ASOnest logo

Privacy policy

Last updated 25 August 2026

This policy explains what data ASOnest collects, why, and what you can do about it. It applies to asonest.com and to the ASOnest web application. ASOnest is operated by RGS Yazılım Ltd. Şti., Acıbadem Mah. Çeçen Sk. Akasya Residence A1 Kule No: 150, Üsküdar, İstanbul, Türkiye.

The short version

  • We collect the minimum needed to run the service and bill you.
  • We do not sell your data, and we do not share it with advertisers.
  • The marketing site sets no advertising or cross-site tracking cookies.
  • You can export your data or delete your account at any time.

Data we collect

Account data

When you create an account we store your email address, a hashed password (or your identity provider’s subject identifier if you sign in with a third party), and your chosen plan. This is necessary to provide the service under the contract between us.

App and workspace data

The apps you add, the keywords you track, the countries you select and the competitors you monitor. All of this originates either from you or from public app store listings.

Billing data

Payments are processed by our payment provider. We never see or store full card numbers. We retain invoices, the last four digits of the card, and your billing country for tax purposes, which we are legally required to do.

Usage data

Server logs including IP address, user agent, requested URL and timestamp, retained for up to 30 days for security, abuse prevention and debugging.

Cookies and consent

asonest.com loads Google Tag Manager, which we use to manage measurement tags. Google Consent Mode is configured so that analytics and advertising storage start denied: on first load nothing is written to your browser for analytics or advertising, and no advertising identifiers are sent. Tags that require storage stay dormant until consent is granted.

Strictly necessary storage — the things without which the site or the application cannot function, such as staying signed in — is always permitted and is exempt from consent requirements. The web application sets a single session cookie for that purpose. It is not used for tracking.

Cookies we set

Cookie Purpose Duration
asonest_consent Remembers your cookie choice so we don’t ask again. Strictly necessary, exempt from consent. 180 days
asonest_attr_first The campaign that first brought you to us. Only set once you grant analytics consent. 180 days
asonest_attr_last The most recent campaign that referred you. Only set once you grant analytics consent; a Google Ads click id inside it is only kept if you also grant marketing consent. 180 days
Google Analytics / Ads cookies Set by Google itself through the Tag Manager container once you grant the matching consent — analytics measurement or ad campaign tracking. We do not control their names or lifetimes; see Google’s own cookie documentation. Set by Google, typically up to 2 years

Analytics

Measurement tags are delivered through Google Tag Manager and are used to understand aggregate traffic: which pages are read, which referrers send visitors, and which parts of the site people struggle with. We do not use this data to build advertising profiles, and we do not sell it.

Because these tags are delivered by Google, Google acts as a processor and may receive your IP address and user agent in order to serve the container. IP redaction and URL passthrough are enabled, and advertising data redaction is switched on while consent is denied.

Third parties we rely on

  • Hosting and CDN — serving this website and the application.
  • Payment processing — handling subscriptions and invoices.
  • Transactional email — account emails, alerts and receipts.
  • Error monitoring — diagnosing crashes, with request data redacted.
  • Google Tag Manager — delivering the measurement tags described above.

Each acts as a processor under our instructions. We do not sell personal data to anyone, and no third party is permitted to use your data for their own purposes.

Where data is stored

Primary data storage is within the European Union. Some processors operate infrastructure elsewhere; where personal data is transferred outside the EU or UK, transfers are covered by Standard Contractual Clauses or an adequacy decision.

Retention

  • Account and workspace data: for as long as your account exists, then deleted within 30 days.
  • Server logs: up to 30 days.
  • Invoices and tax records: as required by law, typically seven years.

Your rights

Depending on where you live you may have the right to access, correct, delete, restrict or port your data, and to object to processing. Exercise any of these by emailing [email protected]. We respond within 30 days and do not charge for it.

You can export your workspace data as CSV at any time from within the application, and delete your account from the settings page without contacting us.

Security

Data is encrypted in transit with TLS and at rest. Access to production systems is limited to the people who need it and is logged. Passwords are hashed with a modern memory-hard algorithm.

Children

ASOnest is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes

If this policy changes materially we will email account holders before the change takes effect. The date at the top of this page always reflects the current version.

Contact

Questions about this policy or about your data: [email protected].