Privacy Policy
How Smartifie collects, uses and protects your personal data.
Last updated: 28 August 2026 · Version v2.10
This Privacy Policy explains how we process your personal data when you use the website, software products and services offered under the Smartifie brand. Your data is processed under Turkish Law No. 6698 (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR).
For the detailed Turkish disclosure see the KVKK Information Notice; for cookies see the Cookie Policy.
1. Data controller
Birileri Dış Ticaret Danışmanlık Sanayi ve Ticaret Limited Şirketi (Smartifie)
Bahariye Mah. 1865 Sk. Karadoğan Blok No: 9, İç Kapı No: 1, Karşıyaka / İZMİR
MERSİS: 0177070525100001 · Trade Registry: 227539 · Tax ID: 1770705251
E-mail: info@smartifie.com · KEP: kayacan.kirpikli@hs01.kep.tr · Phone: +90 555 561 45 47
KVKK contact person: Kayacan Kırpıklı — kayacan.kirpikli@smartifie.com
2. Where your data lives — it depends on the product variant
| Variant | Your business data | Our role |
|---|---|---|
| Windows / Android / iOS / macOS (local SQLite) | Stays on your device. It never reaches us. | We are not a party; you are the controller |
| Cross-platform (cloud) | On our servers in Türkiye | We are the processor; you are the controller |
| Custom DB add-on | On your own database server; we do not store your credentials | We are the processor |
In every variant we are the controller of your account, licence, payment and support data.
3. Data we collect
- Account: name, e-mail, company name.
- Transactions and billing: product/plan purchased, licences, billing address, (where required) national ID / tax number.
- Payment: payment records. We do not store your card details — they stay with the authorised payment providers.
- Technical: IP address, device/browser information, device fingerprint for licence activation, session/audit logs.
- Account security: whether your e-mail is verified; if you turn on two-factor authentication, your authenticator app's secret and your recovery codes; a short-lived cookie recording that you recently confirmed your password for a sensitive action. We do not ask for a phone number — we use an authenticator app rather than SMS.
- Communications: the content of messages and support requests you send us.
4. How we use data
- To provide the Services and to issue, activate and verify licences.
- To process payments and issue invoices.
- To provide support and answer your requests.
- To prevent licence abuse and piracy (device fingerprint, periodic online verification, rate limiting).
- To secure the Services.
- To comply with legal obligations.
- With your consent: analytics measurement to improve the site.
5. Legal basis
Conclusion and performance of the contract (account, licence, delivery of the product); legal obligation (invoices, books); legitimate interest (security, abuse prevention); and, where required, your explicit consent (analytics cookies, marketing).
6. Cookies
No non-essential cookie is loaded unless you give explicit consent. Analytics cookies (Google Analytics) load only if you click "Accept"; if you reject, no request is sent to Google. You can change your decision at any time.
Our web font is self-hosted; opening the page sends no request from your browser to Google. For the full inventory and durations see the Cookie Policy.
7. AI assistant — removed
The AI assistant previously included in our products was removed on 6 August 2026.
- There is no AI assistant in our products today, and no data of yours is transferred abroad for that purpose.
- Even while the assistant was running, chat content was not stored on our servers; only token usage counters were kept. Those counters have also been deleted.
- This section remains as transitional information for readers who may have seen an earlier version of this Policy.
8. Data sharing, sub-processors and transfers abroad
We do not sell your data for marketing. We share it only as necessary to provide the Service:
| Party | Role | Country |
|---|---|---|
| Pentech Bilişim Teknolojileri San. ve Tic. Ltd. Şti. | Server hosting (VM) — all data held on the server | Türkiye (Bursa) |
| Google Ireland/LLC | Analytics — only with your consent | EU/USA |
| Iyzico | Payment (Türkiye) | Türkiye |
| Paddle | Payment — Merchant of Record; for sales outside Türkiye Paddle handles the invoice and the tax | EU / UK |
| Google Play · App Store · Trendyol · Amazon | Distribution channels | USA / TR |
- Analytics (Google): only with your explicit consent.
- Customer business data in the cloud variant is not moved out of Türkiye — hosting is in Türkiye.
