SEPETİM logo SEPETİM
TR EN

Privacy Policy

Last updated and effective: June 29, 2026

Privacy Policy Terms of Use Account Deletion

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you use the SEPETİM mobile app and the www.sepetimapp.com website (together, the “Service”). This is a privacy notice, not a consent form. Where consent is legally required, we request it separately.

1. Contact

For questions about SEPETİM’s personal-data processing, requests under Türkiye’s Personal Data Protection Law (KVKK), privacy questions, or account deletion requests, contact us at sepetim.app1@gmail.com. To help us match your request to your account, please send it from the email address registered to your account whenever possible.

2. Personal Data We Process

Depending on the features you use, we process the following categories:

CategoryDetails
Account and authenticationEmail address, account ID, username, display name, authentication records, and sign-in method. Passwords are securely handled by our authentication provider and are never visible to us in plain text.
Social sign-inIf you sign in with Google or Apple: provider user ID, email address, name/display name, and authorization information. If you use Apple’s private email option, we may receive a relay address instead of your actual address.
ProfileOptional profile photo, username, display name, profile preferences, and friend/follow counts. Profile photos and public profile fields may be visible to other users.
Lists and product contentProduct links; product name, price, image, currency, stock and variant information; lists/categories, visibility setting, quantity, and selected size/variant.
Social and moderationFriend/follow requests and relationships, blocked users, reports, report descriptions, moderation and security actions, and in-app notifications.
NotificationsDevice push/FCM token, notification preferences, notification type, read status, and limited content required to deliver the notification.
Technical and securityIP address, request time, server and security logs, error/diagnostic information, app version, and limited device/network information needed to prevent abuse.
On-device preferencesTheme, language, currency, and list ordering may be stored locally on your device. Unless sent to our servers, these preferences are not collected by us.

3. How We Collect Data

We obtain data electronically: directly from you when you create an account or edit your profile; from Google or Apple when you choose social sign-in; automatically when your app or device communicates with our servers and notification services; and from the product links and e-commerce pages you ask us to process. Reports and social interaction data may also be provided by other users.

4. Purposes and Legal Bases

PurposeLegal basis under Türkiye’s KVKK
Creating and authenticating accounts; providing lists and social featuresArticle 5(2)(c): processing necessary for entering into or performing the service agreement.
Retrieving product information, price/stock tracking, and notifications you requestPerformance of the agreement; your choices and, where required, consent for optional device notifications.
Security, fraud and abuse prevention, troubleshooting, and proportionate service improvementArticle 5(2)(f): our legitimate interests, provided your fundamental rights are not harmed.
Reviewing reports, managing legal requests, and responding to competent authoritiesLegal obligations under Article 5(2)(ç); establishment, exercise, or protection of a right; and legitimate interests.
Optional activities that legally require consentSpecific, informed, freely given consent under Article 5(1), which may be withdrawn at any time.

5. Data Sharing and Service Providers

We do not sell personal data or use it for behavioral advertising. We disclose only the data needed to provide the Service to these recipient categories:

Recipient/serviceData and purpose
SupabaseAccount, profile, list, product, and social data for authentication, database, and profile-image storage.
Google Firebase Cloud MessagingFCM token, app identifier, and limited notification content required to deliver push notifications.
Google and AppleProvider ID, email, and profile data required for authentication when you choose one of these sign-in methods.
Product-information retrieval providerThe product link you submit and technical parameters needed to retrieve product details. The provider may connect to the relevant e-commerce site.
Apple App StoreData the store processes under its own policy for app distribution, downloads, and store security.
Infrastructure and security providersLimited technical logs needed for hosting, network security, troubleshooting, and abuse prevention.
Competent authorities and legal advisersData required by law, an official request, or the establishment, exercise, or protection of legal rights.

If you choose “public” or “friends” visibility for a profile or list, the relevant profile and list data is disclosed to other users according to that setting.

6. International Data Transfers

Supabase, Google, Apple, and other technical providers may operate servers or use subprocessors outside Türkiye. The limited data categories described above may therefore be processed abroad. Regular transfers are made using a valid transfer mechanism under Article 9 of the KVKK, such as the standard contracts published by the Turkish Data Protection Board, or another safeguard permitted by applicable law. You may contact us for current information about recipients, countries, and transfer mechanisms.

7. Data Retention

Data groupRetention criterion
Account, profile, list, product, and social dataWhile your account is active and during the 30-day recovery period after deactivation. It then enters the permanent-deletion process.
FCM tokenWhile needed for notifications and the session; it is removed or invalidated on sign-out, token replacement, or account deactivation.
Reports, moderation, and security recordsFor the period required to review the report, protect the Service, and manage potential disputes, including applicable limitation periods; then deleted or anonymized.
Server and error logsFor the shortest period needed for security and troubleshooting; then deleted or anonymized.
Legal records and privacy requestsFor the period required by law or needed to establish, exercise, or protect legal rights.

Data in backups is removed through the ordinary backup-rotation cycle and is protected solely for disaster recovery until then.

8. Your Rights and Deleting Your Account

Under Article 11 of the KVKK, you may ask the controller to:

  • Confirm whether your personal data is processed and provide information about it,
  • Explain the purpose of processing and whether data is used consistently with that purpose,
  • Identify recipients in Türkiye or abroad,
  • Correct incomplete or inaccurate data,
  • Delete or destroy data where the conditions of Article 7 are met,
  • Notify recipients of correction, deletion, or destruction,
  • Object to an adverse result produced solely by automated analysis, and
  • Seek compensation for damage caused by unlawful processing.

Send a request from the email registered to your account to sepetim.app1@gmail.com, or send a written request to the service address above. Include your name, contact details, request, and enough information to verify your identity. We respond as soon as possible and no later than 30 days, free of charge unless applicable law permits a necessary fee.

You can delete your account through Account → Deactivate my account in the app or by following the instructions on our Account Deletion page. Your account is first disabled and can be restored by signing in within 30 days. After that period, the account and associated data enter the permanent-deletion process. Records that must legally be retained or that have been segregated for security remain subject to the retention criteria above.

9. Children’s Privacy

The Service is not intended for anyone under 18. If we learn that we process data relating to a person under 18, we may review and suspend the account and delete the relevant data as required by law. Please contact us if you believe an account belongs to a person under 18.

10. Data Security

We take reasonable technical and organizational measures to protect your data, including encryption in transit (HTTPS), row‑level access controls, protection against unauthorized access, restricted privileges, and security logging. If a personal-data breach is identified, we make the notifications required by applicable law. No system can be guaranteed to be 100% secure.

11. Website and Cookies

Our website only uses your browser’s local storage to remember your theme (light/dark) preference. We do not use advertising, behavioral analytics, or tracking cookies. Page fonts are delivered through Google Fonts; when a page loads, technical information such as your IP address, browser details, and request time may be sent to Google and processed under Google’s privacy policy.

12. Changes to This Policy

We may update this policy when our processing activities or applicable law changes. We notify you of material changes through the app or another appropriate channel before they take effect. The current version and effective date appear on this page.

13. Contact

For any privacy questions or requests: sepetim.app1@gmail.com

SEPETİM Privacy Terms of Use Account Deletion Contact © 2026 SEPETİM. All rights reserved.