Privacy Policy
This notice describes the data categories used by the current PICTAVA application and why they are needed.
This implementation-aligned draft requires qualified privacy counsel to finalize lawful bases, jurisdiction-specific rights, retention periods and the effective date before launch.
Controller & Contact
PICTAVA PRINTING SYSTEM YAVUZ SELIM DENIZ, registration number 2910706007, Istanbul, Turkey, is the disclosed controller for PICTAVA storefront data. Privacy requests can be sent to help@pictava.com or submitted through Contact.
Account
Registration stores name, email, password hash, phone and saved delivery address. Authentication may also use a configured identity provider.
Orders & Payments
Order configuration, contact and delivery details, price, currency, processor references and fulfillment status are stored. The active payment provider processes payment fields; PICTAVA does not intentionally store full card numbers or card security codes.
Payment Providers
When enabled, iyzico, PayPal or Stripe may receive payment, device, transaction, fraud-prevention and identifying information under their own privacy notices. Only providers actually shown at checkout are active for that transaction.
Uploads & Personalization
Customer images, design placement, mockup references and production identifiers are processed to preview, manufacture, deliver and support personalized products.
Cookies & Analytics
Essential storage supports login, cart, consent and security. If Analytics consent is granted, PICTAVA records first-party storefront events using an anonymous browser-session identifier. The analytics record excludes IP addresses, account identifiers, URL query strings and form data. Marketing tracking remains disabled unless separately consented to and configured.
Service Providers & Transfers
PICTAVA uses providers for authentication, payments, database hosting, printing, fulfillment and delivery. Launch review must document provider locations, contractual safeguards and international transfer mechanisms where required.
Retention
Order and transaction records may be retained for operational, accounting, fraud-prevention and legal obligations. A final retention schedule is required; uploads should be kept only for production and support needs.
Data Rights
Requests for access, correction, deletion, restriction, objection or portability can be submitted through Contact where applicable. Identity verification and legal exceptions may apply. The final notice must identify the controller and any regulator complaint right.
Security
Passwords are hashed and access should be limited to operational need. Security cannot be guaranteed absolutely. An incident-response process and effective date must be completed before launch.