Privacy Policy
Effective date: 1 March 2025
This Privacy Policy explains how karaca-alisveris collects, uses, stores, and protects personal information when you visit our website, karaca-alisveris an account, place an order, contact us, or otherwise use our services.
The data controller is ETEZEN LTD 17443712, trading as karaca-alisveris and ETZEN LTD 17443712, represented by Martin Trevor GUEST. Company and SIRET reference: LTD 17443712. Registered address: 590 Rochester Way, SE9 1RL London, United Kingdom.
Data We Collect
We may collect identification and contact information, including your name, billing address, delivery address, email address, telephone number, and account credentials.
When you place an order, we collect transaction information such as the products purchased, order value, currency, delivery method, payment status, refunds, and related communications. Payment card information is submitted securely to our payment service provider, Stripe. We do not receive or store complete card numbers, card security codes, or full payment credentials on our systems.
We may collect technical and usage information, including your IP address, browser type, device type, operating system, language settings, referring pages, pages visited, approximate location, session identifiers, and the dates and times you access our website.
We also collect information that you voluntarily provide when contacting customer support, submitting a return or refund request, reviewing a product, subscribing to marketing communications, or communicating with us through another channel.
How We Use Personal Data
We use personal data to process and deliver orders, manage payments, send order and delivery updates, provide customer support, administer returns and refunds, maintain customer accounts, and respond to enquiries.
We also use data to prevent fraud, verify transactions, secure our website, detect unauthorised activity, enforce our terms, comply with tax and accounting obligations, resolve disputes, and establish or defend legal claims.
Where permitted by law, we may use contact information to send news, offers, or product recommendations. Marketing emails are sent only where we have valid consent or another lawful basis. You may unsubscribe at any time by using the link in an email or contacting us.
Our lawful bases for processing include performance of a contract, compliance with legal obligations, our legitimate interests in operating and protecting our business, and consent where required. When processing is based on consent, consent may be withdrawn at any time without affecting processing already carried out.
Payments and Stripe
Payments are processed by Stripe and its affiliated entities. When you make a payment, personal and transaction data may be transmitted directly to Stripe so that it can process the transaction, authenticate the payment method, prevent fraud, manage disputes, and comply with financial and regulatory obligations.
Stripe may process your information as an independent data controller in accordance with its own privacy policy. Stripe may use cookies, device information, payment credentials, and fraud-prevention signals to provide its services. We receive only the payment information necessary to confirm and administer your order, such as payment status, transaction reference, payment method type, and limited card details such as the brand and last four digits.
Sharing of Personal Data
We may share personal data with trusted service providers that help us operate the shop, including Stripe, hosting providers, logistics and delivery companies, customer-support services, analytics providers, email platforms, fraud-prevention services, accountants, insurers, and professional advisers. These recipients receive only the information reasonably necessary to perform their services and must protect it appropriately.
We may disclose information to courts, regulators, tax authorities, law-enforcement agencies, or other public bodies when required by law or when reasonably necessary to protect our rights, customers, systems, or the public. Personal data may also be transferred as part of a merger, restructuring, financing, or sale of all or part of the business, subject to appropriate confidentiality safeguards.
International Data Transfers
Some service providers may process personal data outside the United Kingdom or the European Economic Area. Where such transfers occur, we use legally recognised safeguards, such as adequacy regulations, the UK International Data Transfer Agreement, approved contractual clauses, or other valid transfer mechanisms. Information about relevant safeguards may be requested using the contact details below.
Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy. Order, payment, invoicing, and tax records are generally retained for six years after the end of the relevant financial year. Customer-support records are generally retained for up to three years after the matter is closed. Account data is retained while the account remains active and for a reasonable period afterwards. Marketing data is retained until consent is withdrawn or an objection is made, subject to maintaining a suppression record so that we can respect the request.
Retention periods may be extended where necessary to comply with the law, investigate fraud, resolve disputes, or establish, exercise, or defend legal claims. Data that is no longer required is deleted, anonymised, or securely destroyed.
Data Protection and Security
We use reasonable technical and organisational safeguards designed to protect personal data from accidental loss, unauthorised access, misuse, alteration, or disclosure. These measures include encrypted website connections, access controls, password protections, restricted administrative access, secure service providers, system monitoring, and regular software updates.
Payment information is handled through Stripe’s secure payment infrastructure. We do not intentionally store complete payment card details on our servers. No internet transmission or storage system is entirely secure, but we review our safeguards and take appropriate action if a personal-data breach occurs, including notifying affected individuals and regulators where legally required.
Cookies
Our website uses cookies and similar technologies. Strictly necessary cookies support essential functions such as shopping-cart operation, checkout, payment security, account login, fraud prevention, and preference management. These cookies cannot generally be disabled through our consent tool because the website may not function correctly without them.
With your consent where required, we may use analytics, functionality, and advertising cookies to understand website use, remember preferences, measure campaign performance, and improve our services. Third parties, including Stripe, may place or read cookies when providing payment, authentication, security, or fraud-prevention services.
You can manage non-essential cookies through our cookie banner or your browser settings. Blocking cookies may affect certain website features. You may withdraw cookie consent at any time, and withdrawal will not affect the lawfulness of prior processing.
Your Rights
Depending on your location and applicable law, you may have the right to request access to your personal data, correct inaccurate or incomplete data, request deletion, restrict processing, object to processing based on legitimate interests, and receive certain data in a structured, commonly used, machine-readable format.
You may withdraw consent at any time and object to direct marketing without charge. You may also request information about international-transfer safeguards and lodge a complaint with the UK Information Commissioner’s Office or the competent data-protection authority in your country.
To exercise a right, contact us using the details below. We may request reasonable proof of identity before responding. We normally respond within one month, although the period may be extended where permitted by law for complex or multiple requests. Some rights are subject to legal exceptions, including obligations to retain transaction and tax records.
Children’s Privacy
Our shop is not directed at children under 16, and we do not knowingly collect personal data from children without appropriate parental or guardian authorisation. If you believe that a child has provided personal information to us improperly, please contact us so that we can review and delete it where required.
Changes to This Policy
We may update this Privacy Policy to reflect changes to our services, legal obligations, or data-processing practices. The revised version will be published on our website with a new effective date. Where a change materially affects your rights, we will provide additional notice when appropriate.
Contact
For privacy questions, requests, or complaints, contact ETEZEN LTD 17443712, trading as karaca-alisveris and ETZEN LTD 17443712, represented by Martin Trevor GUEST.
Address: 590 Rochester Way, SE9 1RL London, United Kingdom.
Email: [email protected]
Telephone: +44 59 48 74 15 22