Privacy Policy and Information Notice on the Protection of Personal Data
Last updated: 20 July 2026
This document has been prepared pursuant to Law No. 6698 on the Protection of Personal Data in order to inform users of the BugiBox platform of the purposes for which and the legal grounds on which their personal data are processed, the parties to whom such data are transferred, the periods for which they are retained, and the rights available to data subjects. It also sets out the policy applicable to cookies used on the Platform. This is a translation provided for convenience; in the event of any discrepancy, the Turkish version shall prevail.
1. Identity of the Data Controller
1.1. Pursuant to Law No. 6698 on the Protection of Personal Data ("KVKK"), the data controller is ShineSoft Yazılım Hizmetleri ve Ticaret Limited Şirketi ("ShineSoft" or the "Company"), MERSIS no. 0769-2498-9370-0001, having its registered office at Sultanselim Mah. Yamaç Sk. No:6 D:3, 34415 Kağıthane/İstanbul.
1.2. ShineSoft processes the personal data set out below, for the purposes and on the legal grounds set out below, through the website and mobile application operated under the BugiBox brand and domain name (the "Platform").
1.3. The terms "Member", "Buyer", "Seller", "Product" and "Order" used in this document bear the meanings ascribed to them in the User Agreement published on the Platform.
2. Categories of Personal Data Processed
2.1. Identity Data: first name, surname, display name shown on the Platform.
2.2. Contact Data: electronic mail address, mobile telephone number, delivery and consignment addresses (province, district, open address, building and apartment number, postal code).
2.3. Customer Transaction Data: listings created on the Platform, offers made and received, orders, order status history, consignment and delivery records, return requests and related correspondence, ratings and reviews.
2.4. Financial Data: for Members acting as Sellers, IBAN details and records relating to the sub-merchant process conducted with the payment institution; records of transaction amounts, service fees and refund amounts.
2.5. Card data such as payment card number, expiry date and security code are under no circumstances recorded, stored or displayed by ShineSoft. Such data are processed directly through the infrastructure of the contracted payment institution.
2.6. Visual and Audio Data: profile photograph, product images and videos uploaded to listings, images shared within messaging.
2.7. Transaction Security Data: password digest values (passwords are never stored in plain text), session and authorisation information, last login date, account status records.
2.8. Usage and Traffic Data: addresses of pages visited, referring domain, visit date and a visitor identifier value. The visitor identifier is generated daily by means of a one-way digest of the IP address and browser information together with a secret key; the IP address is not recorded in raw form.
2.9. Marketing and Notification Data: notification preferences, device identifiers relating to push notification subscriptions, preferred language.
2.10. Request and Complaint Management Data: requests and complaints submitted through support channels and the responses given to them.
2.11. **Device-recognition signals (during valuation only, in your browser):** In the “What's my device worth?” flow, so that we can suggest the brand and model of the device you are selling instead of asking you, the information your browser reports on its own (user agent, screen resolution and pixel ratio, platform, GPU name, touch support) is read **only inside your own browser**. These signals are **not sent** to our servers, **not stored**, and **not used** for identification or tracking; only the brand and model you confirm reach the server. You can dismiss the suggestion and edit every field by hand.
3. Purposes of Processing
3.1. Creation of the membership record, management of the account, and performance of authentication and authorisation processes.
3.2. Verification of the electronic mail address and issuing of notifications concerning account security.
3.3. Creation of listings on the Platform, publication of listings, making them searchable, and performance of content moderation.
3.4. Conduct of the offer, order and messaging processes between the Buyer and the Seller.
3.5. Execution of payment transactions, collection of the price on behalf of the Seller, operation of the secure payment process, and conduct of transfers to be made to the Seller.
3.6. Creation of consignments, conduct of carriage and delivery processes, and notification of consignment status to the parties.
3.7. Conduct and conclusion of order cancellation, return, dispute and inspection processes.
3.8. Handling and follow-up of requests, complaints and support applications.
3.9. Operation and improvement of the Platform, detection and remedy of errors and faults, and generation of performance and usage statistics.
3.10. Prevention of fraud, abuse, fraudulent listings and use contrary to legislation, and maintenance of Platform security.
3.11. Where explicit consent exists, the sending of commercial electronic messages and conduct of promotional activities.
3.12. Fulfilment of retention, disclosure, reporting and information obligations towards official authorities arising from legislation.
3.13. Exercise of rights of legal claim and defence and follow-up of disputes.
4. Legal Grounds for Processing
4.1. The processing of identity, contact, customer transaction, financial and visual data is based on the ground that it is directly related to the establishment or performance of a contract, pursuant to article 5/2-(c) of the KVKK.
