Privacy Policy — Doğru Adres
Last updated / Son güncelleme: 6 July 2026
English
This policy explains what data the Doğru Adres Shopify app ("the App") collects and how it is used. The App is installed by a Shopify merchant on their own store and adds address dropdown selectors (province / district / neighbourhood) to the cart page or cart drawer.
Data we collect
- Merchant / store data from Shopify: shop domain, OAuth access token, granted scopes, and — when the store owner authenticates — their user id, name, email and locale. This is the data Shopify provides to the App as part of the authentication handshake and is only used to keep the App logged in to the merchant's store.
- Address selections from the cart: when a buyer picks a province (il), district (ilçe) and neighbourhood (mahalle) in the cart, those three Turkish place names are written to the cart as attributes (
Teslimat_Il,Teslimat_Ilce,Teslimat_Mahalle) and copied into the order note. These values are stored inside the merchant's own Shopify order.
Order delivery data
Since June 2026, when an order is completed the App stores a per-order delivery record in its own database: the recipient's name, phone number, shipping address and the selected il / ilçe / mahalle. This data is used solely to show the merchant their own order log inside the App (for example to hand the address to a shipping carrier). It is retained until the merchant uninstalls the App or a GDPR redaction request is received, and it is not shared with third parties.
Data we do not collect
- Buyer emails or payment information.
- IP addresses, analytics cookies, or tracking identifiers.
- Any data from stores that have not installed the App.
How we use the data
Merchant session data is used only to authenticate the App with Shopify. The address dropdown values are written to the cart so that the merchant can see the buyer's preferred delivery area on their own order. The per-order delivery records described above are shown only to the merchant of the store the order belongs to — we do not profile buyers or transmit their data anywhere else.
Sharing
We do not sell, rent or share any data with third parties. The App communicates only with Shopify's APIs (to verify sessions and register webhooks) and its own backend.
Where data is stored
Shopify session records and the per-order delivery records are stored in a PostgreSQL database hosted by Neon in the EU (Frankfurt, eu-central-1). The application server runs on Amazon Web Services App Runner in the same region. Data in transit is protected with TLS.
Retention and deletion
When a merchant uninstalls the App, Shopify sends an app/uninstalled webhook and the App deletes every record it holds for that shop: sessions, settings, analytics events and the per-order delivery records. In addition the App implements the three GDPR mandatory webhooks:
customers/data_request— the request is logged and the delivery data stored for the listed orders is provided to the merchant through our support channel.customers/redact— the App deletes the per-order delivery records for the orders listed in the request.shop/redact— the App deletes every record it holds for the shop (sessions, settings, analytics events and order delivery records).
Your rights (GDPR / KVKK)
You can request access to, correction of, or deletion of any data the App holds about you by emailing keremgvnr@gmail.com. We aim to respond within 30 days.
Children
The App is intended for Shopify merchants and their shoppers; it is not directed at children under 16 and we do not knowingly collect data from them.
Changes to this policy
If this policy changes we will update the "Last updated" date at the top of the page. Material changes will be communicated through the Shopify app listing.
Contact
Türkçe
Bu politika, Doğru Adres Shopify uygulamasının ("Uygulama") hangi verileri topladığını ve bunları nasıl kullandığını açıklar. Uygulama, bir Shopify satıcısı tarafından kendi mağazasına kurulur ve sepet sayfasına veya sepet çekmecesine il / ilçe / mahalle seçim kutuları ekler.
Topladığımız veriler
- Shopify'dan gelen satıcı / mağaza verileri: mağaza alan adı, OAuth erişim anahtarı, verilen yetki kapsamları ve mağaza sahibi oturum açtığında kullanıcı kimliği, adı, e-postası ve dil tercihi. Bu veriler Shopify'ın kimlik doğrulama sürecinde Uygulamaya ilettiği bilgilerdir ve yalnızca Uygulamanın mağazaya bağlı kalabilmesi için kullanılır.
