Skip to content
Back to home

Privacy Policy

Last updated: July 9, 2026

This Privacy Policy explains how Digitalcake ("we", "us") collects, uses and protects personal data when you use the BrightSync platform and this website. We keep it short, honest and in plain language — the same way we build the product.

Who we are

BrightSync is a B2B catalog synchronization platform operated by Digitalcake, based in Türkiye. For any privacy question or request, contact us at hello@brightsync.app.

What data we collect

We collect only what we need to run the service:

  • Account data — name, business email address, company name and password (stored hashed) when you register.
  • Catalog & integration data — product, price, stock and supplier data you connect to the platform. This is your business data; we process it solely to provide the sync service.
  • Usage & log data — IP address, browser type, pages visited and actions performed, kept in technical logs for security and troubleshooting.
  • Communication data — messages you send us via email or support channels.

How long we keep it

Account data is kept for as long as your account is active and deleted or anonymized within 90 days of account closure. Sync activity logs are pruned automatically (change events after 30 days, run history after 90 days). Backups roll off within 35 days.

Who we share it with

We never sell personal data. We share data only with processors that are necessary to operate the service — hosting and infrastructure providers, transactional email delivery, and error monitoring — each bound by data processing agreements. Data may also be disclosed when the law requires it.

International transfers

Where data is processed outside your jurisdiction, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or equivalent mechanisms.

Your rights

Depending on your jurisdiction (including GDPR and KVKK), you have the right to:

  • Access a copy of your personal data.
  • Correct inaccurate data.
  • Request deletion ("right to be forgotten").
  • Restrict or object to processing.
  • Receive your data in a portable format.
  • Withdraw consent at any time (for consent-based processing such as analytics).

To exercise any of these rights, email hello@brightsync.app. We respond within 30 days.

Security

All traffic is encrypted in transit (TLS). Passwords are stored using strong one-way hashing. Access to production systems is limited to authorized personnel and every customer workspace is isolated in a multi-tenant architecture with role-based access control.

Changes to this policy

When we make material changes we will update the date at the top of this page and, for significant changes, notify account holders by email.