Privacy Policy
This Privacy Policy explains how Rosary, LLC processes personal data when you use the Apertina commerce platform: the websites www.apertina.com and studio.apertina.com, the stores hosted on the platform, the Apertina shopping app and the Studio by Apertina app for merchants.
The platform serves two kinds of people: merchants, who run stores, and shoppers, who buy from them. Section 2 explains who is responsible for your data in each case. For any privacy question or request, write to [email protected].
1. Who we are
Rosary, LLC ("Rosary", "we", "us") develops and operates the Apertina commerce platform. Where this policy says that we decide why and how personal data is used, Rosary, LLC is the data controller under the EU General Data Protection Regulation (GDPR) and the data controller (veri sorumlusu) under Turkish Law No. 6698 on the Protection of Personal Data (KVKK).
You can contact us about anything in this policy at [email protected], or by post at the address in section 16.
2. Merchants, stores and our two roles
Apertina hosts independent stores. Each store is run by a merchant, a business or person that decides what the store sells, at what price, how it ships and which payment methods it accepts.
When the merchant is responsible
When you shop in a store, the merchant who runs that store is the controller of your customer and order data in that store: your customer account there, your addresses, your orders, returns and reviews, and the emails and notifications the store sends you. Rosary, LLC processes this data on the merchant’s behalf and on its instructions, as a processor (veri işleyen), to host the store, take your order, pass your payment to the payment provider the store chose and send the store’s messages. If the store has published its own privacy notice, it is linked in the store’s footer.
When we are responsible
Rosary, LLC is the controller for:
- merchant accounts and the data needed to run them, including subscriptions and support conversations;
- the Apertina shopping app itself, including device data, push notification tokens and platform announcements;
- the websites www.apertina.com and studio.apertina.com, including the technical data needed to deliver and protect them.
Where to send a question
If your question is about an order, a delivery, a refund or anything a store did with your data, contact that store first; its contact details are on the store’s pages. For questions about the platform, or if you cannot reach a store, write to [email protected] and we will help you reach the merchant.
3. Personal data we process
Merchant accounts (Apertina Studio)
- Account data: your name, email address and password. We store passwords only as one-way hashes.
- Security data: your two-factor authentication settings and backup codes if you turn two-factor authentication on, and the sessions you are signed in with, including the IP address and the browser or device description recorded for each session.
- Store and team data: the stores you own or belong to, your role in each, and the email addresses of the people you invite to a store.
- Activity records: a log of the changes made in the merchant panel, with the account, time, IP address and browser description, kept to secure stores and investigate problems.
- Subscription data: your plan and its status. Paid plans are charged through Stripe, which receives your card details directly. We do not receive or store card numbers.
- Support conversations: the messages you send to our support team from the merchant panel, together with your name, your email address and the store you were viewing.
- Studio by Apertina app: if you allow notifications, the push notification token of your device with its platform, app version, language and time zone, so that we can send you notifications about your stores. Photos you take or choose in the app are uploaded only when you add them to your store’s media.
Shoppers with an account in a store
- Customer account: your name, email address and password (stored only as a one-way hash), and your phone number if you give it. You can also sign in with a one-time link sent to your email address. Each store has its own customer accounts; an account in one store is not shared with other stores.
- Addresses you save, and the shipping and billing addresses on your orders, including the names and phone numbers in them.
- Orders: the products, prices, discounts, coupon and gift card codes, shipping method, tracking details, order notes and status history, and the returns you request with the reasons you give.
- Product reviews you write, with the name shown on them. A store displays the reviews it approves publicly.
- Wishlists, and the share link of a wishlist if you choose to share it.
- Gift cards: if a gift card is sent to someone, the recipient’s email address, so that the store can deliver it.
- Notification preferences, and the notifications a store sends to your account in the app.
- Sessions: when you sign in, we record the IP address and the browser or device description of the session.
- Notes the store adds: a store’s staff can add internal notes to your customer record and to your orders.
Guest checkout
If a store allows it, you can order without an account. We then process the details you enter at checkout (your email address if you give it or the store requires it, your shipping address and your phone number) and the order itself. A random token, kept in a cookie in your browser or in the app’s encrypted storage, links your cart to your browser or device. The token contains no personal data.
Payments
- Each store chooses its own payment methods. The platform supports Stripe, iyzico, PayTR and Mollie for card and online payments, as well as bank transfer and cash on delivery.
- Card details are entered on the payment provider’s own payment page or form and go directly to that provider. Our servers never receive or store card numbers or card security codes.
