Data Storage Policy
Last updated July 10, 2026
Where ResReturn stores the data that powers your returns operations, how long each category is kept, and how it is securely deleted or anonymized when no longer needed.
1. Purpose and scope
This Personal Data Storage and Destruction Policy ('Policy') is issued by ResReturn, a YourSizer product, operating at Gümüşsuyu Mahallesi İnönü Caddesi Ulusal Apt. No:5 D:5, 34437 Beyoğlu/İstanbul, Türkiye ('ResReturn', 'we'). It is prepared in accordance with the Turkish Law No. 6698 on the Protection of Personal Data (KVKK), the Regulation on the Deletion, Destruction or Anonymization of Personal Data, and the EU General Data Protection Regulation (GDPR).
ResReturn is a returns and exchange management platform for e-commerce merchants. Merchants connect their store (Shopify, Ticimax, ikas, and other commerce platforms), and their shoppers use a hosted returns portal to request returns, exchanges, store credit, or refunds. This Policy explains where the data processed through the platform is stored, for how long each category is retained, and how data is securely deleted, destroyed, or anonymized when the processing purpose ceases.
The Policy is binding on all ResReturn teams and on the external service providers (data processors and sub-processors) we engage. It applies the KVKK Article 4 and GDPR Article 5 principles — lawfulness and fairness, accuracy, purpose limitation, data minimization, storage limitation, and accountability — throughout the data lifecycle.
2. Roles: controller and processor
ResReturn acts in two distinct capacities. For shopper data — order, product, and return information processed to operate a merchant's returns flow — ResReturn acts as a data processor on behalf of the merchant, who remains the data controller. For our own website data and merchant-account data (the business contact, login, and billing details of the merchants who subscribe to the platform), ResReturn acts as the data controller.
In this Policy, 'deletion' means rendering personal data inaccessible and unusable for relevant users; 'destruction' means rendering data irretrievable by anyone in any way; and 'anonymization' means irreversibly severing the link between the data and an identified or identifiable person, so that the data can no longer be attributed to an individual even when combined with other data.
'Periodic destruction' means the recurring, scheduled deletion, destruction, or anonymization of personal data whose processing conditions have ceased, carried out at the intervals defined in this Policy.
3. Data categories we store
Merchant account data: company and contact details, authorized-user credentials, subscription and billing records for the merchants who use ResReturn.
Return-operations data, processed on behalf of merchants: order, product, and customer data synced from the merchant's commerce platform; return requests, return reasons, and resolution outcomes (exchange, store credit, refund); and shipping and refund references generated while a return case is handled.
Optional fit-intelligence measurement data: where a merchant enables the optional fit-intelligence feature and the shopper gives explicit consent, limited body-measurement data may be processed to reduce size-related returns. This data is treated as sensitive, stored with column-level encryption, and kept only for a short retention period as described in Section 5.
Aggregated analytics: statistical, de-identified data about return rates, reasons, and outcomes used to produce merchant dashboards and to improve the service. Aggregated analytics are derived so that no individual shopper can be identified.
4. Where data is stored
Personal data is stored in digital recording media hosted in the secure data centers of internationally recognized cloud infrastructure providers such as Amazon Web Services (AWS) and Google Cloud Platform (GCP). This infrastructure is used for storage, processing, and backup.
The primary media are: relational and document databases holding merchant accounts and return-operations data; application and log servers holding technical and access records; encrypted backup environments; email systems holding support correspondence and notifications; and secure file storage for documents attached to return cases or support requests.
All data is tenant-scoped: each merchant's data is logically isolated so that it can only be accessed within that merchant's tenant context. In rare cases, physical documents such as contracts or invoices may be archived to meet legal requirements; these are kept in locked storage protected from unauthorized access.
5. Retention schedule by category
Merchant account and billing data: retained while the merchant account is active, and for up to 10 years thereafter where required by tax and commercial legislation (e.g., the Turkish Tax Procedure Law) and for the statute of limitations on potential disputes.
Order, product, and return data processed on behalf of merchants: retained for the duration of the merchant's contract and per the merchant's configuration. Upon termination of the contract, this data is deleted or returned to the merchant within a defined off-boarding window, unless a legal obligation requires longer retention. Return reasons and resolution outcomes are kept in identifiable form for up to 3 years after a case is closed, for proof and service-quality purposes, and are aggregated or anonymized thereafter.
Shipping and refund references linked to invoicing: up to 10 years, in line with tax and commercial record-keeping obligations. Support correspondence: 3 years from the date the request is resolved. Device and connection logs (IP address, browser type, access timestamps): 2 years, for information security, fraud prevention, and system integrity.
Optional fit-intelligence measurement data: processed only with the shopper's explicit consent (KVKK Article 6, GDPR Article 9) and retained for a short, defined period — it is deleted or irreversibly anonymized shortly after the related return case is completed, and immediately upon withdrawal of consent. Aggregated analytics contain no personal data and are not subject to a retention limit. All periods are reviewed regularly; when a period expires or the purpose ceases, the data is destroyed as described in Section 6.
