Privacy policy

PRIVACY & DATA PROTECTION POLICY

Last updated: August 23, 2026

GOGOLI respects your privacy and treats your personal information with care.

This Privacy & Data Protection Policy explains how personal information is collected, used, disclosed, stored, and protected when you visit the GOGOLI online store, place or manage an order, subscribe to communications, contact us, or otherwise interact with our services.

This policy is intended to provide transparent information. It is not a request for consent and does not, by itself, constitute consent to marketing, advertising cookies, or any other processing activity for which separate consent is legally required.

Where appropriate, shorter and activity-specific privacy notices may also be provided at the point where personal information is collected, including at checkout, through contact or custom-order forms, during newsletter registration, or through cookie and privacy-preference tools.

Those notices supplement this Policy and provide information specifically relevant to the activity concerned. Where a more specific notice applies to a particular processing activity, it should be read together with this Policy.

Consent, where legally required, will be requested separately from the provision of privacy information.

1. WHO WE ARE

The data controller responsible for the personal information described in this policy is:

Gönül Köseoğlu, trading as GOGOLI
Location: İstanbul, Türkiye
Email: gogolihandmade@gmail.com

In this policy, “GOGOLI,” “we,” “us,” and “our” refer to the person and business identified above.

Our store is hosted and powered by Shopify. Shopify provides the technical ecommerce platform through which the store operates. Depending on the relevant service and feature, Shopify may process personal information as our service provider or for purposes described in Shopify’s own privacy notices.

2. SCOPE OF THIS POLICY

This policy applies to personal information processed through:

The GOGOLI online store
Checkout, order, payment-confirmation, and delivery processes
Customer accounts, if enabled
Customer support and email communications
Contact, custom-order, and other inquiry forms
Newsletter or marketing sign-up forms
Returns, refunds, cancellations, and disputes
Fraud prevention, website security, and legal compliance
Cookie, analytics, and privacy-preference tools
Other services or features expressly linked to this Policy

An activity-specific notice may provide additional information concerning a particular form, feature, communication, or processing activity.

Third-party websites, social media platforms, payment services, and delivery companies may process personal information under their own privacy policies. GOGOLI does not control the independent privacy practices of those third parties.

3. PERSONAL INFORMATION WE COLLECT

The information we collect depends on how you interact with the store.

Information you provide directly

We may collect:

Your name and surname
Email address and telephone number
Billing and delivery addresses
Country or region
Order details, selected products, sizes, colours, materials, personalisation instructions, and other purchase preferences
Account details, preferences, and login information if customer accounts are enabled
Communications, photographs, documents, and other information you send in connection with an inquiry, return, damage claim, custom request, or dispute
Marketing and communication preferences
Information required to verify your identity when you exercise a privacy right

Please do not send sensitive personal information that is not necessary for your order or request.

Transaction and payment information

Payments are processed by Shopify, banks, card networks, and any payment provider made available at checkout.

GOGOLI may receive limited transaction information, such as:

Payment status
Transaction reference
Payment method type
Amount and currency
Fraud or verification status
Refund and chargeback information

GOGOLI does not ordinarily receive or store your complete payment-card number, card security code, or online-banking password.

Information collected automatically

When you visit or use the store, Shopify and authorised technologies may automatically collect:

Internet Protocol address
Browser and device type
Operating system
Language and approximate location
Pages viewed and links selected
Date, time, and duration of visits
Cart, checkout, and purchase interactions
Cookie identifiers and similar technical information
Security, error, and fraud-prevention signals

Non-essential analytics or advertising technologies will be used only where permitted by law and, where required, after the appropriate consent or privacy choice has been obtained.

Information received from service providers

We may receive information from:

Shopify
Payment providers and financial institutions
Delivery, postal, customs, and logistics providers
Email, hosting, security, and technical-service providers
Fraud-prevention and identity-verification providers
Analytics or advertising providers, where enabled and legally permitted
Professional advisers and public authorities, where legally required

We collect only information reasonably necessary for the relevant purpose.

4. PURPOSES AND LEGAL BASES FOR PROCESSING

We process personal information only where a lawful basis exists.

