Privacy Policy
Effective date: 27 August 2026 · Version 1.1
This Privacy Policy (the "Policy") sets out how personal data is processed in connection with DropPanel (the "Service"), in accordance with Turkish Personal Data Protection Law no. 6698 ("KVKK") and, where applicable, the General Data Protection Regulation ("GDPR"). This Policy forms an integral part of the Terms of Service.
1. Data controller and contact
The Service, available at app.droppanel.net, is an application providing shipment tracking, accounting and returns management for Amazon sellers. All requests and enquiries relating to the data controller may be addressed to support@droppanel.net.
2. Definitions
- User: the natural or legal person holding an account in the Service.
- Account Data: data relating to the User's identity and account.
- Business Data: commercial records entered into the panel by the User, or collected by the panel on the User's behalf.
- Subprocessor: a third-party service provider that processes data in order for the Service to be delivered.
- Data Subject: the natural person whose personal data is processed.
3. Allocation of roles
The roles assumed by the parties in respect of data processed through the Service are as follows:
- In respect of Account Data (email address, account settings, support correspondence): DropPanel acts as the data controller.
- In respect of Business Data (orders, tracking numbers, sales and expense records, return records, customer messages): the User is the data controller and DropPanel acts solely as a data processor, on the User's instructions. Where Business Data contains personal data of the User's own customers, the obligation to inform those individuals and to establish a lawful basis for the processing rests with the User.
4. Categories of personal data processed
4.1. Account Data
- Email address and password. Passwords are stored solely as a cryptographic hash; they are never retained or displayed in plain text at any stage.
- A name and company name, where optionally provided by the User.
- Support correspondence and, where a callback is requested, the telephone number provided.
- Notification preferences together with the device push endpoint and timezone offset required to deliver notifications.
4.2. Business Data
- Order and shipment records: order number, product code (ASIN), tracking numbers, carrier information, shipment events, locations and delivery dates.
- Accounting records: sale amounts, costs, expenses and exchange-rate information.
- Return records: reason, amounts and, where entered by the User, the customer name and return label documents.
- Customer service records: customer messages transferred into the panel and replies.
- Reminders, notes, application settings and store definitions.
4.3. Marketing site (droppanel.net)
No cookies are used on the marketing site. Visit measurement is performed without storing IP addresses; only aggregated data such as page views, country-level location and time on page is retained. These records are not linked to any identified or identifiable person.
5. Purposes of processing and legal bases
Personal data is processed on the following legal bases, as set out in Article 5 of the KVKK and Article 6 of the GDPR:
| Purpose | Data category | Legal basis |
|---|---|---|
| Creation and administration of the account | Account Data | Performance of a contract |
| Delivery of the Service: shipment tracking, accounting calculations, returns management | Business Data | Performance of a contract |
| Delivery of notifications | Notification preferences and device endpoint | Performance of a contract; notifications may be disabled by the User at any time |
| Handling of support requests | Support correspondence, contact details | Performance of a contract |
| Ensuring security and continuity of the Service; prevention of misuse | Error and access logs | Legitimate interests |
| Compliance with statutory obligations | Relevant records | Legal obligation |
Personal data is not used for any purpose other than those stated in this Policy. Personal data is not sold, rented, used for advertising profiling, or shared with third parties for marketing purposes. Business Data is not used for DropPanel's own commercial purposes.
6. Method of collection
Personal data is collected by electronic means: through direct entry into the panel by the User, file uploads, retrieval of carrier tracking data by the panel on the User's behalf, and — where the User has granted authorisation — automated retrieval from connected third-party systems (see section 8).
7. Artificial intelligence components
The Service's artificial intelligence functions (event translation, status reports, decision suggestions, reply drafts and similar) are operated through a language model provider. In this context:
- Only the minimum data required by the relevant function is transmitted to the provider. In the majority of functions the order number, customer name and amounts are not transmitted; in the data correction function only the format pattern of a tracking number is sent, never the number itself.
- Where the message translation or reply drafting functions are used, the content of the message transferred into the panel by the User is sent to the provider for processing.
- Under the provider's terms of service such content is not used for model training; it may be retained by the provider only for a limited period and solely for abuse monitoring.
- Use of the artificial intelligence functions is not mandatory; each function operates only upon an explicit instruction from the User.
8. Amazon Selling Partner API integration
This section applies where the User connects an Amazon selling account to the Service. Unless this function is used, no Amazon data is processed in respect of the User.
- The connection is established through Amazon's official Selling Partner API with the User's explicit authorisation. Authorisation may be revoked by the User at any time through the Amazon account.
- The scope of access is limited to order and financial data (order number, product, amounts, dates, marketplace and Amazon fee lines). Access to buyer personal data such as buyer names or addresses is not requested. Should this scope be extended in future, this Policy will be updated in advance and Amazon's data protection requirements — including encryption in transit and at rest and restricted retention periods — will be applied in full.
- Amazon-sourced data is processed solely for the purpose of delivering the Service's functions to the User; it is not used for advertising or marketing purposes, is not shared with third parties, and is not sold.
- Authorisation credentials are stored exclusively server-side and are under no circumstances transmitted to the User's browser or to any other user.
