RiddleMarkt

Privacy & Data Protection Notice

Last updated: 06.10.2026

1. Data Controller

Your personal data is processed within the framework described below by Eaglessoft BV, operator of the RiddleMarkt brand (the "Data Controller"), under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the EU General Data Protection Regulation ("GDPR").

Adres / Address: Excelsiorlaan 31, 1930 Zaventem, België · E-posta / E-mail: info@eaglessoft.com · Tel: +32 456 73 59 66

The Turkish version of this notice is the authentic text; this English translation is provided for convenience.

2. Personal Data We Process

  • Identity and contact: full name (optional), e-mail address, phone number.
  • Account and security: an irreversible hash of your password (bcrypt), your Google account ID if you sign in with Google, session records, IP address, request logs, failed login attempts.
  • Customer activity: uploaded price lists, analysis results, favorites, settings; optionally entered bol.com Retailer API keys (stored encrypted) and the store/sales data retrieved with them.
  • Invoicing and subscription: billing name, address, VAT number if any, subscription and payment history.
  • Payments: payments are processed by the licensed payment institution Mollie. Card details such as card number, expiry date and CVC are never stored or logged on our systems; we keep only the customer and mandate reference numbers generated by Mollie.

3. Purposes of Processing

  • Concluding the membership agreement and providing the service (analyses, panel, data storage),
  • Managing subscriptions, charges and statutory invoicing,
  • Securing accounts and preventing abuse and unauthorized access,
  • Sending service-related notifications such as password resets and trial reminders,
  • Complying with legal obligations (tax and commercial law, responses to official requests),
  • Measuring and improving service quality (aggregated and anonymized usage statistics).

4. Legal Bases

We process your data based on: performance of a contract, compliance with legal obligations, establishment and protection of legal claims, and our legitimate interests provided your fundamental rights are not impaired (KVKK art. 5/2; GDPR art. 6). Where none of these apply, we ask for your explicit consent.

5. Cookies and Local Storage

The Platform uses only the session cookie strictly necessary for the service to work (an httpOnly cookie holding your sign-in state) and your theme/language preferences in browser local storage. No advertising or third-party tracking cookies are used.

6. Data Sharing

  • Mollie B.V. (Netherlands) — payment processing,
  • Google — authentication, only when you sign in with Google,
  • Hetzner Online GmbH (Germany) — server and database hosting,
  • E-mail delivery service (SMTP provider) — delivery of service notifications only,
  • Competent public authorities — only where required by law.

Servers are located within the European Union. Transfers that qualify as international transfers from a Turkish perspective are carried out in line with the KVKK transfer rules and the GDPR. Your data is never sold to third parties.

7. Retention

  • Account data: for the duration of the membership and a reasonable technical deletion window after account closure,
  • Invoicing and payment records: for the statutory retention periods under tax and commercial law (even if the account is deleted),
  • Security logs: for limited, rotating periods.

Expired data is deleted, destroyed or anonymized.

8. Your Rights

Under KVKK art. 11 (and GDPR arts. 15-22) you have the right to:

  • learn whether your data is processed and request information,
  • learn the purpose of processing and whether data is used accordingly,
  • request correction of incomplete or inaccurate data,
  • request erasure or destruction,
  • learn the third parties to whom data is transferred,
  • object to a result arising against you from analysis exclusively by automated systems,
  • claim compensation for damage caused by unlawful processing.

You can send your request to info@eaglessoft.com; requests are answered free of charge within 30 days at the latest. You may also lodge a complaint with the Turkish Personal Data Protection Board or the data protection authority of your place of residence.

9. Updates

This notice may be updated when necessary; the current version is always published on this page and material changes are announced to members.

10. Amazon Selling Partner Data

Riddlemarkt is developing an integration with the Amazon Selling Partner API. Connecting an Amazon seller account is not available yet. This section sets out the commitments that apply, from the moment the integration is in use, to any information obtained through the Selling Partner API on behalf of a seller ("Amazon data"). Details: Amazon integration.

  • Authorisation: the seller authorises Riddlemarkt on Amazon's own consent screen in Seller Central (OAuth / Login with Amazon). We never ask for the seller's Amazon password. Access can be revoked at any time in Seller Central (Manage Your Apps) or by disconnecting the store in Riddlemarkt.
  • Purpose limitation: Amazon data is used only to provide the service to the seller who authorised it. It is never sold, never shared with other customers, and never used to build aggregated datasets across sellers' accounts. Amazon data is not included in the aggregated usage statistics mentioned in section 3. Amazon data is not combined with, or used for, any other marketplace integration.
  • Security: credentials and tokens are stored encrypted with AES-256-GCM and data is transmitted over TLS; access is limited to authorised staff.
  • Location: Amazon data is stored in the European Union, on servers of Hetzner Online GmbH in Germany (see section 6).
  • Deletion: when the store is disconnected or the account is deleted, the seller's Amazon credentials and Amazon data are deleted within 30 days at the latest.
  • Buyer personal data: Riddlemarkt does not currently request Amazon buyer personal data (names, addresses). If a seller later enables shipping features that need it, that data is used only for fulfilment and tax purposes and is deleted or anonymised no later than 30 days after shipment.
  • Security incidents: a security incident involving Amazon data is reported to Amazon (security@amazon.com) within 24 hours, and to the affected sellers.
  • Requests: access and deletion requests concerning Amazon data can be sent to info@eaglessoft.com.

Riddlemarkt is an independent product; it is not affiliated with or endorsed by Amazon. Amazon and Seller Central are trademarks of Amazon.com, Inc. or its affiliates.