Privacy, terms and data handling.
Sellsify separates contractual acceptance, privacy notices and optional consent. Documents below are versioned so acceptance evidence can be tied to the exact version shown to a user.
Pre-launch legal status
Version 2026-09-29-preview-2 is an integrated pre-launch framework. Before paid commercial launch, the individual Sellsify operator's required identity/contact details, official privacy contact channels, commercial billing terms, production subprocessors and transfer schedules must be completed and reviewed by qualified counsel. Sellsify is currently a brand, not a separate incorporated company.
Preview Terms of Service
Pre-launch terms governing access to the Sellsify testing environment. Final commercial terms will replace this preview before paid launch.
1. Scope and business use
Sellsify is a brand and software product for commerce, marketing, sales, support, reporting, automation and AI-assisted workflows. At this stage, Sellsify is operated by an individual and is not a separately incorporated company or legal entity. The current service is a pre-launch environment intended primarily for professional and business use.
By creating an account you agree to this preview Terms version for use of the current testing service. A materially revised commercial version will require a new acceptance before paid commercial use where appropriate.
2. Accounts and access
- You are responsible for accurate account information and safeguarding credentials.
- Workspace owners control team invitations and permissions.
- You must not share credentials in a way that bypasses workspace permissions or security controls.
- Sellsify may suspend access when reasonably necessary to protect the service, users or connected systems.
3. Connected platforms
Connections to Shopify, Google, Meta, Microsoft and other providers are governed by both these Terms and the relevant provider's terms. Sellsify does not control third-party API availability, permissions, rate limits or policy changes.
You authorize Sellsify to access and process connected-account data only to provide the features you activate and within the permissions granted through the relevant integration.
4. Customer data
As between you and Sellsify, you retain rights in data you submit or make available through connected systems. You are responsible for having a lawful basis and necessary notices or permissions for personal data you instruct Sellsify to process.
Where Sellsify processes personal data solely on your documented instructions, the Data Processing Addendum framework applies in addition to these Terms.
5. AI and automated actions
- AI output can be incomplete or incorrect and should be reviewed before material business decisions.
- Actions that can materially affect connected systems should use an approval step unless the user intentionally configures an authorized automation.
- Customer content is not designated for model training merely because it is processed by an AI-assisted feature. Any future training use would require a separately documented legal basis and product disclosure.
6. Acceptable use
- Do not use Sellsify for unlawful, fraudulent, abusive or rights-infringing activity.
- Do not attempt to bypass access controls, probe other tenants, exfiltrate secrets or interfere with service availability.
- Do not upload or process data that you are not authorized to use.
7. Fees, subscriptions and commercial launch
Pricing shown during pre-launch may change. Binding billing, renewal, cancellation, refund, tax and payment terms will be displayed before a paid subscription is purchased.
Sellsify will not store full payment-card numbers or CVV data when payments are enabled; payment processing should be delegated to an authorized payment provider.
8. Intellectual property
Sellsify is the brand name of the service. The software, branding, interfaces and platform materials remain the property of the individual brand operator or applicable licensors. These Terms grant only the limited right to use the service.
Third-party names, trademarks and APIs remain the property of their respective owners.
9. Availability, termination and liability
The pre-launch service may change, be interrupted or contain defects. No production SLA or commercial warranty is promised by this preview document.
Final commercial terms will define applicable service levels, warranty disclaimers, liability limitations, governing law, dispute process and the legal identity/contact details of the individual Sellsify operator. If the operating structure later changes to a legal entity, the terms will be updated accordingly.
Preview Privacy Policy
Explains how account, usage and integration data is handled. This is a notice, not a bundled consent request.
1. Data we process
- Account data such as name, email address, authentication identifiers and workspace membership.
- Subscription, billing-contact and invoice-related metadata when billing is enabled.
- Security and technical data such as IP-related request metadata, session records, audit logs and device/browser information where available.
- Integration metadata and business data retrieved from services you connect, subject to the permissions you grant.
- Support communications, privacy requests and product feedback.
2. Why we process data
- Provide, secure and administer the Sellsify service.
- Authenticate users and enforce workspace permissions.
- Connect, synchronize and report data from authorized third-party platforms.
- Prevent abuse, investigate incidents and maintain auditability.
- Meet legal, accounting and regulatory obligations.
- Send marketing communications only where permitted and subject to the user's communication preferences.
3. Roles
For Sellsify account administration, security, billing and its own product operations, the Sellsify brand operator — currently an individual rather than a separate company — generally acts as the party determining the purposes and means of processing.
