Personal Data Protection and Privacy
Gelsin Teknoloji Limited Şirketi (“TURGAME”) operates https://www.turgame.com, an online store selling digital codes: game keys, gift cards and in-game currency. This page contains the four documents that explain how TURGAME handles your personal data.
Last updated: 7 August 2026
- 1. Clarification Text on the Processing of Personal Data
- 2. Cookie Policy
- 3. Explicit Consent Text
- 4. Applying to Us About Your Personal Data
These documents are written for the Personal Data Protection Law No. 6698 (“KVKK”) and, for data subjects in the European Union and the United Kingdom, for the General Data Protection Regulation (“GDPR”). Where the two laws require the same thing, we say it once.
1. Clarification Text on the Processing of Personal Data
This Clarification Text is the notice TURGAME gives you under Article 10 of the KVKK and Articles 13 and 14 of the GDPR. It tells you what personal data we process, why, on what legal basis, who we share it with, how long we keep it and what you can do about it.
1.1 Who we are and how to reach us
| Data controller | Gelsin Teknoloji Limited Şirketi (“TURGAME”) |
| Address | Mahfesığmaz Mah. 79157 Sk. No:2, Çukurova / Adana / Türkiye |
| Tax office and number | Ziyapaşa VD 2910831287 |
| MERSIS number | 0291083128700012 |
| Contact | Contact form |
| Registered electronic mail (KEP) | [email protected] |
| Website | https://www.turgame.com |
For anything about your personal data, use our Contact form or open a ticket at https://www.turgame.com/my-account/support/new/. If you want to make a formal application under the KVKK or the GDPR, use section 4 of this page.
1.2 Who this text covers
This Clarification Text covers three groups:
- Visitors — anyone who uses turgame.com without buying or registering.
- Buyers — anyone who places an order, whether or not they have an account.
- Members — anyone who registers an account.
If you work for TURGAME, apply for a role with us or represent a supplier, you receive a separate clarification text directly. This page is not that text.
1.3 What personal data we process
We process only the data below. We do not process special categories of personal data — no health data, no biometric data, no religious, political or trade union information — and we ask you not to send us any.
| Category | What it contains |
|---|---|
| Identity data | First name and last name. |
| Contact data | Email address, telephone number, billing address. |
| Account data | Username, encrypted password, account settings, language preference, consent records. |
| Order and transaction data | Order number and history, the digital codes purchased, prices paid, invoice records, cancellation and refund records, and the record of whether and when you revealed a code by clicking “Show Code”. |
| Payment data | Payment method, the masked card number and card type returned to us by our payment provider, payment approval and reference codes, and chargeback records. We never receive or store your full card number, expiry date or security code — those go directly to our payment provider. |
| Technical and security data | IP address, browser and operating system information, device and browser characteristics used to identify a device (device fingerprint), login and logout records, session records, server logs, and the timestamp and IP address recorded when you accept an agreement or reveal a code. |
| Support data | The content of support tickets, emails and WhatsApp messages you send us, and our replies. |
| Marketing data | Only if you consent: your communication preferences and consent records, your responses to campaigns, and the purchase and browsing history we use to build recommendations. |
| Cookie data | As set out in the Cookie Policy in section 2 of this page. |
1.4 Why we process it, and on what legal basis
Every processing activity below has its own legal basis. We do not rely on your consent for anything we can do without it, and refusing consent never stops you from buying or from holding an account.