4.2. Processing activities within the scope of retention, document issuance, disclosure and provision of information to official authorities are based on the ground that it is necessary for compliance with a legal obligation of the data controller, pursuant to article 5/2-(ç) of the KVKK.
4.3. Processing activities aimed at maintaining Platform security, preventing abuse and measuring and improving service quality are based on the legitimate interests of the data controller, pursuant to article 5/2-(f) of the KVKK.
4.4. Processing activities aimed at the exercise of rights of legal claim and defence are based on the establishment, exercise or protection of a right, pursuant to article 5/2-(e) of the KVKK.
4.5. Processing activities relating to the sending of commercial electronic messages and the use of non-essential cookies are based on the explicit consent of the data subject, pursuant to article 5/1 of the KVKK. Explicit consent may be withdrawn at any time.
5. Transfer of Personal Data
5.1. Personal data are transferred to the parties set out below, limited to the purposes stated in this document and in accordance with the conditions set out in articles 8 and 9 of the KVKK.
5.2. By reason of the structure of the Platform, where an Order is created, the Buyer's name, surname, delivery address and telephone details are shared with the relevant Seller for the purpose of creating the consignment and effecting delivery. Likewise, where a return process is initiated, the Seller's consignment address details may be shared with the Buyer. Members are obliged to use such information solely for the purpose of performing the relevant transaction.
5.3. Identity, contact and financial data are transferred to the contracted payment institution for the purposes of executing payment transactions, operating the secure payment process, creating the Seller's sub-merchant registration and fulfilling statutory identification obligations.
5.4. Recipient and consignor name, address and telephone details are transferred to the contracted carriage service provider and the relevant courier companies for the purpose of creating the consignment and effecting delivery.
5.5. Server hosting, database, file storage and electronic mail dispatch services are conducted through a cloud infrastructure service provider located within the borders of the European Union (Frankfurt/Germany).
5.6. For the purpose of detecting errors and faults occurring on the Platform, error records and the technical data generated together with such records may be transferred to an error monitoring service provider.
5.7. During the listing creation process, upon the Seller's request, product images uploaded to the listing are transferred to an artificial intelligence service provider for the purpose of automatically extracting product features. The Member's identity and contact details are not transferred in this process, and the transfer occurs only where the Seller elects to use the said feature.
5.8. For the purpose of conducting support and communication processes, electronic mail correspondence is processed on the infrastructure of a corporate electronic mail service provider.
5.9. The servers of some of the service providers referred to above are located abroad. Transfers within this scope are effected in accordance with the conditions set out in article 9 of the KVKK.
5.10. Personal data may be transferred to public institutions and organisations and judicial authorities legally authorised, within the framework of obligations arising from legislation and where so requested.
5.11. Personal data are not sold, leased or transferred for marketing purposes to any third party other than those stated in this document.
6. Method of Collection
6.1. Personal data are collected directly from the data subject in electronic form by means of the registration, profile, address, listing, offer, order, messaging and return forms on the Platform.
6.2. Usage and traffic data are collected by automated means through the measurement mechanism within the Platform's own infrastructure and through cookies.
6.3. Certain data relating to payment and carriage processes are obtained in electronic form from the relevant service providers as transaction result notifications.
6.4. Data within the scope of support requests are collected through electronic mail and in-Platform communication channels.
7. Cookie Policy
7.1. Cookies are small text files saved to users' devices by the websites they visit. Cookies and similar technologies are used on the Platform for the purposes of providing the service and improving the user experience.
7.2. Essential Cookies: session and refresh tokens used to keep the session open and to provide authorisation, together with the cookie carrying the user role information. The refresh token is stored in such a way that it cannot be read by the browser (HttpOnly). Without these cookies the core functions of the Platform do not operate, and their use is not subject to explicit consent.
7.3. Preference Cookies: cookies and local storage records used to remember the language preference and the cookie consent selection.
7.4. Measurement: the Platform generates visit statistics within its own infrastructure, and no third-party advertising or tracking cookies are used for this purpose. The visitor identifier is generated by means of a one-way digest function as explained in article 2.8 of this document, and the IP address is not stored in raw form.
7.5. Users may delete or block cookies through their browser settings. Where essential cookies are blocked, the functions of the Platform requiring a session cannot be used.
