No raw card data
Card and payment details are processed securely by Stripe. Venroys does not store full card numbers or CVC codes.
This policy explains in clear language what data Venroys processes, why it is needed, and the choices and rights available to you.
Venroys OÜ is established in Estonia and is subject to the GDPR. Depending on the service, Venroys, an independent seller and a service provider may each have a separate role.
Card and payment details are processed securely by Stripe. Venroys does not store full card numbers or CVC codes.
A seller is responsible for its products, customer service and its own legal obligations. Venroys operates the technical infrastructure.
You can exercise privacy rights, stop marketing and manage non-essential cookies.
Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit
Venroys'u nasıl kullandığınıza bağlı olarak (alışveriş yapma, hesap oluşturma, bizimle iletişime geçme veya platformda satış yapma), aşağıdaki kişisel veri kategorilerini işleyebiliriz:
| Kategori | Örnekler |
|---|---|
| Kimlik ve İletişim Verileri | Ad, fatura/teslimat adresi, e-posta adresi, telefon numarası, hesap numarası |
| Ödeme ve Faturalama Verileri | Ödeme sağlayıcı belirteci, işlem kimliği, fatura detayları, ödeme detayları (satıcılar için) |
| Sipariş ve Teslimat Verileri | Sipariş edilen ürünler, miktarlar, gönderim yöntemi, teslimat durumu, iade/geri ödeme bilgileri |
| Hesap ve Giriş Bilgileri | Kullanıcı adı/e-posta, şifrelenmiş parola, hesap tercihleri, giriş zaman damgaları |
| İletişim ve Onay Verileri | Destek mesajları, bülten aboneliği durumu, çerez onayı seçenekleri |
| Teknik ve Cihaz Verileri | IP adresi, tarayıcı türü, cihaz bilgileri, oturum kayıtları, güvenlik olayları |
| Kullanım ve Davranış Verileri | Görüntülenen sayfalar, arama sorguları, tıklamalar, kaydırma davranışı, görüntülenen ürünler |
| Seller and verification data | Business details, representatives, date of birth, tax details, verification status and Stripe Connect account references |
| Storefront and content data | Brand name, domain, website content, product media, theme settings and published pages |
| Derived risk and trust signals | Delivery outcomes, refund and chargeback rates, policy status, suspicious activity and marketplace progress |
Özel kategorideki kişisel verileri (örneğin, sağlık verileri) kasıtlı olarak toplamıyoruz. Kesinlikle gerekli olmadıkça, lütfen sipariş notlarına, destek mesajlarına veya diğer serbest metin alanlarına hassas kişisel bilgiler eklemeyin.
| Amaç | Yasal Dayanak (GDPR) | Detaylar |
|---|---|---|
| Hesap oluşturma ve kimlik doğrulama | Sözleşmenin ifası (Madde 6(1)(b)) | Hesabınızı oluşturmak, güvenli bir şekilde giriş yapmanızı sağlamak ve hesabınızın her zaman kullanılabilir olmasını sağlamak. |
| Sipariş işleme, ödeme ve teslimat | Sözleşmenin ifası (Madde 6(1)(b)) | Satın alımları işlemek, siparişleri onaylamak, gönderimi ayarlamak ve iade veya geri ödemeleri yönetmek. |
| Müşteri desteği ve hizmet iletişimi | Meşru menfaatler (Madde 6(1)(f)) | Soruları yanıtlamak, sorunları araştırmak ve destek kalitesini iyileştirmek. |
| Pazarlama iletişimi ve promosyon teklifleri | Rıza (Madde 6(1)(a)) | Yalnızca kanun gerektirdiği durumlarda ve onayınızı verdikten sonra. İstediğiniz zaman aboneliğinizi iptal edebilir veya onayınızı geri çekebilirsiniz. |
| Güvenlik, dolandırıcılık önleme ve platform bütünlüğü | Meşru menfaatler (Madde 6(1)(f)) ve yasal yükümlülükler (Madde 6(1)(c)) | Suistimali tespit etmek, hesapları güvence altına almak, dolandırıcılığı önlemek ve güvenlikle ilgili yükümlülükleri yerine getirmek. |
| Yasal, vergi ve muhasebe uyumluluğu | Yasal yükümlülük (Madde 6(1)(c)) | Muhasebe, vergi, raporlama ve diğer yasal gereklilikleri karşılamak için. |
| Seller verification and payouts | Contract, legal obligation and legitimate interests | To onboard sellers, verify identity and business details, enable payouts and limit financial fraud. |
| Marketplace trust and policy administration | Legitimate interests and contract | To monitor seller performance, review marketplace applications and protect customers and the platform. |
| Service | Role and data | More information |
|---|---|---|
| Stripe | Payments, direct charges, seller verification, fraud prevention and payouts. Stripe receives data directly through secure payment and onboarding components. | Stripe Privacy |
| Printful | Optional product, fulfillment, shipping, tracking and return services. Name, address, contact and order data may be shared for fulfillment. | Printful Privacy |
| Hosting and database | Cloud hosting, secure storage, backups, network delivery and operational logging. | Contractually restricted providers |
| Email and communications | Transactional messages, verification, order updates, support and consented marketing. | Necessary contact and message data only |
Specific vendors and subprocessors may change as our infrastructure changes. We assess providers before they process personal data.