| What we do | Data used | KVKK basis | GDPR basis |
|---|---|---|---|
| Create and run your account; let you log in | Identity, contact, account | Art. 5/2(c) — necessary for a contract you are party to | Art. 6(1)(b) — performance of a contract |
| Take your order, take payment, deliver the digital code and record whether you revealed it | Identity, contact, order, payment, technical | Art. 5/2(c) | Art. 6(1)(b) |
| Handle cancellations, refunds and invalid-code claims | Order, payment, support | Art. 5/2(c); Art. 5/2(ç) — legal obligation | Art. 6(1)(b); Art. 6(1)(c) |
| Answer your support tickets, emails and messages | Identity, contact, order, support | Art. 5/2(c) | Art. 6(1)(b) |
| Issue invoices; keep tax, accounting and commercial records; answer courts, arbitration committees and public authorities | Identity, contact, order, payment | Art. 5/2(a) — expressly provided for in law; Art. 5/2(ç) | Art. 6(1)(c) — legal obligation |
| Detect and prevent fraud, unauthorised card use and abuse of our refund rules; keep the site and accounts secure | Order, payment, technical | Art. 5/2(f) — our legitimate interests | Art. 6(1)(f) — legitimate interests |
| Defend chargebacks and establish, exercise or defend legal claims | Order, payment, technical, support | Art. 5/2(e) — necessary to establish, exercise or protect a right | Art. 6(1)(f) |
| Send you campaign, discount and new-product messages | Identity, contact, marketing | Art. 5/1 — your explicit consent | Art. 6(1)(a) — consent |
| Analyse your purchase and browsing habits to personalise what we show and offer you | Order, marketing, cookie | Art. 5/1 — your explicit consent | Art. 6(1)(a) |
| Share your data with marketing service providers for those purposes | Identity, contact, marketing | Art. 5/1 — your explicit consent | Art. 6(1)(a) |
| Place analytics and advertising cookies | Cookie, technical | Art. 5/1 — your explicit consent | Art. 6(1)(a) |
The legitimate interests we rely on, named as the GDPR requires, are: preventing fraud and unauthorised use of payment cards; protecting our stock of digital codes from abuse; keeping our website, accounts and systems secure; and defending ourselves in chargebacks and legal disputes. We have weighed these against your rights and freedoms. You can object to any of them at any time under section 1.11.
1.5 Whether you have to give us your data
Identity, contact, order and payment data are required to buy from us — without them we cannot conclude or perform the sale, so we cannot accept your order. Account data is required only if you choose to register; you can buy as a guest instead. Everything marked “your explicit consent” in the table above is optional, and refusing it costs you nothing.
1.6 How we collect it
- Directly from you, through the registration form, the checkout, your account pages, support tickets, email and WhatsApp.
- Automatically as you use the site, through our servers, log files and the cookies described in section 2.
- From our payment provider, which returns the payment result, the masked card number and any fraud signals.
- From third-party login services, if you choose to sign in with one.
1.7 Who we share it with
We do not sell your personal data. We share it only with the recipients below, only for the purposes listed, and only to the extent needed.
| Recipient | Why | Basis |
|---|---|---|
| Our payment provider, iyzico, PayTR, Paysera and Binance Pay | To take payment and screen the transaction for fraud | Contract; legitimate interests |
| Banks and card schemes (including Visa and Mastercard) | To process payments and to answer chargebacks | Contract; establishing and protecting a right |
| Our hosting and IT infrastructure provider, Hetzner Online GmbH, on servers located in Finland | To run the website and store its data | Contract; legitimate interests |
| Our email delivery provider, Brevo (Sendinblue) | To send order confirmations, delivery emails and — if you consent — marketing emails | Contract; consent for marketing |
| The publisher or platform behind a code (for example Steam, Xbox, PlayStation) | Only where we need them to investigate a code that does not work, and limited to the order and code details | Contract |
| İleti Yönetim Sistemi A.Ş. (İYS) | To register and check your consent to commercial electronic messages, as Turkish law requires | Legal obligation |
| Analytics and advertising providers | Only if you consent to those cookies — see section 2 | Explicit consent |
| Our accountant and financial advisers | To issue invoices and keep our books | Legal obligation |
| Our lawyers, courts, consumer arbitration committees, enforcement offices and public authorities | Where the law requires it, or to establish, exercise or defend a legal claim | Legal obligation; establishing and protecting a right |
1.8 Transfers outside Türkiye
Some of the providers above are located outside Türkiye, in the European Union (Lithuania, France and Finland) and the United States. When we transfer your personal data abroad we do it under Article 9 of the KVKK as it now stands, in this order:
- where the Personal Data Protection Board has issued an adequacy decision for the destination, on the basis of that decision;
- otherwise, on the basis of the standard contract clauses published by the Board. We sign these with each provider and notify each signed set to the Personal Data Protection Authority within five business days, as Article 9 requires;
- only where a transfer is genuinely incidental and none of the above is available, on one of the exceptional grounds in Article 9/6.