9. Retention
| Data | Period |
|---|---|
| Invoice, payment, accounting records | 10 years (Commercial Code Art. 82 — cannot be deleted during that period) |
| Account, licence, subscription records | While your account exists + 10 years to the extent tied to invoicing |
| Support correspondence | 3 years after the request is closed |
| Audit/security logs — raw IP address | 90 days. At the end of the period the raw IP address is deleted; only the city/country is kept. Deletion runs automatically once a day. |
| Two-factor authentication secret and recovery codes | While two-factor authentication is on. Deleted when it is turned off or reset by our support team. |
| Password confirmation (step-up) cookie | 15 minutes |
At the end of the period we delete or anonymise the data. Data subject to a statutory retention obligation cannot be deleted during that period — an erasure request may be refused to that extent.
10. Your rights
Under KVKK Art. 11: to learn whether your data is processed, request information, learn the purpose, know the third parties it is transferred to, request correction or erasure, request that these be notified to third parties, object to automated analysis, and claim compensation.
If you are in the EU, GDPR Art. 15-22: access, rectification, erasure, restriction of processing, objection, data portability and the right to complain to your national supervisory authority.
Requests: kayacan.kirpikli@@smartifie.com or info@@smartifie.com. We reply free of charge within 30 days under KVKK and within 1 month under the GDPR.
11. Security and data breaches
We apply encryption in transit and at rest, access controls, logging and regular security audits. In the event of a breach we notify the competent authority within 72 hours and, where there is a high risk, inform you without undue delay.
How your account is protected:
- E-mail verification: starting a trial, buying a plan and linking a device require a verified e-mail address.
- Two-factor authentication (2FA): optional on every account. Required for accounts that manage billing, seats or other people's access. It uses an authenticator app; we do not use SMS.
- Password re-confirmation: for sensitive actions such as removing a device or changing billing details we ask for your password again, so that a stolen session alone cannot perform them.
- Recovery: if you lose your phone you sign in with your recovery codes. If you lose those too, our support team can reset two-factor authentication; you are notified by e-mail when this happens, and you should contact us immediately if the request did not come from you.
These measures rest on our legitimate interest in keeping your account and other users secure (GDPR Art. 6(1)(f) and Art. 32; in Türkiye KVKK Art. 5/2-f and Art. 12). We do not rely on your consent for them — a security measure conditioned on consent would leave anyone who declines unprotected.
12. Mobile app (Android and iOS)
The mobile app is subject to this Policy in full. The points below are the ones specific to the mobile version.
- Camera: used only to read barcodes and QR codes. Frames are processed on the device; no photo or video is recorded or sent to our servers. If you decline the permission the app keeps working and scanning falls back to handheld-terminal/keyboard input.
- Photos: when you attach a photo to a shipment or product, in the cloud variant the file is uploaded to our servers and its EXIF metadata — including location — is stripped before upload. In the device-local variant photos never leave the device.
- Device identifier: we process a random per-installation identifier together with the device name, solely to bind your licence to the device and enforce the device limit. We do not use the Advertising ID.
- Automatic backup is disabled: app data — including the local database on the device — is excluded from the operating system's cloud backup (Google Drive) and from device-to-device transfer. When you move to a new device you link the app again.
- What we do not collect: no location data is collected (the app does not even request the permission); there is no advertising network, analytics or crash-reporting component. The app does not download fonts, icons or scripts from third parties at start-up.
- Purchases: no payment is taken and no payment data is processed inside the mobile app. You manage your subscription from your Smartifie account.
To delete your account and your data use the Account and Data Deletion page; it explains which data is deleted and which is retained under statutory obligations (see sections 9 and 10).
13. Free tool pages (online tools that require no account)
Our site offers free tool pages you can use without an account and without paying: smartifie.com/en/tools. Two tools are live today: the barcode generator (turns the text or number you enter into a barcode or QR code and generates codes in bulk from a spreadsheet file) and the shipping mark generator (produces export shipping marks and carton labels). In the barcode generator you can download the result as PNG, SVG or PDF, and in bulk mode also as an A4 label sheet, an Excel file or a ZIP of the PNG/SVG files; the shipping mark generator outputs PDF, PNG, direct printing and an Excel packing list — it has no SVG output. This section applies to all tool pages, both today's and any added later.
