Privacy Policy
Last updated: July 22, 2026
This Privacy Policy explains how TurnKit collects and processes personal data through the TurnKit website, developer dashboard, APIs, SDKs and related services.
1. Who operates TurnKit
TurnKit is operated by:
Nenad Nikolić, operating as TurnKit
Svetosavska 107v/17
Kikinda, Serbia
Email: support@turnkit.dev
Nenad Nikolić is the data controller for developer accounts, website usage, subscriptions, support, security and administration of the TurnKit service.
When developers use TurnKit to process information relating to players of their games or applications, the developer generally acts as the data controller and TurnKit acts as the data processor.
2. Data we process
Developer account data
When you create or access a TurnKit account, we may receive your:
- Name or username
- Email address
- Profile image
- Google or GitHub account identifier
- Account settings and project configuration
We do not receive or store your Google or GitHub password.
Billing data
When you purchase a subscription, we may receive:
- Subscription and payment status
- Transaction and customer identifiers
- Billing country and currency
- Invoice, refund and tax information
Payments are processed by our merchant-of-record or payment provider. TurnKit does not store complete payment-card details.
Technical and usage data
We may process:
- IP addresses
- Login and authentication events
- Browser, device, application and SDK information
- API requests and usage volumes
- Concurrent-user usage
- Connection and session events
- Error, diagnostic and security logs
Player data submitted by developers
Depending on the modules used, developers may submit:
- Player identifiers and display names
- Matchmaking and game-session information
- Leaderboard scores and rankings
- PlayerStore keys, values and transaction information
- Relay messages and turn information required to operate an active game session
Relay message contents are intended to be transient and are not intentionally retained after the relevant session, except where limited processing is necessary for security, debugging or abuse prevention.
Developers are responsible for deciding what player data they submit and must not submit unnecessary or highly sensitive personal data.
3. How and why we use data
We process data to:
- Create and maintain developer accounts
- Authenticate users
- Provide TurnKit modules and APIs
- Operate matchmaking, relay, leaderboard and PlayerStore features
- Manage subscriptions and usage limits
- Process billing and refunds
- Provide support
- Monitor performance and reliability
- Prevent fraud, attacks, cheating and abuse
- Enforce our Terms of Service
- Comply with legal and accounting obligations
Where applicable, our legal bases are:
- Performance of a contract, when processing is necessary to provide TurnKit
- Legitimate interests, including service security, fraud prevention, debugging and improvement
- Legal obligations, including accounting, tax and lawful disclosure requirements
- Consent, where we specifically request it for optional processing
We do not sell personal data.
4. Service providers and recipients
We may share data with providers necessary to operate TurnKit, including:
- Amazon Web Services, for backend, database and infrastructure hosting
- Vercel, for website and web-application hosting
- Google and GitHub, when you use their authentication services
- Polar, for subscription, payment, tax and billing administration
We may also disclose information to professional advisers, regulators, courts or public authorities where required by law or necessary to protect legal rights.
Each independent provider may process information under its own privacy policy.
5. International transfers
TurnKit is operated from Serbia and uses service providers that may process data in Serbia, the European Economic Area, the United States and other countries.
Where required by applicable law, international transfers are protected through an adequacy decision, approved contractual clauses, provider data-protection agreements or another legally recognized safeguard.
Information about applicable safeguards may be requested at support@turnkit.dev.
6. Data retention
We retain data only for as long as necessary for the purposes described above:
- Developer account data is retained while the account is active and is normally removed or anonymized within 30 days after account deletion.
- Persistent player data is retained until it is deleted by the developer, the relevant project is deleted or the service relationship ends.
- Routine technical and security logs are normally retained for up to 90 days.
- Support communications may be retained for up to three years after resolution.
- Billing and transaction records are retained for the period required by applicable accounting and tax laws.
- Deleted information may remain temporarily in protected backups until the normal backup cycle expires.
Information may be retained longer where necessary to investigate fraud or security incidents, resolve disputes, comply with law or establish or defend legal claims.
7. Your rights
Depending on applicable law, you may have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion
- Restrict certain processing
- Object to processing based on legitimate interests
- Receive eligible data in a portable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with a competent data-protection authority
To exercise these rights, contact support@turnkit.dev. We may need to verify your identity before completing a request.
When TurnKit processes player data on behalf of a developer, requests concerning that data should normally be submitted to the developer responsible for the relevant game or application.
You may lodge a complaint with the Serbian Commissioner for Information of Public Importance and Personal Data Protection or, where applicable, a supervisory authority in the country where you live or work.
8. Security
We use reasonable technical and organizational measures intended to protect personal data, including encryption in transit, access controls, restricted infrastructure access and security monitoring.
No online service can guarantee absolute security.
Developers are responsible for protecting their TurnKit credentials and for not submitting unnecessary personal data through player identifiers, logs, Relay messages or PlayerStore values.
9. Children
TurnKit developer accounts are not intended for individuals under 18.
Developers using TurnKit in games or applications intended for children are responsible for complying with applicable children’s privacy laws, providing appropriate notices and obtaining any required parental consent.
10. Cookies
TurnKit may use cookies or similar technologies that are necessary for authentication, security, session management and user preferences.
If TurnKit introduces non-essential analytics, advertising or marketing cookies, we will provide additional information and obtain consent where required.
11. Changes to this Policy
We may update this Privacy Policy when our services, providers or legal obligations change.
The current version will be published on the TurnKit website with an updated revision date. Where required, we will provide additional notice of material changes.
12. Contact
For privacy questions or requests, contact:
Nenad Nikolić, operating as TurnKit
Svetosavska 107v/17
Kikinda, Serbia
Email: support@turnkit.dev