Depending on the circumstances and the law that applies, processing may be based on:

The performance of a contract or steps requested before entering into a contract
Compliance with a legal obligation
GOGOLI’s legitimate interests, provided that your fundamental rights and freedoms are not overridden
The establishment, exercise, or defence of legal claims
Your consent, where consent is required
Other legal grounds expressly permitted by applicable law

Processing orders and providing services

We use identity, contact, delivery, order, and transaction information to:

Receive and review orders
Confirm availability and production details
Produce, personalise, pack, and deliver products
Process payments, refunds, returns, and cancellations
Provide order and delivery updates
Respond to customer-service requests
Administer customer accounts, if enabled

The principal legal basis is the performance of the sales contract or steps taken at your request before a contract is formed.

Custom and personalised orders

Where you request personal measurements, personalised wording, special colour combinations, bespoke dimensions, or other individual specifications, we process those instructions to assess and fulfil your request.

Please provide only information necessary for the requested product. Do not provide health information or other sensitive data unless it is strictly necessary and we have expressly agreed to receive it.

Legal, tax, accounting, and regulatory compliance

We process and retain order, transaction, invoice, communication, refund, delivery, and identity information where necessary to:

Meet tax, accounting, consumer-protection, electronic-commerce, customs, and recordkeeping obligations
Respond to lawful requests from courts, regulators, tax authorities, customs authorities, law enforcement, or other authorised public bodies
Demonstrate compliance with applicable laws and contractual obligations

The legal basis is compliance with legal obligations and, where applicable, the establishment, exercise, or defence of legal rights.

Security, fraud prevention, and dispute management

We may process account, transaction, device, technical, communication, and delivery information to:

Protect the store, customers, and payment process
Detect or investigate suspected fraud, misuse, unauthorised transactions, or security incidents
Prevent chargeback abuse and policy violations
Verify order authenticity
Establish, exercise, or defend legal claims
Resolve complaints and disputes

The legal basis may be legal obligation, contractual necessity, or our legitimate interest in protecting the store, customers, and lawful business operations.

Customer communication

We use contact and order information to respond to questions and send necessary service communications, including:

Order confirmations
Production or fulfilment updates
Delivery information
Return and refund communications
Security notices
Policy or service changes that materially affect an order or account

These messages are transactional and may still be sent even when you do not subscribe to marketing.

Marketing communications

We send promotional emails or similar marketing communications only where:

You have actively subscribed or otherwise provided valid consent; or
Applicable law expressly permits the communication without separate consent

You may withdraw consent or unsubscribe at any time by using the unsubscribe link in the message or contacting us.

Withdrawing marketing consent does not affect previous lawful processing and does not prevent us from sending necessary order, account, security, or legal communications.

Analytics, store improvement, and advertising

Where enabled and legally permitted, we may process technical, device, browsing, interaction, purchase, and preference information to:

Understand how visitors use the store
Measure website performance
Identify technical problems
Improve navigation, products, content, and customer experience
Measure the effectiveness of communications or campaigns
Prevent fraud and misuse
Provide or measure personalised advertising, where the required consent or privacy choice has been obtained

The legal basis may be consent or legitimate interests, depending on the relevant technology, purpose, jurisdiction, and rights of the individual.

Non-essential advertising, analytics, or personalisation technologies will not be treated as strictly necessary merely because they may benefit the store.

5. COOKIES AND SIMILAR TECHNOLOGIES

The store may use cookies, pixels, local storage, software development kits, tags, and similar technologies.

These technologies may be used for:

Essential store operation
Cart and checkout functions
Security and fraud prevention
Remembering preferences
Measuring website performance
Analytics
Marketing and advertising, if enabled
Managing privacy choices
Supporting enabled Shopify features

Strictly necessary technologies may operate without consent where legally permitted because the store cannot function securely without them.

Non-essential analytics, personalisation, or advertising technologies will be controlled through the available cookie banner or privacy settings where consent or an opt-out right is legally required.

Where Shopify Network Intelligence, advertising integrations, social-media pixels, analytics services, remarketing tools, or similar features are enabled, information concerning browsing, device, cart, checkout, or purchase activity may be processed by Shopify or the relevant provider in accordance with the store’s configuration, applicable law, and the provider’s own privacy terms.

