Privacy notice
How Specoria handles the personal data collected through specoria.com and app.specoria.com (the project panel), under Turkey’s Personal Data Protection Law No. 6698 and, where it applies, the EU General Data Protection Regulation (GDPR) and the UK GDPR.
1. Who is responsible for your data
Controller: Webtures Ltd (“Specoria”) · Address: 494a Fulham Road, London SW6 5NH, United Kingdom · Company no.: 11948574 (England and Wales) · Email: contact@specoria.com
This notice covers people who visit our site, fill in our forms, use our free tools, open a panel account or buy a plan. For this processing Specoria is the controller.
When we process data that our customers send or connect to us (server access logs, Google Analytics 4 / Search Console data, store and marketplace data) on their behalf and on their instructions, Specoria is a processor and our customer is the controller. The terms for that processing are in our Data Processing Addendum.
2. What we collect and how
We collect data through the electronic forms on the site and in the panel, your use of the panel, email correspondence, the APIs of services you connect, and the technical information your browser sends, by automated or partly automated means.
- Report form: first and last name, work email, company, job title, sector, optional store address; which version of this notice you acknowledged, your marketing preference and when; email delivery and download records.
- Readiness report and sign-up form: store address and email; your optional answer to “How did you hear about us?”.
- Deep audit report form (test result page) and simulator form: work email and store address; the version of this notice and your optional marketing preference. Your test score is matched from the most recent stored test result for your store address.
- Campaign tags and referring site: if you arrived through a link with campaign tags (utm_source, utm_medium, utm_campaign, utm_term, utm_content), those tags and the date, and if you came from another site, only that site’s domain (for example google.com, never the page address), are kept in your browser only, as your first and last visit. If you send a form, the campaign tags go to us with it and are stored with your request. When you use the free test, the simulator or the report form, and when an event reaches the cookieless counter below, the tags and domain are used only as the source in that count. They contain nothing that identifies you.
- Cookieless usage counting: to see in aggregate how the site is used, we count page views and a few events (for example a free test starting and its outcome, form submissions, clicks on the main buttons) with Cloudflare Workers Analytics Engine. Each record holds only the event name, the page path, the language, the referring site’s domain, campaign tags, the device type (mobile, tablet, desktop or bot), the country Cloudflare derives from the connection and, for test results, a 20-point score range and level instead of the score itself. Your IP address, your browser’s full identifier (User-Agent), your email, your store address and the tested domain are never written; no cookie or visitor ID is used, so records can’t be tied to a person or to each other.
- Cookieless site analytics (Cloudflare Web Analytics): to see how fast specoria.com pages load and how many visits they get in aggregate, we use Cloudflare Web Analytics. A small script on the page sends the page address, the referring site, the browser and device type and page load timings to Cloudflare; Cloudflare derives the country from the connection. It uses no cookies or browser storage, does not try to recognise visitors by fingerprinting and builds no per-visitor profile; we only see aggregate numbers.
- Free test: the server stores only the scanned store’s domain and the check results, nothing that identifies you. A copy of the result is also kept in your browser’s local storage so the page can show it.
- Deep audit and agent simulator: the email you leave in the form (and your name, if you gave it; to send the report), the store address and the task you write in the simulator; the results measured from your store’s public pages, the product sample and screenshots of the real-browser steps. The real-browser test never types personal details into your store’s forms, never places orders and never pays.
- Project panel account: name, email, a one-way hash of your password (never the password itself), your project memberships and roles; records of what you do in the panel (sign-ins, completed tasks, re-checks, plan views); the platform and return window you confirm; the company name, your role and the monthly order range you optionally add to your profile; the email addresses of teammates you invite; support requests, messages and documents you upload; password reset requests.
- Server access logs (agent traffic analysis): the IP address, browser identifier (User-Agent), time and address of each request in the logs you upload or (on paid plans) send continuously. The full IP address is read only in memory, to check whether a bot comes from its provider’s published IP ranges, and then cut to its network (IPv4 /24, IPv6 /48); for human visitors, IP addresses and browser identifiers are not stored, query strings are dropped, and raw logs are not kept. We process this data as a processor on our customer’s behalf.
- Google Analytics 4 and Search Console connection (optional): if you connect your Google account in the project panel, we read aggregate numbers from Google with read-only access (analytics.readonly, webmasters.readonly), and only from the property and site you select that match your domain: sessions from AI platforms, landing pages, key event and revenue totals; clicks and impressions per page and search query. No visitor-level data is read or stored. The refresh token Google issues is stored encrypted; we don’t ask for your Google account name or email address.
- Store, marketplace and notification connections (optional): if you connect your Shopify or WooCommerce store, your Trendyol or Hepsiburada seller account, or a Slack / Microsoft Teams notification address, the access keys are stored encrypted and product and listing data (title, price, stock, attributes) is read. Only changes you approve one by one are written to your store, and each can be undone. We don’t ask for your customers’ orders or personal data.