Some providers or their subprocessors are located outside the European Economic Area. Where the GDPR requires it, we rely on an adequacy decision, European Commission Standard Contractual Clauses or another valid safeguard. We assess supplementary organizational and technical measures where appropriate.
European Commission Standard Contractual Clauses ↗| Veri Kategorisi | Saklama Süresi |
|---|---|
| Faturalar ve işlem kayıtları | At least 7 years under applicable Estonian accounting and tax rules, calculated from the legally prescribed starting date |
| Müşteri hesap verileri | Hesap açık olduğu sürece ve hareketsizlik veya kapatma sonrasında sınırlı bir süre boyunca geçerlidir. |
| Pazarlama tercihleri ve onay kayıtları | Onay geri çekilene veya onay gösterme ihtiyacı ortadan kalkana kadar. |
| Güvenlik, kayıt ve analiz verileri | Güvenlik ve analiz amaçlarına uygun sınırlı bir süre için |
| Seller KYC and payout records | While needed for the payment relationship and afterward as required for financial, anti-fraud and legal obligations; Stripe also applies its own retention periods |
| Order and fulfillment records | As needed for delivery, returns, disputes, warranties and applicable accounting and tax periods |
After the applicable period, we delete or anonymize data unless it remains necessary for a legal claim, investigation, dispute or other legal obligation.
Kişisel verilerin korunması için uygun teknik ve organizasyonel önlemler uyguluyoruz, bunlar arasında şunlar yer almaktadır:
No system is entirely risk-free. Protect your account with a unique password and two-factor authentication where available.
Bulunduğunuz yere ve geçerli yasalara bağlı olarak, aşağıdaki haklara sahip olabilirsiniz:
Send requests to info@venroys.com. We may request additional information to verify your identity. We normally respond within one month; the GDPR permits a reasoned extension for complex requests.
Venroys uses security, fraud and performance indicators such as delivery outcomes, refunds, chargebacks, account age, policy incidents and verification status. These signals support risk management and marketplace review. Marketplace access is not automatically guaranteed by a score. Decisions with a material effect may be reviewed by a person, and you may contact us to request an explanation or review.
We investigate suspected personal-data breaches, limit their effects and notify the competent authority and affected people where legally required. Report suspected security issues to info@venroys.com without sending passwords or complete payment details.
Sellers receiving personal data through Venroys must use it lawfully, securely and only for permitted business purposes. They may not use customer data for unsolicited marketing, sell it or disclose it outside necessary order and support processes. Sellers must provide their own privacy information where required and respond to data-subject requests for which they are responsible.
Venroys, ilgili yasalara göre kendi başlarına veri işlemeye rıza göstermeleri gereken yaşın altındaki çocuklar için tasarlanmamıştır (örneğin, bazı yargı bölgelerinde 16 yaş). Gerekli rıza olmadan çocuklardan bilerek kişisel veri toplamıyoruz.
Bu Gizlilik Politikasını zaman zaman güncelleyebiliriz. Sayfanın en üstündeki "Son güncelleme" tarihi, bu sayfanın en son ne zaman değiştirildiğini gösterir. Önemli değişiklikler yaparsak, uygun olduğu durumlarda sizi web sitesi, e-posta veya hesap bildirimleri aracılığıyla bilgilendirebiliriz.
Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit
info@venroys.com