Privacy Policy
Last updated: 18 August 2026
At SETURA YAZILIM VE TİCARET LİMİTED ŞİRKETİ ("Setura", "we"), we value your privacy. This Privacy Policy covers our website at setura.tr, the sales we make through it, and the mobile apps we publish on the App Store and Google Play. It explains what personal data we process and why, who we share it with, how we protect it, and what rights you have.
1. Data Controller
Data controller: SETURA YAZILIM VE TİCARET LİMİTED ŞİRKETİ
Address: Fenerbahçe Mah. İğrip Sok. No: 13/1, Kadıköy / İstanbul, Türkiye
MERSIS No: 0764-0921-2410-0001
Email: [email protected]
Website: setura.tr
2. Scope of This Policy
This policy covers the two channels through which we provide our services:
- The setura.tr website, including its store section — corporate pages, contact and support requests, and the digital software products, installation and support services you purchase through the site.
- Our mobile apps — the applications we publish on the App Store and Google Play, and the features within them.
In sales made through the site, we are the seller. Turkish distance selling legislation applies to these sales, and the order, payment, delivery, refund and support processes are handled by us.
In our mobile apps, however, it is Apple or Google that sells and distributes the app — and any in-app purchases — to the user. On this channel, refunds, subscription management and billing are governed by the relevant store's own terms; your payment details are processed by Apple or Google and never reach us.
The app stores and any third-party sites we link to have their own privacy policies; this policy does not cover their data processing.
3. Data We Collect
The data we process differs by channel. The categories collected on each channel are set out separately below.
3.1. The setura.tr Site and Store
- Identity and contact details (name and surname, email address, phone number).
- Billing information — the Turkish national ID number (TCKN) for individual invoices; the company title, tax office and tax number (VKN) for corporate invoices, together with the billing address in both cases.
- Order and transaction data (order number, purchased products and services, amount, payment method and status, delivery and download records).
- Account data — when you create an account, your email address and an irreversible cryptographic hash of your password. Your password is never stored in plain text.
- Transaction security data (IP address, browser information (User-Agent), transaction and access records relating to order confirmation, payment, email delivery and download access, together with the text and version of the agreement you approved).
- The content of your support and contact correspondence, and the delivery records of the emails we send you.
- Technical data (session information held in essential cookies, language preference).
3.2. Mobile Apps
- Device and app information (device model, operating system version, app version, language and region settings).
- In-app usage records together with error and crash logs.
- Account data — only where the app in question requires an account (e.g. email address and in-app profile details).
- Push notification token — only if you have granted notification permission. You can withdraw that permission at any time in your device settings.
- In-app purchase verification data — the receipt or transaction identifier issued by Apple or Google, the purchased item and the status of the purchase. It contains no card number or other payment details.
- Advertising identifier and ad-serving data — only in our ad-supported apps (e.g. Karpuzo): the IDFA on iOS or the Advertising ID on Android, together with approximate location, device and usage information. See the "Advertising and Third-Party Services" section below for details.
Some of our apps contain ads so that they can be offered for free; in those apps ads are served through Google AdMob and the advertising identifier listed above may be processed. In our apps without ads, no data is processed for advertising purposes. We process usage and crash records to measure app stability and fix defects, and we never sell your personal data on any channel.
The statements in this section are consistent with the privacy labels published for our apps on the App Store and with our "Data safety" declarations on Google Play. If the data collected by an app changes, both the relevant store declaration and this policy are updated.
4. How We Collect Data
We collect data through contact and order forms, account operations, email correspondence, your use of our website and mobile apps, and essential cookies — by automated or partially automated means.
Transaction security data is additionally generated automatically by our servers during operations such as order confirmation, payment, email delivery and download.
In our mobile apps, data is generated on your device as you use the app and is processed only for the purposes listed above. For in-app purchases, verification data is obtained through Apple's or Google's purchase validation services.
5. Purposes of Processing and Legal Bases
- To provide, maintain and improve our services.
