MeraFraud ("we", "us", "our") provides a fraud-detection API and dashboard for e-commerce businesses ("Merchants", "you"), and acts as the "veri sorumlusu" (data controller) under KVKK for the account and usage data described below. This policy explains what data we collect, why, and how it's handled — both about our Merchants and about the transactions Merchants send us to score.
Data controller contact details: [Legal company name, registered address, and Mersis/trade registry number to be added here before real customer data is processed]. Requests under this policy can be sent to hello@merafraud.com.
When you call our API, you send transaction-level signals to be scored — for example transaction amount, account age, device/payment novelty flags, and similar behavioral indicators. We do not require or intentionally collect full card numbers, CVV codes, or other regulated cardholder data (PCI scope) — Merchants must not submit such data to our API.
Under KVKK Article 5, we rely on the following legal bases rather than blanket consent for each use:
In this MVP, the underlying model is trained on synthetic data, not on live merchant transactions. If and when we introduce training on real merchant data, we will: (a) anonymize or aggregate signals wherever feasible, (b) not share one Merchant's raw transaction records with another Merchant, and (c) obtain your explicit consent ("açık rıza") before including your data in shared model training, rather than relying on an opt-out — consistent with KVKK's requirement that consent be freely given, specific, and informed. This section should be revisited and finalized with legal counsel before that capability ships.
Account and usage data is retained for as long as your account is active, plus a reasonable period afterward for legal, tax, and dispute-resolution purposes. You may request deletion of your account data by contacting us (see Contact page).
Tenant and API key data is stored in a managed PostgreSQL database accessed over an encrypted connection, rather than a local file. Before handling real customer data at scale, we still recommend an independent security review of access controls and encryption settings.
Some of our infrastructure providers — including our hosting provider (Render) and our transactional email provider (Resend) — process data on servers located outside Türkiye. Under KVKK Article 9, transferring personal data abroad requires either the data subject's explicit consent, an adequacy decision by the Personal Data Protection Board (Kurul) for that country, or an approved safeguard (such as a Kurul-approved undertaking or binding corporate rules). Until one of these bases is formally documented for each provider, real customer personal data should not be transferred through this infrastructure — this is a priority item for legal review before onboarding paying customers with real end-user data.
As a data subject ("ilgili kişi"), Article 11 of KVKK gives you the right to:
To exercise these rights, contact us using the details in Section 1 or the Contact page; depending on your jurisdiction (e.g. under GDPR), you may have additional or overlapping rights.
This dashboard and marketing site do not currently use third-party advertising cookies or trackers. The map component loads map tiles from third-party providers (Esri), which may log standard request metadata (e.g. IP address) per their own policies. If we introduce non-essential cookies later, we will provide a consent banner letting you accept or reject them, in line with KVKK guidance — essential cookies required for the site to function will remain non-optional.
The Data Controllers' Registry (VERBİS) registration requirement generally applies to data controllers with more than 50 employees, or annual balance sheet totals above the threshold set by the Personal Data Protection Board, among other criteria. As an early-stage company below these thresholds, MeraFraud is not currently required to register with VERBİS. We will monitor our headcount and balance sheet each year and register if and when a registration trigger is met.
We may update this policy as the product evolves. Material changes will be reflected with an updated "Last updated" date above.
Questions about this policy? Reach us at hello@merafraud.com or via our Contact page.