Privacy notice
Last updated:
This notice explains what personal data Sourcenia collects, why, how long it is kept, and how to exercise the rights that the KVKK in Türkiye and the GDPR in the European Union give you. It covers this website only. A supplier you contact through the site handles what you send it under its own policy, not ours.
Who is responsible
Sourcenia operates this site and decides why and how the personal data described below is processed. In the language of the law it is the data controller — veri sorumlusu under the KVKK (Law No. 6698), controller under the GDPR.
Requests about your data go to the address on the contact page, with Data request in the subject line.
What we collect
Account data. When someone registers: email address, name, the role chosen at registration and the registration date. Passwords are handled by our authentication provider and stored only as hashes; we never see them.
Company profile and product content. Everything a supplier fills in is meant to be public: company name, description, address, city and country, founding year, employee range, website, logo and cover image, and for each product its title, description, specifications, price and photographs.
Supplier contact channels. Telephone, WhatsApp and public email are stored apart from the profile and are never printed on the page. They are released only when a visitor asks for them, through a dedicated endpoint; the anonymous client that renders public pages has no permission to read them at all.
Quote requests. When a buyer asks a supplier for a quote we record the name, email address, telephone number where given, quantity, target price and message, together with the product or company it concerns, and a one-way hash of the sender's IP address used to rate-limit the form. This is delivered to the supplier so it can reply; from that moment the supplier is a controller of that copy in its own right.
Contact reveal events. When a visitor presses Show contact details we record which supplier and product was involved, which channel was revealed, the time, and a one-way hash of the visitor's IP address. The raw IP address is not stored. The hash exists to limit abuse and to count genuine interest for the supplier's dashboard, and it cannot be turned back into an address.
Product view counts. Opening a product page records that the product was viewed, with a one-way hash of your IP address and the time. The raw IP address is not stored. The hash is there for one reason: so that the same visitor reloading the same page within thirty minutes is counted once, and the view figure shown to the supplier means something. This happens on every product page, independently of the cookie banner, because it sets no cookie and reads nothing already on your device.
Technical data. Our hosting and database providers keep ordinary server logs — IP address, user agent, requested address, timestamp — for security and troubleshooting.
Cookies and similar technologies, described in their own section below.
Why we process it, and on what basis
- To provide what you asked for: showing a supplier's listing, delivering an enquiry to the company it was addressed to, keeping you signed in. Basis: performance of a contract — GDPR Art. 6(1)(b), KVKK Art. 5(2)(c).
- To keep the directory usable and honest: reviewing listings, preventing spam, abuse and automated harvesting, and counting contact reveals for the supplier whose details were shown. Basis: legitimate interests — GDPR Art. 6(1)(f), KVKK Art. 5(2)(f).
- To meet legal obligations, including answering lawful requests and keeping the records the law requires. Basis: legal obligation — GDPR Art. 6(1)(c), KVKK Art. 5(2)(ç).
- To show advertising. No advertising cookie is set today: the site carries no ad network yet, and a non-essential cookie is set only where the cookie banner has been accepted. Basis: consent — GDPR Art. 6(1)(a), KVKK Art. 5(1).
Where we rely on legitimate interests, we have weighed them against your interests and rights, and you can object at any time using the addresses below.
How long it is kept
- Account and company profile data: while the account exists, and for up to 12 months afterwards so that a closed account can be restored and any dispute settled.
- Published listings: while published, plus a short archive period after removal.
- Quote requests, including the IP hash: 24 months from the date sent, so a supplier can look back over a season's enquiries. The supplier's own copy is kept under the supplier's policy, not ours.
- Contact reveal records, including the IP hash: 12 months.
- Product view events, including the IP hash: 30 minutes — the length of the de-duplication window. Rows older than that are deleted as new views are recorded; only the total count remains, and a total is not personal data.
- Server and security logs: up to 12 months.
- Messages you send through the contact form, including the IP digest and any reply we send you: 24 months from the last message in the thread.
Where the law requires a longer period — accounting and tax records, for instance — that period applies instead. When a period ends, data is deleted or irreversibly anonymised.
