Privacy Policy

How Smartifie collects, uses and protects your personal data.

Last updated: 6 August 2026 · Version v2.5

This Privacy Policy explains how we process your personal data when you use the website, software products and services offered under the Smartifie brand. Your data is processed under Turkish Law No. 6698 (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR).

For the detailed Turkish disclosure see the KVKK Information Notice; for cookies see the Cookie Policy.

1. Data controller

Birileri Dış Ticaret Danışmanlık Sanayi ve Ticaret Limited Şirketi (Smartifie)
Bahariye Mah. 1865 Sk. Karadoğan Blok No: 9, İç Kapı No: 1, Karşıyaka / İZMİR
MERSİS: 0177070525100001 · Trade Registry: 227539 · Tax ID: 1770705251
E-mail: info@smartifie.com · KEP: kayacan.kirpikli@hs01.kep.tr · Phone: +90 555 561 45 47
KVKK contact person: Kayacan Kırpıklı — kayacan.kirpikli@smartifie.com

2. Where your data lives — it depends on the product variant

VariantYour business dataOur role
Windows / Android / iOS / macOS (local SQLite)Stays on your device. It never reaches us.We are not a party; you are the controller
Cross-platform (cloud)On our servers in TürkiyeWe are the processor; you are the controller
Custom DB add-onOn your own database server; we do not store your credentialsWe are the processor
An important, honest warning. Even in the device-local variant, licence verification does reach us (device fingerprint, IP, technical logs). We do not claim "no data ever reaches us", because that would not be true.

In every variant we are the controller of your account, licence, payment and support data.

3. Data we collect

  • Account: name, e-mail, company name.
  • Transactions and billing: product/plan purchased, licences, billing address, (where required) national ID / tax number.
  • Payment: payment records. We do not store your card details — they stay with the authorised payment providers.
  • Technical: IP address, device/browser information, device fingerprint for licence activation, session/audit logs.
  • Account security: whether your e-mail is verified; if you turn on two-factor authentication, your authenticator app's secret and your recovery codes; a short-lived cookie recording that you recently confirmed your password for a sensitive action. We do not ask for a phone number — we use an authenticator app rather than SMS.
  • Communications: the content of messages and support requests you send us.

4. How we use data

  • To provide the Services and to issue, activate and verify licences.
  • To process payments and issue invoices.
  • To provide support and answer your requests.
  • To prevent licence abuse and piracy (device fingerprint, periodic online verification, rate limiting).
  • To secure the Services.
  • To comply with legal obligations.
  • With your consent: analytics measurement to improve the site.

5. Legal basis

Conclusion and performance of the contract (account, licence, delivery of the product); legal obligation (invoices, books); legitimate interest (security, abuse prevention); and, where required, your explicit consent (analytics cookies, marketing).

6. Cookies

No non-essential cookie is loaded unless you give explicit consent. Analytics cookies (Google Analytics) load only if you click "Accept"; if you reject, no request is sent to Google. You can change your decision at any time.

Our web font is self-hosted; opening the page sends no request from your browser to Google. For the full inventory and durations see the Cookie Policy.

7. AI assistant — removed

The AI assistant previously included in our products was removed on 6 August 2026.

  • There is no AI assistant in our products today, and no data of yours is transferred abroad for that purpose.
  • Even while the assistant was running, chat content was not stored on our servers; only token usage counters were kept. Those counters have also been deleted.
  • This section remains as transitional information for readers who may have seen an earlier version of this Policy.

8. Data sharing, sub-processors and transfers abroad

We do not sell your data for marketing. We share it only as necessary to provide the Service:

PartyRoleCountry
Pentech Bilişim Teknolojileri San. ve Tic. Ltd. Şti.Server hosting (VM) — all data held on the serverTürkiye (Bursa)
Google Ireland/LLCAnalytics — only with your consentEU/USA
IyzicoPayment (Türkiye)Türkiye
PaddlePayment — Merchant of Record; for sales outside Türkiye Paddle handles the invoice and the taxEU / UK
Google Play · App Store · Trendyol · AmazonDistribution channelsUSA / TR
  • Analytics (Google): only with your explicit consent.
  • Customer business data in the cloud variant is not moved out of Türkiye — hosting is in Türkiye.