- Upon termination of the connection or closure of the account, Amazon-sourced data is deleted within a reasonable period.
9. Storage location and security measures
- Server: live data and backups are held in a database hosted within the European Union (Frankfurt, Germany). Each account may access only its own data; this separation is enforced at the database layer through row-level security policies.
- User device: for performance and protection against data loss, the application retains a copy of the data in the User's browser storage. This copy is not transmitted off the device.
- User's own disk (optional): where the User selects a folder in Settings, automatic backup copies are written to that folder and remain entirely under the User's control.
- All data transfers are carried out over encrypted connections (TLS); the database is encrypted at rest. Access logs are maintained, permissions are limited on a least-privilege basis, and multi-factor authentication is applied to administrative access.
10. Subprocessors and international transfers
The following subprocessors are engaged in order to deliver the Service. Each receives only the data required for the function it performs:
| Subprocessor | Function | Location | Data transferred |
|---|---|---|---|
| Supabase | Database, authentication, backups | European Union (Frankfurt) | Account Data and Business Data |
| Vercel | Hosting and server functions | Functions executed in an EU region; global content delivery network | Request traffic (during processing) |
| TrackingMore | Collection of carrier tracking data | Outside Türkiye/EU | Tracking number and carrier information only; customer name, address and amounts are not transferred |
| Anthropic | Artificial intelligence functions | United States | The limited content described in section 7 |
Subprocessors may process the data solely for the purpose of providing services to DropPanel and within the scope of their contractual obligations. Beyond this, personal data is disclosed only upon a duly issued request from a competent public authority and strictly within the scope of that request.
As certain subprocessors are located abroad, personal data is transferred internationally. Such transfers are limited to the categories of recipients set out in the table above and are subject to data processing and confidentiality agreements concluded with each subprocessor.
11. Retention periods
- Account Data and Business Data are retained for as long as the account remains open.
- Backup copies are maintained in versioned form and are automatically thinned over time; their sole purpose is protection against data loss.
- Upon a request for account deletion, following identity verification, live data and server-side backup copies are deleted within 30 days.
- Records that must be retained under applicable legislation (such as commercial books and invoice records) fall outside this period and are retained for the statutory period, after which they are deleted, destroyed or anonymised.
- Copies held on the User's device and on the User's own disk remain under the User's control, and their deletion is the User's responsibility.
12. Automated decision-making and profiling
The Service does not carry out any decision based solely on automated processing that produces legal effects concerning the Data Subject or similarly significantly affects them. Artificial intelligence functions generate suggestions only; the decision is taken by the User and no suggestion is applied automatically. No profiling is carried out for marketing purposes.
13. Data subject rights and how to exercise them
Under Article 11 of the KVKK and, where applicable, Articles 15–22 of the GDPR, the Data Subject has the right to: ascertain whether their personal data is being processed and request information in that regard; learn the purpose of processing and whether the data is used in accordance with that purpose; be informed of third parties to whom the data is transferred domestically or abroad; request rectification of incomplete or inaccurate data; request erasure or destruction of the data; request that rectification, erasure or destruction be notified to third parties to whom the data has been transferred; object to any adverse outcome arising from analysis carried out solely by automated means; and claim compensation for damage suffered as a result of unlawful processing. Where the GDPR applies, the Data Subject additionally holds the rights to restriction of processing and to data portability.
Requests may be submitted from the email address registered on the account to support@droppanel.net, and must clearly state the requester's identity details and the subject of the request. Requests are handled free of charge as soon as practicable and in any event within thirty days; where the process entails additional cost, a fee within the tariff set by the competent authority may be charged. Where a request is refused or is not answered within the applicable period, the Data Subject is entitled to lodge a complaint with the Turkish Personal Data Protection Board or, where the GDPR applies, with the competent supervisory authority.
The User may in addition export all panel data at any time from the Settings section.
14. Cookies
No cookies are used in the application or on the marketing site. Session information in the application is held solely in the User's browser storage; this record is strictly necessary for the operation of the Service and serves no marketing or tracking purpose. No third-party advertising or tracking scripts are loaded.
15. Children's data
The Service is directed at businesses engaged in commercial activity and is not made available to persons under the age of eighteen. Personal data of persons under eighteen is not knowingly collected.
16. Merger, transfer and reorganisation
In the event of a transfer, merger or reorganisation of all or part of the business, personal data may be transferred provided that the level of protection set out in this Policy is maintained by the transferee. In such a case, the User will be informed in advance.
17. Personal data breach notification
Where personal data is unlawfully obtained by third parties, the Data Subject and the Turkish Personal Data Protection Board are notified as soon as practicable in accordance with Article 12 of the KVKK; where the GDPR applies, the competent supervisory authority is notified within 72 hours. DropPanel maintains a written incident response plan for this purpose. As no system can provide absolute security, any suspected incident should be reported without delay to support@droppanel.net.
18. Amendments to this Policy
Where this Policy is updated, it is published on this page with a revised effective date and version number. Changes materially affecting User rights are additionally announced within the application. The current version is always available at this address: support@droppanel.net