Personal Data Processing
Last updated July 10, 2026
How ResReturn processes personal data — as a processor for merchants’ shopper data and as a controller for its own website and account data — including purposes, legal bases, retention, and your rights under GDPR and KVKK.
1. Who we are and our roles
ResReturn, a YourSizer product, is a returns and exchange management platform for e-commerce merchants. Merchants install ResReturn on their store (Shopify, Ticimax, ikas, and other platforms), and their shoppers use a hosted returns portal to request returns, exchanges, store credit, or refunds. Registered address: Gümüşsuyu Mahallesi İnönü Caddesi Ulusal Apt. No:5 D:5, 34437 Beyoğlu/İstanbul, Türkiye. Email: contact@resreturn.com.
We act in two distinct roles. For shopper data processed through the returns portal and merchant integrations, we act as a data processor on behalf of the merchant, who is the data controller and determines the purposes of processing. Our processing of shopper data is governed by our agreement with each merchant and carried out on the merchant’s documented instructions.
For our own website, marketing, and merchant-account data (the merchant’s staff accounts, billing details, support history), we act as the data controller. This document records our processing activities in both roles, in line with the Turkish Personal Data Protection Law No. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR).
2. Scope and processing principles
This record has been prepared using an activity-based approach: each business process (account management, returns processing, payments, support, security) is documented together with the categories of data it touches, the purpose and legal basis of processing, maximum retention periods, and the groups that may receive the data. It is a living document, reviewed as our operations or the law change.
All processing follows the general principles of Article 4 KVKK and Article 5 GDPR: personal data is processed lawfully and fairly; collected for specific, explicit, and legitimate purposes and not further processed in incompatible ways; adequate, relevant, and limited to what is necessary (data minimization); kept accurate and up to date; stored no longer than the purpose or the law requires; and protected with appropriate integrity and confidentiality measures.
3. Whose data we process and what it includes
We process personal data relating to three groups: merchants’ staff (the people who administer a merchant account and use the merchant dashboard), shoppers (the merchant’s customers who use the hosted returns portal), and website visitors (people who browse resreturn.com or contact us).
For shoppers, the data categories are: identity and contact information (name, email, phone); order and product data received from the merchant’s e-commerce platform (order number, items, prices, delivery details); return request data (return reasons, exchange preferences, requested resolution); refund and store-credit references (transaction identifiers — we do not store full card numbers); and fraud signals such as return frequency and request patterns.
Where a merchant enables the optional fit-intelligence feature, body-measurement data voluntarily provided by the shopper may also be processed — see the dedicated section below. For merchants’ staff and website visitors we process identity and contact information, account and billing data, support correspondence, and technical data such as IP address, browser type, and access timestamps, together with usage analytics about how the dashboard and website are used.
4. Processing activities, purposes, and legal bases
Account management and service delivery: we create and manage merchant accounts, authenticate staff, and operate the platform. Legal basis: performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6(1)(b)). Account data is retained while the account is active and for up to 10 years afterwards, reflecting limitation periods for potential disputes.
Returns and exchange processing: on the merchant’s behalf we receive return requests through the portal, validate them against order data, apply the merchant’s return policy, and coordinate the outcome (return, exchange, store credit, or refund reference). Legal basis: for us, the processing agreement with the merchant; for the merchant, typically performance of its contract with the shopper. Payment and billing for our own services relies on performance of a contract and legal obligation (KVKK Art. 5/2-c and 5/2-ç; GDPR Art. 6(1)(b) and 6(1)(c)); invoicing records are kept for 10 years under the Turkish Commercial Code and Tax Procedure Law.
Customer support: we receive, answer, and resolve support requests from merchants and, where routed to us, from shoppers. Legal basis: performance of a contract and legitimate interest. Support records are kept for three years after a request is closed, for possible follow-ups and audits.
Platform security, performance, and service improvement: we log technical and usage data to secure our systems, prevent fraud and abuse, diagnose problems, and improve the Services. Legal basis: legitimate interest, and legal obligation where cybersecurity rules apply. Security and access logs are kept for up to two years. Aggregated, de-identified usage analytics may be used to improve the platform; such data can no longer be linked to an individual. Marketing communications to merchants are sent only with consent (which can be withdrawn at any time); proof of consent or refusal is kept for three years.
5. Optional fit-intelligence measurement data
Some merchants enable an optional fit-intelligence feature that helps reduce size-related returns. Where enabled, a shopper may voluntarily provide body-measurement data during the returns or exchange flow. This data is treated as a special category: it is collected only with the shopper’s explicit consent (KVKK Art. 6; GDPR Art. 9(2)(a)), is never required to complete a return, and consent can be withdrawn at any time.
Measurement data is stored separately from directly identifying information, pseudonymized, protected with additional field-level encryption, and kept under a deliberately short retention period, after which it is deleted or irreversibly anonymized. Only aggregated, non-identifying fit statistics are used to improve recommendations for the merchant.
6. Automated decision-making and profiling
To help merchants detect return abuse, the platform computes fraud signals — for example unusually frequent returns, mismatched items, or patterns across requests — and may flag a return request for review or score its risk. This constitutes a limited form of profiling.
Fraud scores are decision support, not decisions: the final decision on whether to accept, reject, or escalate a return request always rests with the merchant. No return is automatically refused by ResReturn solely on the basis of an automated score. Shoppers who believe a decision was wrong can contest it with the merchant, who can review the request and any flag manually; we assist merchants in fulfilling such reviews.
