Legal
Privacy Policy for this website.
This page describes what happens — and mostly what doesn’t happen — when you visit ozjam.com. It covers the website only. Warry is a separate piece of software with its own policy, because the facts there are different.
The short version
ozjam.com is a set of static files on a shared host. There is no account to create, no login, no basket and no personalisation, so there is very little for this site to know about you — and nothing here has been built to find out.
The site sets no cookies at all. It runs no analytics, carries no advertising, and loads no social widget, chat bubble or tracking pixel. Your browser saves two small values — the language you chose and the fact that you dismissed the cookie notice — and neither ever leaves your device.
Two things do involve someone other than us: the web fonts, which your browser fetches from Google, and the contact form, which becomes an e-mail on our hosting provider’s mail server. Both are set out in full below, because a privacy policy made only of things we don’t do is not worth reading.
Who is responsible
OZJAM is an independent studio based in Türkiye. For this website OZJAM is the data controller under the GDPR, and the veri sorumlusu under Turkish Law No. 6698 on the Protection of Personal Data (KVKK).
- E-mail: support@ozjam.com
- Country: Türkiye
There is no data protection officer, because a studio this size is not required to appoint one. Privacy mail arrives in the same inbox as everything else and is read by the person who wrote both the site and this page.
What this policy covers
It applies to ozjam.com, and to ozjam.com.tr, which redirects here. It covers the pages you are reading and the contact form on them.
It does not cover the Warry iOS app. Warry keeps everything on your own device and shows a single banner advertisement, which is an entirely different set of facts; they are written up in the Warry privacy policy.
It also does not cover the App Store. When you open our listing or download the app you are on Apple’s service, and Apple’s privacy policy governs that visit rather than this one.
What this website does not do
It is easier to be precise about the absences than the presences, so here they are, one at a time.
- No cookies. Not first-party, not third-party, not even “strictly necessary” ones. The site sets none at all. The notice at the bottom of the screen is there to say exactly that.
- No analytics. No Google Analytics, no Plausible, no Matomo, no self-hosted counter. We genuinely do not know how many people have read this page.
- No advertising. The website has never carried any and does not now. The Warry app does show one banner; that belongs to the app, not to this site.
- No third-party scripts. No embedded video, social buttons, comment system, live-chat widget, A/B test, session recorder or fingerprinting library. Every script here is a file we wrote, served from this domain.
- No mailing list. There is nothing to subscribe to, so there is no list you could quietly end up on.
- No profiling, no automated decisions. Nothing on this site scores you, segments you or decides anything about you.
- No sale or sharing of personal data. Not as a policy we could quietly reverse — we hold nothing a buyer would want.
What the site stores in your browser
Two values are written to your browser’s local storage. They are not cookies: they are never attached to a request, so they are never sent to us or to anyone else. They exist so the site remembers a preference you expressed.
| Key | Type | What it holds | Why it exists |
|---|---|---|---|
oz-lang |
localStorage | tr or en | So the site opens in the language you last chose, instead of guessing from your browser every time. |
It has no expiry date and is not refreshed behind your back. It stays until you clear this site’s data in your browser, which removes it at once — the cookie policy walks through how to do that in Safari, Chrome and Firefox.
The site also adds ?lang=tr or ?lang=en to the address bar so that a link you copy carries the language with it. That is part of the URL, not something stored, and it says nothing about you.
Fonts: the one request that leaves your browser
Every page loads two typefaces — Plus Jakarta Sans and Inter — from Google Fonts. While the page is drawn, your browser therefore makes a request to fonts.googleapis.com and fonts.gstatic.com.
That request reaches Google, not us. Like any web request it carries your IP address, your browser’s user agent and the name of the file being asked for. What happens to it afterwards is governed by Google’s own privacy policy, which we would rather link than paraphrase.
We mention it because “we use no third parties” would be untrue while a Google request sits in the page head. If you would rather not make it, a content blocker that blocks those two domains stops it, and the site falls back to your system typeface without anything breaking.
The contact form
The form on the contact page asks for four things: your name, your e-mail address, a topic, and your message. A consent box has to be ticked before it will send. Nothing else about you is requested, and no field is filled in for you.
When you submit it, a small script on our own hosting composes an e-mail and sends it to the studio inbox. There is no database on this site — not an empty one, none at all — so your message is never written to storage on the way through. It ends up as an e-mail, and nowhere else.
Alongside your message, that e-mail records four technical details: the topic you picked, the time in UTC, a shortened one-way hash of your IP address rather than the address itself, and the first 200 characters of your browser’s user agent. They are there so that if the form is abused we can tell one sender from another.
