This Privacy Policy explains how Digitalcake ("we", "us") collects, uses and protects personal data when you use the BrightSync platform and this website. We keep it short, honest and in plain language — the same way we build the product.
Who we are
BrightSync is a B2B catalog synchronization platform operated by Digitalcake, based in Türkiye. For any privacy question or request, contact us at hello@brightsync.app.
What data we collect
We collect only what we need to run the service:
- Account data — name, business email address, company name and password (stored hashed) when you register.
- Catalog & integration data — product, price, stock and supplier data you connect to the platform. This is your business data; we process it solely to provide the sync service.
- Usage & log data — IP address, browser type, pages visited and actions performed, kept in technical logs for security and troubleshooting.
- Communication data — messages you send us via email or support channels.
Why we process it (legal bases)
- To provide the service you signed up for — performance of a contract.
- To secure the platform, prevent abuse and keep audit trails — legitimate interest.
- To send service notifications such as sync digests and health alerts — performance of a contract.
- To measure website usage with analytics cookies — only with your consent.
How long we keep it
Account data is kept for as long as your account is active and deleted or anonymized within 90 days of account closure. Sync activity logs are pruned automatically (change events after 30 days, run history after 90 days). Backups roll off within 35 days.
International transfers
Where data is processed outside your jurisdiction, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or equivalent mechanisms.
Your rights
Depending on your jurisdiction (including GDPR and KVKK), you have the right to:
- Access a copy of your personal data.
- Correct inaccurate data.
- Request deletion ("right to be forgotten").
- Restrict or object to processing.
- Receive your data in a portable format.
- Withdraw consent at any time (for consent-based processing such as analytics).
To exercise any of these rights, email hello@brightsync.app. We respond within 30 days.
Security
All traffic is encrypted in transit (TLS). Passwords are stored using strong one-way hashing. Access to production systems is limited to authorized personnel and every customer workspace is isolated in a multi-tenant architecture with role-based access control.
Changes to this policy
When we make material changes we will update the date at the top of this page and, for significant changes, notify account holders by email.