13.1. The tools run entirely inside your browser. Generation happens on your own device, using program code your browser downloads when you open the page. Our servers take no part in it.
13.2. Nothing you enter into a tool is sent to our servers. The barcode contents, label texts and the spreadsheet file you select are never transmitted to us under any circumstance: they are not sent to our servers, not seen by us, not stored and not shared with third parties. The file you select is not uploaded — it is read in your browser's memory. The images and PDF files you produce are likewise created in your browser and saved only to your own device.
We carry out no processing operation whatsoever in respect of this data: we do not collect it within the meaning of KVKK Art. 3/1-e, and we are neither the controller (KVKK Art. 3/1-ı) nor the processor (KVKK Art. 3/1-ğ). The same conclusion applies under GDPR Arts. 4(7) and 4(8).
13.3. What does happen: the records that arise from serving you the page. Because the tool page is served from our server — as with every page of our site — two records arise. We state them explicitly so that 13.2 is not read more broadly than it is true:
- Web server access logs: your IP address, browser/device information and a timestamp. They are kept for security, fault diagnosis and abuse prevention on the basis of our legitimate interest (GDPR Art. 6(1)(f); in Türkiye KVKK Art. 5/2-f and Art. 12). Period: 14 days. The web server logs are rotated daily and at most 14 copies are retained; anything older is deleted automatically.
- A page counter that holds no personal data: it keeps aggregate counts only, by day, page path, language, referring source and a bot/human bucket. It creates no record that can be linked to a visitor and never looks at the query parameters in the address bar.
These 14 days are separate from the 90 days in section 9. The period in section 9 covers the audit and security records of users who have an account. When you visit a tool page without an account, no such record is created at all; the only record that exists for you is the web server access log above.
Neither item is specific to the tool pages; both apply across the whole site. If you have consented to analytics cookies, the measurement described in 13.6 also runs.
13.4. You are the controller of any third-party data you enter. If you enter another person's personal data into a tool — for example your customer's name, address or order details in a label text — you are the controller of that data. Establishing a legal basis, informing the data subject and, where required, obtaining their consent are your obligations. Because we never see, receive or store that data, we cannot discharge those obligations on your behalf; nor are we your processor in respect of it.
13.5. The tool pages use no cookies and no browser-local storage. For their own operation the tool pages write no cookie and use no localStorage or sessionStorage. Your inputs and settings are not stored anywhere; refreshing the page returns everything to its defaults. This is a deliberate design decision. The site-wide strictly necessary cookies (language preference, your session cookie if you are signed in, form security) and the analytics cookies that load only if you consent are separate from this; the tool page adds no new cookie to them. The record of your cookie choice falls under that same exception: it is kept in your browser's localStorage and belongs to the site as a whole — even if you answer the cookie banner for the first time on a tool page, that record is not the tool's own. Details: Cookie Policy.
13.6. The tool's own operation sends no request to any third-party server — the one exception is analytics measurement, and only if you have consented.
All software libraries the tool needs (barcode generation, PDF creation, spreadsheet reading, archiving) are hosted on our own server. To do its work, the tool sends no request to any content delivery network (CDN), font provider or script provider, and the data you enter into it reaches no third party.
The one exception — analytics measurement, only if you have consented. The tool pages use our site's general page layout. If you have consented to analytics cookies, the Google Analytics script loads here just as it does on our other pages: your browser sends a request to googletagmanager.com and data about your visit (IP, device/browser information, navigation) is transferred to Google, listed in section 8. If you have not consented, or you rejected, the script is not added to the page at all and no request is sent to Google. This is not a transfer specific to the tool pages and it adds no new recipient to the list in section 8; you can change your decision at any time (Cookie Policy).
13.7. Terms for the tools. The tools are provided free of charge and as is; checking the output before you use it is your responsibility.
14. Changes and contact
We update this Policy from time to time; the version number and last-updated date change with every revision. We notify you of material changes. Questions: info@@smartifie.com.