What we collect and why, who we share it with, how long we keep it, and the rights you hold over your data.
Last updated: 11 August 2026
1. Scope
This policy explains our general approach to the processing of personal data collected through the Shark Electric website and dealer portal.
The disclosure obligation under article 10 of Personal Data Protection Law no. 6698 is met by a separate notice. A privacy policy does not replace that notice; the two should be read together.
2. Data We Collect
We ask only for the data needed to provide the service:
Account data: name, e-mail address, telephone number and an irreversible hash of your password
Dealership data: trade name, tax office and number, authorised contact, billing and delivery address
Order data: order contents, amount, invoice details, delivery address and current account movements
Payment data: payment method, transaction reference and result. Card number, expiry date and security code are never visible to us and are not stored
Technical data: IP address, browser information, request logs and session security events
3. Purposes of Processing
We process data to assess dealership applications, create and secure your account, receive and deliver orders, collect and reconcile payments, issue invoices and receipts, respond to support requests, meet legal obligations and protect the security of the service.
4. Legal Bases
Our processing relies on the formation and performance of a contract, express provision of law, compliance with a legal obligation, the establishment and exercise of a right, and legitimate interest. Where none of these applies, your explicit consent is obtained.
5. Cookies
The site uses strictly necessary cookies for session security, form security and your appearance preference. The names, purposes and lifetimes of the cookies used are listed in detail in the Cookie Policy.
6. Sharing with Third Parties
Your personal data is never sold or rented to third parties for marketing. It is shared only to the limited extent the service requires, with:
Payment institution and banks: to execute and reconcile card payments
Courier and freight companies: name, address and telephone so the consignment can be delivered
Accountants and audit service providers: for statutory books and records
Hosting and e-mail infrastructure providers: so the service can be delivered technically
Competent public authorities: within the scope of requests and obligations arising from legislation
7. Retention Periods
Invoice, order and payment records are kept for ten years under the Tax Procedure Law and the Turkish Commercial Code. Account and contact data are kept for as long as your membership continues and for the limitation period thereafter.
Security event records and technical request logs are kept for the reasonable period needed for security review. Once the periods expire, data is deleted, destroyed or anonymised.
8. Data Security
The principal technical and administrative measures we take are:
All traffic encrypted with TLS and strict security headers sent to the browser
Passwords stored as irreversible hashes, with no plaintext password held anywhere
Progressive account lockout on failed sign-in attempts and invalidation of sessions
Role-based access and recording of critical operations in a security event log
The payment page hosted by the payment institution so card data never enters our systems
9. Your Rights
You hold the rights listed in article 11 of the Law in relation to your personal data. Their scope and the application procedure are explained in detail in the Data Protection Notice.
10. Changes and Contact
This policy may be updated in line with changes in legislation or in our services. The current text is always published on this page and the date of last update is shown at the top.
Questions about this policy can be sent to the contact address below.