Privacy Policy
How Smartifie collects, uses and protects your personal data.
Last updated: 6 August 2026 · Version v2.5
This Privacy Policy explains how we process your personal data when you use the website, software products and services offered under the Smartifie brand. Your data is processed under Turkish Law No. 6698 (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR).
For the detailed Turkish disclosure see the KVKK Information Notice; for cookies see the Cookie Policy.
1. Data controller
Birileri Dış Ticaret Danışmanlık Sanayi ve Ticaret Limited Şirketi (Smartifie)
Bahariye Mah. 1865 Sk. Karadoğan Blok No: 9, İç Kapı No: 1, Karşıyaka / İZMİR
MERSİS: 0177070525100001 · Trade Registry: 227539 · Tax ID: 1770705251
E-mail: info@smartifie.com · KEP: kayacan.kirpikli@hs01.kep.tr · Phone: +90 555 561 45 47
KVKK contact person: Kayacan Kırpıklı — kayacan.kirpikli@smartifie.com
2. Where your data lives — it depends on the product variant
| Variant | Your business data | Our role |
|---|---|---|
| Windows / Android / iOS / macOS (local SQLite) | Stays on your device. It never reaches us. | We are not a party; you are the controller |
| Cross-platform (cloud) | On our servers in Türkiye | We are the processor; you are the controller |
| Custom DB add-on | On your own database server; we do not store your credentials | We are the processor |
In every variant we are the controller of your account, licence, payment and support data.
3. Data we collect
- Account: name, e-mail, company name.
- Transactions and billing: product/plan purchased, licences, billing address, (where required) national ID / tax number.
- Payment: payment records. We do not store your card details — they stay with the authorised payment providers.
- Technical: IP address, device/browser information, device fingerprint for licence activation, session/audit logs.
- Account security: whether your e-mail is verified; if you turn on two-factor authentication, your authenticator app's secret and your recovery codes; a short-lived cookie recording that you recently confirmed your password for a sensitive action. We do not ask for a phone number — we use an authenticator app rather than SMS.
- Communications: the content of messages and support requests you send us.
4. How we use data
- To provide the Services and to issue, activate and verify licences.
- To process payments and issue invoices.
- To provide support and answer your requests.
- To prevent licence abuse and piracy (device fingerprint, periodic online verification, rate limiting).
- To secure the Services.
- To comply with legal obligations.
- With your consent: analytics measurement to improve the site.
5. Legal basis
Conclusion and performance of the contract (account, licence, delivery of the product); legal obligation (invoices, books); legitimate interest (security, abuse prevention); and, where required, your explicit consent (analytics cookies, marketing).
6. Cookies
No non-essential cookie is loaded unless you give explicit consent. Analytics cookies (Google Analytics) load only if you click "Accept"; if you reject, no request is sent to Google. You can change your decision at any time.
Our web font is self-hosted; opening the page sends no request from your browser to Google. For the full inventory and durations see the Cookie Policy.
7. AI assistant — removed
The AI assistant previously included in our products was removed on 6 August 2026.
- There is no AI assistant in our products today, and no data of yours is transferred abroad for that purpose.
- Even while the assistant was running, chat content was not stored on our servers; only token usage counters were kept. Those counters have also been deleted.
- This section remains as transitional information for readers who may have seen an earlier version of this Policy.
8. Data sharing, sub-processors and transfers abroad
We do not sell your data for marketing. We share it only as necessary to provide the Service:
| Party | Role | Country |
|---|---|---|
| Pentech Bilişim Teknolojileri San. ve Tic. Ltd. Şti. | Server hosting (VM) — all data held on the server | Türkiye (Bursa) |
| Google Ireland/LLC | Analytics — only with your consent | EU/USA |
| Iyzico | Payment (Türkiye) | Türkiye |
| Paddle | Payment — Merchant of Record; for sales outside Türkiye Paddle handles the invoice and the tax | EU / UK |
| Google Play · App Store · Trendyol · Amazon | Distribution channels | USA / TR |
- Analytics (Google): only with your explicit consent.