- Enterprise and agency call requests: the full name, work email, company, optional website, number of stores, platforms, note on your needs and preferred meeting time you leave in the form; the stage of the request in our sales process.
- Purchases: the plan and billing period you choose, your buyer type (business or consumer), the version of the contract documents you accepted and when, your request as a consumer for the service to start immediately, subscription status, customer and subscription numbers at Stripe, the details needed for invoicing; the phone, preferred time and note you leave in a call request. Your card details never reach Specoria; you enter them directly with Stripe.
- Technical data: we don’t store your IP address itself. Our hosting provider Cloudflare processes it briefly to prevent abuse (for example, per-minute attempt limits). For the agent simulator’s daily run limit, an irreversible salted hash of the IP address is stored with the simulation record.
We don’t ask for special categories of data (health, biometric data and the like); please don’t include them in forms or messages.
3. Why we use it and on what basis
- To prepare and send the report or readiness report you asked for and to answer your requests: performing a contract or taking steps at your request (Law No. 6698 art. 5/2-c; GDPR art. 6(1)(b)).
- To open your project panel account, provide the service and manage your subscription, including service emails (report ready, panel invitation, password reset, at most five trial emails with your project’s measured status and next step, subscription notices; these are not marketing; you can turn the trial emails off with the link in each one or in your panel settings): performing a contract (Law No. 6698 art. 5/2-c; GDPR art. 6(1)(b)).
- Invoicing, accounting and tax records, and the record-keeping duties of distance-selling and consumer law: legal obligations (Law No. 6698 art. 5/2-ç; GDPR art. 6(1)(c)).
- To keep the site, forms and panel secure and prevent abuse (including sign-in attempt limits and password reset records): our legitimate interests (Law No. 6698 art. 5/2-f; GDPR art. 6(1)(f)).
- To measure in aggregate which pages and tools are used and how fast pages load (cookieless usage counting and Cloudflare Web Analytics): the records don’t identify anyone; to the extent they could relate to a person, our legitimate interests (Law No. 6698 art. 5/2-f; GDPR art. 6(1)(f)).
- To keep consent, contract and delivery records: establishing or defending legal claims and meeting legal obligations (Law No. 6698 art. 5/2-e and 5/2-ç; GDPR art. 6(1)(c) and (f)).
- To send news, reports and event invitations: only with the separate consent you give in the form and then confirm by clicking the link in the email we send you (Law No. 6698 art. 5/1; GDPR art. 6(1)(a)), which is also your consent to commercial electronic messages under Turkish Law No. 6563 (consent text). If you don’t confirm, we don’t send these emails. You can withdraw consent at any time.
- Data we process on our customers’ behalf (server logs, Google data, store and marketplace data): as a processor, only on the customer’s instructions and under the Data Processing Addendum; the customer, as controller, determines the legal basis.
4. Who we share it with
We never sell your data and never use it to train AI models. We share it only with providers that process it on our instructions to run the service (subprocessors), with services you connect, and with authorities where the law requires:
- Cloudflare, Inc. (USA): hosting of the site and panel, database, file and backup storage, security; the bot check on our forms (Turnstile; your browser connects to Cloudflare during the check), the real browser used by audits and the simulator, cookieless usage counting (Workers Analytics Engine) and cookieless site analytics (Web Analytics). Data may be processed across Cloudflare’s global network.
- Resend (USA; emails are sent from its EU region in Ireland): sending report, confirmation, panel invitation, password reset and subscription emails.
- Stripe, Inc. and its affiliates (USA, Ireland): processing card payments, subscriptions and refunds; your email, name, billing and payment details go directly to Stripe. For some processing, such as fraud prevention and its own legal obligations, Stripe is a separate controller under its own privacy policy.
- OpenRouter, Inc. (USA) and AI model providers (Anthropic, OpenAI, Google, Perplexity): the models receive the measured site’s public page content, screenshots, measurement questions and the task you write in the simulator; never your name, email or account details. Every request to OpenRouter is sent with a setting (data_collection: deny) that routes it only to providers that, under the provider policies listed by OpenRouter, don’t collect prompts or use them for model training; if no provider qualifies, the request goes to no provider. This classification relies on the providers’ own policies, and some providers may keep requests for a limited time for abuse monitoring. When the simulator experimentally uses a provider’s own API, that provider’s API terms apply.
- Google LLC (USA), as a data source: only if you set up the Google Analytics 4 / Search Console connection in the project panel. You give consent on Google’s own screen, and we read the aggregate numbers listed above from Google. When you remove the connection in the panel, access is also revoked at Google.
- Services you connect: if you connect Shopify, WooCommerce, Trendyol, Hepsiburada, Slack or Microsoft Teams, data is exchanged with them only on your instructions and with your approval.
- Professional advisers and authorities: our accountants and lawyers, under confidentiality, as far as needed for invoicing and legal matters; public authorities and courts, on request and as far as the law requires.
