Personal Data Protection (KVKK)
Last updated July 10, 2026
How ResReturn processes personal data under Turkey’s Law No. 6698 on the Protection of Personal Data (KVKK) — acting as data processor for shopper data on behalf of merchants, and as data controller for its own website and merchant-account data.
1. Purpose and scope
This information text (aydınlatma metni) is provided in accordance with the Law No. 6698 on the Protection of Personal Data (KVKK) and related legislation. It explains how personal data is processed in connection with the ResReturn platform: the resreturn.com website, the merchant panel, and the hosted returns portal through which shoppers submit return and exchange requests.
ResReturn is a returns and exchange management platform for e-commerce merchants operating on Shopify, Ticimax, ikas, and other platforms. For the personal data of shoppers who use a merchant’s returns portal, the merchant is the data controller (veri sorumlusu) and ResReturn acts as data processor (veri işleyen) on the merchant’s behalf and under its instructions. For data relating to our own website visitors and merchant accounts, ResReturn acts as the data controller.
In all processing activities we adhere to the general principles set out in Article 4 of the KVKK: compliance with the law and rules of fairness; accuracy and, where necessary, being kept up to date; processing for specific, explicit and legitimate purposes; being relevant, limited and proportionate to those purposes; and retention only for the period required by legislation or by the purpose of processing.
2. Identity of the data controller (veri sorumlusu)
Trade name: ResReturn (a YourSizer product). Address: Gümüşsuyu Mahallesi İnönü Caddesi Ulusal Apt. No:5 D:5, 34437 Beyoğlu/İstanbul, Türkiye. E-mail: contact@resreturn.com.
As the data controller for our website and merchant-account data, we are responsible for determining the purposes and means of processing and for establishing and managing the data recording system. In accordance with Article 10 of the KVKK, this section clearly identifies the data controller and serves as the notification address in legal proceedings.
3. Personal data we process and collection methods
Data provided directly by merchants: when a merchant creates an account, connects a store (Shopify, Ticimax, ikas, or another platform), or contacts us, we collect information such as name, surname, e-mail address, business and store identifiers, limited billing information (your full card details are processed directly by our payment service provider and are not stored by us), and the content of support and contact-form messages.
Shopper data processed on behalf of merchants: when a shopper uses the hosted returns portal, we process the data needed to run the return or exchange — name and contact details, order number and order contents, the items being returned, return reasons and comments, the chosen outcome (exchange, store credit, or refund), refund and shipment status, and, where applicable, withdrawal declarations submitted through the EU Directive 2023/2673 withdrawal button.
Optional fit-intelligence data: if the merchant enables the optional fit-intelligence layer, limited body-measurement data may be processed to reduce size-related returns. This data is collected only with the shopper’s explicit consent (açık rıza), is limited to the minimum measurements necessary, is not derived from or stored as raw images, and is kept for a short retention period with a clear deletion path. The returns portal remains fully functional if this data is not provided.
Data collected automatically: when you use our services, technical and usage data such as IP address, browser type and version, device and operating system, language preference, access timestamps, pages visited, and in-service actions are recorded to keep the platform secure and performant. Cookies and similar technologies are used for session management, remembering preferences, and performance analysis; please see our cookie policy for details.
4. Purposes of processing
Operating the returns service (core function): receiving, evaluating, and resolving return and exchange requests through the returns portal; guiding requests through the exchange-first outcome ladder (exchange, store credit, refund); issuing store credit and triggering refunds on the merchant’s platform; generating return shipping information; and keeping shoppers and merchants informed of request status.
Account management, support, and billing: creating and managing merchant accounts, providing technical support, answering questions received through contact forms, and processing limited payment data to manage subscription billing and fulfill related financial obligations.
Security, fraud detection, and service improvement: analyzing device, connection, and usage data to secure the platform, prevent abusive or fraudulent return activity, optimize technical performance, and improve the user experience. Recording and relaying withdrawal-button declarations is also carried out to help merchants meet their legal obligations under EU Directive 2023/2673.
Returns analytics: we provide merchants with returns analytics — return rates, return reasons, and similar insights — using aggregated and/or pseudonymized data. These analyses help merchants reduce returns and improve their products and operations, and are produced without directly disclosing any shopper’s identity to third parties. Anonymized and aggregated data may also be used to improve our own detection and analytics models.
5. Legal grounds for processing (KVKK Articles 5 and 6)
Establishment or performance of a contract (KVKK Article 5/2-c): processing merchant-account data and operating the returns portal — including executing returns, exchanges, store credit, and refunds — is directly necessary for the establishment and performance of the service contract. Without this data, the platform cannot perform its basic functions.
Fulfillment of a legal obligation (KVKK Article 5/2-ç): limited processing of payment and billing data under tax and commercial legislation, retention of withdrawal declarations, and responses to lawful requests from authorized public authorities are carried out because they are mandatory for fulfilling legal obligations.
Legitimate interest (KVKK Article 5/2-f) and protection of a right (KVKK Article 5/2-e): platform security, fraud prevention, service improvement, and aggregated analytics are based on our legitimate interests, provided the fundamental rights and freedoms of data subjects are not harmed; the principle of data minimization (KVKK Article 4) is observed throughout. Data may also be processed where necessary for the establishment, exercise, or protection of a legal right, such as in potential disputes.
