Privacy Policy 

Last Updated: September 25, 2025
Applies To: All visitors and customers worldwide

Controller / Company: Buy Fragrance Oil (Owner: İbrahim Halil Çakmaktaşı)
Registered Office: Istanbul, Turkey (full legal address available upon request)
Privacy Contact: support@buyfragranceoil.com (Subject: “Privacy Request”)

This Privacy Policy explains how we collect, use, share, secure, and retain personal data when you visit or purchase from our website. Read this together with our Cookies Policy and Customer Service Policy. If there is a conflict, the most protective document applies.


1) What Personal Data We Collect

  • Identifiers & Contact: name, email, phone, billing/shipping address.

  • Account & Authentication: login email, hashed password, order history.

  • Commercial Info: products viewed/purchased, wishlists, cart, invoices, support tickets.

  • Payment Info: processed by our providers (e.g., Stripe/iyzico/PayPal). We do not store full card numbers or CVV.

  • Technical/Usage: IP address, device/browser type, pages viewed, referral/UTM, cookie IDs, approximate location.

  • Communications: messages sent to Support/Billing/Help.

  • B2B/Wholesale: company name, tax/VAT ID, purchase and invoice data.

  • User-Generated Content: reviews/ratings/questions you submit.

We do not intentionally collect sensitive personal data (e.g., health, biometric, precise geolocation). If you believe such data was submitted, contact us to request deletion.


2) Why We Use Your Data (Purposes & Legal Bases)

  • Order & Delivery: process orders, payments, shipping, returns (contract performance; legitimate interests).

  • Customer Support: respond to queries and service issues (legitimate interests).

  • Fraud & Security: prevent fraud, secure checkout (legitimate interests; legal obligation).

  • Site Performance & Analytics: improve site, troubleshoot, measure usage (legitimate interests; consent where required).

  • Marketing & Personalization: newsletters, offers, on-site recommendations (consent where required; legitimate interests otherwise).

  • Legal & Tax Compliance: records, audits, responding to lawful requests (legal obligation; legitimate interests).


3) Cookies & Similar Technologies

We use essential cookies for core functions (cart, checkout, login) and optional cookies for analytics/ads. You can manage preferences via our banner or browser settings. Details (types, retention, third parties) are in our Cookies Policy.


4) Sharing Personal Data (Processors & Partners)

We share data with trusted providers under contract:

  • Payment processors: secure transaction handling.

  • Carriers & logistics: DHL/FedEx/UPS/PTT for delivery & tracking.

  • Analytics & ads: e.g., Google/Meta—only where consented.

  • IT/Security & Hosting/CDN: site operation, backups, anti-fraud.

We do not sell personal data. We do not share personal data for cross-context behavioral advertising where prohibited without the opt-out rights required by law.


5) International Transfers

Your data may be processed in countries outside your residence (e.g., TR/EU/US). Where required, we use Standard Contractual Clauses (SCCs) or other lawful safeguards.


6) Retention

We retain data only as long as necessary:

  • Orders, invoices, tax: up to 10 years (legal obligation).

  • Support communications: up to 3 years after resolution.

  • Marketing data: until you opt out or after 24 months of inactivity.

  • Analytics cookies: typically ≤24 months (see Cookies Policy).


7) Security

Checkout is SSL/TLS-encrypted. We apply least-privilege access, AVS/CVV checks, 3D Secure where available, and provider-side PCI DSS compliance. No method is 100% secure—please keep your credentials confidential and use strong passwords.


8) Your Rights

Depending on your location, you may have rights to access/port, correct, delete, object/restrict processing, withdraw consent, and opt-out of marketing (and, where applicable, the “sale” or “sharing” of personal information).

How to exercise your rights: Email support@buyfragranceoil.com with the subject “Privacy Request” and describe your request. We may need to verify your identity. We aim to respond within 30 days (GDPR/UK) or 45 days (CCPA/CPRA), extendable as permitted.


9) Children’s Privacy

Our site is not directed to children under 13 (or local equivalent). We do not knowingly collect their data. If you believe a child provided data, contact us to delete it.


10) Marketing, Preferences & GPC

You can unsubscribe from emails at any time (link in email footer) or contact us. Where applicable, we honor Global Privacy Control (GPC) signals for cookie-based marketing where legally required.


11) Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects without human review.


12) Region-Specific Addenda

GDPR / UK GDPR (EEA & UK)

  • Legal bases: Art. 6(1) (a) consent, (b) contract, (c) legal obligation, (f) legitimate interests.

  • Data subject rights: access, rectification, erasure, restriction, portability, objection, complaint to a supervisory authority.

  • Transfers: SCCs or other lawful mechanisms.

  • Marketing: opt-in where required; unsubscribe available at any time.

CCPA/CPRA (California) — “Notice at Collection”

Categories collected in the last 12 months: Identifiers (A), Customer records (B), Commercial info (D), Internet/usage (F), Geolocation (approximate) (G), Inferences (minimal, for on-site recommendations), Professional info (B2B) (I).
Purposes: see Sections 2–4.
Sold/Shared: We do not sell personal information. We do not share for cross-context behavioral advertising without required opt-out rights.
Retention: see Section 6.
Your CA rights: know/access, correct, delete, portability, opt-out of sale/share, limit use of sensitive PI (we do not purposefully process sensitive PI), non-discrimination.
Authorized agents: provide proof of authorization; we may also verify you directly.
Appeals (VA/CO/CT): If we decline your request, reply “Appeal” to our response; we review within 45 days.

Türkiye (KVKK)

Veri Sorumlusu: Buy Fragrance Oil (İstanbul, Türkiye).
KVKK m.11 hakları: işlenip işlenmediğini öğrenme, bilgi talebi, amacına uygun kullanımı öğrenme, aktarım yapılan üçüncü kişileri bilme, düzeltme/silme, itiraz, zarar tazmini talebi.
Başvuru: support@buyfragranceoil.com (Konu: “KVKK Başvuru”).


13) Links to Other Policies

  • Cookies Policy: /cookies-policy/

  • Personal Data Protection Policy: /personal-data-protection-policy/

  • Customer Service Policy: /customer-service-policy/

  • Delivery Terms: /delivery-terms/

  • Returns & Refunds: /shipping-returns/

  • Secure Payment: /secure-payment/


14) Changes to This Policy

We may update this Policy from time to time. Changes take effect upon posting with the revised “Last Updated” date above.

Contact:
Privacy requests & questions: support@buyfragranceoil.com
Billing data issues: billing@buyfragranceoil.com


(Optional) “Do Not Sell or Share” Link (US)

If you plan to run advertising cookies in the US, create a page at /do-not-sell-or-share-my-personal-information/ and link it in the footer and here.