The current list of subprocessors, the data they process and their locations is on our Subprocessors page.
5. International transfers
Sharing data with Cloudflare, Resend, Stripe, OpenRouter, AI model providers and Google transfers it outside Turkey. Under article 9 of Law No. 6698 and the Turkish regulation on transfers of personal data abroad, these transfers rely on an appropriate safeguard: the standard contracts announced by the Turkish Personal Data Protection Board, which are notified to the Board within five business days of signature. We make no regular transfer without an adequacy decision or an appropriate safeguard; explicit consent is asked only for the occasional transfers the law allows.
For users in the European Union: your data is collected directly by Specoria, established in Turkey; onward transfers to subprocessors rely on the EU-US Data Privacy Framework where the provider is certified and otherwise on the European Commission’s Standard Contractual Clauses. For the United Kingdom, the UK Addendum applies.
6. How long we keep it
- Report, readiness report and detailed report requests: up to 2 years from the request, after which they are deleted automatically.
- Deep audit and simulator: your email and name are deleted automatically 2 years after the audit; results measured from your store’s public data stay with the project.
- Project panel account: until you ask us to delete it or the account is closed. Password reset links are valid for 1 hour.
- Server access logs: raw logs are not kept; hourly summaries of continuously sent logs are deleted after 35 days; reports compiled from them stay with the project.
- Google, store, marketplace and notification connections: encrypted access keys and summaries are kept while the connection lasts. When you remove a connection, its keys are deleted; for Google, access is also revoked at Google and the summaries are deleted immediately.
- Subscription, contract acceptance and invoice records: 10 years, as Turkish tax and commercial law requires (which covers the minimum 3 years for pre-contract information and acceptance records under Turkish distance-selling rules); in a dispute, for the limitation period.
- Marketing preference and consent records: until you withdraw consent; after that, for 3 years from the end of the consent, as the Turkish regulation on commercial electronic messages requires.
- Cookieless usage counting: records are kept in Cloudflare Workers Analytics Engine for 3 months, after which Cloudflare deletes them automatically. Cloudflare Web Analytics data is kept only in aggregate, for the period Cloudflare applies.
- Backups: database backups are deleted after 56 days; a deleted record also leaves the backups at the end of that period.
- Data whose retention period has ended or whose purpose no longer applies is deleted in the next periodic deletion run (within 6 months at the latest), as Turkish law requires. If you ask us to delete your data, we’ll do so before then, except records we must keep by law.
7. Your rights and how to make a request
You can ask whether we process your data and get information and a copy of it, learn why we process it and who we have shared it with in Turkey or abroad, ask us to correct incomplete or inaccurate data, to delete it, and to tell those we shared it with, object to a result against you that comes solely from automated analysis, and claim compensation for damage caused by unlawful processing. If the GDPR applies to you, you also have the rights to data portability, to restrict processing and to object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time.
How to apply: send your request with your name, your nationality and an ID or passport number where needed, your postal address, your email if any and what you are asking for: in writing to 494a Fulham Road, London SW6 5NH, United Kingdom; signed with a secure electronic or mobile signature; or by email to contact@specoria.com from the email address you have already given us. We may ask for more information to confirm your identity.
We answer within 30 days, free of charge; if a request involves an extra cost, we may charge the fee set by the Turkish Personal Data Protection Board. If you are not satisfied, you can complain to the Turkish Personal Data Protection Authority or, if you are in the EU or the UK, to your local data protection authority.
8. Cookies and browser storage
We don’t use advertising, tracking or analytics cookies on the site or in the panel; cookieless usage counting and Cloudflare Web Analytics set no cookies. To remember the free test’s scan allowance, a sp_scan cookie (7 days) and local storage entries are kept in your browser; campaign tags are kept in a specoria.utm entry (90 days), in your browser only. The panel uses only cookies it needs to work: session (__Host-sc_session), device recognition (__Host-sc_device), language (__Host-sc_lang), Google connection check (__Host-sc_gstate) and a marker for what’s new in a project (sc_seen_…).
Because these cookies and storage entries are strictly necessary for the service you asked for, they don’t rely on your consent (Law No. 6698 art. 5/2-c and 5/2-f; for EU users, the strictly-necessary exemption of the ePrivacy rules). The full list with names, purposes and durations is in our Cookie policy.
9. Google user data
Specoria’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used only for the measurements and suggestions shown to you in the panel; it is not used for advertising, not sold, not read by people (except at your request, for security or where the law requires) and not used to train AI models.
10. Automated assessment, AI and changes
Store scores are computed by fixed, published rules; AI models are used only to test public pages. We make no decision based solely on automated processing that has legal or similarly significant effects on you.
We update this notice when the law or the service changes; each version is published on this page with its date and version number, and we email panel users about significant changes. Related documents: Terms of Service · Cookie policy · Data Processing Addendum.