Privacy Policy
Last updated: 23 August 2026
This Privacy Policy explains how your personal data is collected, used, protected and shared in connection with the services offered on komshia.com (the "Platform"). The Platform operates in compliance with the EU General Data Protection Regulation (GDPR) and Turkish Law No. 6698 on the Protection of Personal Data (KVKK).
0. Scope — Which Product Does This Text Cover?
This policy covers two separate products, and some clauses apply to only one of them. Which clause applies where is stated below; read the rest of the text with that distinction in mind.
- The iOS app (Komshia on the App Store): the app has no account, no sign-in, no registration, no orders, no escrow, no payment, no listings, no messaging and no cookies. The app WRITES nothing to our servers; it only sends read requests for markets, exchange rates and the product catalogue, and those requests carry no account, session or device identifier. Your shopping list is kept solely in the device's own storage. Consequently no account record exists for the app that could be deleted. The account, order, payment, cookie and seller clauses below DO NOT apply to the app.
- The iOS app uses NO CAMERA and has no barcode scanning. It never asks for camera permission; you will not see a camera permission row for Komshia in iOS Settings. The camera clause in section 13 DOES NOT apply to the app.
- The komshia.com website: every clause below applies to the website — it has membership, orders, escrow payments, a seller panel, cookies and the barcode ("Scan") screen.
1. Data Controller
The data controller is SMARTIA OOD (СМАРТИЯ ООД) · Tria City Center, Burgas · Bulgaria, a limited liability company (ООД) registered in Bulgaria, which operates the komshia.com platform. The data controller is established in Bulgaria (EU) and is subject to the General Data Protection Regulation (GDPR, (EU) 2016/679) and the Bulgarian Personal Data Protection Act (ЗЗЛД). To the extent services are offered to users located in Türkiye, Turkish Law No. 6698 (KVKK) also applies. All privacy-related requests can be sent to .
2. Scope
This policy covers buyers registered on the Platform, business representatives applying as or approved as sellers, and all visitors. For users resident in Türkiye the KVKK applies; for users resident in the EU the GDPR applies; where the two regimes differ, the provision more favourable to the user prevails.
3. Data We Collect
- Account data: full name, e-mail address, phone number, password (stored as an irreversible hash).
- Seller business data: trade name, tax/company number, authorised contact details, bank account details (for payouts).
- Order data: delivery address, invoice details, order history.
- Payment data: payments are processed by Stripe (EUR) and iyzico (TRY); your card number is never stored on our servers.
- Technical data: session cookies, IP address (truncated/masked in security logs), browser information.
4. Social-ID: Pseudonymisation and Encryption
The Platform protects personal data through a pseudonymisation architecture we call "Social-ID". Directly identifying data (PII) such as name, e-mail, phone and address is stored in the database encrypted with the AES-256-GCM algorithm.
In internal processes (order records, support tickets, seller dashboards) users are represented by a unique number (Social-ID) assigned to them instead of their real identity. As a result, no party accessing operational records can see your identity without decryption authorisation.
Encryption keys are managed separately from application data and access is restricted under the principle of least privilege.
5. Purposes and Legal Bases of Processing
- Conclusion and performance of the membership agreement — performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5/2-c).
- Handling of orders, payments, escrow and delivery — performance of a contract.
- Compliance with legal obligations (tax, accounting, anti-money-laundering) — legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5/2-ç).
- Fraud prevention and platform security — legitimate interest (GDPR Art. 6(1)(f); KVKK Art. 5/2-f).
- Marketing communications — only with your explicit consent (GDPR Art. 6(1)(a); KVKK Art. 5/1).
6. Recipients of Data
- Payment institutions: Stripe Payments Europe Ltd. and iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. — for payment processing.
- Carriers and logistics companies — only the delivery details required to fulfil the shipment.
- Hosting and infrastructure providers (EU region, Frankfurt) — encrypted data storage; our hosting provider Vercel additionally operates the cookieless visitor measurement (Vercel Analytics and Speed Insights) — see section 5 of the Cookie Policy for details.
- Competent public authorities — only where legally required.
- Sellers — the minimum delivery details necessary to fulfil the order; the buyer’s other personal data is not shared with the seller.
7. International Data Transfers
Your data is stored primarily on servers within the European Union (Frankfurt). Transfers between Türkiye and the EU are carried out with appropriate safeguards (including standard contractual clauses and explicit consent) pursuant to KVKK Art. 9 and Chapter V of the GDPR.
8. Retention Periods
- Account data: for the duration of membership and, after termination, for the statutory limitation period (maximum 10 years).
- Order and invoice records: 10 years as required by tax legislation.
- Security and access logs: 2 years.
- Marketing consent data: until consent is withdrawn.
9. Your Rights
Under GDPR Arts. 15-22 and KVKK Art. 11 you have the following rights:
- To learn whether your data is processed and to access it,
- To request rectification of incomplete or inaccurate data,
- To request erasure or destruction of your data (the "right to be forgotten"),
- To request restriction of processing and to object to processing,
- Data portability (receiving your data in a structured format),
- To object to outcomes produced against you solely by automated analysis,
- To claim compensation in case of damage.
10. Requests and Complaints
To exercise your rights, you may submit a written request to . Requests are answered free of charge within 30 days at the latest. You also retain the right to lodge a complaint with the Turkish Personal Data Protection Authority (KVKK), the Bulgarian Commission for Personal Data Protection (CPDP), or the supervisory authority of the EU member state in which you reside.
11. Security Measures
All connections are encrypted with TLS; PII fields are stored encrypted with AES-256-GCM; access is restricted via role-based authorisation; personal data is redacted in system logs; rate limiting and security headers (CSP, HSTS) are enforced.
12. Children’s Data and Changes
The Platform is not directed at persons under 18; accounts found to belong to minors are closed and the data deleted.
This policy may be updated; material changes are announced on the Platform. The current version is always published on this page.
13. Device Capabilities in the App (iOS / Android)
This section describes device capabilities. The scope distinction in section 0 applies here too: THE CAMERA and barcode scanning belong to the website's "Scan" screen ONLY and DO NOT EXIST in the iOS app on the App Store, while local notifications and device storage exist in both. All of them are optional — if permission is not granted, the rest of the app or site keeps working normally.
- Camera (barcode scanning) — WEBSITE ONLY, NOT PRESENT in the App Store app: Opens only on the website's "Scan" screen and only when you press the scan button yourself. The barcode is decoded on the device; no photo or video frame is recorded, stored, or sent to our servers or to any third party. The only data that reaches the server is the digits of the scanned barcode, used to look the product up in the catalogue. That request carries no account, session, or device identifier. Where the site is opened inside an app shell, camera permission can be withdrawn at any time in the device settings; without it you can type the barcode instead.
- Local notifications (price watch): When a product on your watch list gets cheaper, a notification is shown on your phone. Notifications are scheduled by the device itself; no remote (push) delivery is used, no notification token is collected, and the notification content never passes through our servers. Permission can be withdrawn in iOS Settings › Komshia › Notifications; the watch list keeps working, only the notifications stop.
- Device storage (shopping list and watch list): Your "My Pocket" shopping list and your "Scan" watch list are kept in the device's own storage (UserDefaults on iOS, localStorage in a browser). These lists are never uploaded to our servers and we cannot see them. To fetch current prices, only product identifiers are sent to the server, with no information about who you are. The lists are deleted by removing their entries or by uninstalling the app.
Secure B2B + B2C trade platform between Türkiye and Bulgaria.