- To conclude and perform the contract and to prove delivery of digital products.
- To ensure payment security and to detect and prevent fraud and abuse attempts.
- To keep our mobile apps stable, fix errors and crashes, and monitor version and device compatibility.
- To verify the validity of in-app purchases and any subscriptions, and to unlock the purchased content.
- To serve and measure ads in our ad-supported apps.
- To respond to your requests and support inquiries.
- To fulfil our legal obligations, such as invoicing, accounting and record retention.
- To ensure security and prevent misuse.
The legal bases for processing transaction security data are Article 5/2-c of the KVKK (directly related to the conclusion and performance of a contract), Article 5/2-ç (necessary for compliance with our legal obligations) and Article 5/2-f (our legitimate interest in proving delivery and preventing fraud).
For mobile app data, the legal bases are Article 5/2-c of the KVKK (providing the app and any account, and verifying in-app purchases) and Article 5/2-f (keeping the app stable, fixing defects and preventing abuse). Push notifications are sent on the basis of the permission you grant on your device and stop as soon as you withdraw it.
Serving ads in our ad-supported apps is carried out so that the app can be offered free of charge, on the basis of Article 5/2-f of the KVKK (legitimate interest). Personalizing those ads through the advertising identifier on your device relies on your explicit consent under Article 5/1 of the KVKK; that consent is obtained through the App Tracking Transparency and Google User Messaging Platform flows described below and can be withdrawn at any time in your device settings. If you do not consent, the app keeps working and only non-personalized ads are shown.
6. Sharing and Third Parties
We do not sell your personal data. Your data is shared only with the parties below, with whom we work in order to deliver the service, and only to the extent each of them requires:
- iyzico (payment institution) — taking card payments made through the site, 3D Secure verification, payment security and fraud checks. Your name, email, phone, billing details and order amount are transferred for this purpose.
- Apple App Store and Google Play — distributing and updating our mobile apps, handling in-app purchases and the refunds relating to them, and providing app stability reports. On this channel, purchase data is collected directly by these platforms, and only the information needed to verify a purchase is passed on to us.
- Our advertising partner Google (Google Ireland Ltd. / Google LLC — Google AdMob) — serving, capping and measuring ads, only in our ad-supported mobile apps. The advertising identifier, approximate location and device and usage information are processed for this purpose; no such transfer takes place on the site or in our apps without ads.
- Our email infrastructure provider — sending order confirmation, delivery, account and support emails. Your name, email address and delivery records are processed for this purpose.
- Our hosting provider — running and backing up the website, the store and the database.
- Authorized public institutions and our accountants and legal advisers — solely to comply with statutory obligations and to handle legal claims.
Payments are taken through the infrastructure of the payment institution iyzico with 3D Secure verification. Your credit/debit card details are transmitted to iyzico over an encrypted connection solely in order to complete the payment; your card number, expiry date and security code (CVV) are not stored on our systems and are never written to any log.
In order to prove the transaction and to handle refund and chargeback processes, only the first six digits (BIN) and last four digits of the card number, together with the card brand/type, as returned in iyzico's transaction response, are kept with your order record. This data alone cannot be used to make a payment.
For in-app purchases, payment is collected directly by Apple or Google; your card and payment details are processed by those platforms, are not transferred to us and are never visible to us. All we receive is the receipt or transaction record evidencing the validity of the purchase. Refund requests, subscription management and billing for such purchases are governed by the relevant store's terms and are handled through that store.
7. Advertising and Third-Party Services
Some of our mobile apps (e.g. Karpuzo) contain ads so that they can be offered for free. Ads are served through Google AdMob (Google Ireland Ltd. / Google LLC). To serve and measure ads, AdMob may process your device's advertising identifier (IDFA on iOS, Advertising ID on Android), approximate location, and device and usage information.
- Ads may be personalized or non-personalized depending on your consent. Users in the European Economic Area, the UK and Switzerland are shown a consent form (Google User Messaging Platform) on first launch.