Two things keep bots away: a hidden field no human ever sees, and a limit of five messages an hour per IP address. That limit lives in a single temporary file on the server holding hashed addresses with timestamps, and every entry drops out of it an hour after it was written.
With JavaScript switched off the form still works: the browser posts it the ordinary way and you get a plain confirmation page. And if you would rather skip the form altogether, an ordinary e-mail to the address on the contact page reaches exactly the same inbox — the form has no advantage over it.
Server logs and hosting
This site is plain files on shared hosting. Like every web server on the internet, it produces access logs: your IP address, the date and time, the page you asked for, the HTTP status code, the referring page and your user agent.
Those logs are produced and kept by our hosting provider, IHS Kurumsal Teknoloji Hizmetleri A.Ş., on servers located in Türkiye, as part of running the service. They exist to keep the site available and to deal with abuse. We do not analyse them for insight, we do not turn them into statistics, and we do not join them to anything else. In practice we look at them only when something is broken.
A contact-form message also passes through that provider’s mail server on its way to the inbox. If that server sits outside Türkiye or the European Economic Area, the transfer is covered by the provider’s own safeguards rather than by anything we arrange separately.
Why we are allowed to process this
Under the GDPR, Article 6:
- Your contact-form message — Article 6(1)(a), the consent you give by ticking the box and pressing send. You can withdraw it at any time by asking us to delete the thread.
- Server logs and the anti-spam limit — Article 6(1)(f), our legitimate interest in keeping the site online and free of abuse. Nothing in them is used to profile anyone.
- The two values in your browser — no consent is required, because they are strictly necessary for something you asked for: a language you chose and a notice you dismissed.
Under KVKK, Law No. 6698, Article 5:
- Contact-form messages rest on your explicit consent (açık rıza) under Article 5(1).
- Logs and spam protection rest on the legitimate-interest ground in Article 5(2)(f), which does not require consent.
How long anything is kept
Short answer: not long, and mostly not by us.
- Contact e-mails — for as long as the conversation is useful. A thread about a bug is worth keeping while the bug is open; after that it is clutter. Ask us to delete yours and we will.
- The anti-spam counter — one hour. It holds hashed addresses and drops each entry sixty minutes after it was written.
- Server logs — kept for our hosting provider’s own standard cycle, which we do not set.
- Browser storage — until you clear it. It is on your machine; we cannot reach it and we cannot delete it for you.
Your rights
If you are in the European Economic Area or the United Kingdom, the GDPR lets you ask for a copy of the personal data we hold about you, have it corrected or deleted, restrict or object to how it is used, receive it in a portable form, and withdraw a consent you gave earlier.
If you are in Türkiye, Article 11 of Law No. 6698 gives you a comparable set: to learn whether your data is processed, to request information about it, to learn the purpose and whether it is used in line with that purpose, to know the third parties it is transferred to, to have incomplete or incorrect data corrected or erased, to have those changes passed on to anyone it was shared with, to object to a conclusion drawn against you purely by automated analysis, and to claim compensation for damage caused by unlawful processing.
To use any of them, write to support@ozjam.com. Under KVKK the application comes to us first. We answer within thirty days at the latest, and there is no charge.
One practical note, and it matters more here than the list above. Outside a message you sent us yourself, this website holds nothing that identifies you. An access request will usually be answered with your own e-mail thread and a plain statement that there is nothing else. If we cannot match a request to anything we hold, we will say so rather than guess and hand over someone else’s data.
If you think we have handled something badly, you can complain to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu), or to your local supervisory authority in the EEA or the UK. We would rather you told us first, but that is your choice, not ours.
Children
This site is not directed at children. There is nothing to sign up for, nothing to buy and no field that asks anyone’s age, so it does not knowingly collect anything from a child.
If a child has written to us through the contact form and a parent or guardian would like that message removed, ask and it will be deleted.
Changes to this policy
When something here changes, the effective date at the top of the page changes with it. If a change alters what actually happens to your data rather than just the wording, we will write it up in the studio journal instead of hoping you notice.
We do not keep a public archive of earlier versions. If you need to see the wording that was live on a particular date, ask and we will send it to you.
How to reach us
Privacy questions, requests and complaints all go to the same place: support@ozjam.com. Put “Privacy request” in the subject line and it will be picked out of the rest.
If you would rather use a form, the contact page has one, with a privacy-request topic already in the list. It reaches the same inbox.
Related documents
This policy is written to be read and understood rather than to be lawyer-proof. It is provided for information and is not legal advice. For users in Türkiye the Turkish text is the version that prevails; the English text is a translation of it.