Limited by design
Google sign-in requests only basic identity scopes: openid, email and profile.
This policy explains, in practical language, what personal data Market of Kids processes when you browse our wholesale website, sign in with Google, manage an account, send an order request or speak with our team.
We collect limited identity, contact, order and technical information to operate a secure B2B service. Choices such as optional marketing remain separate from service messages.
Google sign-in requests only basic identity scopes: openid, email and profile.
Account and order data help our team confirm stock, prepare orders and provide support.
You may ask about, correct or delete eligible data and object where applicable.
This Privacy Policy applies to marketofkids.com, its language versions, customer-account features, wholesale catalog, order-request forms and communications sent directly through the website. Market of Kids, operating from Nişanca Bostanı Sokak No:47/4, Fatih, Istanbul, Türkiye, determines the purposes and means of the website processing described here and acts as the data controller for that processing. The legal seller or contracting business shown on an invoice, payment instruction or written order confirmation may also process information required for that particular transaction under its own legal obligations.
The policy does not govern independent websites or services that you choose to open, including Google, WhatsApp, Instagram, Telegram, Trustpilot, mapping services, payment services, couriers or manufacturers. Their own notices apply once you use those services. Links do not mean that Market of Kids controls their privacy practices.
The information depends on how you use the service. Browsing does not require an account. If you sign in, request an order or contact us, we may process the categories below. We do not intentionally request special-category data such as health, biometric, religious or political information; please do not place such information in free-text fields.
Google sign-in is optional. Market of Kids uses the OAuth 2.0 authorization-code flow with PKCE and requests only the standard openid, email and profile scopes. Google authenticates you and returns a signed identity token. We verify that token to create or locate your Market of Kids account. We do not request access to Gmail, Google Drive, Google Contacts, Google Calendar, photos, advertising data or any other restricted or sensitive Google API scope.
Access and refresh tokens received during the sign-in exchange are not stored in the customer database and are not used after identity verification. The website stores the Google subject identifier and the basic profile fields needed to keep the account unique and display it. Google user data is used only for authentication, account security, account display and the account controls you request. It is not sold, rented, used to build advertising profiles or disclosed to data brokers.
Creating an account does not search for or attach older guest orders. Orders placed before sign-in remain separate unless a lawful, documented support process is expressly agreed for a specific case. Deleting the account removes the login identity and eligible profile data; transaction or security records that must be retained for legal claims, accounting, fraud prevention or order administration may remain isolated for the applicable period.
We process information only for defined purposes and rely on the lawful ground appropriate to the context. Under Turkish Law No. 6698 and, where applicable, the GDPR or equivalent rules, this can include steps requested before a contract, performance of a contract, compliance with a legal obligation, legitimate interests that do not override your rights, or consent for a genuinely optional activity.
Essential cookies or similar storage keep the website secure and remember a signed-in session. The customer session cookie is HTTP-only, uses SameSite protection, is marked Secure in production and normally expires after 30 days. Temporary OAuth state, nonce and PKCE values ordinarily expire within about ten minutes. Disabling essential storage may prevent sign-in or account features from working.
If a Google Analytics measurement identifier is configured, the optional analytics script is not loaded until you choose Allow analytics in the privacy panel. After that choice, Google Analytics may receive technical usage data such as viewed pages, device or browser signals, approximate location derived from IP and interaction events. Analytics is used to understand aggregate site performance, not to read Google-account content or determine wholesale eligibility. You can reopen Privacy choices and withdraw permission for future measurement. Browser controls, content blockers and Google’s own controls may also limit storage. We do not use the Google sign-in profile as an analytics advertising identifier.
Market of Kids does not sell personal data. Information is disclosed only when reasonably necessary for the purposes described here and with access limited by role and need. Recipients may include website hosting, infrastructure, database, security, email and support providers; Google for identity and, when enabled, analytics; the assigned sales team; the seller shown on commercial documents; couriers or logistics partners selected for an order; professional advisers; and competent authorities when lawfully required.
A supplier or manufacturer does not automatically receive your account profile merely because you view its products. If product availability, customization or fulfilment requires limited information to be passed to a relevant commercial partner, we share only what is necessary for that request. Service providers act under their contractual or legal responsibilities and are not permitted to use data for unrelated purposes on our instructions.
Market of Kids serves buyers internationally and uses technology and communication providers that may operate or store information outside Türkiye or the country where you are located. Consequently, limited personal data may be accessible from or transferred to another country. Different countries can provide different levels of legal protection.