In some jurisdictions, particular disclosures or uses of identifiers, device information, browsing activity, or purchase information for targeted or cross-context behavioural advertising may be legally described as the “sale,” “sharing,” or use of personal information for targeted advertising, even where no money is paid for the information.

Where such laws apply and the relevant processing is enabled, we will provide the consent, rejection, opt-out, or privacy-preference mechanism required by applicable law.

Further information will be provided in the GOGOLI Cookie Policy and privacy-preference tools.

6. HOW WE DISCLOSE PERSONAL INFORMATION

We do not sell personal information for money.

We do not rent personal information.

As explained above, some laws may define certain advertising-related disclosures or uses as a “sale” or “sharing” even where no money is exchanged. Where such processing is enabled and the law applies, the relevant disclosure and privacy choice will be provided.

We may otherwise disclose personal information only where reasonably necessary and legally permitted.

Shopify

Information submitted through the store is processed through Shopify’s ecommerce infrastructure.

Shopify may process information to:

Host and operate the store
Operate checkout
Provide security
Prevent fraud
Support customer accounts
Process customer privacy requests
Improve or provide platform services
Support enabled analytics, advertising, or network features
Provide other enabled ecommerce functions

Depending on the relevant service, configuration, and legal relationship, Shopify may process personal information as a processor, service provider, contractor, or independent controller for purposes described in its own privacy notices and contractual terms.

Payment providers and financial institutions

Identity, order, billing, and transaction information may be shared with payment providers, banks, card networks, anti-fraud services, and financial institutions to:

Authorise payments
Authenticate transactions
Issue refunds
Handle disputes and chargebacks
Prevent fraud
Comply with financial regulations

Delivery and customs providers

Your name, address, telephone number, email address, order information, parcel value, product description, country of origin, and other required information may be disclosed to postal services, couriers, logistics companies, customs representatives, and customs authorities for delivery and international clearance.

Technical, analytics, advertising, and professional service providers

We may use carefully selected providers for:

Website hosting and ecommerce functions
Email and customer communications
Data storage and cybersecurity
Fraud prevention and technical support
Analytics and performance measurement
Consent and privacy-preference management
Advertising and campaign measurement, where enabled
Accounting, legal, insurance, or professional advice

These providers may use personal information only for authorised purposes and subject to the applicable contractual, technical, organisational, and legal protections.

Advertising-related providers will receive or process personal information only where the relevant feature is enabled and the processing is legally permitted.

Public authorities and legal proceedings

Information may be disclosed where necessary to:

Comply with law, court orders, regulatory requests, or lawful investigations
Protect the rights, safety, property, and security of GOGOLI, customers, or others
Prevent or investigate fraud or illegal activity
Establish, exercise, or defend legal claims

Business restructuring

If GOGOLI is reorganised, transferred, or sold, relevant information may be disclosed to professional advisers and a potential successor only where legally permitted and subject to appropriate confidentiality and data-protection safeguards.

7. INTERNATIONAL DATA TRANSFERS

GOGOLI is based in Türkiye, while Shopify and some service providers may operate, store data, access data, or provide support from other countries.

As a result, personal information may be transferred to and processed in a country different from your country of residence.

The laws and protections applicable in the receiving country may differ from those in your country.

Where international-transfer rules apply, GOGOLI will take the steps required by applicable law before relying on the relevant transfer arrangement.

Depending on the applicable law, the recipient, the countries involved, and the arrangements actually available, a lawful transfer mechanism may include:

A legally recognised adequacy decision
Standard contractual clauses, standard contracts, or another form of approved contractual safeguard
Binding corporate rules
Another legally recognised appropriate safeguard
A limited statutory exception, where legally available
Another transfer mechanism expressly permitted by applicable law

The inclusion of a possible transfer mechanism in this Policy does not mean that every listed mechanism is used for every transfer.

GOGOLI will rely only on a transfer mechanism that is available, appropriate, and implemented as required for the relevant transfer.

Where Turkish data-protection law applies, transfers abroad will be handled in accordance with Article 9 of Law No. 6698 and the applicable secondary legislation.

Where European Economic Area or United Kingdom law applies, recognised transfer safeguards will be used where required.

