Privacy & Data Handling Policy
This policy explains how Alkaç WMS (the "Service"), operated by Bora Alkaç, Türkiye ("we", "us"), collects, processes, stores, uses, shares and disposes of information, including personal data received from Amazon and other marketplaces through their APIs. It is written to meet the Turkish Personal Data Protection Law No. 6698 (KVKK) and the Amazon Selling Partner API Data Protection Policy and Acceptable Use Policy.
1. Our role
The Service is a warehouse and order management platform used by online merchants ("Customers"). For the personal data of the Customer's buyers, the Customer is the data controller and we act as a data processor on the Customer's instructions. For our own Customer account and contact data, we are the data controller.
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Customer account data | User names, business e-mail, role, login and security logs | The Customer |
| Order data | Order and item numbers, products, quantities, prices, status, carrier and tracking | Marketplace / store APIs authorized by the Customer |
| Buyer personal data (PII) | Recipient name, shipping address, phone, e-mail; for invoices: billing name, Turkish ID or tax number | Marketplace APIs (e.g. Amazon Selling Partner API restricted data) |
| Product and stock data | Catalog, barcodes, prices, stock by location | The Customer, its ERP, marketplace listings |
| Financial data | Fees, commissions, settlements per order | Marketplace APIs |
We do not collect payment card data. This website uses no tracking or advertising cookies; it only stores your language choice in your browser.
3. How we use data
- To import and fulfil the Customer's orders: stock reservation, picking, packing and quality control.
- To create carrier shipments, print shipping labels and confirm shipment and tracking back to the marketplace.
- To issue legally required e-invoices / e-archive invoices through the Customer's ERP or accounting integrator.
- To synchronise stock and prices with sales channels and to report order profitability to the Customer.
- To secure and operate the Service (authentication, audit logs, troubleshooting).
Legal bases under KVKK Article 5: performance of a contract, compliance with legal obligations (tax and invoicing law) and our legitimate interest in securing the Service.
4. Amazon information
5. Storage, security and access
- Encryption in transit: all connections to the Service, to marketplace APIs and to service providers use TLS.
- Encryption at rest: Amazon buyer PII (name, address, phone, e-mail, national ID) and raw Amazon order payloads are encrypted field by field with AES-256-GCM. Encryption keys are stored outside the database and source code, readable only by the application, and are not part of database backups. API credentials are stored encrypted.
- Minimisation: Amazon buyers appear in order lists and customer records only as "Amazon buyer" with an anonymous code; the readable details exist only in the encrypted shipping and invoicing records.
- Access control: named personal accounts only, role-based permissions on a need-to-know basis, mandatory two-factor authentication, and passwords of at least 12 characters with upper and lower case letters, numbers and symbols, renewed every 365 days.
- Infrastructure: databases and internal services are not reachable from the internet; administrative access is restricted.
- Change management: every release is tested on a staging environment and dependencies are scanned for known vulnerabilities before release.
6. Sharing
We share personal data only with parties the Customer uses to fulfil its own orders, and only the fields they need:
- Carriers (e.g. MNG Kargo, Yurtiçi Kargo, Aras Kargo): recipient name, address and phone to create the shipment.
- e-Invoice / ERP providers (e.g. Paraşüt, Nebim): buyer name, address and tax identifier to issue the legally required invoice.
- The marketplace itself: shipment confirmation and tracking numbers.
- Authorities: where required by law.
Data is sent over encrypted connections through the providers' APIs. We do not sell personal data.
7. Retention and disposal
- Amazon buyer PII is masked (irreversibly overwritten) no later than 30 days after the order has shipped, unless a longer period is required by law. Order records then keep only non-personal information such as products, quantities, amounts and city.
- Invoices are retained by the Customer's ERP / e-invoice provider for the period required by Turkish tax law.
- Customer account data is kept for the duration of the contract and deleted or anonymised afterwards, except where the law requires longer retention.