- We keep the payment record that the order needs: the provider, the amount, the currency, the status and the provider’s reference and response. Identity numbers are removed from provider responses before they are stored.
- If a store that uses iyzico asks for your Turkish identity number (T.C. kimlik numarası), it is passed to iyzico for that payment only and is not stored by us.
- For bank transfer, the store shows you its own payment instructions. For cash on delivery, you pay the store or its carrier when your order arrives.
The Apertina shopping app
- The list of stores you add is kept on your device. To show a store, the app asks our servers for that store’s public information.
- If you allow notifications, the app registers your device’s push notification token with our servers, together with its platform, app version, language and time zone. Until you sign in to a store, the token is not linked to any account and is used only for platform announcements. When you sign in to a store, the token is linked to your customer account in that store so that the store can notify you, for example about your orders. When you sign out, the link is removed.
- Sign-in tokens and guest cart tokens are kept in encrypted storage on your device.
- The camera is used only on your device, to scan a store’s QR code. The image is not sent to us.
Our websites
When you visit www.apertina.com, a store on the platform or studio.apertina.com, our servers and Cloudflare, which sits in front of them, process technical data such as your IP address, your browser type, the pages you request and the time of each request. We use it to deliver the pages, to protect the services against abuse (for example by limiting the number of requests from one address) and to find and fix problems.
Emails
- We send account emails (address verification, sign-in links and password resets), store emails on behalf of stores (such as order confirmations and shipping updates) and service emails to merchants. For each email we keep a record of the recipient address, the subject, the type of email and its delivery status.
- A store can choose to send a reminder email to signed-in shoppers who leave items in their cart. You can turn off a store’s emails in that store’s notification settings in the Apertina app.
4. No advertising, analytics or tracking tools
The Apertina websites and apps do not contain advertising, analytics, session recording or third-party error reporting tools. We do not sell personal data, we do not use it for advertising, and we do not track you across other companies’ apps or websites. Merchants see sales reports built from the orders of their own stores.
5. Why we process personal data and our legal bases
- To create and run accounts, host stores, take orders, process payments, arrange delivery and send the emails and notifications that belong to them: performance of a contract (KVKK Article 5(2)(c); GDPR Article 6(1)(b)).
- To keep the order, payment and invoice records that commercial and tax law require: compliance with a legal obligation (KVKK Article 5(2)(ç); GDPR Article 6(1)(c)).
- To secure the services, prevent fraud and abuse, keep activity records and fix problems: our legitimate interests in running a safe and reliable platform (KVKK Article 5(2)(f); GDPR Article 6(1)(f)).
- To establish, exercise or defend legal claims (KVKK Article 5(2)(e); GDPR Article 6(1)(f)).
- To send push notifications, including platform announcements: your consent, given through your device’s notification permission, which you can withdraw at any time in your device settings (KVKK Article 5(1); GDPR Article 6(1)(a)).
For the store data we process on a merchant’s behalf, the merchant decides the purposes and the legal basis.
6. Who receives personal data
We do not sell personal data. We share it only as described in this section.
Service providers we use
- Hetzner Online GmbH hosts our servers and databases in data centres in Germany.
- Cloudflare, Inc. provides the network in front of our websites and stores uploaded images and files (Cloudflare R2).
- Expo (650 Industries, Inc.) relays push notifications to Apple Push Notification service and Firebase Cloud Messaging, which deliver them to your device.
- Our emails are sent from our own mail server. If it cannot be reached, platform emails are delivered through Resend, an email delivery service.
- Stripe processes the subscription payments of merchants.
Store search runs on our own servers and indexes store catalogue content, not customer data.
Providers a store chooses
When a merchant connects one of the following to its store, the data that provider needs is sent to it for that store’s orders:
- payment providers (Stripe, iyzico, PayTR or Mollie), which receive the amount and the buyer details they require, such as name, email address, phone number and billing address;
- shipping integrations (MNG Kargo or Shippo), which receive the recipient’s name, address and phone number to create shipping labels;
- e-invoice providers (Nilvera or Paraşüt), which receive the billing details needed to issue an invoice;
- the store’s own mail server, if the store sends its emails through it;
- the store’s own systems, if the merchant connects them to the store through webhooks or API keys.
These providers process the data under their own terms and privacy policies.
Others
We disclose personal data to authorities, courts or other parties where the law requires it, or where it is needed to establish, exercise or defend legal claims.