Who else sees it
We do not sell personal data and we do not share it for anyone else's marketing.
- The supplier you contact. A quote request is delivered to the company it was addressed to, with the contact details you provided — that is the purpose of sending it.
- Supabase — database, authentication and file storage.
- Vercel — hosting and content delivery for the site itself.
- Google AdSense — planned for advertising, not yet integrated. When it is, it will run only where advertising cookies have been accepted, and for the data it collects through those cookies Google acts as an independent controller under its own policy.
These providers process data outside Türkiye and, in some cases, outside the European Economic Area. Transfers are made on the bases the KVKK and the GDPR provide for cross-border transfer, including standard contractual clauses.
We also disclose data where a court or a competent authority lawfully requires it. Where we are allowed to tell you about such a request, we do.
Cookies
Essential cookies are set without asking, because the site cannot work without them and none of them carries an advertising identifier:
- A language cookie (NEXT_LOCALE) so that the site opens in the language you last read it in. Kept for about a year.
- Session cookies from our authentication provider, with names beginning sb-, set only once you sign in. They keep you signed in and expire when the session ends or you sign out.
- The anti-spam check that guards the quote form and the Show contact details button is loaded from Cloudflare Turnstile and may store a short-lived value in your browser to record that the check was passed. It appears only on pages carrying one of those controls, and it is there to stop automated abuse, not to profile you.
Measurement and advertising cookies are set only if you accept them. A banner asks the first time you visit; until you answer, and for as long as your answer is Reject, none of them is set and no advertising script is loaded. Accept and Reject sit side by side, in the same size and the same colour: refusing costs exactly one click, like accepting.
Advertising is not live yet. Google AdSense is planned but not integrated, so at this moment no advertising script runs on any page — not even for a visitor who has accepted. If you have accepted, advertising cookies will begin to be set when AdSense goes live, within the consent you gave here and for the purpose described in it. If a future change would go beyond what this section describes, we raise the version of the consent record so that the banner asks again: a consent given today is not stretched to cover a wider purpose tomorrow.
Your answer is kept in your browser's local storage under the name sourcenia.consent.v1, not in a cookie — nothing at all is written for advertising or measurement before you decide. It holds the choice and the date it was made, stays on your device, is never sent to us, and remains until you change it or clear the site's data.
To change your mind, use the link at the end of this page: the banner reappears with the same text and shows your current choice. Rejecting after having accepted stops any further non-essential cookie from being set; anything already stored can be removed through your browser. Your browser can block or delete cookies at any point in any case. Blocking the essential ones signs you out and breaks the dashboard, while the directory itself works without a single optional cookie.
Your rights
Under the KVKK (Art. 11) and the GDPR (Art. 15–22) you may ask us to:
- confirm whether we hold data about you, and give you a copy of it;
- correct data that is wrong or incomplete;
- delete data we no longer have a reason to keep;
- restrict or stop processing that rests on our legitimate interests;
- hand your data over in a portable, machine-readable format;
- tell you to whom your data has been transferred, at home and abroad;
- object to a decision produced solely by automated analysis. We do not make decisions of that kind with legal effect.
Send the request to the address on the contact page. We answer within thirty days at the latest, and free of charge unless a request is manifestly excessive or repetitive. If we cannot identify you from the request we will ask for more detail — we would rather ask twice than hand your data to the wrong person.
If our answer does not satisfy you, you may complain to the Personal Data Protection Authority in Türkiye, or to the supervisory authority of the country in which you live if you are in the European Economic Area.
How it is protected
Data sits on managed infrastructure, and each part of the system is given only the access it needs. Database rules mean a supplier can read and change its own records and nothing else, while the anonymous client that renders public pages cannot read contact details at all — those come from a separate endpoint, one reveal at a time.
No system is beyond reach. If a breach ever affects your data and is likely to put your rights at risk, we notify you and the competent authority within the periods the law sets.
Children
This is a business-to-business site and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has sent us personal data, tell us and we will delete it.
Changes to this notice
This notice changes when the site changes or the law does. The date at the top of the page shows which version is in force, and a material change is announced on the site before it takes effect.