For personal data protected by the GDPR, we transfer on the basis of the European Commission’s Standard Contractual Clauses, together with any additional measures the transfer requires.
You can ask us for a copy of the safeguards that apply to a transfer through our Contact form.
1.9 How long we keep it
We keep personal data for the periods below. When a period ends, we delete, destroy or anonymise the data at the next periodic destruction date and in any event within six months.
| Data | How long | Why that period |
|---|---|---|
| Account and membership records | While your account is open, then 10 years | Limitation period for contractual claims |
| Orders, invoices and payment records | 10 years from the order | Commercial and tax record-keeping obligations |
| The sales agreement, your acceptance record and the code-reveal log for an order | 10 years from the order | Evidence of the contract and of delivery |
| Server logs, IP addresses and device information kept for security | 2 years | Security, fraud prevention and legal obligations on traffic records |
| Records of orders cancelled for suspected fraud, and related account blocks | 5 years | Establishing and protecting a legal right |
| Support tickets and correspondence | 3 years after the ticket is closed | Handling and evidencing complaints |
| Marketing consent records | While your consent stands, then 1 year | Commercial Communication Regulation, Art. 13 |
| The behavioural profile built with your consent | Until you withdraw consent — then deleted within 30 days | Consent |
| Cookies | See the durations in the cookie table in section 2 | — |
If you ask us to delete your data and no retention period above applies to it, we delete it within 30 days. If a retention period does apply, we cannot delete that data early, and we will tell you which period applies and when it ends.
1.10 Automated checks and profiling
Two of our processes are automated, and you have a right to know about both.
Fraud screening. When you place an order, our systems and our payment provider automatically check it against risk signals — the order details, your IP address, device information and the payment provider’s own scoring. If an order scores as high risk it may be held for review or cancelled and refunded, and in serious or repeated cases the account may be blocked. This can affect whether you get the product, so: you can always ask a person to review the decision. Open a ticket at https://www.turgame.com/my-account/support/new/, tell us the order number, and a member of staff — not a system — will look at it, explain the reason and correct it if the check was wrong.
Personalisation. If, and only if, you consent under section 3, we analyse what you have bought and looked at to decide which products and offers to show you. This changes what you see on the site and in our messages. It has no other effect, and you can switch it off at any time without losing anything else.
We do not make any other decision about you by purely automatic means.
1.11 Your rights
Under Article 11 of the KVKK you have the right to:
- learn whether we process your personal data;
- ask for information about it if we do;
- learn why we process it and whether we use it for that purpose;
- know the third parties, in Türkiye or abroad, to whom we transfer it;
- ask us to correct it if it is incomplete or wrong;
- ask us to delete or destroy it where the conditions in the KVKK are met;
- ask us to tell anyone we transferred it to about a correction, deletion or destruction;
- object to a result produced against you by analysing your data purely automatically; and
- claim compensation if you suffer loss because your data was processed unlawfully.
If the GDPR applies to you, you also have the right to:
- receive a copy of your data in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible (Art. 20);
- ask us to restrict processing while a dispute about accuracy or lawfulness is resolved (Art. 18);
- object to processing based on our legitimate interests (Art. 21), and to object to direct marketing at any time, which we will always honour;
- ask for human intervention in an automated decision (Art. 22) — see section 1.10; and
- withdraw any consent at any time, without affecting what we did lawfully before you withdrew it.
To use any of these rights, see section 4.
Complaints. If our answer does not satisfy you, you can complain to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu), and, if the GDPR applies to you, to the supervisory authority in the EU or UK country where you live or work. You can also go to court.
1.12 Security
We take the technical and administrative measures required by Article 12 of the KVKK and Article 32 of the GDPR. These include encrypted connections across the site, storing passwords in encrypted form, restricting access to personal data to staff who need it, keeping access logs, and written data protection terms with our providers. If a breach affects your personal data, we notify the Personal Data Protection Authority and, where the law requires it, you.
1.13 Children
TURGAME is for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has given us personal data, tell us through our Contact form and we will delete it.
1.14 Changes to this text
TURGAME may update this Clarification Text. We publish the current version on this page with the date it was last updated. If a change materially affects how we use data we already hold, we tell registered Members by email before it takes effect.
