Privacy Policy
Creatives Data Customer Portal
Last Updated: April 15, 2026
Creatives Data (“we,” “us,” or “our”), a digital agency headquartered in Istanbul, Turkey, operates the Creatives Data Customer Portal (the “Portal”) accessible at customer.creativesdata.com and management.creativesdata.com. This Privacy Policy describes how we collect, use, store, and protect information when you use our Portal.
By accessing or using the Portal, you agree to this Privacy Policy. If you do not agree, please do not use the Portal.
1. Who We Are
Creatives Data is a digital agency and SaaS company based in Kadıköy, Istanbul, Turkey. We provide branding, web development, mobile development, e-commerce, and digital marketing services to our clients. The Portal is a proprietary analytics and reporting platform we operate on behalf of our clients to aggregate, visualize, and report performance data from third-party platforms.
Data Controller: Creatives Data Website: https://creativesdata.com Contact Email: contact@creativesdata.com
2. Information We Collect
2.1 Account Information
When your account is created on the Portal, we collect:
- Full name
- Email address
- Company/brand name
- Phone number (optional)
- Password (stored in hashed form)
2.2 Third-Party Platform Data
The Portal connects to the following third-party platforms to retrieve analytics, advertising, e-commerce, and operational data on behalf of our clients. We access only the data necessary to provide reporting and analytics services:
Google Services (via OAuth 2.0):
- Google Analytics 4: Website traffic metrics, user behavior data, session data, page views, conversions, audience demographics, acquisition channels, and engagement metrics.
- Google Search Console: Search performance data including impressions, clicks, click-through rates, average position, indexing status, and search query data.
- Google Ads: Campaign performance metrics including impressions, clicks, conversions, cost data, keyword performance, ad group metrics, and quality scores.
- Google Merchant Center: Product listing data, product status, pricing information, feed diagnostics, and shopping performance data.
Meta Services (via Meta Marketing API):
- Meta Ads (Facebook & Instagram Ads): Campaign performance data, ad spend, impressions, reach, clicks, conversions, audience insights, and creative performance metrics.
E-Commerce Platforms:
- Shopify: Store performance data, order metrics, product data, sales analytics, and inventory information accessed via the Shopify Admin API.
- Trendyol Marketplace: Order data, product listings, sales metrics, customer questions, pricing information, and seller performance data accessed via the Trendyol Seller API.
Food Delivery Platforms:
- Yemeksepeti: Order data, menu items, sales metrics, store status, and operational data accessed via the Yemeksepeti Integration API.
- Getir Yemek: Order data received via webhook notifications, menu information, and delivery metrics.
- Trendyol GO Yemek: Order data, restaurant information, menu data, and sales metrics accessed via the Trendyol GO API.
- Migros Yemek: Order data, menu items, and sales metrics accessed via POS integration.
Analytics & UX Tools:
- Microsoft Clarity: Session recordings, heatmaps, and user behavior analytics data. Clarity data is processed by Microsoft and accessed through the Clarity dashboard; we do not store raw Clarity session data on our servers.
2.3 Usage Data
We automatically collect:
- IP address
- Browser type and version
- Pages visited within the Portal
- Date and time of access
- Referring URL
2.4 Cookies
The Portal uses essential cookies for session management and authentication. We do not use third-party advertising cookies within the Portal.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing Analytics Services: Aggregating, calculating, and displaying performance metrics and reports from connected third-party platforms.
- Dashboard & Reporting: Generating visual dashboards, trend analyses, KPI summaries, and comparative reports across platforms.
- Account Management: Authenticating users, managing access permissions, and maintaining account security.
- Platform Synchronization: Periodically fetching updated data from connected platforms via APIs and webhooks to keep reports current.
- Notifications: Sending alerts about account status, synchronization errors, or significant metric changes.
- Service Improvement: Analyzing usage patterns to improve Portal functionality and user experience.
We do not use your data for:
- Selling to third parties
- Targeted advertising
- Profiling for purposes unrelated to our analytics services
- Training machine learning models
4. Legal Basis for Processing
We process personal data based on the following legal grounds:
- Contractual Necessity: Processing is necessary to fulfill our service agreement with you or your organization.
- Legitimate Interest: We have a legitimate interest in providing analytics and reporting services, maintaining platform security, and improving our services.