7.6. Cookie preferences may be managed through the cookie information banner on the Platform.
8. Retention Periods
8.1. Personal data are retained for the period required by the purpose for which they are processed and, in any event, in accordance with the minimum retention periods prescribed by legislation.
8.2. Identity and contact data within the scope of the membership relationship are retained for the duration of the membership; where the membership comes to an end, they are retained limited to the periods of prescription arising from legislation.
8.3. Records relating to order, payment and invoicing processes are retained for the periods prescribed within the framework of obligations arising from tax and commercial legislation.
8.4. Usage and traffic data are retained for statistical purposes and in a manner not directly capable of identifying the data subject.
8.5. Upon expiry of the retention period, personal data are deleted, destroyed or anonymised.
8.6. Requests relating to closure of an account and deletion of data may be submitted through the data deletion page on the Platform or by means of the application procedure set out in article 11 of this document. Data whose retention is mandatory under legislation shall continue to be preserved for the duration of the retention period.
9. Data Security Measures
9.1. All data communication between the Platform and the user is effected in encrypted form using current encryption protocols (TLS).
9.2. Passwords are not stored in plain text; only irreversible digest values are retained.
9.3. Access to personal data is limited to personnel who need to access it by reason of their job description, and authorisation and role-based access control are applied.
9.4. Payment card data are under no circumstances processed or stored within the Platform's infrastructure; payment processes are conducted through the infrastructure of a licensed payment institution and with 3D Secure verification.
9.5. Systems are updated regularly, access records are kept, and rate limiting and monitoring mechanisms are applied against unusual access attempts.
9.6. Data subjects are informed that, notwithstanding all technical and administrative measures taken, absolute security of data transmission over the internet cannot be guaranteed.
10. Rights of the Data Subject
10.1. Pursuant to article 11 of the KVKK, every data subject has the following rights, exercisable by applying to the data controller.
10.2. To learn whether their personal data are processed.
10.3. To request information as to processing, if their personal data have been processed.
10.4. To learn the purpose of processing of their personal data and whether the data are used in accordance with that purpose.
10.5. To know the third parties, in Türkiye or abroad, to whom their personal data have been transferred.
10.6. To request rectification of their personal data where they have been processed incompletely or inaccurately, and to request that the action taken in this respect be notified to the third parties to whom the personal data have been transferred.
10.7. To request deletion or destruction of their personal data where the reasons requiring processing have ceased to exist, notwithstanding that the data have been processed in accordance with the KVKK and other applicable legislation, and to request that the action taken in this respect be notified to the third parties to whom the personal data have been transferred.
10.8. To object to a result arising to their detriment through analysis of the processed data exclusively by automated systems.
10.9. To claim compensation for damage suffered by reason of unlawful processing of their personal data.
11. Application Procedure
11.1. Data subjects may submit their requests concerning the rights listed in article 10 of this document to ShineSoft, in accordance with the procedures set out in the Communiqué on the Procedures and Principles of Application to the Data Controller.
11.2. Applications may be made by sending an electronic mail to destek@bugibox.com or in writing to the address stated in article 1.1 of this document.
11.3. The application must clearly set out the name, surname, signature (where the application is in writing), contact details and the subject matter of the request. Attaching information and documents relating to the request will facilitate its conclusion.
11.4. Applications are concluded as soon as possible according to the nature of the request and in any event within 30 (thirty) days at the latest. Where the process requires an additional cost, the fee set out in the tariff determined by the Personal Data Protection Board may be charged.
11.5. Where the application is rejected, the response is found insufficient or no response is given within the applicable period, the data subject is entitled to lodge a complaint with the Personal Data Protection Board.
12. Provisions Concerning Children
12.1. The Platform is not intended for use by persons under the age of 18. Persons under the age of 18 may not become Members of the Platform and may not carry out transactions through the Platform.
12.2. Where it is determined that personal data belonging to a person under the age of 18 are being processed, such data shall be deleted without delay and the relevant account shall be closed.
13. Amendments to This Document
13.1. ShineSoft reserves the right to update this document in line with changes in legislation and changes in the services offered on the Platform.
13.2. Updates take effect on the date of their publication on the Platform. The most current version of this document is kept accessible on the Platform at all times.
13.3. Where there is an expansion in the scope of processing activities based on explicit consent, the consent of the data subjects shall be obtained separately.
14. Contact
14.1. For questions and requests under this document, ShineSoft may be contacted at destek@bugibox.com.
14.2. The trading name, address, MERSIS number and other contact details of the data controller are set out on the "About" page of the Platform.
14.3. This document entered into force on the date of its publication on the Platform.