1. Who we are and in which capacity we process data
We act in two distinct roles, and which one applies determines who you exercise your rights against:
- As a data controller: for people who visit our website, submit a demo request, or create an account in the application.
- As a data processor: for the end-customer data that our business customers (brands) upload to their workspace or stream in through integrations. The brand decides why and how that data is processed; we only process it on their instructions.
- If you are a customer of a brand and want your data deleted, you can contact that brand directly or write to us — we will forward the request to the brand and make sure it is handled.
2. Data we process
The data we handle falls into four groups:
- Account and billing data: name, work email, phone, company and workspace name, user role, password stored as a hash, session records, usage counters and invoice details.
- Website and support data: the email, phone, company, industry and message fields of the demo form; emails you send us; server logs containing IP address, browser information and timestamps.
- End-customer data processed on behalf of brands: name, email, phone, platform identifiers (Shopify/İkas customer id, Instagram-scoped user id, WhatsApp number and similar), order and cart records, events and traits, consent records, and delivery results (delivered, opened, clicked, failed).
- Integration credentials: access tokens and API keys for the services you connect. These are stored encrypted and are never displayed in clear text in the interface.
3. Where the data comes from
- E-commerce platforms: Shopify, İkas, WooCommerce, Ticimax, Ideasoft — order, cart and customer records.
- Meta platforms: Lead Ads forms, Instagram messaging and the WhatsApp Business Platform.
- The brand’s own sources: web forms, REST API calls, CSV/XLSX imports.
- Messaging providers: delivery and engagement reports for the email, SMS and WhatsApp messages you send.
4. Why we process it
- To provide the service: identity resolution, building a single customer profile, segmentation, and running campaigns and automation journeys.
- To deliver messages: email, SMS, WhatsApp, push notifications and voice calls through the providers you choose.
- To measure and report: campaign performance, segment size and usage statistics.
- To bill: calculating the contractual usage counters (events and monthly tracked profiles).
- For support, security and abuse prevention: troubleshooting, detecting unauthorised access, reviewing logs.
- To meet legal obligations and to establish or defend legal claims.
5. Legal bases
Where we act as controller, we rely on the following bases under GDPR Art. 6 and KVKK Art. 5:
- Performance of a contract (creating an account, providing the service, billing).
- Compliance with a legal obligation (tax and commercial legislation, official requests).
- Legitimate interests (service security, abuse prevention, product improvement).
- Consent (only for commercial electronic messages that require it).
- For end-customer data processed on behalf of brands, the brand determines the legal basis and manages consent; compliance with marketing rules — including Turkey’s İYS registry — is the brand’s responsibility.
6. Data received from Meta platforms
When a brand connects its Facebook Page, Instagram account or WhatsApp Business account to PlugMesh, we receive through Meta APIs only what that brand needs for its own customer communication:
- Responses submitted to Lead Ads forms (the fields asked in the form, such as name, email, phone).
- Direct messages and comments sent to the connected Page/Instagram account, together with the sender’s platform-scoped id and display name.
- Technical metadata about the connected account (account id, username, token validity).
- We do not archive message content. Incoming messages are analysed for intent and sentiment; what we keep is a short snippet of the latest message, a message counter and the detected intent/sentiment label.
- We never sell data obtained from Meta, never use it for our own advertising, and never share it outside the brand’s workspace.
- When the connection is removed or a deletion request is received, data obtained through Meta is deleted within 30 days. See our Data Deletion page for the exact steps.
7. Who we share it with
We do not sell personal data. We share it only where the service requires it:
- Infrastructure providers: the cloud and CDN services hosting the application and databases.
- Channel providers: the email, SMS, WhatsApp, push and call-centre providers the brand chooses. Only the data needed for a given send is transmitted.
- AI provider: to generate the narrative summaries on the dashboard we send aggregate statistics only (counts and ratios) — never personal data.
- Accounting and payment services: billing data only.
- Competent public authorities: where and to the extent required by law.
8. International transfers
Some of the infrastructure and channel providers we use are established outside Turkey. In that case personal data is transferred under the safeguards required by KVKK Art. 9 and GDPR Chapter V (standard contractual clauses, undertakings or explicit consent). We share the current provider list on request.
9. Retention periods
- Account and workspace data: for the term of the contract; deleted or anonymised within 30 days after it ends.
- End-customer data processed for brands: until the brand deletes it or the workspace is closed. Removal from backups follows the backup rotation and takes at most 90 days.
- Invoices and accounting records: for the periods required by tax and commercial law (up to 10 years).
- Server and security logs: as a rule up to 90 days.
- Opt-out records: kept indefinitely with the minimum data needed to make sure the person is not contacted again.
10. Security
- All traffic is encrypted with TLS; provider tokens and API keys are stored encrypted in the database.
- Each workspace’s data lives in its own database schema, and tenant isolation is enforced in the application layer.
- Access is role-based, and access to production is limited on a least-privilege basis.
- Passwords are stored as irreversible hashes — no member of our team can see your password.
- In the event of a personal data breach we notify the competent authority, and where required the affected individuals, within the periods set by KVKK and GDPR.
11. Cookies and similar technologies
- We use no advertising or profiling cookies on the marketing website.
- In the application we use only cookies that are strictly necessary for session management and security.
- The website loads fonts from Google Fonts; your IP address is transmitted to that provider as part of the request.
12. Your rights
Under KVKK Art. 11 and GDPR Art. 15-22 you have the right to learn whether your data is processed, to request information and a copy, to have it corrected, deleted or its processing restricted, to data portability, to object to automated decisions, and to seek compensation for damages.
Send your requests to hello@getplugmesh.com. Once we have verified your identity we respond free of charge within 30 days at the latest. Step-by-step guidance for deletion requests is on the Data Deletion page.
If you are making a request as a customer of a brand, that brand is the controller — we may route your request to them and inform you of the outcome.
13. Children
PlugMesh is a service for businesses. It is not directed at people under 18 and we do not knowingly collect data from them.
14. Changes
We may update this policy from time to time. For material changes we notify workspace administrators by email and update the date shown at the top of this page.
Questions about this document? Write to us: hello@getplugmesh.com