Pazaryeri Entegrasyonu — Privacy policy

Last updated: · Version 1

Legal notice. This text is informational and has not been reviewed by a lawyer. A legal adviser must review the final version before publication.

1. Scope

This policy covers the Pazaryeri Entegrasyonu (Marketplace Integration) Shopify app and the Pazaryeri Merkezi service it connects to — together, the “Service”. The Service moves products, inventory and orders between a Shopify store and Turkish marketplaces (Trendyol, Hepsiburada, N11 and others). Personal data of the buyer is processed during this flow.

2. Roles

Party Role
Merchant (store owner) Data controller (GDPR) / veri sorumlusu (KVKK)
Lydros (Hanifi Ertuğrul Aslan) (Service provider) Data processor (GDPR) / veri işleyen (KVKK)
Marketplaces, carriers, e-invoice integrator Sub-processors and, under Turkish law, independent controllers

The customer data belongs to the merchant. We process it only on the merchant’s instructions and never for our own purposes.

3. Protected customer data we process

Field Why we need it
Customer name Shipping label and tax invoice
Shipping and billing address Shipping label, carrier API, e-Invoice / e-Archive invoice
Phone number Carrier delivery notifications and resolving delivery problems

We do not request customer email addresses from Shopify. Email is deliberately excluded from our Shopify protected customer data request: shipping labels and Turkish e-Archive invoices work without it, so the field is never collected from Shopify.

However: orders imported from Turkish marketplaces (Trendyol, Hepsiburada and others) may include the buyer’s email address — masked on most channels — as part of the order record, and it is stored. That data comes from the merchant’s own marketplace account, not from Shopify. It is used only to process and invoice the order, never for marketing.

We also process non-customer data: store domain and Shopify access token, product/inventory/location data, order totals and line items, merchant company and tax details, and encrypted third-party API credentials. We never receive payment card data.

4. Purposes

  1. Convert marketplace orders into Shopify orders and vice versa.
  2. Create shipping labels and submit shipments to carrier APIs.
  3. Issue e-Invoice / e-Archive invoices as required by Turkish tax law.
  4. Process returns, exchanges and cancellations.
  5. Keep inventory and pricing consistent across channels.
  6. Provide merchant support and troubleshoot failures.
  7. Secure the Service and detect abuse.

We never sell, rent or monetise personal data, use it for advertising or marketing, build customer profiles, combine data across merchants, or train AI models on it.

5. Legal basis

  • Order fulfilment, shipping, returns — GDPR Art. 6(1)(b); KVKK Art. 5/2-c (necessary for performance of a contract).
  • Invoicing and record keeping — GDPR Art. 6(1)(c); KVKK Art. 5/2-ç (legal obligation under the Turkish Tax Procedure Law).
  • Security logging and abuse detection — GDPR Art. 6(1)(f); KVKK Art. 5/2-f (legitimate interest).

6. Storage and isolation

  • Customer data is stored in the Pazaryeri Merkezi PostgreSQL database, isolated per merchant by a tenantId column. Merchants cannot access each other’s data.
  • The Shopify app’s own database stores no customer personal data — only the store session, the encrypted API key and sync settings.
  • All traffic uses TLS. Third-party credentials are encrypted with AES-256-GCM at the field level.
  • Hosting: Hetzner Online GmbH (Almanya, AB).

7. Retention

  • Orders and addresses: 10 years, because the records are tied to tax invoices that Turkish law requires to be retained.
  • Customer-data access logs: 1 year.
  • Application and webhook delivery logs: 90 days.
  • Store session (access token): deleted when the app is uninstalled (app/uninstalled and shop/redact webhooks).
  • Encrypted API key: cleared by the same webhooks; the account is suspended rather than deleted, so reinstalling reconnects you to the same account.
  • Customer data-request exports: kept encrypted inside the app for 30 days, then emptied.

8. Customer redaction requests

When Shopify sends a customers/redact request, we do not delete the order record. Instead we mask its personal fields (name, address, phone) and stamp the record with personalDataRedactedAt. Reason: Turkish tax law requires invoiced order records to be retained; deleting them entirely would breach a legal obligation. After masking, the record only holds amounts, dates and tax data and no longer identifies a person. Once the statutory retention period expires, the record is fully anonymised.

Masked fields: name, e-mail, phone, street address, postal code, buyer tax/national ID number and the raw marketplace order payload. Retained fields: amount, currency, date, order number, SKU, invoice data and province/district. A shop/redact request follows the same path: all personal data of the store is masked and the account is closed, while records are retained for the statutory period.

9. Sub-processors

Personal data is shared only as needed with: the marketplaces connected by the merchant (Trendyol, Hepsiburada, N11, Pazarama, Çiçeksepeti, İdefix, Koçtaş, PttAVM), the carrier chosen by the merchant, the e-Invoice integrator, the hosting provider (Hetzner Online GmbH (Almanya, AB)), and Shopify Inc. The current list is maintained in the Data Processing Agreement, and merchants are notified before changes take effect. We also disclose data to public authorities where a lawful written request requires it.

10. Security

  • TLS in transit; AES-256-GCM field-level encryption for credentials at rest.
  • API keys stored only as HMAC-SHA256 digests, never in plaintext.
  • Tenant isolation enforced on every query.
  • All Shopify webhooks are HMAC-verified; unsigned requests are rejected.
  • Minimum necessary API scopes are requested.
  • A dedicated access log for customer personal data is part of the design: it records the purpose and the fields read, and identifies the data subject by a one-way hash rather than a plaintext identifier. Wiring this log into every read path is in progress.

In the event of a personal data breach we notify affected merchants without undue delay and within 72 hours, as described in our Security Incident Response Policy.

11. Your rights

Customers: the merchant you purchased from is the controller of your data. Contact that merchant to exercise your rights under GDPR Art. 15–22 or KVKK Art. 11. When a merchant forwards such a request to us, we act on it within 30 days.

Merchants: you may request a machine-readable export of your data, request return or deletion of your data on termination, object to a sub-processor, and request a signed DPA.

12. Cookies

The app runs embedded in the Shopify admin and authenticates with session tokens; it does not rely on third-party cookies and uses no tracking, advertising or analytics cookies. This page sets no cookies.

13. Changes

We update the version and date at the top of this page whenever the policy changes. Material changes affecting merchants — such as adding a sub-processor — are announced at least 30 days before they take effect.

14. Contact

  • Data processor: Lydros (Hanifi Ertuğrul Aslan)
  • Address: [ADRES]
  • Email: [İLETİŞİM E-POSTASI]
  • Support request: support form