- Consent: Where required, we obtain your explicit consent before accessing third-party platform data via OAuth authorization flows.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share data in the following limited circumstances:
- Service Providers: We use Vercel (hosting), Supabase (database), and similar infrastructure providers to operate the Portal. These providers process data on our behalf under data processing agreements.
- Third-Party Platform APIs: Data is transmitted to and from connected platforms (Google, Meta, Shopify, Trendyol, etc.) solely to provide our analytics services. Each platform’s own privacy policy governs their handling of data.
- Legal Requirements: We may disclose information if required by law, regulation, legal process, or governmental request.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.
6. Data Storage and Security
6.1 Storage Location
Your data is stored on servers located in the European Union (EU) region, specifically:
- Database: Supabase (eu-central-1, Frankfurt, Germany)
- Application Hosting: Vercel (fra1, Frankfurt, Germany)
6.2 Security Measures
We implement the following security measures:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS).
- Encryption at Rest: Sensitive credentials (API keys, OAuth tokens, platform secrets) are encrypted using AES-256 encryption before storage.
- Access Controls: Role-based access control (RBAC) ensures users can only access data belonging to their own organization.
- Authentication: Passwords are hashed using industry-standard algorithms. Session tokens are securely managed.
- Regular Synchronization: Platform data is periodically synchronized and cached locally to minimize exposure to API credential usage.
6.3 OAuth Token Management
When you authorize access to Google services or other OAuth-based platforms:
- Access tokens and refresh tokens are encrypted (AES-256) before storage.
- Tokens are used exclusively to fetch authorized data on your behalf.
- You may revoke access at any time through the Portal or through the respective platform’s account settings (e.g., Google Account → Security → Third-party apps).
- Upon disconnection, stored tokens are immediately deleted from our database.
7. Data Retention
- Account Data: Retained for the duration of the service agreement. Upon account deletion or service termination, account data is deleted within 30 days.
- Analytics/Platform Data: Historical analytics data is retained for up to 12 months to enable trend analysis and year-over-year comparisons. Data older than 12 months may be archived or deleted.
- Raw API Response Data: Cached temporarily for debugging and accuracy purposes, typically retained for 90 days before automatic deletion.
- Logs: Access logs and error logs are retained for 90 days.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data, subject to legal retention obligations.
- Right to Restrict Processing: Request that we limit how we use your data.
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interest.
- Right to Withdraw Consent: Withdraw consent for data processing at any time, without affecting the lawfulness of prior processing.
- Right to Revoke Platform Access: Disconnect any connected platform at any time through the Portal settings, which immediately stops data collection from that platform and deletes stored credentials.
To exercise any of these rights, contact us at info@creativesdata.com.
9. Third-Party Platform Policies
The Portal integrates with third-party platforms, each governed by their own privacy policies. We encourage you to review them:
- Google: https://policies.google.com/privacy
- Meta (Facebook/Instagram): https://www.facebook.com/privacy/policy
- Shopify: https://www.shopify.com/legal/privacy
- Trendyol: https://www.trendyol.com/gizlilik
- Yemeksepeti: https://www.yemeksepeti.com/gizlilik-ilkeleri
- Getir: https://getir.com/en/privacy-policy
- Microsoft (Clarity): https://privacy.microsoft.com/en-us/privacystatement
Our access to data from these platforms is limited to the scopes and permissions you explicitly authorize. We adhere to each platform’s API terms of service and developer policies.
10. Google API Services User Data Policy
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide and improve the Portal’s analytics and reporting features.
- We do not transfer Google user data to third parties except as necessary to provide or improve the Portal, as required by law, or with explicit user consent.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data unless we have your affirmative agreement, it is necessary for security purposes, it is necessary to comply with applicable law, or our use is limited to internal operations and the data has been aggregated and anonymized.
11. International Data Transfers
If you are located outside the European Union, please note that your data is processed and stored in the EU (Frankfurt, Germany). We ensure that any international data transfers comply with applicable data protection laws, including the use of Standard Contractual Clauses (SCCs) or equivalent mechanisms where required.
12. Children’s Privacy
The Portal is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete such information.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated policy on this page and updating the “Last Updated” date. Your continued use of the Portal after changes are posted constitutes your acceptance of the revised policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Creatives Data Kadıköy, Istanbul, Turkey Email: contact@creativesdata.com Website: https://creativesdata.com