9. Retention

DataPeriod
Invoice, payment, accounting records10 years (Commercial Code Art. 82 — cannot be deleted during that period)
Account, licence, subscription recordsWhile your account exists + 10 years to the extent tied to invoicing
Support correspondence3 years after the request is closed
Audit/security logs — raw IP address90 days. At the end of the period the raw IP address is deleted; only the city/country is kept. Deletion runs automatically once a day.
Two-factor authentication secret and recovery codesWhile two-factor authentication is on. Deleted when it is turned off or reset by our support team.
Password confirmation (step-up) cookie15 minutes

At the end of the period we delete or anonymise the data. Data subject to a statutory retention obligation cannot be deleted during that period — an erasure request may be refused to that extent.

10. Your rights

Under KVKK Art. 11: to learn whether your data is processed, request information, learn the purpose, know the third parties it is transferred to, request correction or erasure, request that these be notified to third parties, object to automated analysis, and claim compensation.

If you are in the EU, GDPR Art. 15-22: access, rectification, erasure, restriction of processing, objection, data portability and the right to complain to your national supervisory authority.

Requests: kayacan.kirpikli@@smartifie.com or info@@smartifie.com. We reply free of charge within 30 days under KVKK and within 1 month under the GDPR.

11. Security and data breaches

We apply encryption in transit and at rest, access controls, logging and regular security audits. In the event of a breach we notify the competent authority within 72 hours and, where there is a high risk, inform you without undue delay.

How your account is protected:

  • E-mail verification: starting a trial, buying a plan and linking a device require a verified e-mail address.
  • Two-factor authentication (2FA): optional on every account. Required for accounts that manage billing, seats or other people's access. It uses an authenticator app; we do not use SMS.
  • Password re-confirmation: for sensitive actions such as removing a device or changing billing details we ask for your password again, so that a stolen session alone cannot perform them.
  • Recovery: if you lose your phone you sign in with your recovery codes. If you lose those too, our support team can reset two-factor authentication; you are notified by e-mail when this happens, and you should contact us immediately if the request did not come from you.

These measures rest on our legitimate interest in keeping your account and other users secure (GDPR Art. 6(1)(f) and Art. 32; in Türkiye KVKK Art. 5/2-f and Art. 12). We do not rely on your consent for them — a security measure conditioned on consent would leave anyone who declines unprotected.

12. Mobile app (Android and iOS)

The mobile app is subject to this Policy in full. The points below are the ones specific to the mobile version.

  • Camera: used only to read barcodes and QR codes. Frames are processed on the device; no photo or video is recorded or sent to our servers. If you decline the permission the app keeps working and scanning falls back to handheld-terminal/keyboard input.
  • Photos: when you attach a photo to a shipment or product, in the cloud variant the file is uploaded to our servers and its EXIF metadata — including location — is stripped before upload. In the device-local variant photos never leave the device.
  • Device identifier: we process a random per-installation identifier together with the device name, solely to bind your licence to the device and enforce the device limit. We do not use the Advertising ID.
  • Automatic backup is disabled: app data — including the local database on the device — is excluded from the operating system's cloud backup (Google Drive) and from device-to-device transfer. When you move to a new device you link the app again.
  • What we do not collect: no location data is collected (the app does not even request the permission); there is no advertising network, analytics or crash-reporting component. The app does not download fonts, icons or scripts from third parties at start-up.
  • Purchases: no payment is taken and no payment data is processed inside the mobile app. You manage your subscription from your Smartifie account.

To delete your account and your data use the Account and Data Deletion page; it explains which data is deleted and which is retained under statutory obligations (see sections 9 and 10).

13. Changes and contact

We update this Policy from time to time; the version number and last-updated date change with every revision. We notify you of material changes. Questions: info@@smartifie.com.

KVKK Information Notice · Cookie Policy