For personal data that a business customer imports from commerce, CRM, advertising or support systems for Sellsify to process on that customer's instructions, Sellsify generally acts as a processor/service provider and the customer remains responsible for its controller/business obligations.
4. Sharing and subprocessors
Data may be shared with infrastructure, hosting, authentication, communications, analytics, payment and AI service providers only as needed to provide or secure the service. A public subprocessor register will identify production subprocessors before commercial launch.
Connected platforms receive or expose data according to the actions and permissions you authorize through those platforms.
5. International transfers
Sellsify may use providers that process data outside the user's country. Applicable transfer safeguards must be documented for production use, including relevant KVKK transfer mechanisms and, where applicable, GDPR/UK GDPR transfer instruments.
6. Retention and deletion
Data is retained only for the period needed for the relevant service, security, contractual or legal purpose. Production retention periods will be published in the retention register before commercial launch.
Account deletion does not necessarily mean every record can be deleted immediately when a legal retention requirement applies; data no longer required should be deleted or anonymized according to the applicable policy.
7. Your choices and requests
- Review or change marketing communication preferences.
- Request access/export, correction or deletion through Privacy & Data settings.
- Manage optional analytics and marketing cookies through Cookie Settings.
- Contact the future published privacy/legal contact for statutory rights requests.
8. Security
Sellsify uses technical and organizational controls including tenant authorization, row-level security, access logging and server-side handling of privileged integration credentials. No security system can guarantee absolute protection.
KVKK Aydınlatma Metni — Ön Taslak
6698 sayılı KVKK kapsamındaki aydınlatma yapısının ürün içi ön taslağıdır; açık rıza metni değildir.
Önemli ön lansman notu
Bu metin ticari lansman öncesi ürün entegrasyonu amacıyla hazırlanmış ön taslaktır. Sellsify şu aşamada ayrı bir şirket veya tüzel kişi değil, bireysel olarak işletilen bir marka ve yazılım ürünüdür. Nihai KVKK aydınlatma metninde markayı işleten gerçek kişinin veri sorumlusu sıfatıyla gerekli kimlik ve iletişim bilgileri yer alacaktır; ileride işletme yapısı değişirse metin buna göre güncellenecektir.
Aydınlatma ile açık rıza birbirinden ayrıdır. Sellsify, sözleşmenin kurulması/ifası veya başka bir hukuki sebebe dayanabilecek işlemleri genel bir 'KVKK onayı' kutusuna bağlamaz.
1. İşlenebilecek veri kategorileri
- Kimlik ve iletişim: ad-soyad, e-posta ve hesap iletişim bilgileri.
- Müşteri işlem: workspace, plan, abonelik ve kullanım kayıtları.
- İşlem güvenliği: oturum, erişim, audit log ve güvenlik olayları.
- Pazarlama: yalnızca ilgili hukuki şartlar sağlandığında ileti tercihleri ve kampanya etkileşimleri.
- Entegrasyon verileri: kullanıcının yetkilendirdiği Google, Meta, Shopify ve benzeri sistemlerden gelen iş verileri.
2. İşleme amaçları
- Hesabın ve Sellsify hizmetlerinin sunulması.
- Yetkilendirme, veri güvenliği, kötüye kullanımın önlenmesi ve denetim izi tutulması.
- Entegrasyonların çalıştırılması, senkronizasyon ve raporlama.
- Destek taleplerinin ve kullanıcı başvurularının yönetimi.
- Yasal yükümlülüklerin yerine getirilmesi ve bir hakkın tesisi/kullanılması/korunması.
- Ayrı hukuki şartlara tabi olmak üzere pazarlama iletişimi.
3. Hukuki sebepler
Her veri işleme faaliyeti için uygulanabilir KVKK m.5/m.6 hukuki sebebi veri envanterinde ayrıca eşleştirilmelidir. Sözleşmenin kurulması veya ifası, hukuki yükümlülük, bir hakkın tesisi/kullanılması/korunması ve meşru menfaat gibi sebepler uygulanabildiğinde gereksiz açık rıza alınmamalıdır.
4. Aktarım
Hizmetin sunulması için altyapı ve entegrasyon sağlayıcılarına veri aktarımı gerekebilir. Yurt dışına aktarımlar, üretim ortamında kullanılan sağlayıcı ve lokasyonlar kesinleştirilerek KVKK'nın güncel yurt dışı aktarım mekanizmalarına göre belgelendirilmelidir.