- On iOS 14.5+ devices, App Tracking Transparency permission is requested for tracking; if you decline, non-personalized ads are shown.
- You can manage ad personalization in your device settings (iOS: Settings → Privacy & Security → Tracking; Android: Settings → Google → Ads).
- In apps that may appeal to children, we use settings that ensure only general-audience (G-rated) ads are served; personalized advertising and remarketing are disabled for this traffic.
- How Google processes data: policies.google.com/technologies/partner-sites
8. Transfers Abroad
Because of the infrastructure used by the app stores, by our advertising partner Google and by our hosting, cloud and email providers, your personal data may be processed on servers located abroad. Such transfers are made in accordance with the conditions set out in Article 9 of the KVKK (the safeguards prescribed by legislation, mechanisms such as undertakings or standard contracts, or your explicit consent where required) and are limited to the data necessary to provide the service.
9. Cookies
Our website uses cookies necessary for its operation; we do not use tracking or advertising cookies on the site. For details, see our Cookie Policy.
10. Data Security
All data transmitted between the site, the store and our servers is encrypted with TLS. Access to administrative interfaces requires authorization, passwords are stored in irreversible form, critical operations are logged, and card data is never held on our systems.
We apply appropriate technical and administrative measures to protect your personal data against unauthorized access, loss and misuse. However, please note that no transmission over the internet is 100% secure.
11. Retention Periods
We retain your personal data for as long as required by the purposes of collection and the retention periods stipulated by applicable legislation.
Contract, order and invoice records are retained for the limitation and retention periods prescribed by the applicable legislation; access, transaction and email delivery records are retained for as long as required by the purposes of ensuring security and proving delivery, and for the periods prescribed by the applicable legislation. At the end of these periods the data is deleted, destroyed or anonymized.
Usage, error and crash records from our mobile apps are kept only for as long as monitoring app stability requires, and are deleted or anonymized thereafter.
12. Children's Data
Some of our apps are intended for a general audience and may appeal to a wide range of users, including children (e.g. Karpuzo). In apps that may be directed to children, we serve only general-audience (G-rated) ads, disable personalized advertising and remarketing, and do not knowingly collect personal data from children. If we determine that we have processed a child's personal data without parental/guardian consent, we will delete it without undue delay. For questions about your child's data, contact us at [email protected] — we will delete the data and inform you of the outcome.
13. Account and Data Deletion
You may request deletion of your account and the personal data linked to it at any time. How to submit a request, which data is deleted and how long the process takes are explained on our Account and Data Deletion Request page. You can also send your request to [email protected].
Upon a deletion request, your account and the data linked to it are deleted. Records that must be kept under legislation — such as invoice, order and payment records — are retained solely for that obligation and only for the retention periods prescribed by law; at the end of those periods they are deleted, destroyed or anonymized.
14. Your Rights (KVKK Art. 11)
Under Article 11 of Turkish Law No. 6698 (KVKK), you have the right to learn whether your personal data is being processed and to request information about it, to learn the purpose of processing and whether the data is used in line with that purpose, to know the third parties in Türkiye or abroad to whom it is transferred, to request correction of incomplete or inaccurate data and its deletion or destruction where the conditions are met, to request that such actions be notified to the third parties to whom the data was transferred, to object to a result that works against you produced solely by automated analysis, and to claim compensation if you suffer damage due to unlawful processing.
To exercise these rights, send your request to [email protected] by email, or in writing to Fenerbahçe Mah. İğrip Sok. No: 13/1, Kadıköy / İstanbul, Türkiye. Your application is concluded within 30 days at the latest, in accordance with Article 13 of the KVKK. For details, see our KVKK Notice.
15. Changes
This Privacy Policy may be updated from time to time. The current version is always published on this page; significant changes will be announced on the page.
For orders placed through the site, the version of the legal texts in force at the moment of approval is recorded with your order, so it can later be established exactly which text you approved.
16. Contact
For questions about this policy: [email protected]