8. Security incidents
If a security incident affects personal data we follow our incident response procedure: we contain it (revoke credentials and tokens, block access), investigate its cause, restore from clean backups, rotate keys, and notify affected Customers without undue delay. Incidents involving Amazon Information are reported to Amazon at security@amazon.com within 24 hours of detection, and personal data breaches are reported to the Turkish Personal Data Protection Authority as required by KVKK.
9. Your rights
Under KVKK Article 11 you may ask whether your personal data is processed, request information, correction or deletion, object to processing and request compensation for unlawful processing. Buyers of our Customers may also contact the merchant they purchased from, who is the data controller of their order data. Requests: info@alkac.com.tr.
10. Contact
Alkaç WMS — Bora Alkaç, Türkiye · info@alkac.com.tr
We may update this policy; the "last updated" date above shows the current version.
Gizlilik ve Veri İşleme Politikası
Bu politika, Bora Alkaç (Türkiye) tarafından işletilen Alkaç WMS'in ("Hizmet") Amazon ve diğer pazaryerlerinden API ile alınanlar dahil kişisel verileri nasıl topladığını, işlediğini, sakladığını, kullandığını, paylaştığını ve imha ettiğini açıklar. 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) ile Amazon Selling Partner API Veri Koruma ve Kabul Edilebilir Kullanım politikalarına uygun hazırlanmıştır.
1. Rolümüz
Hizmet, çevrim içi satıcıların ("Müşteri") kullandığı bir depo ve sipariş yönetim platformudur. Müşterinin alıcılarına ait kişisel verilerde veri sorumlusu Müşteridir; biz Müşterinin talimatıyla veri işleyen konumundayız. Müşteri hesabı ve iletişim verileri için veri sorumlusu biziz.
2. İşlediğimiz veriler
| Kategori | Örnekler | Kaynak |
|---|---|---|
| Müşteri hesap verisi | Kullanıcı adı, iş e-postası, yetki, giriş ve güvenlik kayıtları | Müşteri |
| Sipariş verisi | Sipariş ve kalem numaraları, ürün, adet, fiyat, durum, kargo ve takip | Müşterinin yetkilendirdiği pazaryeri / mağaza API'leri |
| Alıcı kişisel verisi | Alıcı adı, teslimat adresi, telefon, e-posta; fatura için ad, TC kimlik ya da vergi numarası | Pazaryeri API'leri (ör. Amazon SP-API kısıtlı veri) |
| Ürün ve stok verisi | Katalog, barkod, fiyat, raf bazında stok | Müşteri, ERP'si, pazaryeri ilanları |
| Finansal veri | Sipariş bazında komisyon, kesinti, hakediş | Pazaryeri API'leri |
Kart verisi toplamayız. Bu web sitesi takip ya da reklam çerezi kullanmaz; yalnız dil tercihiniz tarayıcınızda saklanır.
3. Kullanım amaçları
- Müşterinin siparişlerini içe almak ve hazırlamak: stok ayırma, toplama, paketleme, kontrol.
- Kargo kaydı oluşturmak, etiket basmak, gönderi ve takip bilgisini pazaryerine bildirmek.
- Yasal zorunlu e-fatura / e-arşiv faturayı Müşterinin ERP'si ya da muhasebe entegratörü üzerinden kesmek.
- Stok ve fiyatı satış kanallarıyla eşitlemek, sipariş kârlılığını Müşteriye raporlamak.
- Hizmetin güvenliği ve işletimi (kimlik doğrulama, denetim kayıtları, hata giderme).
KVKK md. 5 hukuki sebepleri: sözleşmenin ifası, hukuki yükümlülük (vergi ve fatura mevzuatı) ve Hizmetin güvenliğine yönelik meşru menfaat.
4. Amazon verisi
5. Saklama, güvenlik ve erişim
- Aktarımda şifreleme: Hizmete, pazaryeri API'lerine ve hizmet sağlayıcılara tüm bağlantılar TLS ile şifrelidir.