5. Toplama yöntemi
Veriler; web ve uygulama arayüzleri, hesap oluşturma, OAuth/API entegrasyonları, destek kanalları, ödeme sağlayıcıları ve güvenlik/log sistemleri üzerinden elektronik yollarla elde edilebilir.
6. İlgili kişi hakları
KVKK m.11 kapsamındaki talepler için Sellsify içinde Privacy & Data başvuru kaydı oluşturulabilir. Ticari lansman öncesinde bireysel veri sorumlusunun uygun resmi başvuru ve iletişim kanalları bu metne eklenecektir.
Preview Cookie Policy
Defines essential, analytics and marketing cookie categories and the consent controls used by Sellsify.
Essential storage
Essential cookies or browser storage support authentication, security, theme, session continuity and remembering the cookie choice itself. They are required for requested service functionality and cannot be disabled through the cookie preference panel.
Analytics
Analytics technologies are optional. They must remain disabled until the visitor opts in where consent is required. When enabled, they may measure product/site usage, reliability and aggregate performance.
Marketing
Advertising or remarketing technologies are optional and must remain disabled until the visitor opts in where consent is required.
Changing your choice
Visitors can reopen Cookie Settings from the site footer. Rejecting optional cookies must be as accessible as accepting them. A preference change replaces the local preference and, for signed-in users, can also be recorded as an auditable consent event.
Preview Data Processing Addendum
Framework for customer-controller / Sellsify-processor obligations when Sellsify processes customer personal data on documented instructions.
1. Roles and instructions
Where a customer determines the purposes and means of processing personal data and Sellsify processes that data only to provide configured services, the customer acts as controller/business and Sellsify acts as processor/service provider, subject to applicable law.
Sellsify will process such data only on documented customer instructions, including instructions expressed through configured product features, except where law requires otherwise.
2. Confidentiality and security
- Access should be limited to authorized personnel and systems.
- Tenant authorization, credential protection, encryption in transit and appropriate storage protections should be maintained.
- Security events affecting customer personal data should be investigated and communicated without undue delay where legally required.
3. Subprocessors
Production subprocessors will be listed in the public subprocessor register. Sellsify should impose data-protection obligations appropriate to the processing performed by each subprocessor and maintain a process for material changes.
4. Data-subject requests and incidents
Taking into account the nature of processing, Sellsify should reasonably assist customers with data-subject requests, security obligations and breach-response duties relating to customer personal data.
5. Return, deletion and transfers
On termination, customer personal data should be returned, exported, deleted or anonymized according to the customer's instructions and applicable retention requirements. International transfers require the relevant production transfer mechanism.
6. Commercial execution
This preview is a product architecture document, not a fully executed commercial DPA. The final DPA must identify the customer and the individual Sellsify operator (or any future legal entity if the operating structure changes), together with governing terms, approved subprocessors, processing details, transfer annexes and security schedule.
Preview Acceptable Use & AI Terms
Rules for platform use, AI-generated content and automated actions.
Acceptable use
- No unlawful, deceptive, abusive, malicious or rights-infringing use.
- No unauthorized access, credential harvesting, tenant probing, security bypass or destructive testing.
- No processing of data beyond the permissions and legal rights available to the user.
AI transparency and review
- AI-generated recommendations and content may be inaccurate and should be reviewed.
- Sellsify should visibly identify AI-assisted experiences where appropriate.
- High-impact external actions should remain approval-gated unless the workspace intentionally configures an authorized automation.
- AI provider usage and data flows must be listed in the subprocessor/data-flow registers before production use.
Security & Data Handling Overview
Current security architecture commitments without claiming certifications Sellsify has not obtained.
Current controls
- Workspace and tenant access controls with database row-level security.
- Server-side handling of privileged OAuth credentials and separation from public client keys.
- Role-based workspace permissions and privileged admin controls.
- Audit logging for security-relevant and workspace events.
- Encrypted transport using HTTPS/TLS through hosted application infrastructure.
- Database backups and provider-managed infrastructure controls subject to configured service plans.
Security roadmap
- Formal incident-response and breach-notification runbooks.
- Documented retention/deletion schedules and subprocessor register.
- Regular dependency/vulnerability review and penetration testing before enterprise commitments.
- Business continuity/disaster recovery documentation.
- Future ISO 27001 / SOC 2 readiness only when the underlying controls and independent assurance process are actually in place.
No certification claim
Sellsify does not claim ISO 27001, SOC 2 or another certification merely because related security controls are planned or implemented. Certifications and audit reports will be represented only after they are formally obtained.