6. Deletion, destruction, and anonymization methods
Secure deletion: personal data that directly identifies an individual — merchant contact details, shopper records, support correspondence — is rendered inaccessible and unusable by irreversibly deleting database records or overwriting data via software. Critical destruction operations follow a four-eyes principle: initiation and approval are performed by two people with different authorization levels, and every operation is logged.
Cryptographic destruction: for encrypted data, including encrypted backups and column-level-encrypted measurement data, the associated encryption keys are irreversibly destroyed, rendering the data permanently unreadable. Physical destruction: any physical media containing personal data is destroyed irreversibly (shredding of paper, physical destruction of storage devices).
Anonymization: data needed only for aggregate or statistical output — return-rate benchmarks, reason distributions, model performance metrics — is anonymized using techniques such as aggregation, generalization and bucketization, masking and rounding, noise injection, and k-anonymity. Anonymization is designed to be irreversible, and methods are reviewed periodically against the risk of re-identification.
Merchants and, through their merchant, shoppers may request deletion at any time. Verified requests are fulfilled promptly, subject only to overriding legal retention obligations, and confirmation is provided once destruction is complete.
7. Backup policy
Personal data is backed up regularly to ensure business continuity and prevent data loss, with backup frequency determined by the criticality of each data set. Backups are stored encrypted, on media logically or physically separated from live systems, and access to them is restricted to a minimal set of authorized personnel protected by multi-factor authentication.
Backups are audited and restore drills are performed on a scheduled basis to verify that backups are complete, intact, and recoverable. Backup and destruction operations are logged and documented.
Backup retention follows the minimum-requirement principle and never extends the maximum retention of the live system. Measurement-data backups are kept on short rotation cycles (approximately 30–90 days), and operational and log-data backups on cycles of approximately 30–180 days, depending on operational need. Expired backups are removed by automated rotation, and encrypted backups additionally undergo cryptographic destruction.
8. Technical and administrative security measures
Encryption: all data is encrypted in transit using TLS between the merchant's store, the hosted returns portal, and our systems, and encrypted at rest in databases and file storage using strong algorithms. Encryption keys are managed in a separate, access-restricted key management system (KMS). Fit-intelligence measurement data receives additional column-level encryption and a narrower access matrix.
Access control: role-based access control (RBAC) on the least-privilege principle governs all access to personal data, and tenant-scoped isolation ensures no merchant's data is reachable from another tenant's context. Multi-factor authentication is mandatory for production systems. All access and administrative actions are logged, and logs are monitored for anomalies. Access authorizations are reviewed periodically, and departing personnel lose access immediately.
Network and application security: firewalls and web application firewalls monitor traffic, network segmentation separates databases from application layers, and systems undergo regular vulnerability scanning and penetration testing, with identified issues prioritized and remediated.
Administrative measures: staff receive regular data-protection training, confidentiality agreements are signed with all employees and partners with data access, internal policies cover minimization, retention, destruction, and breach response, and a documented incident response plan enables rapid reaction and notification in the event of a data breach.
9. Sub-processors and international transfers
We use a limited set of sub-processors to operate the platform, principally cloud infrastructure providers (such as AWS and GCP) for hosting, storage, and backup. Data is also exchanged with the merchant's own commerce platform (Shopify, Ticimax, ikas, or another connected platform) and, where a return shipment is created, with the designated shipping carrier — in each case only to the extent needed to execute the return flow.
Contracts with all sub-processors include data security, confidentiality, and breach-notification obligations consistent with KVKK and GDPR, and compliance is audited periodically.
Where personal data is transferred internationally, appropriate safeguards are applied: standard contractual clauses, undertakings, or other mechanisms recognized under Article 9 of the KVKK and Chapter V of the GDPR. Transfer arrangements are reviewed when providers, regions, or legal requirements change.
10. Periodic destruction and audits
Data whose retention period has expired or whose processing purpose has ceased is destroyed in the first periodic destruction cycle following that date, and in no case later than six months after the obligation arises. Periodic destruction combines automated retention rules enforced at the software level with manual verification.
Internal audits of retention and destruction processes are conducted at least every six months, and more frequently after significant product changes, new integrations, or regulatory updates. Audit reports cover expired records, executed destruction and anonymization operations, backup rotation and destruction evidence, and sub-processor compliance, and are reviewed by senior management.
In accordance with Article 7 of the KVKK, records of all deletion, destruction, and anonymization operations are kept for at least three years, without prejudice to other legal obligations.
11. Policy updates and contact
This Policy took effect on July 10, 2026 and is reviewed whenever legislation changes, infrastructure or sub-processors change, new data categories or product features are introduced, or audit findings require it. Updates take effect on the date of publication on our website.
Questions and requests regarding this Policy, including access, correction, and deletion requests, can be directed to ResReturn, a YourSizer product, Gümüşsuyu Mahallesi İnönü Caddesi Ulusal Apt. No:5 D:5, 34437 Beyoğlu/İstanbul, Türkiye, or by email to contact@resreturn.com. Shoppers whose data we process on behalf of a merchant may also contact the merchant directly, and we will assist the merchant in fulfilling the request.
Questions about this document? Contact us.
