Privacy Policy
Last updated: June 3, 2026
This Privacy Policy explains how ShopShot, operated by OPTIMIZE IT BİLİŞİM VE YAZILIM TEKNOLOJİLERİ LİMİTED ŞİRKETİ (“Optimize IT”, “we”, “us”) — the data controller — collects, uses, shares, and protects your personal data when you use the ShopShot website and product (the “Services”). As a company based in Türkiye, we process personal data under the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and, where it applies, the EU General Data Protection Regulation (“GDPR”).
What we collect
Account information — your email address and name. We use these to create your account, send magic-link sign-in emails, and contact you about your subscription. If you choose to sign in with Google, Google shares your basic profile (email and name) with us for that sign-in.
Profile information — optional details you give us during onboarding: company, industry, team size, and how you heard about us.
Your content — the product photos you upload and the shots we generate from them. Photos are stored on Cloudflare R2 and sent to our image-processing providers (listed below) for the sole purpose of producing the shots you request.
Subscription information — your plan, billing interval, subscription status, and credit history. Payments are handled by Dodo Payments as our Merchant of Record; we do not collect or store your card details — we only receive the email tied to the subscription and your plan/status.
Usage and device information — IP address, browser and device type, referring page, and how you interact with the Services. Collected via your session, server logs, and — only with your consent — analytics (see “Cookies and analytics” below).
Legal bases for processing
We rely on the following bases under GDPR (with the corresponding grounds under KVKK Arts. 5–6): performance of a contract to provide the Services (accounts, generating shots, billing); legitimate interests to keep the Services secure and to prevent abuse; your consent for non-essential analytics and session replay; and compliance with legal obligations such as tax and accounting record-keeping. You can withdraw consent at any time without affecting processing carried out before withdrawal.
How we use it
- Provide the Services — sign-in, dashboard, and shot generation.
- Process the shots you request through our image-processing providers.
- Manage subscriptions and credits (via Dodo Payments).
- Communicate with you about your account.
- Keep the Services secure and screen for fraud and abuse.
- With your consent, understand usage and improve the Services.
Who we share with
We share data with the following service providers (subprocessors) solely to operate the Services. Several are located outside Türkiye and the EEA (see “International transfers”).
- Dodo Payments (Merchant of Record) — subscription billing, invoicing, customer portal, and tax compliance. Receives your email and subscription data; holds your payment details. privacy · terms.
- fal.ai — AI image generation and background removal. Receives your uploaded product photos and prompts to produce the requested shot. terms.
- OpenRouter (routing to a Google Gemini vision model) — reads your product photo to extract on-label text so shots preserve it. privacy.
- Cloudflare — R2 object storage and CDN delivery of your uploads and shots. privacy.
- Google Workspace — delivery of transactional (magic-link) emails. privacy.
- PostHog (EU region) — product analytics and session replay. Only active after you consent (see below). privacy.
- Google Analytics — traffic analytics. privacy · opt out.
We may also disclose information to comply with applicable laws, respond to a lawful request from a public authority, or protect our rights, property, or safety.
AI providers
To create your shots, your uploaded photos are sent to the image-processing providers listed above only to fulfil the specific generation you request. We don’t sell or license your content. Each provider’s handling of your data is governed by its own terms and privacy policy, linked above; we encourage you to review them.
Cookies and analytics
Essential cookies keep you signed in and remember your preferences (including your analytics choice). These are necessary for the Services and are always on.
Analytics — we use PostHog and Google Analytics to understand how the Services are used. PostHog also records session replay — a reconstruction of your screen interactions (clicks, scrolls, navigation, and the content shown on your screen) — to help us spot and fix usability issues. What you type into form fields is masked (passwords always), but a replay can still capture personal data shown on the page, such as your name, email, and the product names and prompts you work with.
These are off by default. On your first visit we ask for consent via a banner. Until you accept, PostHog captures nothing (no events, no replay, no cookies) and Google Analytics sends only anonymous, cookieless signals. If you accept, you can change your mind at any time using the “Cookie preferences” link in the site footer.
International transfers
ShopShot is operated from Türkiye, and several of our providers are located outside Türkiye and the EEA, including in the United States. Where your personal data is transferred internationally, we take steps to ensure appropriate safeguards are in place as required by applicable data-protection law.
Data retention
We keep your account data and content for as long as your account is active. If you ask us to delete your account (see “Your rights”), we delete your personal data and content within 30 days, except where we must keep certain records longer — for example, billing and invoicing records held by Dodo Payments for tax compliance, and your credit transaction history, which we retain as a financial audit record.
Security
We use technical and organizational measures to protect your data, including encryption in transit, scoped access controls, and storage keys that bind your content to your account. No system is perfectly secure, but we work to protect your information and to limit access to it.
Your rights
You have the right to know whether we process your personal data and to request details about it; to learn the purpose of processing and the third parties (in Türkiye or abroad) to whom it is transferred; to request correction, erasure, or destruction; to have such changes passed on to those third parties; to object to decisions made solely by automated analysis; and to claim compensation for damage caused by unlawful processing (these rights are granted under the KVKK, Art. 11).
If you are in the EEA or UK, you also have the GDPR rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent.
To exercise any of these — including deleting your account and data — email [email protected]. You also have the right to lodge a complaint with the Turkish Data Protection Authority (KVKK Board) or, in the EEA/UK, your local supervisory authority.
Children
The Services are not directed at children. You must be at least 16 to use ShopShot, and we do not knowingly collect personal data from children.
Changes
We may update this Privacy Policy from time to time. The “Last updated” date above reflects the latest version; material changes will be communicated through the Services.
Contact
Questions about our privacy practices, or want to exercise a right? Email [email protected] or write to us at:
OPTIMIZE IT BİLİŞİM VE YAZILIM TEKNOLOJİLERİ LİMİTED ŞİRKETİ (Optimize IT)Maslak Mahallesi, Eski Büyükdere Caddesi, Giz 2000 Plaza,
Blok No: 7, Daire: 34, Sarıyer / İstanbul.
ZIP Code: 34398, Türkiye.