Notice
Personal payment details
Card payments use payer name, email, verified account phone, identity number and billing address. Known details are prefilled for you to review and edit before saving. Saving does not change your account name; delivery remains to the institution address. The identity number is stored encrypted. When signed in to your own account, you can view and edit the full number in your payment details without an additional SMS verification. The number is not persisted in browser storage or captured by analytics or session replay; personal exports keep it masked. Institution admins and operations screens cannot access this profile.
When adding a card from your profile, the email address is reused from your saved payment details without asking again in the card form. If it is missing, you are directed to complete your payment details first.
Encrypted buyer details are frozen when a payment starts; later profile edits do not change a pending transaction. Account closure removes access to reusable payment details. The destruction step in the existing account-deletion process deletes the reusable profile and clears the new encrypted buyer snapshots. Existing retention of financial amounts and audit records is unchanged. Required buyer details are transferred to the active iyzico service when a card payment is initiated.
Personal in-app notices of confirmed payment outcomes follow the erasure process above. Payment push records showing the hold, charge and uncharged difference, or the cancelled hold, follow the existing notification retention and erasure rules. Pending payment pushes cannot be delivered after account closure removes the native registration. External-adjustment evidence and period-close financial records follow existing financial retention rules; erasure of the payment profile does not change their amounts. See the Privacy Policy for details.
Erasing the in-app payment profile does not mean transaction records retained by the active payment provider iyzico under its own obligations are erased at the same time. See the provider disclosure in the Privacy Policy.
Saved-card aliases, email, identity and address fields are cleared at the existing personal-data erasure step. Existing retention periods for masked financial references remain unchanged. See the Privacy Policy for details.
Residual encrypted bank content and return state are cleared at erasure. Payer/address copies in direct-authentication requests are scrubbed; amount, item and provider bindings remain for financial reconciliation.
Your default payment-card preference is stored on your account and used for future orders; existing orders keep their original card. The preference is included in personal-data exports and cleared at the existing account-data erasure step.