Where reasonably required by applicable law, supplementary technical, contractual, or organisational measures may also be considered in light of the nature of the information, the recipient, and the destination.

You may contact us for further information about the categories of international transfer safeguards applicable to your personal information. The disclosure of contractual or security information may be limited where necessary to protect confidentiality, security, trade secrets, another person’s rights, or a legal obligation.

8. DATA RETENTION

We retain personal information only for as long as reasonably necessary for the purposes described in this policy.

Retention periods depend on:

The status and duration of the customer relationship
The type of order, request, or dispute
Tax, accounting, consumer, ecommerce, and customs requirements
Fraud-prevention and security needs
Limitation periods and legal claims
Instructions or requirements imposed by authorised public bodies

Order, transaction, invoice, payment-confirmation, delivery, and related legal records are generally retained for at least the period required by Turkish recordkeeping rules, which may be five years or longer where another legal obligation, dispute, investigation, or claim applies.

Marketing-subscription information is retained until you unsubscribe or the information is no longer necessary, subject to records we may keep to demonstrate that an opt-out request has been honoured.

Records of consent, withdrawal, objection, cookie preferences, or other privacy choices may be retained where reasonably necessary to demonstrate compliance and respect the choice concerned.

Information associated with a complaint, chargeback, fraud inquiry, legal claim, or regulatory investigation may be retained until the matter and any applicable limitation or review period have ended.

When information is no longer required, it will be deleted, destroyed, anonymised, or otherwise handled in accordance with applicable law and technical capabilities.

9. DATA SECURITY

We use reasonable technical and organisational measures designed to protect personal information against:

Unauthorised access
Accidental loss
Improper disclosure
Alteration
Misuse
Destruction

These measures may include:

Access controls
Account-security settings
Multi-factor authentication where available and appropriate
Reputable service providers
Secure payment processing
Restricted access
Appropriate record-management practices
Security monitoring
Fraud-prevention measures
Back-up and recovery arrangements where appropriate

No online transmission or storage system can be guaranteed to be completely secure.

Please do not send payment-card details, account passwords, identity documents, or other sensitive information through ordinary email unless specifically requested through an appropriate secure process.

You are responsible for maintaining the confidentiality of your account credentials and for taking reasonable steps to protect devices and email accounts used to access the store.

If you believe that your account, communication, or personal information may have been compromised in connection with GOGOLI, please contact us promptly.

10. CHILDREN’S PRIVACY

The store is intended for adults and is not directed to children.

We do not knowingly collect personal information directly from children under 18 or below the age at which they may independently enter into the relevant transaction under applicable law.

A parent or legal guardian who believes that a child has provided personal information may contact us to request review and, where appropriate, deletion.

Where a product is purchased by an adult for a child, information about the child should not be provided unless it is reasonably necessary for the order and legally permitted.

11. AUTOMATED DECISION-MAKING

At the date of this Policy, GOGOLI does not itself ordinarily make decisions based solely on automated processing that produce legal or similarly significant effects on customers.

Shopify, payment providers, banks, card networks, fraud-prevention services, identity-verification providers, and security providers may use automated tools to:

Assess transaction risk
Authenticate a payment
Identify suspected fraud
Verify identity or account information
Protect their systems
Select transactions for review
Delay, decline, block, or otherwise restrict a transaction
Apply other security or regulatory controls

Depending on the provider, configuration, and circumstances, an automated assessment may contribute to or result in a payment being delayed, declined, referred for review, or otherwise restricted.

GOGOLI may not control, receive, or have access to every factor, score, model, or rule used by an independent provider.

Where GOGOLI receives sufficient information and is legally and technically able to do so, we may review relevant order information and contact the customer for additional verification.

GOGOLI is not required to override a lawful payment, security, sanctions, fraud-prevention, or regulatory decision made by an independent provider where we have no authority or reasonable basis to do so.

Where applicable law provides rights concerning automated decision-making, those rights remain available.

Where a decision producing legal or similarly significant effects is made solely by automated means and the applicable law grants the relevant right, you may be entitled to:

Request information about the decision
Request human intervention
Express your point of view
Contest the decision
Request review or correction of relevant inaccurate information

Any request will be considered subject to applicable law, security requirements, the rights of others, and the information and authority available to GOGOLI.

