Complimentary delivery · 30-day returns · Secure checkout

Solfetti

Privacy Policy

This policy explains what personal data Solfetti collects when you visit or order from solfetti.com, why we collect it, who we share it with and what rights you have. We have tried to write it in plain language rather than legal shorthand.

1. Who is responsible for your data

The data controller is:

  • Remzi Kaan Çağlar, trading as Solfetti
  • Ölüdeniz Mahallesi, 210. Sokak No: 5, 48300 Fethiye / Muğla, Türkiye
  • Email: info@norogr.com
  • Telephone: +90 553 832 90 42
  • Tax number (VKN): 2180338857

For visitors in the European Union and the United Kingdom this policy follows the GDPR and the UK GDPR. For visitors in Türkiye it follows Law no. 6698 on the Protection of Personal Data (KVKK).

2. What we collect

When you place an order

  • Name, delivery address, billing address
  • Email address and telephone number
  • Order contents, order value and order history
  • Payment confirmation and the last four digits and brand of your card

We never see or store your full card number, expiry date or security code. Those go directly to the payment provider shown at checkout.

When you contact us

  • Your name, email address and the content of your message, so that we can answer it and keep a record of what was agreed

When you subscribe to emails

  • Your email address, the date you subscribed, and whether you opened or clicked our messages

When you simply browse

  • IP address, browser and device type, operating system, referring page
  • Pages viewed, products viewed, items added to the cart, time on site
  • Cookie identifiers (see section 5)

3. Why we use it, and on what legal basis

Purpose Legal basis
Taking payment, packing and shipping your order, sending order and delivery notifications Performance of the contract with you
Handling returns, refunds and warranty claims Performance of the contract; legal obligation
Answering your questions and complaints Performance of the contract; our legitimate interest in supporting customers
Keeping accounting and tax records Legal obligation under Turkish tax legislation
Preventing fraudulent orders and protecting the store Our legitimate interest in preventing fraud
Understanding how the site is used so we can improve it Consent, where consent is required for the cookies involved; otherwise our legitimate interest
Sending marketing emails Your consent, which you can withdraw at any time

4. Who we share it with

We do not sell your personal data. We share it only with the service providers we need in order to run the store, and only with what they need:

  • Shopify Inc. — the platform that hosts this store, processes orders and stores customer and order records on our behalf.
  • The payment provider shown at checkout — to take and verify your payment. It acts as its own controller for the payment data you enter.
  • Shipping carriers and our fulfilment partners — your name, delivery address, telephone number and email address, so the parcel can be delivered and you can track it.
  • Email and messaging providers — to send order confirmations, dispatch notifications and, if you have subscribed, marketing emails.
  • Public authorities — where we are legally required to disclose information, for example to tax or customs authorities.

5. Cookies

We use cookies and similar technologies for three things:

  • Strictly necessary — keeping your cart, keeping you signed in, remembering your language and currency, and protecting checkout against fraud. These cannot be switched off.
  • Analytics — counting visits and understanding which pages and products people look at, so we can improve the site.
  • Marketing — measuring whether an advert or an email led to a visit or an order.

Where the law requires consent, analytics and marketing cookies are only set after you have given it. You can change your choice at any time on the Your Privacy Choices page, or by clearing cookies in your browser.

6. Transfers outside your country

We are based in Türkiye and our platform provider operates from Canada and the United States. This means your data may be processed outside the European Economic Area, the United Kingdom or Türkiye. Where that happens, the transfer is protected by the appropriate safeguards — normally the European Commission's Standard Contractual Clauses agreed with the provider, and, for transfers from Türkiye, by your explicit consent or by the exceptions permitted under Article 9 of the KVKK.

7. How long we keep it

  • Order and invoice records: 10 years, as required by Turkish commercial and tax legislation.
  • Customer support messages: 3 years after the case is closed.
  • Marketing subscriptions: until you unsubscribe, and then a minimal record that you unsubscribed.
  • Analytics data: normally no longer than 14 months.

When a retention period ends, the data is deleted or irreversibly anonymised.

8. Your rights

Wherever you live, you can ask us to:

  • tell you what data we hold about you and give you a copy;
  • correct data that is wrong or incomplete;
  • delete your data, where we have no legal reason to keep it;
  • restrict or object to how we use it;
  • transfer your data to another provider in a machine-readable format;
  • withdraw your consent to marketing at any time, either by using the unsubscribe link in any email or by writing to us.

Write to info@norogr.com. We reply within 30 days at the latest, and free of charge.

If you are not satisfied with our answer, you can complain to the data protection authority in your country. In Türkiye this is the Personal Data Protection Authority (KVKK Kurumu, kvkk.gov.tr).

9. Children

This store is not intended for children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.

10. Security

The whole site runs over an encrypted HTTPS connection, payment data is handled by a PCI-DSS compliant provider, and access to the store's admin is limited to the people who need it and protected by two-factor authentication. No system is completely secure, but if a breach ever affected your data and put your rights at risk, we would notify you and the competent authority within the legal deadline.

11. Changes to this policy

We may update this policy as the store changes. The date below always tells you which version is current, and we will say clearly on this page if something significant has changed.

12. Contact

Questions about this policy or about your data: info@norogr.com, or Ölüdeniz Mahallesi, 210. Sokak No: 5, 48300 Fethiye / Muğla, Türkiye.

Last updated: 3 September 2026

A NORO GROUP COMPANY