Document version: 1.0
Account and Membership Privacy Notice
Personal data processed for GrowShop accounts, authentication and account security.
This translation is provided for accessibility and remains outside search indexing until jurisdiction and international-transfer review is complete. The Turkish text remains the operative local version.
Open the Turkish versionData controller
Under KVKK, the data controller is DOMİNO AGRO TEKNOLOJİ DANIŞMANLIK İTHALAT İHRACAT LİMİTED ŞİRKETİ. MERSIS number: 0310153539500001. Trade-registry number: 269901. Registered address: Adalet Mah. Manas Bul. Folkart Towers No: 39 İç Kapı No: 3408 Bayraklı / İzmir. Contact: hello@dominoagro.com.
Account and security data
Email-link sign-in processes the email address. Google sign-in processes the Google account's stable user identifier, primary email address, display name and profile-photo URL when present. Both methods process the Firebase user ID, email-verification state, account role and status, and account creation and update times.
Sign-in and security operations may process IP address, request time, browser and device information, session cookie, failed actions, rate-limit records and security logs. Terms acceptance records include the document version and digest, acceptance time and source page. Notice-display records contain the version and digest, display time, source page and a user or temporary-session identifier without creating a consent record.
Google sign-in scope
The application requests no additional Google OAuth permissions. It uses only openid, email and profile to match the user to a unique account and receive the primary email and basic profile. It does not request access to contacts, Calendar, Drive, Gmail or any other Google service.
Purposes and legal grounds
Authentication, account creation, session establishment and account features rely on KVKK Article 5/2(c), necessity for contract formation or performance.
Abuse prevention, access security and investigation of errors or attacks rely on Article 5/2(f), legitimate interests that do not override fundamental rights. Responses to competent-authority requests rely on Article 5/2(ç), legal obligation.
Terms-acceptance and dispute records rely on Article 5/2(e), establishment, exercise or protection of a right. Notice-display evidence relies on Article 5/2(ç), proof of the transparency obligation. Displaying a notice is not acceptance or explicit consent.
Collection method
Data is collected electronically and automatically from the email field, Google OpenID Connect response, Firebase Authentication records, and HTTP request and security logs generated by the Vercel-hosted application. Notice-display and terms-acceptance records are created server-side during the sign-in flow.
Recipients
Google LLC and relevant Google Cloud/Firebase entities process email, basic profile, Firebase user ID, session and transaction data for Google authentication, Firebase Authentication and Firestore account and acceptance records.
Vercel Inc. processes IP, device, request, session and transaction data for hosting, server routes and security/access logs. Cloudflare Inc. processes IP, device, browser and challenge data when Turnstile is enabled. Email-link authentication in this version is sent through Firebase Authentication; no separate transactional-email provider is configured.
Public authorities and courts receive only the account or transaction records covered by a binding legal request. Data is not shared with advertising networks, data brokers, contacts, Calendar or Drive services.
International transfers
Google/Firebase, Vercel and Cloudflare may use systems outside Türkiye. A continuous transfer requires the applicable safeguard under KVKK Article 9, including a standard contract with the relevant overseas processor and notification to the Personal Data Protection Authority within the statutory period where required.
This code repository does not contain a signed standard contract or Authority notification record. The technical setup alone therefore does not prove completion of the KVKK international-transfer safeguard; the contracts and notifications remain an operational compliance requirement.
Retention
Firebase account and profile records are kept while the account remains open and are deleted from active systems within 30 days after an account-closure request is completed. Security and access logs are retained for 90 days; one-time sign-in-link and delivery records are retained for 30 days.
Terms acceptance, notice-display and dispute-evidence records are retained for 10 years after the account relationship ends. If a dispute or judicial or administrative review continues, only relevant records are retained until the process and statutory periods end, then deleted, destroyed or anonymised.
Rights and requests
Subject to KVKK Article 11, you may ask whether your data is processed; request information; learn the purpose and whether processing matches it; learn recipients in Türkiye or abroad; request correction, deletion or destruction and notification of those actions to recipients; object to an adverse result produced solely by automated analysis; and claim compensation for unlawful processing.
Send a request with sufficient identity-verification information to Adalet Mah. Manas Bul. Folkart Towers No: 39 İç Kapı No: 3408 Bayraklı / İzmir, from an email address previously supplied to GrowShop to hello@dominoagro.com, or through the site's privacy request form.
You can print this document using your browser's print command.