- Customer business data in the cloud variant is not moved out of Türkiye — hosting is in Türkiye.
9. Retention
| Data | Period |
|---|---|
| Invoice, payment, accounting records | 10 years (Commercial Code Art. 82 — cannot be deleted during that period) |
| Account, licence, subscription records | While your account exists + 10 years to the extent tied to invoicing |
| Support correspondence | 3 years after the request is closed |
| Audit/security logs — raw IP address | 90 days. At the end of the period the raw IP address is deleted; only the city/country is kept. Deletion runs automatically once a day. |
| Two-factor authentication secret and recovery codes | While two-factor authentication is on. Deleted when it is turned off or reset by our support team. |
| Password confirmation (step-up) cookie | 15 minutes |
At the end of the period we delete or anonymise the data. Data subject to a statutory retention obligation cannot be deleted during that period — an erasure request may be refused to that extent.
10. Your rights
Under KVKK Art. 11: to learn whether your data is processed, request information, learn the purpose, know the third parties it is transferred to, request correction or erasure, request that these be notified to third parties, object to automated analysis, and claim compensation.
If you are in the EU, GDPR Art. 15-22: access, rectification, erasure, restriction of processing, objection, data portability and the right to complain to your national supervisory authority.
Requests: kayacan.kirpikli@@smartifie.com or info@@smartifie.com. We reply free of charge within 30 days under KVKK and within 1 month under the GDPR.
11. Security and data breaches
We apply encryption in transit and at rest, access controls, logging and regular security audits. In the event of a breach we notify the competent authority within 72 hours and, where there is a high risk, inform you without undue delay.
How your account is protected:
- E-mail verification: starting a trial, buying a plan and linking a device require a verified e-mail address.
- Two-factor authentication (2FA): optional on every account. Required for accounts that manage billing, seats or other people's access. It uses an authenticator app; we do not use SMS.
- Password re-confirmation: for sensitive actions such as removing a device or changing billing details we ask for your password again, so that a stolen session alone cannot perform them.
- Recovery: if you lose your phone you sign in with your recovery codes. If you lose those too, our support team can reset two-factor authentication; you are notified by e-mail when this happens, and you should contact us immediately if the request did not come from you.
These measures rest on our legitimate interest in keeping your account and other users secure (GDPR Art. 6(1)(f) and Art. 32; in Türkiye KVKK Art. 5/2-f and Art. 12). We do not rely on your consent for them — a security measure conditioned on consent would leave anyone who declines unprotected.
12. Mobile app (Android and iOS)
The mobile app is subject to this Policy in full. The points below are the ones specific to the mobile version.
- Camera: used only to read barcodes and QR codes. Frames are processed on the device; no photo or video is recorded or sent to our servers. If you decline the permission the app keeps working and scanning falls back to handheld-terminal/keyboard input.
- Photos: when you attach a photo to a shipment or product, in the cloud variant the file is uploaded to our servers and its EXIF metadata — including location — is stripped before upload. In the device-local variant photos never leave the device.
- Device identifier: we process a random per-installation identifier together with the device name, solely to bind your licence to the device and enforce the device limit. We do not use the Advertising ID.
- Automatic backup is disabled: app data — including the local database on the device — is excluded from the operating system's cloud backup (Google Drive) and from device-to-device transfer. When you move to a new device you link the app again.
- What we do not collect: no location data is collected (the app does not even request the permission); there is no advertising network, analytics or crash-reporting component. The app does not download fonts, icons or scripts from third parties at start-up.
- Purchases: no payment is taken and no payment data is processed inside the mobile app. You manage your subscription from your Smartifie account.
To delete your account and your data use the Account and Data Deletion page; it explains which data is deleted and which is retained under statutory obligations (see sections 9 and 10).
13. Changes and contact
We update this Policy from time to time; the version number and last-updated date change with every revision. We notify you of material changes. Questions: info@@smartifie.com.