Privacy and Security Policy
Card details
Card payments are taken through the infrastructure of N Kolay Ödeme ve Elektronik Para Kuruluşu A.Ş. (Paynkolay), licensed by the Central Bank of the Republic of Turkey (TCMB). Card details are processed in the payment institution's PCI DSS compliant systems; PayDM does not store the card number, expiry date or security code. Every payment is confirmed with the bank's 3D Secure verification, using a one-time code sent to the cardholder's phone.
Connection security
The site and payment pages work only over an encrypted connection (HTTPS/TLS).
Account security
- Accounts are opened with an email verification code; passwords are stored as irreversible hashes.
- Password resets and account management actions are tied to the verified email address.
- Payment starts, messaging and sign-in attempts are limited to prevent abuse.
- Order tracking pages open only with an unguessable link sent to the buyer, and are closed to search engines.
Personal data
The purposes for which personal data is processed, who it is transferred to and your rights are explained in the KVKK Privacy Notice. PayDM does not sell personal data or share it for advertising.
Reporting a security issue
If you notice a security vulnerability or a suspicious transaction, write to [email]. If you suspect your account has been used without permission, change your password right away.