Last updated: 27 July 2026
Privacy Policy
Seller / data controller details
- Trade name
- Vesta Vision
- Brand / product
- VestaQR
- Registered address
- Esentepe Mah. Akademiyolu Sk. Teknoloji Geliştirme Bölgeleri, Serdivan / Sakarya, Türkiye
- Tax office
- Gümrükönü
- Tax ID
- 5421197118
- [email protected]
- KEP (registered email)
- [email protected]
- Website
- https://vestavision.io
1. Purpose and scope
This Privacy Policy describes how Vesta Vision (“Company”, “we”) processes personal data via the VestaQR website, account console, and related services, in line with Türkiye’s Personal Data Protection Law No. 6698 (“KVKK”) and other applicable rules.
By accepting this policy or using the service, you acknowledge the processing described here. We may update this policy; the current version is published on this page.
2. Data controller
Data controller: Vesta Vision. Address, tax, and contact details appear in the company identity block above. For KVKK requests, email [email protected].
3. Personal data we process
- Account data: name, email, password (hashed), organization name, language and theme preferences.
- Billing and subscription: selected plan, billing period, payment status; sensitive card data is not stored on Company servers.
- Business content: menus, products, images, 3D models, and branding tied to your account.
- Technical and usage data: IP address (security and logs), browser type, device info, session identifiers, error logs.
- Contact forms: name, email, phone (optional), message content.
- Guest menu interactions: first-party analytics where practicable (e.g. visits, product views); no advertising fingerprinting.
4. Purposes and legal bases
We process data to form and perform contracts, provide and improve the service, security, fraud prevention, legal compliance, billing, and support—under KVKK Art. 5 bases including contract, legitimate interest, legal obligation, and where required, explicit consent.
5. Payments
Online payments are processed through a licensed payment provider’s secure infrastructure. Card data is not stored on Company servers; the payment page is protected with SSL/TLS. The payment provider processes data under its own policies and regulations. We process payment outcomes (success/failure, references) to activate subscriptions.
6. Transfers and retention
Data may be shared with hosting, email, storage, and payment providers only as needed to run the service, with appropriate safeguards. Cross-border transfers follow KVKK requirements.
Data is retained for as long as needed for the purpose and any legal retention periods, then deleted, destroyed, or anonymized.
7. Cookies
We use essential cookies for session, language, and theme. Analytics cookies, if used, are kept as de-identified as practicable. You can manage cookies in your browser; disabling some may affect login or locale.
8. Your rights
Under KVKK Art. 11 you may request to learn whether your data is processed, obtain information, learn the purpose and third-party recipients, request correction or deletion/destruction, object to automated analysis outcomes, and seek remedies for unlawful processing.
Send requests to [email protected] or via KEP. We may verify identity and respond within statutory timelines.
9. Security
We apply technical and organizational measures (encryption, access control, secure connections) against unauthorized access, loss, and misuse. No system is perfectly secure—please report suspicious activity.