Explicit consent (KVKK Articles 5/1 and 6): body-measurement data processed through the optional fit-intelligence layer is processed only with the shopper’s explicit consent, which is specific, informed, and freely given, and may be withdrawn at any time. Separate explicit consent is likewise sought for optional uses such as marketing communications. In line with the Communiqué on the Procedures and Principles for Fulfilling the Obligation to Inform, informing and obtaining explicit consent are carried out as separate processes.
6. Transfer of personal data (KVKK Articles 8 and 9)
Domestic transfers: personal data may be transferred to service providers acting as our data processors (hosting, infrastructure, software, and security providers), to payment service providers for secure completion of billing transactions, and to authorized public institutions and organizations where required by law or by a competent judicial or administrative authority.
Transfers to merchants and their platforms: return and exchange data is shared with the relevant merchant — the data controller for its own customers — and written back to that merchant’s e-commerce platform (Shopify, Ticimax, ikas, or another connected platform) to execute refunds, exchanges, and store credit. Shopper data belonging to one merchant is never shared with another merchant. Analytics provided to merchants beyond their own transaction records are aggregated and/or pseudonymized, and our contracts prohibit attempts at re-identification.
International transfers: our storage and processing infrastructure relies on international cloud providers, so personal data may be transferred abroad. Such transfers are carried out in accordance with Article 9 of the KVKK and the Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad — to countries subject to an adequacy decision, or with appropriate safeguards such as standard contracts or undertakings announced by the Personal Data Protection Board. The engagement of sub-processors requires written authorization and the same data-protection obligations are imposed on them.
7. Retention and destruction of personal data
Personal data is retained only for as long as required by the processing purposes and the statutory retention periods in the relevant legislation. When the purpose ceases or the statutory period expires, data is securely deleted, destroyed, or anonymized in accordance with the Regulation on the Deletion, Destruction or Anonymization of Personal Data.
Indicative retention periods: merchant-account data is kept while the subscription remains active; return and exchange records are kept in line with the merchant’s instructions and applicable commercial and consumer legislation; billing data is kept for the periods required by tax legislation (typically 5 to 10 years); support correspondence for a limited period after the request is closed (e.g., 2 years); and technical logs for as long as needed for security and performance (typically 6 months to 2 years). Optional fit-intelligence measurement data is kept for a deliberately short period and is destroyed if consent is withdrawn or deletion is requested. Backups are kept on limited rotation cycles that do not exceed live-system retention, and periods are reviewed regularly.
Destruction methods include secure erasure (rendering data inaccessible and unusable, including by overwriting), cryptographic destruction (irreversibly destroying the encryption keys of encrypted data and backups), anonymization (aggregation, bucketing, and similar techniques so that data can no longer be linked to an identifiable person), and physical destruction of media where applicable.
When a merchant’s contract ends, shopper data processed on that merchant’s behalf is returned to the merchant or deleted in accordance with our data processing agreement, without prejudice to statutory retention obligations.
8. Rights of the data subject (KVKK Article 11)
Under Article 11 of the KVKK, every data subject has the right to: learn whether their personal data is processed; request information about such processing; learn the purpose of processing and whether the data is used in line with that purpose; know the third parties to whom data is transferred, domestically or abroad; request correction of incomplete or inaccurate data; request deletion or destruction of data under the conditions in Article 7 of the KVKK; request that corrections and deletions be notified to third parties to whom the data was transferred; object to a result that is detrimental to them arising from analysis exclusively by automated systems; and claim compensation for damage caused by unlawful processing.
The right to object to exclusively automated outcomes also applies to our fraud-detection features: a shopper whose return request is affected by an automated fraud signal may request human review of that outcome.
For shopper data processed on behalf of a merchant, the merchant is the data controller: shoppers should direct their requests to the merchant in the first instance, and we support merchants in fulfilling such requests through the platform. If a shopper contacts us directly, we forward the request to the relevant merchant without undue delay.
9. How to apply (Veri Sorumlusuna Başvuru)
You may submit requests concerning your rights under Article 11 of the KVKK in writing to our address at Gümüşsuyu Mahallesi İnönü Caddesi Ulusal Apt. No:5 D:5, 34437 Beyoğlu/İstanbul, Türkiye, or electronically — via registered electronic mail (KEP), secure electronic signature, mobile signature, or the e-mail address you previously provided and registered in our system — to contact@resreturn.com, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller.
Your application must clearly state your identity-verification information and the subject of your request. Applications are concluded free of charge within thirty days at the latest; if the process requires an additional cost, a fee may be charged according to the tariff determined by the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).
10. Data security measures (KVKK Article 12)
In accordance with Article 12 of the KVKK, we take all necessary technical and administrative measures to prevent unlawful processing of and access to personal data and to ensure its preservation.
Technical measures include: encryption of data in transit and at rest; role-based access control with least-privilege authorization, so that access to shopper data is scoped to the relevant merchant tenant; multi-factor authentication for access to sensitive systems; firewalls and intrusion detection/prevention systems; regular penetration testing and security audits; and the use of masked or anonymized data instead of real personal data in development and testing environments.
Administrative measures include: data minimization as a design principle, with optional data clearly marked as optional; regular personal-data-protection and security training for employees; confidentiality agreements with all employees and business partners who access personal data; regular auditing and improvement of processing activities; and data processing agreements with sub-processors that set out security obligations consistent with the KVKK.
Questions about this document? Contact us.
