Castavor: Kargo Entegrasyonu — Privacy Policy
Last updated: 29 August 2026
Castavor: Kargo Entegrasyonu (“the App”), operated by Castavor Software, connects a Shopify store to Turkish shipping carriers so merchants can create shipments, print labels and track deliveries. Creating a shipment necessarily involves the recipient's personal data, so this policy explains exactly what is processed, why, and who receives it.
What we store
Merchant / store data
- Your shop domain, installation date, plan and app settings.
- Your carrier API credentials and SMS provider credentials. These are encrypted at rest with AES-256-GCM and are never displayed back to you in full.
- The Shopify session and access token required to run an embedded app.
Customer (recipient) data
To declare a shipment we process the order data Shopify provides:
- Recipient name, delivery address, phone number and e-mail address.
- Order number, line items, quantities and — for cash-on-delivery — the amount to collect.
- The tracking number and the carrier's raw API response for each shipment.
We do not use this data for marketing, profiling or any purpose other than fulfilling the shipment you asked us to create.
Who we share data with
The App only sends data to the services below, and only when the corresponding feature is used.
Shipping carriers
When you declare a shipment, the recipient's name, address, phone number, parcel contents and any cash-on-delivery amount are sent to the carrier you selected (HepsiJet, Yurtiçi Kargo, Aras Kargo, DHL (MNG), PTT Kargo, UPS, Sürat Kargo or Horoz Lojistik). This is the core purpose of the App and cannot be avoided. Each carrier processes that data under its own privacy policy and its contract with you.
SMS providers
If you enable SMS notifications, the recipient's phone number and the message text are sent to your chosen provider (NetGSM or Verimor) using your own account credentials. SMS is off by default.
Google (Gemini API)
If you use the optional AI address correction feature, the raw address text alone is sent to Google's Gemini API to be parsed and corrected. The recipient's name, phone number, e-mail address and order contents are deliberately excluded from that request. This happens only when you explicitly trigger the feature on a specific order — never automatically for every order. Google processes that request under its own API terms. If you would rather no address data reach Google, simply do not use AI address correction; every other part of the App works without it.
Public tracking page
The App can host a branded tracking page at /takip/<tracking-number>. That page is intentionally limited to the order number, carrier, shipment status and dates. It never shows the recipient's name, address, phone number or e-mail address, so a leaked tracking link cannot expose personal data.
What we do not do
- We do not sell or rent your data, or your customers' data.
- We do not embed third-party trackers in your storefront.
- We do not see or store your payment card details — billing is handled entirely by Shopify.
Data location & retention
- Data is stored in our application database (Microsoft SQL Server) on a server located in Türkiye.
- Order and shipment records are kept while the App is installed, so that you can track and report on past shipments.
- When you uninstall the App, all data for your shop is permanently deleted within 48 hours via Shopify's
shop/redactrequest.
GDPR / KVKK compliance
We implement Shopify's mandatory compliance webhooks:
customers/data_request— we forward any data we hold for the named orders.customers/redact— the stored order payload and the carrier's raw response are erased for the named orders, which removes the recipient's personal data while leaving the shipment record itself intact for your accounting.shop/redact— every record belonging to the shop (shipments, orders, settings, carrier credentials, sessions) is permanently deleted.
Under GDPR and KVKK you may request access to, correction of, or deletion of your data at any time by writing to the address below.
Data processing agreement
This section forms a data processing agreement between you (the merchant) and Castavor Software. By installing and using the App you accept it. It applies in addition to Shopify's own Partner Program and App Store agreements.
Roles
You are the data controller for your customers' personal data. We act only as a data processor and process that data solely on your documented instructions — which in practice are the actions you take in the App: creating a shipment, printing a label, requesting an address check, or sending an SMS.
Scope and duration
Subject matter: creating and tracking shipments with Turkish carriers. Data subjects: the recipients of your orders. Categories of data: name, delivery address, phone number and email address. Duration: for as long as the App is installed on your store.
Sub-processors
We use the following sub-processors, each only for the feature it serves:
- The shipping carrier you select (HepsiJet, Yurtiçi, Aras, DHL/MNG, PTT, UPS, Sürat or Horoz) — recipient name, address, phone, email and parcel details.
- Your own SMS provider (NetGSM or Verimor), using your own account credentials — recipient phone number and message text. Disabled by default.
- Google (Gemini API) — the raw address text only, and only when you trigger the AI address check on a specific order. The recipient's name, phone, email and order contents are deliberately excluded from that request.
We will tell you before adding a new sub-processor. We engage no others, and we do not sell or rent personal data to anyone.
Security measures
- Encryption in transit — TLS 1.2 or higher on every connection.
- Encryption at rest — recipient personal data (stored order payloads, carrier responses and shipping labels) and your carrier and SMS credentials are encrypted with AES-256-GCM.
- Encrypted backups — daily database backups encrypted with AES-256, automatically verified after every run and restore-tested on a monthly schedule.
- Least privilege — the App connects to its database with an account that holds no administrative rights and cannot reach any other database on the server.
- Access logging — access to every table holding personal data is recorded, and the log is reviewed monthly.
- Confidentiality — access is limited to named personnel bound to confidentiality, and strong passwords are enforced on every account.
Assistance and audits
We help you meet your own obligations: the mandatory Shopify compliance webhooks described above are implemented and delete real data, and we will answer data subject requests you forward to us. On reasonable request we will provide the information needed to demonstrate compliance with this section.
Personal data breaches
If we become aware of a breach affecting your customers' personal data we will notify you without undue delay and in any case within 72 hours, describing what happened, which data was affected, and what we are doing about it.
Deletion
When you uninstall the App, every record belonging to your shop is permanently deleted from our live database within 48 hours. Encrypted backups are kept for 7 days and are then overwritten, after which no copy remains with us. Data already transmitted to a carrier is held by that carrier under its own policy and is outside our control.
Payments
Subscriptions are billed by Shopify through Shopify App Pricing. We never see or store your payment details; we only read whether your store has an active subscription and which plan it is on.
Changes to this policy
If we change how data is processed, we will update this page and the “last updated” date above. Material changes will also be announced inside the App.
Contact
Questions or data requests: info@castavor.com