Where Turkish transfer rules apply, transfers are evaluated under Article 9 of Law No. 6698 and the current mechanisms for adequacy, appropriate safeguards or applicable exceptional situations. Where the GDPR applies, transfers outside the EEA are handled through an adequacy decision, approved safeguards such as standard contractual clauses, or another lawful Chapter V mechanism as appropriate. We do not claim that every provider or destination is adequate; the relevant mechanism is assessed for the actual transfer.
We keep personal data only as long as reasonably necessary for the purpose collected, a documented retention need or a mandatory legal period. Retention varies by record: an active account remains until deletion or justified administrative action; the session cookie normally lasts 30 days; temporary OAuth values about ten minutes; support and security logs for a limited troubleshooting or defence period; and order, payment, invoice, customs or commercial records for the period required by applicable accounting, tax, commercial and limitation rules.
When a retention period ends, data is deleted, anonymized or securely isolated. A deletion request does not require us to erase records that must be preserved by law or are reasonably necessary to establish, exercise or defend a legal claim, investigate fraud, protect another person’s rights or complete an outstanding transaction. In those cases, use is restricted to the remaining purpose.
Depending on the law that applies to you, you may ask whether your data is processed, request access or a copy, correct inaccurate or incomplete data, request deletion or restriction, object to processing based on legitimate interests or direct marketing, withdraw consent without affecting earlier lawful processing, and request portability where legally available. You may also complain to the competent authority, including the Turkish Personal Data Protection Authority where Turkish law applies or the supervisory authority in your country where applicable.
Turkish data subjects have the rights listed in Article 11 of Law No. 6698, including learning the purpose of processing and whether data is used consistently with that purpose, knowing recipients in Türkiye or abroad, requesting correction or deletion where conditions are met, requesting notice of those actions to recipients, objecting to an adverse result produced exclusively through automated analysis, and claiming compensation for unlawful processing. We do not make decisions producing legal or similarly significant effects solely by automated means.
You can edit supported profile fields or start account deletion from the Account page. For a broader request, email [email protected] with enough information to identify the account and the right being exercised. We may ask for proportionate verification and will respond within the period required by applicable law. Never send a password or a copy of an identity document unless we specifically explain why it is necessary and provide a secure method.
We use layered technical and organizational measures appropriate to the nature of the service, including encrypted HTTPS transport, signed HTTP-only sessions, short-lived OAuth verification values, role-limited access, server-side validation, logging and backups. No internet or storage system can be guaranteed completely secure, so users should protect their Google account, sign out on shared devices and promptly report suspicious activity.
If a personal-data breach occurs, we investigate scope and risk, contain the issue, preserve necessary evidence and notify authorities or affected people when the applicable law requires it. Security logs may be retained for the time reasonably needed to investigate and prevent recurrence.
Although our catalog contains children’s clothing, Market of Kids is a wholesale B2B service intended for adult business representatives. It is not designed for children and we do not knowingly create accounts for children or ask buyers to provide children’s personal data. Product sizes, model photographs and clothing descriptions do not form a customer profile about a child.
If you believe a child submitted personal data through the website without appropriate authorization, contact us so that we can investigate and delete it where required. Business users must not place a child’s name, photograph, health information or other identifying data in order notes unless a lawful, necessary purpose has been agreed in advance.
Order, security and service messages are transactional and may be necessary even if you do not choose marketing. An optional marketing preference can be changed in the Account page or by contacting us. We do not treat a social-media follow, a Google sign-in or an order request by itself as unlimited permission for unrelated promotions.
When you contact us through WhatsApp, Instagram, Telegram, email or another independent service, that provider may process account, device and message data under its own rules. Avoid sending payment credentials or unnecessary sensitive data through social messaging. Our team may copy necessary order details into the order record so the request can be fulfilled and audited.
We may update this policy when the website, providers, legal requirements or processing practices change. The current version and effective date remain published here. Material changes will be highlighted through a reasonable website or account notice when appropriate; an update does not retroactively create a new purpose without a valid legal ground.
Translations are provided to make the notice accessible. They are intended to convey the same substance. Mandatory rights under the law applicable to you remain unaffected by a translation inconsistency. Questions, objections or rights requests may be sent to [email protected] or delivered to Market of Kids, Nişanca Bostanı Sokak No:47/4, Fatih, Istanbul 34130, Türkiye.
This notice is a transparent description of the website’s data practices, not a waiver of any mandatory privacy right. The law and the facts of an individual processing activity always prevail.
Ask a privacy question, exercise an applicable right or report an account-security concern by email.
Email privacy contact