- Depolamada şifreleme: Amazon alıcı kişisel verisi (ad, adres, telefon, e-posta, TC) ve ham Amazon sipariş verisi alan bazında AES-256-GCM ile şifrelenir. Anahtarlar veritabanı ve kaynak kod dışında, yalnız uygulamanın okuyabileceği şekilde tutulur ve veritabanı yedeğine girmez. API kimlik bilgileri şifreli saklanır.
- Veri azaltma: Amazon alıcısı sipariş listelerinde ve müşteri kayıtlarında yalnız "Amazon Alıcısı" ve anonim bir kodla görünür; okunabilir bilgiler yalnız şifreli teslimat / fatura kaydındadır.
- Erişim kontrolü: yalnız kişiye özel hesaplar, gerektiği kadar rol bazlı yetki, zorunlu iki adımlı doğrulama; en az 12 karakter, büyük ve küçük harf, rakam ve sembol içeren, 365 günde bir yenilenen parolalar.
- Altyapı: veritabanı ve iç servisler internete açık değildir; yönetim erişimi kısıtlıdır.
- Değişiklik yönetimi: her sürüm önce test ortamında denenir; yayından önce bağımlılıklar bilinen açıklar için taranır.
6. Paylaşım
Kişisel veriyi yalnız Müşterinin kendi siparişini tamamlamak için kullandığı taraflarla ve yalnız gereken alanlarla paylaşırız:
- Kargo firmaları (ör. MNG Kargo, Yurtiçi Kargo, Aras Kargo): gönderi için alıcı adı, adresi ve telefonu.
- e-Fatura / ERP sağlayıcıları (ör. Paraşüt, Nebim): yasal fatura için alıcı adı, adresi ve vergi kimliği.
- Pazaryerinin kendisi: gönderi onayı ve takip numarası.
- Resmî makamlar: kanunen gerektiğinde.
Veri, sağlayıcıların API'leri üzerinden şifreli bağlantıyla iletilir. Kişisel veri satmayız.
7. Saklama süresi ve imha
- Amazon alıcı kişisel verisi, kanunen daha uzun süre gerekmedikçe sipariş gönderildikten en geç 30 gün sonra maskelenir (geri döndürülemez şekilde silinir). Sipariş kaydında yalnız ürün, adet, tutar ve il gibi kişisel olmayan bilgiler kalır.
- Faturalar, vergi mevzuatının öngördüğü süre boyunca Müşterinin ERP / e-fatura sağlayıcısında saklanır.
- Müşteri hesap verisi sözleşme süresince tutulur; sonrasında kanuni süreler saklı kalmak kaydıyla silinir ya da anonimleştirilir.
8. Güvenlik olayları
Kişisel veriyi etkileyen bir güvenlik olayında olay müdahale prosedürümüzü uygularız: olayı sınırlar (kimlik bilgilerini ve anahtarları iptal eder, erişimi keseriz), nedenini inceler, temiz yedekten geri yükler, anahtarları yeniler ve etkilenen Müşterileri gecikmeksizin bilgilendiririz. Amazon verisini ilgilendiren olaylar tespitten itibaren 24 saat içinde security@amazon.com adresine bildirilir; kişisel veri ihlalleri KVKK uyarınca Kişisel Verileri Koruma Kurumu'na bildirilir.
9. Haklarınız
KVKK md. 11 uyarınca kişisel verinizin işlenip işlenmediğini öğrenme, bilgi talep etme, düzeltme ya da silinmesini isteme, işlemeye itiraz etme ve kanuna aykırı işleme nedeniyle zararın giderilmesini talep etme haklarına sahipsiniz. Müşterilerimizin alıcıları, sipariş verisinin sorumlusu olan satıcıya da başvurabilir. Talepler: info@alkac.com.tr.
10. İletişim
Alkaç WMS — Bora Alkaç, Türkiye · info@alkac.com.tr
Bu politika güncellenebilir; geçerli sürüm yukarıdaki "son güncelleme" tarihiyle gösterilir.