12. YOUR PRIVACY RIGHTS

Your rights depend on your location and the law that applies. They are not absolute and may be subject to lawful exceptions.

You may have the right to:

Learn whether your personal information is processed
Request information about processing
Access or obtain a copy of your personal information
Request correction of incomplete or inaccurate information
Request deletion, destruction, or erasure where legal conditions are met
Request restriction of processing
Object to certain processing based on legitimate interests
Object to direct marketing
Withdraw consent at any time where processing relies on consent
Request data portability where legally applicable
Learn the recipients or categories of recipients to whom information has been disclosed
Request notification of certain corrections or deletions to recipients
Object to an adverse result arising exclusively from automated analysis
Request compensation where unlawful processing causes damage and the law provides such a remedy
Lodge a complaint with the competent data-protection authority
Exercise an applicable right to opt out of the sale, sharing, or use of personal information for targeted advertising
Request information concerning applicable international-transfer safeguards where the law provides such a right

We may request information reasonably necessary to verify your identity and protect personal information from unauthorised disclosure.

We may also request evidence that an authorised agent is legally permitted to act on your behalf.

We will respond within the period required by applicable law. Requests under Turkish data-protection law will be concluded as soon as possible and no later than 30 days, subject to the conditions and exceptions provided by law.

A request may be refused or limited where necessary to:

Protect another person’s rights
Comply with a legal obligation
Preserve legally required records
Prevent or investigate fraud
Protect security
Protect confidential commercial information
Establish, exercise, or defend legal claims
Comply with another lawful exception

Where required, the reason will be explained.

We will not discriminate unlawfully against you merely because you exercise a privacy right.

13. RIGHTS UNDER TURKISH DATA-PROTECTION LAW

Where Law No. 6698 on the Protection of Personal Data applies, Gönül Köseoğlu, operating under the name GOGOLI, acts as the data controller.

Personal information may be collected electronically through:

The online store
Checkout
Customer accounts
Emails
Contact and custom-order forms
Newsletter forms
Cookies and similar technologies
Service providers
Payment providers
Delivery processes
Customer communications

Depending on the relevant processing activity, the legal grounds may include:

Processing necessary for the establishment or performance of a contract
Processing expressly provided for by law
Processing necessary for compliance with a legal obligation
Processing necessary for the establishment, exercise, or protection of a right
Processing necessary for our legitimate interests, provided that your fundamental rights and freedoms are not harmed
Your explicit consent, only where legally required

An activity-specific privacy notice may identify the particular categories, purposes, recipients, collection method, and legal grounds relevant to the form or process concerned.

Under Article 11 of Law No. 6698, requests concerning your personal information may be submitted through one of the methods recognised by applicable law, including:

  • By using an email address that you previously provided to GOGOLI and that is recorded in our systems, sent to gogolihandmade@gmail.com
  • By registered electronic mail (KEP), secure electronic signature, mobile signature, or another legally recognised electronic method. GOGOLI's registered KEP details are available on our Contact Information page.
  • By another method recognised under applicable legislation.

General questions may be sent to gogolihandmade@gmail.com from any email address.

However, an email that does not satisfy the legally prescribed application method and identification requirements may not be treated as a formal application under Article 11.

Please write “Personal Data Request / KVKK Başvurusu” in the subject line.

To allow us to identify you, understand your request, and respond securely, your application must contain the information required by applicable law, including:

Your name and surname
Your signature, where the application is submitted in writing
Your Turkish identity number, if you are a Turkish citizen; or your nationality, passport number, or identification number, if you are not a Turkish citizen
Your residential or business address for formal notifications
Your email address, telephone number, and fax number, where available
A clear description of your request
Any information or documents reasonably necessary to support the request

Please do not send a copy of your identity document or other unnecessary sensitive information by ordinary email unless we specifically request it through an appropriate secure method.

We may request additional information reasonably necessary to verify your identity, authority, or relationship with the relevant personal information.

We may refrain from disclosing, deleting, correcting, or transferring personal information until adequate verification has been completed. This measure is intended to protect personal information against unauthorised access or disclosure.

