NodesyAI Connect · Shopify uygulaması / Shopify app

Türkçe metin (KVKK) ve English text (GDPR) aynı sayfadadır. / Turkish (KVKK) and English (GDPR) versions are on this page.

NodesyAI Connect — Gizlilik Politikası / Privacy Policy

Son güncelleme / Last updated: 2026-09-03


A. Türkçe — 6698 sayılı KVKK kapsamında aydınlatma metni

1. Veri sorumlusu

NodesyAI Connect uygulaması, ThinkOne Bilişim Teknoloji Tic. Ltd. Şti. (Maslak Mah. Taşyoncası Sok. Blok: T4b Ofis No: 144, Maslak 1453 Ağaoğlu, Sarıyer/İstanbul, Türkiye, info@thinkone.com.tr) tarafından sunulur. Mağaza sahibi (Shopify satıcısı) kendi müşterilerinin verileri bakımından veri sorumlusu, Nodesy ise satıcı adına işlem yapan veri işleyen konumundadır. Nodesy'nin kendi hesap verileriniz (kullanıcı adı, e-posta, faturalama) bakımından veri sorumlusu olduğu durumlar ayrı Nodesy Hizmet Sözleşmesi'nde düzenlenir.

2. İşlenen veri kategorileri

Kategori Alanlar Kaynak
Mağaza bilgisi mağaza alan adı, mağaza adı, e-posta, para birimi, ülke, saat dilimi, erişim jetonu (şifreli) Shopify OAuth / shop API
Müşteri kimlik Shopify müşteri no, ad, soyad, e-posta, telefon (E.164), etiketler, pazarlama izinleri customers/*, orders/*, checkouts/* webhook'ları
Sipariş sipariş no/adı, tutar, para birimi, ödeme/kargo durumu, ödeme yöntemi, ürün satırları (başlık, adet, fiyat, SKU, görsel), teslimat adresi, kargo takip no/URL, iade tutarı orders/*, fulfillments/*, refunds/*
Sepet sepet token'ı, sepet URL'si, tutar, ürünler, e-posta/telefon checkouts/*
Stok envanter kalemi no, konum no, mevcut adet (kişisel veri değildir) inventory_levels/update
Mesajlaşma WhatsApp konuşma kayıtları, gönderim durumu, akış değişkenleri WhatsApp Business Platform
Kullanım webhook alım zamanı, olay durumu, hata kayıtları (PII içermez) Nodesy sunucuları

Ham webhook gövdeleri (raw) yalnızca sorun giderme amacıyla saklanır ve akış motoruna verilmez.

3. İşleme amaçları ve hukuki sebep (KVKK m.5)

4. Aktarım ve alt işleyiciler

Alt işleyen Amaç Konum
Meta Platforms Ireland Ltd. (WhatsApp Business Platform) mesaj iletimi AB / ABD (Meta SCC)
Shopify International Ltd. mağaza verisi kaynağı Kanada / AB
FixCloud sunucu, veritabanı, Redis Türkiye / İstanbul

Yurt dışına aktarım KVKK m.9 kapsamında açık rıza veya Kurul'ca ilan edilen yeterli koruma / standart sözleşme mekanizmalarıyla yapılır. Mesaj gönderimi için müşterinin telefon numarası ve mesaj içeriği zorunlu olarak Meta'ya iletilir.

5. Saklama süreleri

Veri Süre
Erişim jetonu uygulama kaldırılınca anında silinir
Olay kayıtları 90 gün, sonra otomatik temizlik
Sipariş / sepet / müşteri projeksiyonları mağaza bağlı olduğu sürece; kaldırıldıktan sonra 48 saat içinde shop/redact ile silinir
WhatsApp konuşma kayıtları Nodesy hesabı ayarına göre (varsayılan 24 ay)
Uyum (compliance) olay kayıtları 3 yıl (ispat yükümlülüğü)

6. Silme ve uyum webhook'ları

7. İlgili kişi hakları (KVKK m.11)

Müşteriler haklarını önce mağaza sahibine, mağaza sahibi de info@thinkone.com.tr adresine iletir. Başvurular 30 gün içinde yanıtlanır. Nodesy panelinden kişi silme/anonimleştirme ve dışa aktarma araçları sunulur.

8. Güvenlik

Jetonlar Fernet (AES-128-CBC + HMAC) ile şifreli saklanır; webhook'lar HMAC-SHA256 ile doğrulanır; tüm trafik TLS 1.2+; erişim rol tabanlıdır; loglarda PII ve jeton bulunmaz; düzenli sızma testleri yapılır.


B. English — GDPR notice

1. Controller and processor

NodesyAI Connect is provided by ThinkOne Bilişim Teknoloji Tic. Ltd. Şti. ("ThinkOne") (Maslak Mah. Taşyoncası Sok. Blok: T4b Ofis No: 144, Maslak 1453 Ağaoğlu, Sarıyer/İstanbul, Türkiye, info@thinkone.com.tr). The merchant is the controller of their customers' data; Nodesy acts as processor under the merchant's instructions (Art. 28 GDPR). A Data Processing Agreement is available on request.

2. Data we process

Shop profile (domain, name, email, currency, country, time zone, encrypted access token); customer identity (Shopify customer ID, name, email, phone, tags, marketing consents); orders (number, totals, currency, financial/fulfillment status, payment gateway, line items, shipping address, tracking, refunds); checkouts (token, recovery URL, totals, items, email/phone); inventory levels (no personal data); WhatsApp conversations and delivery status; technical logs without PII.

3. Purposes and legal bases (Art. 6)

Transactional notifications (order, payment, shipping, refund) — performance of a contract (6(1)(b)); abandoned checkout reminders, campaigns, segments — consent (6(1)(a), taken from the customer's SMS/phone marketing consent in Shopify; no consent, no message); COD confirmation and back-in-stock alerts — contract / legitimate interest (6(1)(f)); security and compliance logs — legal obligation (6(1)(c)).

4. Sub-processors and transfers

Meta Platforms Ireland Ltd. (WhatsApp Business Platform, EU/US under SCCs); Shopify International Ltd.; FixCloud in Istanbul, Türkiye. Transfers outside the EEA rely on Standard Contractual Clauses (Art. 46).

5. Retention

Access tokens: deleted immediately on uninstall. Event records: 90 days. Order/checkout/customer projections: while the store is connected, erased within 48 hours after shop/redact. WhatsApp conversation history: per merchant setting (default 24 months). Compliance logs: 3 years.

6. Mandatory compliance webhooks

customers/data_request (export within 10 days), customers/redact (anonymise contact, delete store records), shop/redact (delete all store data). All three are received on a dedicated, HMAC-verified endpoint.

7. Data subject rights (Arts. 15–22)

Requests go to the merchant, who forwards them to info@thinkone.com.tr; we answer within 30 days. Tools for erasure, anonymisation and export are available in the Nodesy panel.

8. Security

Tokens encrypted at rest (Fernet), HMAC-SHA256 webhook verification, TLS 1.2+, role-based access, no PII or tokens in logs, regular penetration tests.

9. Contact

Privacy inquiries: info@thinkone.com.tr (Ticaret Sicil No 482263-5, MERSİS 0843085534500001).