Privacy Policy
Last updated: 14 July 2026
Pending legal review. This document should be reviewed by a qualified Turkish + EU data-protection lawyer, and the company's registered trade title, MERSIS number and tax office added, before it is relied upon.
Your privacy matters to us. This policy describes what personal data Verintra collects, why, who we share it with, and the rights you have under the GDPR and Turkey's KVKK.
1. Who we are (Data Controller)
This Privacy Policy explains how Verintra ("Verintra", "we", "us") processes personal data through the Verintra web application, website and related services (the "Service"). It serves as both our GDPR privacy notice and our KVKK aydınlatma metni (information notice).
Data controller (veri sorumlusu): Verintra, Kadıköy, İstanbul, Türkiye. Email: info@verintra.com. Phone: +90 506 625 0603. Our registered trade title, MERSIS number and tax office are filed with the İstanbul Trade Registry and available on request at info@verintra.com.
For data-protection questions and requests, contact us at info@verintra.com.
2. Scope and definitions
"Personal data" means any information relating to an identified or identifiable person. "Processing" means any operation performed on personal data. "Merchant"/"User" is the business customer using Verintra. "Connected Accounts" are third-party accounts (e.g. Google) a Merchant links to Verintra.
Verintra is the controller for account, billing and usage data. For data a Merchant accesses through their Connected Accounts (e.g. Google Analytics or Merchant Center data), Verintra generally acts as a processor on the Merchant's behalf.
3. Personal data we collect
We collect the following categories of personal data:
- Account & identity data — name, email, password (stored hashed), company name, role.
- Connected-account credentials — Google OAuth access/refresh tokens and account identifiers, stored encrypted and used only to call the APIs you authorize.
- Google Analytics (GA4) data — reporting metrics and dimensions we retrieve on your behalf to compute performance scores.
- Google Merchant Center data — product/feed data, account IDs and product-status/issue data.
- Feed & product data — titles, descriptions, attributes, images and prices you import or that we optimize (may incidentally contain personal data if you include it).
- Payment-related data — billing name, plan and subscription status. Full card details are handled directly by our payment processors; Verintra does not store full card numbers.
- Usage & product-event data — first-party records of in-app actions (e.g. sign-up, email verification, AI generation, feed sync) with timestamps, used to operate, secure and improve the Service; these records do not contain your IP address. With your consent, we also use a privacy-focused product-analytics tool (PostHog, EU-hosted) that records in-app usage (pages, clicks) keyed only to your account id and plan — never your email or payment data. It loads only after you accept analytics cookies and can be declined or withdrawn at any time.
- Device & log data — limited technical data including IP address and browser. IP addresses are processed transiently for security, rate-limiting and abuse prevention and are not stored against your account.
- Communications — support messages and emails you send us.
4. Why we process your data (purposes)
We process personal data to: provide and operate the Service (feed optimization, analytics retrieval, AI content generation); create and authenticate accounts and verify your email address; manage billing and subscriptions; send transactional emails and alerts; provide support; ensure security and prevent fraud and abuse (including signup rate-limiting and bot-protection challenges); comply with legal obligations; and improve the Service through first-party usage analytics.
5. Legal bases for processing
We rely on the following legal bases (GDPR Art. 6 / KVKK Art. 5):
- Performance of a contract — to deliver the Service and process billing.
- Legitimate interests — for security, fraud prevention and service improvement; you may object (see your rights below).
- Consent — for marketing emails and non-essential cookies; you may withdraw it at any time.
- Legal obligation — to retain tax/accounting records and respond to lawful requests.
6. AI features and Google Gemini
Verintra's AI features (title/description generation, attribute extraction, category suggestions, semantic search) send the relevant product content you provide to Google's generative AI service (Google Gemini) to produce suggestions. AI output is generated automatically and may be inaccurate — you should review it before publishing.
We aim to use Gemini in a configuration that does not use your content to train Google's models; confirm the current arrangement at info@verintra.com. In line with EU AI Act transparency obligations, we tell you clearly when content is AI-generated.
7. Google API Services — Limited Use
When you connect a Google account, Verintra requests only the scopes needed for the features you use:
- See, edit, create and delete your Google Merchant Center data (https://www.googleapis.com/auth/content) — to read your product feed, account IDs and product-status/issue data, and to submit or update the optimized feed you ask us to publish. This is the only scope Google offers for the Merchant Center Content API.
