Privacy Policy

This policy explains how your personal data is processed when you use the catalogtopia.com website and the Catalogtopia application at app.catalogtopia.com. It is organised under the headings of Türkiye's Personal Data Protection Law No. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR).

Last updated:

1. Data controller

The data controller is Serdal Güldap (a natural person), who operates Catalogtopia.

  • Address: Gülbahçe Mah. Kavas Çıkmazı Sk. No: 6 A, Osmangazi / Bursa, Türkiye
  • E-mail (including KVKK applications, privacy and data deletion requests): privacy@catalogtopia.com

2. Scope

This policy covers two services: catalogtopia.com (the website and these legal pages) and app.catalogtopia.com (the application in which businesses analyse their product catalogues). Catalogtopia is a service for businesses; it processes the data of the people who open an application account on behalf of a company or a sole proprietorship.

3. Data we process

CategoryDataSource
AccountName, e-mail address, whether the e-mail is verified, an irreversible hash of your password (scrypt). The password itself is never stored.Sign-up form
SessionA session cookie; in our database only the SHA-256 hash of the session key and its expiry; depending on how you sign in, your IP address and browser information (User-Agent).Your browser
Activity recordsWho performed which action in the application (user identifier, action, target, time). No IP address is written to these records.The application
Store and catalogue dataProduct information from the Shopify store you connect or the CSV/XML feed you add (title, description, brand, price, stock, image links, etc.), a raw copy of the source, and the feed address. If you put personal information into product data (e.g. a brand that is a person's name), that is processed too.Shopify / your feed
Connection keysShopify and Meta access keys — encrypted with AES-256-GCM.Your connection
Meta catalogue informationThe Meta catalogue ID and name; the catalogue items' IDs, retailer_id values, review and visibility statuses and Meta's error codes.Meta (through your connection)
Images you uploadFiles you upload as product images, as they are. Metadata inside the file (e.g. EXIF, which may include where a photo was taken) is not removed.You
Server logsOn both sites: IP address, time of the request, the address requested, response code, referring page (Referer) and browser information.Your browser's request
Preferences stored in the browserOn catalogtopia.com only: your theme, language and currency preference (in your browser's localStorage; never sent to us).Your choice

4. Data we do not process

  • We do not read your Shopify store's customer or order data; we ask Shopify only for permission to read products (and, if you explicitly allow it, to write product titles).
  • We do not read user, advertising, pixel or event data from Meta.
  • We do not process payment information (there is no paid plan at present).
  • We use no analytics, advertising or tracking tool; we do not sell your data or use it for advertising.

5. Purposes and legal bases

PurposeDataKVKK Art. 5 / GDPR Art. 6
Opening your account, signing you in, e-mail verification and password resetAccount, sessionEntering into and performing the contract (KVKK 5/2-c; GDPR 6/1-b)
Analysing your catalogues, showing issues and what Meta reports; writing titles to Shopify on your instructionStore/catalogue data, connection keys, Meta catalogue information, imagesPerforming the contract (KVKK 5/2-c; GDPR 6/1-b)
Security of the service, preventing abuse, debuggingServer logs, activity records, sessionLegitimate interest (KVKK 5/2-f; GDPR 6/1-f)
Legal obligations and protecting rightsThe data concerned, as far as necessaryLegal obligation; establishing a right (KVKK 5/2-ç, 5/2-e; GDPR 6/1-c, 6/1-f)

We do not use your data for automated decision-making or profiling.

6. Meta (Facebook) data

When you connect your Meta catalogue, we read from Meta only the catalogue ID and name and, for the catalogue's items, their IDs, retailer_id values, review and visibility statuses and error codes. Meta's error description texts are not stored. We use this information only to show it to you in the application as "Meta reports"; it does not enter Catalogtopia's health score.

Your Meta access key is stored encrypted, is never sent to a browser and is used only for requests to Meta. The current version writes nothing to Meta.

In the application, Settings → Meta connection → "Disconnect" deletes the key and the catalogue mapping immediately. Item statuses already read from Meta are not deleted by this step. What can be deleted today and how to make a deletion request: Data Deletion Instructions.

7. Shopify data

When you connect your Shopify store we read its product data. Writing a product title to Shopify needs a separate, explicit permission and is done only for corrections you approve. The Shopify access key is stored encrypted.

Removing the app from your Shopify admin does not by itself start the deletion of your data on our side; to delete it, use the route in the Data Deletion Instructions.

8. Security

  • All traffic is encrypted with HTTPS.
  • Passwords are hashed with scrypt; session keys are kept in the database only as hashes.
  • Shopify and Meta access keys are encrypted with AES-256-GCM and are never sent to a browser.
  • Each customer account's data is separated from the others by row-level security in the database.
  • Backups are stored encrypted (GPG).

9. Retention

The table below shows how the system actually behaves today; only measured periods or periods configured in the system are given.

DataToday
Account, catalogue, product and connection data; raw copies of the source; activity recordsNo automatic deletion; kept as long as your account is open.
SessionA session unused for 7 days expires; its record is deleted when you sign out. Expired session records are not cleaned up automatically today.
Password reset and e-mail verification linksValid for 1 hour.
Images you uploadThere is no way to delete them today; they stay at their public addresses.
Server logs (nginx)Deleted after 14 days.
System logsNo time limit; rotated by a disk size limit. The application writes no e-mail address or IP address to these logs.
Encrypted database backupsDaily backups are deleted on the server after 7 days; the same clean-up job also covers the copies in Cloudflare R2.
Preferences in the browser (catalogtopia.com)In your browser until you delete them.

10. Deleting your data

The application has no account deletion screen today. You can send your deletion request from your account's e-mail address to privacy@catalogtopia.com. We answer your request within 30 days at the latest (KVKK Art. 13); our answer states clearly which data was deleted and which cannot yet be deleted in today's system.

What can and cannot be deleted from the application today, and how to make the request: Data Deletion Instructions.

11. Your rights

Under KVKK Art. 11 you have the right to learn whether your personal data is processed and, if so, to request information about it; to learn the purpose of processing and whether it is used accordingly; to know the third parties it is transferred to; to request its correction if it is incomplete or wrong, and its deletion or destruction; to request that these actions be notified to the recipients; to object to a result against you arising from analysis by automated systems; and to claim compensation for damage caused by unlawful processing.

If the GDPR applies to you, you also have the rights of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21), and the right to lodge a complaint with the supervisory authority of your country.

Send your requests by e-mail to privacy@catalogtopia.com. Your request is concluded free of charge within 30 days at the latest. If you are not satisfied with the outcome you may complain to Türkiye's Personal Data Protection Board (KVKK Kurulu).

12. Cookies and browser storage

catalogtopia.com uses no cookies; it keeps only your theme, language and currency preference in your browser's localStorage. The application uses only the cookies it needs to work. Details: Cookie Policy.

13. Children

Catalogtopia is a service for businesses; it is not intended for people under 18 and we do not knowingly process children's data.

14. Changes

When we update this policy we change the "Last updated" date at the top of the page. We also notify significant changes to your account's e-mail address.

15. Contact

For every privacy question and request: privacy@catalogtopia.com — Serdal Güldap, Gülbahçe Mah. Kavas Çıkmazı Sk. No: 6 A, Osmangazi / Bursa, Türkiye.

Our policy documents

DocumentLast updated
Privacy PolicyHow personal data is collected, used and protected.
Terms of ServiceThe terms that apply when you use Catalogtopia.
Data Deletion InstructionsHow to ask for your data to be deleted.
Cookie PolicyCookies and preferences stored in your browser.