7. Retention, backup, and destruction
Retention periods are set per processing activity, taking into account the purpose of processing, statutory retention duties, and the need for evidence in potential disputes. Financial and accounting records are kept for 10 years under the Turkish Commercial Code and the Tax Procedure Law. Shopper data processed on a merchant’s behalf is retained according to the merchant’s instructions and deleted or returned at the end of the engagement, subject to any legal duty to retain it.
Backups are taken regularly to ensure business continuity and are protected to the same security standard as live systems. Backup media follow a fixed rotation, after which they are automatically overwritten, and backup retention never extends data life beyond the maximum periods that apply in the live system. Backups containing sensitive data are encrypted with strictly restricted access.
When the purpose of processing ends or the retention period expires, data is deleted, destroyed, or anonymized — automatically or on request — through periodic destruction runs performed at intervals not exceeding six months. Methods used include secure erasure (irreversible deletion or overwriting of records), cryptographic destruction (irreversibly destroying encryption keys), anonymization (severing any link to an identifiable person, verified for irreversibility), and physical destruction of storage media.
All destruction operations are logged, and destruction records are kept for at least three years.
8. Recipients, sub-processors, and international transfers
Internally, personal data is shared only on a need-to-know basis: support staff see what is needed to resolve a request, engineers see what is needed to operate and debug the platform, and finance sees billing data. Access follows a role-based authorization matrix.
Externally, data may be shared with: technical infrastructure providers (hosting, database, log management, and security services) engaged as sub-processors under written data-processing agreements; the merchant’s e-commerce platform (Shopify, Ticimax, ikas, or another connected platform), with which order and return status data is exchanged to execute the return; payment service providers, for refund references relating to our own billing; and email/SMS providers used to send transactional notifications about a return. We maintain a current list of sub-processors and notify merchants of changes as agreed. Personal data may also be disclosed to competent public authorities where the law requires it (KVKK Art. 5/2-ç; GDPR Art. 6(1)(c)).
We never sell personal data. Merchants receive analytics about their own returns; any insights that cross merchants are aggregated and de-identified.
Where personal data is transferred outside Türkiye or the European Economic Area — for example to a cloud provider’s data center — we comply with Article 9 KVKK and Chapter V GDPR: transfers rely on adequacy decisions where available, or on standard contractual clauses and equivalent written safeguards, combined with technical measures such as encryption, access restriction, and logging. Recipients are contractually bound to provide the same level of protection.
9. Technical and administrative security measures
Technical measures include: databases isolated in private virtual networks with no direct internet access; TLS encryption for all data in transit; encryption at rest with keys managed in a separate, restricted key-management system; additional field-level encryption for sensitive data such as measurement data; role-based access control on the least-privilege principle; mandatory multi-factor authentication for production access; detailed access logging with anomaly monitoring; pseudonymization of analytical datasets; regular security patching, vulnerability scanning, and penetration testing; and secrets management outside application code.
Administrative measures include: regular staff training on data protection and this policy; confidentiality agreements with all employees and partners who access personal data; data-minimization review of every new data field before collection; periodic internal audits of processing and security controls; and a documented incident-response plan. In the event of a personal-data breach we notify the affected merchants and the competent authorities within the timeframes required by KVKK and GDPR.
Tenant isolation is enforced throughout the platform: each merchant’s data is logically segregated, and no merchant can access another merchant’s shopper data.
10. Special categories and free-text fields
Apart from the explicitly consented fit-intelligence data described above, ResReturn does not seek to process special categories of personal data. However, shoppers or merchant staff may occasionally volunteer sensitive information — for example health details as a return reason — in free-text fields or support messages.
Such unsolicited data is processed only to the minimum extent needed to handle the specific request, is not used for any other purpose, and is deleted or destroyed as soon as the request is closed and any short evidentiary need has passed. Free-text fields carry reminders advising users not to share sensitive personal data, and such content is not shared with third parties except essential service providers acting on instruction under contractual safeguards.
11. Your rights and how to exercise them
Under KVKK Article 11 and GDPR Articles 15–22, data subjects have the right to learn whether their data is processed, to request access and information about the processing, to have inaccurate data corrected, to request deletion or destruction, to object to processing (including profiling), to restrict processing, to receive their data in a portable format, and to withdraw consent at any time without affecting the lawfulness of prior processing.
Shoppers should direct requests to the merchant they shopped with, since the merchant is the controller of returns-portal data; we provide merchants with the tools to fulfill access, correction, and erasure requests through the platform, and we forward any request we receive directly to the relevant merchant without undue delay.
Merchants’ staff and website visitors can contact us directly at contact@resreturn.com or in writing to Gümüşsuyu Mahallesi İnönü Caddesi Ulusal Apt. No:5 D:5, 34437 Beyoğlu/İstanbul, Türkiye. We respond within the statutory deadlines (30 days under KVKK, one month under GDPR). Data subjects also have the right to lodge a complaint with the Turkish Personal Data Protection Authority (KVKK Kurumu) or their local EU supervisory authority.
12. Review and updates
This record of processing activities is binding on all ResReturn teams and is reviewed at least every six months, and additionally whenever our services, sub-processors, or applicable legislation change. Material changes are published on this page and, where they affect merchants’ processing agreements, notified directly.
This version is effective as of July 10, 2026.
Questions about this document? Contact us.