Applications will be concluded as soon as reasonably possible and no later than 30 days, as required by applicable law.

Applications are generally processed free of charge. If processing the request creates an additional cost, a fee may be charged only in accordance with the tariff determined by the Turkish Personal Data Protection Board.

We may accept the request or reject it by providing the legally required reasons.

Our response may be provided in writing or electronically, using a method appropriate to the application and the security of the information concerned.

If your application is rejected, you consider the response insufficient, or no response is provided within the legal period, you may lodge a complaint with the Turkish Personal Data Protection Board within 30 days after learning of our response and, in all cases, within 60 days from the date of your application, subject to the applicable procedures and legal requirements.


14. RIGHTS IN THE EUROPEAN ECONOMIC AREA AND UNITED KINGDOM

Where the EU GDPR or UK GDPR applies, you may have rights including:

Access
Rectification
Erasure
Restriction
Data portability
Objection
Withdrawal of consent
Complaint to your local supervisory authority
Information concerning applicable international-transfer safeguards
Protection concerning certain solely automated decisions

Where processing is based on legitimate interests, you may object based on your particular situation.

You have an unconditional right to object to direct marketing.

Where processing is based on consent, withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

Where applicable, you may lodge a complaint with the data-protection supervisory authority in the country or territory where you live, work, or believe that a data-protection infringement occurred.

EEA and United Kingdom representatives

Where applicable law requires GOGOLI to appoint a data-protection representative in the European Economic Area or the United Kingdom, the representative will be separately authorised in writing and the representative’s name and contact information will be added to this Policy or otherwise made readily accessible as required by law.

No third party is authorised to represent GOGOLI for EU GDPR or UK GDPR purposes merely because that person provides another service to GOGOLI.

In particular, a person appointed as an economic operator, authorised representative, responsible person, contact person, or other product-safety representative under the General Product Safety Regulation — GPSR, or another product law, does not automatically act as GOGOLI’s data-protection representative.

A separate written appointment is required where a data-protection representative must be appointed.

Where no representative details are published, this must not be interpreted as appointing any customer, service provider, delivery provider, GPSR responsible person, social-media platform, or other third party as GOGOLI’s data-protection representative.

For product-safety information and relevant product-safety contact details, please review our GPSR Product Safety Information page.

15. THIRD-PARTY LINKS AND SOCIAL MEDIA

The store may contain links to:

Social-media pages
Delivery services
Payment services
Privacy tools
Product-safety information
Other third-party websites or services

Opening or interacting with a third-party service may allow that third party to collect information independently.

Please review the third party’s privacy and cookie notices before providing information.

The inclusion of a link does not mean that GOGOLI controls or accepts responsibility for that third party’s privacy, security, content, availability, or practices.

Information that you publicly disclose on a third-party platform may be visible to other users and processed according to that platform’s rules.

Please do not publish order numbers, addresses, telephone numbers, payment information, identity documents, or other confidential information in a public social-media comment.

16. CHANGES TO THIS POLICY

We may update this policy to reflect:

Changes in the store or services
New service providers or technologies
Changes in legal or regulatory requirements
Security or operational developments
Changes in enabled analytics, advertising, or Shopify features
Changes in international-transfer arrangements
Changes in applicable privacy rights or procedures

The revised policy will be published with an updated revision date.

Where a change materially affects your rights or the way personal information is used, additional notice or consent will be provided where required by law.

A revised Policy will not retrospectively make unlawful processing lawful or remove a right that applied when the relevant processing occurred.

Previous versions may be retained where reasonably necessary to demonstrate the information and terms applicable at a particular time.

17. CONTACT

For questions about this policy, the use of your personal information, or the exercise of a privacy right, contact:

GOGOLI
Data controller: Gönül Köseoğlu, trading as GOGOLI
Email: gogolihandmade@gmail.com
Location: İstanbul, Türkiye

Formal requests under Turkish data-protection law should be submitted through one of the legally recognised methods described in Section 13.

Where an EEA or United Kingdom data-protection representative is legally required and appointed, the representative’s contact information will be added to this Policy or otherwise made readily accessible.

Please do not send complete payment-card details, passwords, or unnecessary identity documents by ordinary email.