- Sepetten alınan adres seçimleri: Bir alışveriş yapan sepette il, ilçe ve mahalle seçtiğinde, bu üç değer sepete özellik olarak (
Teslimat_Il,Teslimat_Ilce,Teslimat_Mahalle) yazılır ve sipariş notuna eklenir. Bu değerler satıcının kendi Shopify siparişinde saklanır.
Sipariş teslimat verileri
Haziran 2026'dan itibaren, bir sipariş tamamlandığında Uygulama kendi veritabanında sipariş başına bir teslimat kaydı saklar: alıcının adı, telefon numarası, teslimat adresi ve seçilen il / ilçe / mahalle. Bu veri yalnızca satıcının Uygulama içindeki kendi sipariş dökümünü görebilmesi için kullanılır (örneğin adresi kargo firmasına iletmek için). Satıcı Uygulamayı kaldırana veya bir GDPR silme (redaction) talebi gelene kadar saklanır; üçüncü taraflarla paylaşılmaz.
Toplamadığımız veriler
- Alışveriş yapanın e-postası veya ödeme bilgisi.
- IP adresi, analiz çerezleri veya takip tanımlayıcıları.
- Uygulamayı kurmamış mağazalara ait hiçbir veri.
Verileri nasıl kullanıyoruz
Satıcı oturum verileri yalnızca Uygulamanın Shopify ile kimlik doğrulaması için kullanılır. Adres seçim değerleri, satıcının kendi siparişinde alıcının tercih ettiği teslimat bölgesini görebilmesi için sepete yazılır. Yukarıda açıklanan sipariş başına teslimat kayıtları yalnızca siparişin ait olduğu mağazanın satıcısına gösterilir — alıcılar hakkında profil çıkarmaz, verileri başka bir yere iletmeyiz.
Paylaşım
Hiçbir veriyi üçüncü taraflara satmıyor, kiralamıyor veya paylaşmıyoruz. Uygulama yalnızca Shopify API'leri ile (oturum doğrulama ve webhook kaydı için) ve kendi arka uç sunucusu ile iletişim kurar.
Verilerin saklandığı yer
Shopify oturum kayıtları ve sipariş başına teslimat kayıtları, Avrupa Birliği bölgesinde (Frankfurt, eu-central-1) Neon tarafından barındırılan bir PostgreSQL veritabanında saklanır. Uygulama sunucusu aynı bölgede Amazon Web Services App Runner üzerinde çalışır. İletimdeki veriler TLS ile korunur.
Saklama süresi ve silme
Bir satıcı Uygulamayı kaldırdığında Shopify app/uninstalled webhook'u gönderir ve Uygulama o mağazaya ait tuttuğu tüm kayıtları siler: oturumlar, ayarlar, analiz olayları ve sipariş başına teslimat kayıtları. Uygulama ayrıca Shopify'ın zorunlu tuttuğu üç GDPR webhook'unu uygular:
customers/data_request— talep kaydedilir ve listedeki siparişler için saklanan teslimat verileri destek kanalımız üzerinden satıcıya iletilir.customers/redact— talepte listelenen siparişlere ait sipariş başına teslimat kayıtları silinir.shop/redact— mağazaya ait tutulan tüm kayıtlar silinir (oturumlar, ayarlar, analiz olayları ve sipariş teslimat kayıtları).
Haklarınız (KVKK / GDPR)
Uygulamanın sizinle ilgili tuttuğu verilere erişmek, bunları düzeltmek veya silmek için keremgvnr@gmail.com adresine e-posta gönderebilirsiniz. Taleplere 30 gün içinde yanıt vermeyi hedefliyoruz.
Çocuklar
Uygulama Shopify satıcıları ve alışveriş yapanlar için tasarlanmıştır; 16 yaş altındaki çocuklara yönelik değildir ve bilinçli olarak bu kişilerden veri toplanmaz.
Politikadaki değişiklikler
Bu politika güncellendiğinde sayfanın en üstündeki "Son güncelleme" tarihi yenilenir. Önemli değişiklikler Shopify uygulama ilanı üzerinden duyurulur.