Privacy Policy
This policy explains how your personal data is processed when you use the catalogtopia.com website and the Catalogtopia application at app.catalogtopia.com. It is organised under the headings of Türkiye's Personal Data Protection Law No. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR).
Last updated:
1. Data controller
The data controller is Serdal Güldap (a natural person), who operates Catalogtopia.
- Address: Gülbahçe Mah. Kavas Çıkmazı Sk. No: 6 A, Osmangazi / Bursa, Türkiye
- E-mail (including KVKK applications, privacy and data deletion requests): privacy@catalogtopia.com
2. Scope
This policy covers two services: catalogtopia.com (the website and these legal pages) and app.catalogtopia.com (the application in which businesses analyse their product catalogues). Catalogtopia is a service for businesses; it processes the data of the people who open an application account on behalf of a company or a sole proprietorship.
3. Data we process
| Category | Data | Source |
|---|---|---|
| Account | Name, e-mail address, whether the e-mail is verified, an irreversible hash of your password (scrypt). The password itself is never stored. | Sign-up form |
| Session | A session cookie; in our database only the SHA-256 hash of the session key and its expiry; depending on how you sign in, your IP address and browser information (User-Agent). | Your browser |
| Activity records | Who performed which action in the application (user identifier, action, target, time). No IP address is written to these records. | The application |
| Store and catalogue data | Product information from the Shopify store you connect or the CSV/XML feed you add (title, description, brand, price, stock, image links, etc.), a raw copy of the source, and the feed address. If you put personal information into product data (e.g. a brand that is a person's name), that is processed too. | Shopify / your feed |
| Connection keys | Shopify and Meta access keys — encrypted with AES-256-GCM. | Your connection |
| Meta catalogue information | The Meta catalogue ID and name; the catalogue items' IDs, retailer_id values, review and visibility statuses and Meta's error codes. | Meta (through your connection) |
| Images you upload | Files you upload as product images, as they are. Metadata inside the file (e.g. EXIF, which may include where a photo was taken) is not removed. | You |
| Server logs | On both sites: IP address, time of the request, the address requested, response code, referring page (Referer) and browser information. | Your browser's request |
| Preferences stored in the browser | On catalogtopia.com only: your theme, language and currency preference (in your browser's localStorage; never sent to us). | Your choice |
4. Data we do not process
- We do not read your Shopify store's customer or order data; we ask Shopify only for permission to read products (and, if you explicitly allow it, to write product titles).
- We do not read user, advertising, pixel or event data from Meta.
- We do not process payment information (there is no paid plan at present).
- We use no analytics, advertising or tracking tool; we do not sell your data or use it for advertising.
5. Purposes and legal bases
| Purpose | Data | KVKK Art. 5 / GDPR Art. 6 |
|---|---|---|
| Opening your account, signing you in, e-mail verification and password reset | Account, session | Entering into and performing the contract (KVKK 5/2-c; GDPR 6/1-b) |
| Analysing your catalogues, showing issues and what Meta reports; writing titles to Shopify on your instruction | Store/catalogue data, connection keys, Meta catalogue information, images | Performing the contract (KVKK 5/2-c; GDPR 6/1-b) |
| Security of the service, preventing abuse, debugging | Server logs, activity records, session | Legitimate interest (KVKK 5/2-f; GDPR 6/1-f) |
| Legal obligations and protecting rights | The data concerned, as far as necessary | Legal obligation; establishing a right (KVKK 5/2-ç, 5/2-e; GDPR 6/1-c, 6/1-f) |
We do not use your data for automated decision-making or profiling.
6. Meta (Facebook) data
When you connect your Meta catalogue, we read from Meta only the catalogue ID and name and, for the catalogue's items, their IDs, retailer_id values, review and visibility statuses and error codes. Meta's error description texts are not stored. We use this information only to show it to you in the application as "Meta reports"; it does not enter Catalogtopia's health score.
Your Meta access key is stored encrypted, is never sent to a browser and is used only for requests to Meta. The current version writes nothing to Meta.
In the application, Settings → Meta connection → "Disconnect" deletes the key and the catalogue mapping immediately. Item statuses already read from Meta are not deleted by this step. What can be deleted today and how to make a deletion request: Data Deletion Instructions.
7. Shopify data
When you connect your Shopify store we read its product data. Writing a product title to Shopify needs a separate, explicit permission and is done only for corrections you approve. The Shopify access key is stored encrypted.
Removing the app from your Shopify admin does not by itself start the deletion of your data on our side; to delete it, use the route in the Data Deletion Instructions.
8. Security
- All traffic is encrypted with HTTPS.
- Passwords are hashed with scrypt; session keys are kept in the database only as hashes.
- Shopify and Meta access keys are encrypted with AES-256-GCM and are never sent to a browser.
- Each customer account's data is separated from the others by row-level security in the database.
- Backups are stored encrypted (GPG).
9. Retention
The table below shows how the system actually behaves today; only measured periods or periods configured in the system are given.
| Data | Today |
|---|---|
| Account, catalogue, product and connection data; raw copies of the source; activity records | No automatic deletion; kept as long as your account is open. |
| Session | A session unused for 7 days expires; its record is deleted when you sign out. Expired session records are not cleaned up automatically today. |
| Password reset and e-mail verification links | Valid for 1 hour. |
| Images you upload | There is no way to delete them today; they stay at their public addresses. |
| Server logs (nginx) | Deleted after 14 days. |
| System logs | No time limit; rotated by a disk size limit. The application writes no e-mail address or IP address to these logs. |
| Encrypted database backups | Daily backups are deleted on the server after 7 days; the same clean-up job also covers the copies in Cloudflare R2. |
| Preferences in the browser (catalogtopia.com) | In your browser until you delete them. |
10. Deleting your data
The application has no account deletion screen today. You can send your deletion request from your account's e-mail address to privacy@catalogtopia.com. We answer your request within 30 days at the latest (KVKK Art. 13); our answer states clearly which data was deleted and which cannot yet be deleted in today's system.
What can and cannot be deleted from the application today, and how to make the request: Data Deletion Instructions.
11. Your rights
Under KVKK Art. 11 you have the right to learn whether your personal data is processed and, if so, to request information about it; to learn the purpose of processing and whether it is used accordingly; to know the third parties it is transferred to; to request its correction if it is incomplete or wrong, and its deletion or destruction; to request that these actions be notified to the recipients; to object to a result against you arising from analysis by automated systems; and to claim compensation for damage caused by unlawful processing.
If the GDPR applies to you, you also have the rights of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21), and the right to lodge a complaint with the supervisory authority of your country.
Send your requests by e-mail to privacy@catalogtopia.com. Your request is concluded free of charge within 30 days at the latest. If you are not satisfied with the outcome you may complain to Türkiye's Personal Data Protection Board (KVKK Kurulu).
13. Children
Catalogtopia is a service for businesses; it is not intended for people under 18 and we do not knowingly process children's data.
14. Changes
When we update this policy we change the "Last updated" date at the top of the page. We also notify significant changes to your account's e-mail address.
15. Contact
For every privacy question and request: privacy@catalogtopia.com — Serdal Güldap, Gülbahçe Mah. Kavas Çıkmazı Sk. No: 6 A, Osmangazi / Bursa, Türkiye.
Our policy documents
| Document | Last updated |
|---|---|
| Privacy PolicyHow personal data is collected, used and protected. | |
| Terms of ServiceThe terms that apply when you use Catalogtopia. | |
| Data Deletion InstructionsHow to ask for your data to be deleted. | |
| Cookie PolicyCookies and preferences stored in your browser. |


