Privacy Policy
Which personal data we collect, for what purpose, and your rights under applicable data protection law.
Last updated: August 10, 2026
Last updated: August 2026
1. Data controller
Your personal data is processed by [Company Name] as the data controller under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") and, where applicable, other data protection regulations.
2. Data we process
Account data: full name, email address, phone number, business information.
Usage data: login records, IP address, browser information, in-panel activity logs.
Payment data: plan, amount, invoice date, and payment status. Collection is handled via Stripe; we never receive, see, or store your card details at any stage. Card data is processed solely by Stripe in accordance with PCI DSS standards.
Site visitor data: information visitors submit through the booking and contact forms on our customers' sites. For this data, our customer is the data controller; we act as a data processor (see the Data Processing Agreement).
3. Purposes of processing and legal basis
- Providing the Service and performing the contract
- Billing, collection, and accounting obligations
- Responding to support requests and communication — legitimate interest
- Security, fraud prevention, and record-keeping — legal obligation and legitimate interest
- Marketing communications, where you have given consent — explicit consent
4. Sharing
We do not sell your data. We use the following infrastructure providers to deliver the Service:
- Vercel — application hosting and content delivery
- Supabase — database, authentication, and file storage
- Resend — transactional email delivery
- Google Analytics — visitor statistics, only on sites where the relevant setting is enabled
Data may also be shared with authorized public authorities where required by law.
5. International transfers
The servers of the providers above may be located outside your country. In that case, transfers are carried out in accordance with applicable data protection requirements and with appropriate safeguards in place.
6. Retention period
We retain data for as long as the service relationship continues and for the statutory limitation periods required by applicable law. After an account closes, we delete or anonymize the data within a reasonable period.
7. Your rights
You have the right to learn whether your data is processed, request information, request correction or deletion, object to processing, and seek compensation for damages.
You can submit requests through our contact page. Requests are resolved within 30 days at the latest.
8. Security
Your data is transmitted over an encrypted connection (HTTPS). We recommend enabling two-factor authentication for panel access. We apply technical and administrative measures to prevent unauthorized access.
9. Changes
We may update this policy. We will notify you of material changes via the email address registered to your account.