2. Cookie Policy
This Cookie Policy explains how Gelsin Teknoloji Limited Şirketi (“TURGAME”), of Mahfesığmaz Mah. 79157 Sk. No:2, Çukurova / Adana / Türkiye, uses cookies and similar technologies on turgame.com. It forms part of the Clarification Text above.
2.1 What cookies are
Cookies are small text files a website puts on your device so it can recognise that device later. We also use similar technologies that read characteristics of your browser and device. Everything this policy says about cookies applies to those too.
2.2 The rule we apply
Strictly necessary cookies are the ones without which the site cannot do what you asked — keeping you logged in, keeping your basket, and protecting the checkout. We place these without asking, because we could not provide the service otherwise. Our legal basis is Article 5/2(c) of the KVKK, and Article 6(1)(b) of the GDPR.
Every other cookie — analytics, functionality and advertising — is placed only if you consent. Our legal basis for all of them is your explicit consent: Article 5/1 of the KVKK, Article 6(1)(a) of the GDPR, and the consent requirement for access to terminal equipment. We do not rely on legitimate interests for analytics or advertising cookies.
We ask for that consent through a cookie notice when you first visit. Until you accept, non-essential cookies are not placed. Refusing is as easy as accepting, and refusing does not limit your access to the site or to any product.
2.3 Cookies we use
| Cookie | Category | Provider | Purpose | Duration | Consent needed |
|---|---|---|---|---|---|
| wordpress_logged_in_* | Strictly necessary | TURGAME | Keeps you logged in to your account | Session | No |
| wp_woocommerce_session_* | Strictly necessary | TURGAME | Links your device to your basket and order data on our server | 2 days | No |
| woocommerce_cart_hash | Strictly necessary | TURGAME | Tells the site when your basket contents have changed | Session | No |
| woocommerce_items_in_cart | Strictly necessary | TURGAME | Tells the site when your basket contents have changed | Session | No |
| turgame_cookie_consent | Strictly necessary | TURGAME | Records the cookie choices you made, so we do not ask again and can prove what you chose | 1 year | No |
| woocommerce_recently_viewed | Functionality | TURGAME | Remembers the products you looked at most recently | Session | Yes |
| store_notice* | Functionality | TURGAME | Remembers that you dismissed a store notice | Session | Yes |
| _ga, _gid, _gat | Analytics | Google Analytics | Measures traffic and how the site is used | 1 minute to 2 years | Yes |
| IDE, NID | Advertising | Google Ads | Personalised advertising and remarketing | Up to 2 years | Yes |
| _fbp, fr | Advertising | Meta (Facebook, Instagram) | Measures ad performance and targets ads | 3 months to 2 years | Yes |
Third-party cookies are set by those companies and governed by their own privacy and cookie policies as well as this one. If we add or remove a tool, we update this table.
2.4 How to change your mind
You can withdraw or change your cookie consent at any time, and it takes effect immediately:
- reopen the cookie notice from the Cookie Settings link in the footer of every page, and change your choices there;
- opt out of Google Analytics for every site at https://tools.google.com/dlpage/gaoptout;
- manage Google’s personalised advertising at https://adssettings.google.com/authenticated;
- manage advertising cookies across many companies at Your Online Choices.
You can also block or delete cookies in your browser — see Chrome, Firefox, Safari, Opera and Edge. Browser settings are an extra control you have over your own device. They are not how we ask for or record your consent, and changing them does not tell us anything. Use the Cookie Settings link if you want to change what we do. Blocking strictly necessary cookies will stop the basket, login and checkout from working.
3. Explicit Consent Text
This section explains the consents TURGAME asks for. It matches the Explicit Consent Form shown when you register.
3.1 What this is for
You do not need an account to shop at TURGAME, and you do not need to give any of the consents below in order to register, to buy, or to get support. We ask for them so that we can send you offers and tailor what we show you. You can refuse every one of them and use TURGAME normally. If you refuse, we still process your data for orders, delivery, support, invoicing, security and our legal obligations, on the bases set out in section 1.4 — those do not depend on your consent.
3.2 The consents we ask for, separately
Each of these is asked separately and can be given, refused or withdrawn on its own. None is a condition of anything.
- Commercial messages by email — campaigns, discounts, new products and special offers, sent to your email address.