- View your Google Analytics data (https://www.googleapis.com/auth/analytics.readonly) — read-only access we use to retrieve the reporting metrics that compute your performance scores. This is Google's minimal, read-only Analytics scope.
Verintra's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the user-facing features you have connected (feed optimization, product-issue insights and performance scoring); we do not sell it; we do not use it for advertising; we do not transfer it to others except as necessary to provide those features (to the sub-processors listed below), to comply with applicable law, or as part of a merger or acquisition with notice to you; and we do not allow humans to read it except with your explicit consent, for security or to comply with applicable law, or where the data has been aggregated and anonymized. Google user data is never used to train generalized or non-personalized AI/ML models.
You can review or revoke Verintra's access at any time at https://myaccount.google.com/permissions. Disconnecting your Google account, or deleting your Verintra account, removes the stored tokens.
8. Sharing and sub-processors
We share personal data with the following service providers (sub-processors), each under a data processing agreement and only as needed to run the Service:
- Google LLC — Gemini API (AI content generation), and the OAuth / Google Analytics Data API / Merchant Center Content API you connect (United States).
- Stripe — payment processing (United States / EU).
- iyzico — payment processing (Türkiye).
- Resend — transactional email delivery (United States).
- Cloudflare — bot-protection (Turnstile) on our signup form and network security (United States / global).
- Hostinger — hosting and database infrastructure (European Union).
- PostHog — product analytics (EU-hosted), loaded only with your consent; receives in-app usage keyed to your account id and plan, never your email or payment data (European Union).
We may also disclose data where required by law, and to advisors or a successor entity in a corporate transaction. We do not sell your personal data.
9. International data transfers
Some recipients are located outside your country, including outside the EEA and outside Türkiye (e.g. the United States). For EEA data, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
For transfers from Türkiye under KVKK, we rely on the applicable Art. 9 mechanism (adequacy, the KVKK Standard Contract, or another lawful ground). A copy of the relevant safeguards is available on request at info@verintra.com.
10. How long we keep data (retention)
We keep account data while your account is active and for 12 months after closure; billing and tax records for the period required by Turkish tax and commercial law (currently up to 10 years); server logs for 12 months; and Connected-account tokens until you disconnect the account or delete your account, whichever is first.
11. Your rights
Under the GDPR you have the rights of access, rectification, erasure, restriction, data portability, objection (including to direct marketing and to processing based on legitimate interests), rights regarding automated decision-making, and the right to withdraw consent.
Under the KVKK (Art. 11) you may: learn whether your data is processed and request information about it; learn the purpose and whether it is used accordingly; know the third parties (domestic or abroad) to whom it is transferred; request correction, deletion or destruction; request that corrections/deletions be notified to third parties; object to outcomes of solely automated analysis; and claim compensation for damages caused by unlawful processing.
To exercise any right, contact info@verintra.com. We respond within one month (GDPR) / 30 days (KVKK).
12. Cookies and tracking
We use strictly necessary cookies (no consent required) and, subject to your prior consent, analytics cookies. Non-essential cookies do not load before you consent via our cookie banner. You can manage or withdraw consent at any time. See your cookie settings for the cookies in use and their purposes.
13. Automated decision-making
Verintra does not make decisions producing legal or similarly significant effects about you solely by automated means. AI suggestions and performance scores are advisory and intended for your review.
14. Security
We apply appropriate technical and organizational measures, including encryption of data in transit and of sensitive credentials at rest, access controls, and secure token storage. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
15. Children
Verintra is a business tool not directed to children. It is not intended for individuals under 18, and we do not knowingly collect their personal data.
16. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email and an in-app notice, and the "Last updated" date above reflects the latest version.
17. Contact and complaints
For privacy questions or to exercise your rights: Verintra, Kadıköy, İstanbul, Türkiye, info@verintra.com.
EEA users may lodge a complaint with their local data protection supervisory authority. Users in Türkiye may submit a formal application to us (in writing or by email, including your name, identification, address and the subject of your request); if unsatisfied with our response, you may apply to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).