7. International transfers
Our servers are in Germany. For users in Turkey, this is a transfer of personal data abroad. Some of the providers listed in section 6, such as Cloudflare, Expo, Resend, Stripe and Shippo, are based in or process data in the United States and other countries. The Turkish providers a store may choose (iyzico, PayTR, MNG Kargo, Nilvera and Paraşüt) process data in Turkey, which is a transfer outside the European Economic Area for users there.
We make these transfers under the mechanisms that KVKK Article 9 and Chapter V of the GDPR provide, such as adequacy decisions or standard contractual clauses, as they apply to each transfer.
9. How long we keep data
- Accounts and their data: for as long as the account exists.
- Order, payment, invoice and return records: for the period that commercial and tax law require, including after an account is deleted (see section 10).
- Sessions: until they expire (up to 30 days for shoppers and 7 days for merchants) or you sign out.
- Sign-in, verification and password reset links: they expire after a short time.
- Data exports that merchants create: deleted after 30 days.
- Backups: our database backups are replaced on a rolling schedule, so deleted data leaves them when the last backup that contains it expires.
10. Deleting your account
Shopper accounts
You can delete your customer account in a store at any time, in the account settings of the Apertina app or of the store’s website. Because each store has its own accounts, deleting your account in one store does not affect your accounts in other stores.
Deletion takes effect immediately. We delete your saved addresses, sign-in credentials, sessions, push notification tokens, notifications, notification preferences, wishlist and carts, and we remove your name, phone number and email address from your customer record. Orders, payments, invoices and returns are kept because the law requires it, with their addresses reduced to the country and their notes removed. Reviews you wrote stay on the product without your name. We send a confirmation to your email address.
Merchant accounts
To close a merchant account, write to [email protected] from the email address of the account. The order, payment and invoice records of your stores are kept for the period the law requires.
11. Security
We protect personal data with technical and organisational measures suited to the risk, including:
- encrypted connections (HTTPS) to our websites, apps and servers;
- passwords stored only as one-way hashes, and optional two-factor authentication for merchant accounts;
- encryption of the payment, shipping, invoice and email credentials that stores connect;
- separation of each store’s customer data from every other store;
- encrypted storage of sign-in tokens in the Apertina app;
- administration of the platform restricted to authorised staff on a private network.
No system is completely secure. If a personal data breach occurs, we notify the competent authority and the people affected where the law requires it.
12. Your rights
Under KVKK (Turkey)
Under Article 11 of KVKK, you have the right to:
- learn whether your personal data is processed;
- request information about the processing if it is;
- learn the purpose of the processing and whether the data is used in line with that purpose;
- know the third parties, in Turkey or abroad, to whom your data is transferred;
- request the correction of incomplete or inaccurate data;
- request the deletion or destruction of your data under the conditions of Article 7 of KVKK;
- request that the third parties who received your data be notified of a correction, deletion or destruction;
- object to a result against you that arises from analysis carried out exclusively by automated systems;
- claim compensation for damage caused by unlawful processing.
Under the GDPR (European Economic Area)
Under Articles 15 to 22 of the GDPR, you have the right to:
- access your personal data and receive a copy of it (Article 15);
- have inaccurate data corrected (Article 16);
- have your data erased (Article 17);
- restrict the processing (Article 18), and have the recipients of your data told of a correction, erasure or restriction (Article 19);
- receive the data you gave us in a structured, machine-readable format and have it transmitted to another controller (Article 20);
- object to processing based on our legitimate interests (Article 21);
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you (Article 22). We do not make such decisions.
Where processing is based on your consent, you can withdraw it at any time; this does not affect processing carried out before the withdrawal.
Store data
For data that a store controls, the store answers your request. You can send it to the store or to us, and we will assist the store in answering it.
13. How to make a request or a complaint
Send your request to [email protected], where possible from the email address of your account, and tell us which account or store it concerns. We may ask you to confirm your identity before we act on it. We answer within the period the law requires: under KVKK, within thirty days at the latest; under the GDPR, within one month, which may be extended in the cases the GDPR allows. Requests are free of charge, except where the law allows a fee.
You also have the right to complain to the Turkish Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) or, in the European Economic Area, to the data protection supervisory authority of the country where you live or work or where the alleged infringement took place.
14. Children
The Apertina commerce platform is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe that a child has given us personal data, write to [email protected] and we will delete it.
15. Changes to this policy
We update this policy when our services or the law change. The date at the top of this page shows when it was last updated. If a change materially affects how we use your personal data, we will make it visible on the services before it takes effect.
16. Contact
Rosary, LLC, operator of the Apertina commerce platform. Postal address: 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Email: [email protected]