EU/International Customers: This page is available in English for GDPR compliance.
For Turkish version, see
KVKK Aydınlatma Metni.
PRIVACY POLICY (GDPR)
Last updated: June 10, 2026 |
Effective date: June 10, 2026
1. Data Controller
The data controller responsible for your personal data is:
2. What Personal Data We Collect
We collect the following categories of personal data:
- Identity Data: First name, last name
- Contact Data: Email address, phone number, billing and delivery address
- Financial Data: Payment method details (processed securely via payment providers — we do not store card numbers)
- Transaction Data: Details about purchases, order history
- Technical Data: IP address, browser type, device information, cookies
- Usage Data: Information about how you use our website
- Marketing Data: Preferences for receiving marketing communications (only with consent)
3. Legal Basis for Processing
We process your personal data under the following legal bases (GDPR Article 6):
- Contract Performance (Art. 6(1)(b)): Processing necessary to fulfill your order and deliver products
- Legal Obligation (Art. 6(1)(c)): Processing required by applicable laws (tax, accounting)
- Legitimate Interests (Art. 6(1)(f)): Fraud prevention, security, improving our services
- Consent (Art. 6(1)(a)): Marketing communications, non-essential cookies (you can withdraw at any time)
4. How We Use Your Data
- Processing and fulfilling your orders
- Managing your account and customer relationship
- Processing payments through secure payment providers
- Sending order confirmations and shipping notifications
- Providing customer support
- Complying with legal obligations
- Preventing fraud and ensuring security
- Sending marketing communications (only with your consent)
- Improving our website and services
5. Data Sharing and Third Parties
We share your personal data with the following categories of third parties:
- Payment Processors: PayPal, Stripe, iyzico, PayTR — for secure payment processing
- Shipping Companies: Yurtiçi Kargo, Aras Kargo, MNG, DHL, UPS — for order delivery
- IT Service Providers: Hosting, email services
- Legal Authorities: When required by law
We do not sell your personal data to third parties.
International Transfers: When using PayPal or Stripe, your data may be transferred outside the EU/EEA. These transfers are protected by Standard Contractual Clauses (SCCs) or adequacy decisions.
6. Data Retention
- Order data: 10 years (legal requirement for accounting)
- Customer account data: Until account deletion + 1 year
- Marketing data: Until consent is withdrawn
- Technical/log data: 12 months
- Cookie data: As specified in our Cookie Policy
7. Your Rights Under GDPR
As an EU/EEA resident, you have the following rights:
- Right of Access (Art. 15): Request a copy of your personal data
- Right to Rectification (Art. 16): Correct inaccurate data
- Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten")
- Right to Restriction (Art. 18): Restrict processing of your data
- Right to Data Portability (Art. 20): Receive your data in a machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: Withdraw consent at any time without affecting prior processing
To exercise your rights, contact us at: payitahtivobl@gmail.com
We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.
8. Cookies
We use the following types of cookies:
- Strictly Necessary: Session management, security (cannot be disabled)
- Functional: Language preferences, shopping cart
- Analytics: Understanding how visitors use our site (with consent)
- Payment: Required by PayPal/Stripe for fraud prevention
You can manage cookie preferences through your browser settings or our cookie consent banner.
9. Payment Security
We take payment security seriously:
- All payments are processed by PCI-DSS compliant payment providers
- We never store full credit card numbers on our servers
- All data transmission is encrypted using TLS/SSL
- PayPal and Stripe handle payment data under their own privacy policies
PayPal Privacy Policy |
Stripe Privacy Policy
10. Children's Privacy
Our services are not directed to children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by email or by posting a notice on our website. The "Last updated" date at the top of this page indicates when the policy was last revised.
12. Contact & Complaints
For privacy-related questions or to exercise your rights:
If you are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority.
This policy applies to Trend Ticaret and its website https://trendticaret.com.tr
For Turkish privacy notice: KVKK Aydınlatma Metni