- Commercial messages by SMS and messaging apps — the same content, sent by SMS or WhatsApp.
- Commercial messages by telephone call — the same content, by a call from us.
- Personalised recommendations — we analyse what you have bought and looked at on the site to choose which products and offers to show you, and to invite you to occasional surveys.
- Sharing with marketing service providers — we share your name, email address and marketing preferences with the marketing and advertising providers we use, so they can deliver the messages and personalisation you asked for on our behalf. They may only use it for that, and only on our instructions.
Cookie consent is separate again, and is asked through the cookie notice described in section 2.
3.3 Commercial messages and İYS
If you consent to commercial electronic messages, Turkish law requires us to register that consent with the İleti Yönetim Sistemi (İYS) and to check İYS before we send. We record the date, the channel and the type of message your consent covers. Every message we send carries our identity and a way to stop the messages immediately.
3.4 How to withdraw
You can withdraw any consent at any time, free of charge, and we act on it at once:
- change your choices in the Communication Preferences section of your account at https://www.turgame.com/my-account/;
- use the unsubscribe link at the bottom of any marketing email;
- reply to any marketing SMS with the opt-out word shown in it;
- withdraw through the İleti Yönetim Sistemi at https://iys.org.tr;
- open a ticket at https://www.turgame.com/my-account/support/new/; or
- use our Contact form.
Withdrawing does not affect the lawfulness of what we did with your consent before you withdrew it. If you withdraw the personalisation consent, we delete the behavioural profile within 30 days.
3.5 What you are confirming
By ticking a box in the Explicit Consent Form, you confirm for that box only that you have read this section, that you understand what you are agreeing to, and that you are agreeing freely. Ticking nothing is a valid choice and has no consequence for your account or your orders.
4. Applying to Us About Your Personal Data
This section tells you how to exercise the rights in section 1.11. You can write your own application — you do not have to use a form. If you would like a template, you can download our application form: KVKK Application Form (PDF). It is optional.
4.1 If your request is under the KVKK
What your application must contain, as required by the Communiqué on the Procedures and Principles of Application to the Data Controller:
- your name and surname, and your signature if the application is in writing;
- your Turkish identity number, or if you are not a Turkish citizen, your nationality and passport number or identity number if you have one;
- your address for notification, at home or at work;
- your email address, telephone number and fax number for notification, if you have them;
- a clear statement of what you are asking for; and
- any documents that support your request.
If you apply for someone else, you must hold a special power of attorney for it and send it with the application. We do not act on applications made for another person without one.
How to send it. Any of these four channels works:
- By post or in person, signed by hand and with a copy of your identity document, to Mahfesığmaz Mah. 79157 Sk. No:2, Çukurova / Adana / Türkiye. If you come in person, bring a valid identity document.
- Through a notary.
- From your registered electronic mail (KEP) address, or signed with a secure electronic signature or mobile signature, to [email protected].
- Through our Contact form, from the email address already registered in your TURGAME account.
Our answer. We answer within 30 days of receiving your application, through the channel you used or by email or post. If we refuse, we tell you why.
Cost. Answering is free. If our answer runs to more than ten pages in writing, we may charge the fee in the Authority’s tariff for each page after the tenth. If you ask for the answer on a CD or flash memory, we may charge the cost of the medium. We charge nothing else.
If you are not satisfied. You can complain to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) within 30 days of receiving our answer, and in any event within 60 days of the date you applied to us. If we do not answer within 30 days, you can complain once that period has ended. You can also go to court.
4.2 If your request is under the GDPR
If the GDPR applies to you, a plain message is enough. Send it through our Contact form, or open a ticket at https://www.turgame.com/my-account/support/new/, and tell us what you want.
- We answer within one month. If your request is complex or you have made several, we may extend this by up to two further months, and we will tell you within the first month if we do.
- It is free. We only charge, or refuse, if a request is manifestly unfounded or excessive, and we explain why if that happens.
- We ask for identification only if we have a real doubt about who you are, and we ask for no more than we need. You do not have to send a wet signature, an identity number or a power of attorney for a GDPR request.
If you are not satisfied, you can complain to the supervisory authority in the EU or UK country where you live, where you work, or where the problem happened.