🌿 Free shipping on orders over 60 $!
My Cart (0)

Your cart is empty

🎁 Send a Gift

Privacy Notice — Data Protection Information (GDPR)

1. Identity of the Data Controller

My Tiny Garden is a brand owned and operated by STARTUP CREATIVE TEKNOLOJİ VE DANIŞMANLIK LİMİTED ŞİRKETİ (hereinafter referred to as the "Company"). The Company acts as the data controller in respect of all personal data collected through this website and in connection with the sale of its products.

  • Legal name: STARTUP CREATIVE TEKNOLOJİ VE DANIŞMANLIK LİMİTED ŞİRKETİ
  • Brand: My Tiny Garden
  • Registered address: Eğitim Mah. Poyraz Sok. No:1/68, Kadıköy, İstanbul, Türkiye
  • Contact e-mail: info@mytinygarden.com

2. Categories of Personal Data We Process

In the course of providing our products and services, the Company processes personal data falling within the following categories:

  • Identity data: First name and last name.
  • Contact data: E-mail address, telephone number, delivery address, and billing address.
  • Order and transaction data: Order number, products purchased, order history, return and cancellation requests, gift packaging and message card preferences.
  • Financial data: Payment method type and billing information. Sensitive payment details such as card numbers are processed exclusively by our secure payment infrastructure provider and are never stored by the Company.
  • Technical and traffic data: IP address, browser type and version, operating system, website navigation data, cookie data, and session duration.
  • Marketing preference data: Newsletter subscription status and marketing communication preferences, where you have given your explicit consent.
  • Customer service data: Records of customer service interactions, support requests, and correspondence.

3. Purposes of Processing

We process your personal data for the following purposes:

  1. Entering into and performing the distance sales contract, and managing order processes.
  2. Arranging shipment of products and managing delivery and logistics operations.
  3. Issuing invoices and fulfilling accounting and financial compliance obligations.
  4. Managing withdrawal rights, returns, exchanges, and complaints.
  5. Providing customer services and after-sales support.
  6. Sending transactional communications such as order confirmations, shipping notifications, and delivery updates.
  7. Ensuring website security and technical functionality.
  8. Complying with applicable legal obligations and responding to requests from competent authorities.
  9. Where you have given explicit consent: sending commercial electronic communications, running promotional campaigns, and carrying out personalised marketing activities.
  10. Conducting analytical and statistical work to improve our services (using anonymised or aggregated data where possible).

4. Legal Bases for Processing

We process your personal data on the following legal bases under Article 6 of the General Data Protection Regulation (GDPR):

  • Performance of a contract (Art. 6(1)(b) GDPR): Processing necessary to fulfil your order, arrange delivery, manage returns, and provide customer support.
  • Compliance with a legal obligation (Art. 6(1)(c) GDPR): Processing required by applicable tax legislation, accounting rules, and other statutory obligations.
  • Legitimate interests (Art. 6(1)(f) GDPR): Processing for website security, fraud prevention, and service quality improvement, provided that such interests are not overridden by your fundamental rights and freedoms.
  • Consent (Art. 6(1)(a) GDPR): Processing for marketing and promotional communications is carried out solely on the basis of your explicit consent, which you may withdraw at any time without affecting the lawfulness of prior processing.

5. Recipients and Purposes of Data Sharing

Your personal data may be disclosed to third parties only to the extent necessary and for the purposes set out below:

  • Shipping and logistics providers: Your name, delivery address, and telephone number are shared to fulfil and deliver your order.
  • Secure payment infrastructure providers: Data necessary to complete payment transactions securely is transferred; card details are not stored by the Company.
  • Accounting and financial advisory services: To fulfil statutory financial and tax obligations.
  • Cloud computing and SaaS providers: For operating the e-commerce platform, managing orders, and customer relationship management, subject to data processing agreements that ensure appropriate safeguards.
  • E-mail and communication infrastructure providers: To deliver order notifications and customer communications.
  • Competent public authorities: Where required by applicable law or a binding request from a regulatory or law enforcement authority.

Your personal data is never sold, rented, or otherwise transferred to third parties for their own commercial purposes outside the scope described above.

6. International Data Transfers

The Company is based in Türkiye, which the European Commission has not yet issued a formal adequacy decision for. Transfers of personal data outside the European Economic Area (EEA) or the United Kingdom may take place in connection with order management, logistics, payment infrastructure, and cloud-based software services.

Any such international transfer is carried out in compliance with Chapter V of the GDPR and, where applicable, the UK GDPR, using one or more of the following safeguards:

  • An adequacy decision issued by the European Commission or the UK Secretary of State in respect of the recipient country;
  • Standard Contractual Clauses (SCCs) adopted by the European Commission or the equivalent UK International Data Transfer Agreement (IDTA); or
  • Other appropriate safeguards as permitted under applicable data protection law.

All third-party service providers receiving your personal data internationally are contractually and technically bound to maintain its confidentiality and security. You may request further information about the specific safeguards in place by contacting us at the details provided in Section 10.

7. Methods of Data Collection

We collect your personal data through the following methods and channels:

  • Website: Account registration, order forms, contact forms, and newsletter subscription forms.
  • Electronic communications: Requests and correspondence submitted via e-mail, live chat, or other digital communication channels.
  • Automated means: Website usage data collected through cookies, web analytics tools, and server logs.
  • Payment transactions: Transactions processed through our secure payment infrastructure provider.

8. Retention Periods

We retain your personal data only for as long as necessary for the purposes for which it was collected and in accordance with applicable legal requirements. In particular:

  • Order, contract, and invoice data is retained for the periods prescribed by applicable commercial and tax legislation.
  • Customer service correspondence and complaint records are retained for the duration of any applicable limitation period following the resolution of the relevant request.
  • Marketing data is deleted or anonymised promptly upon withdrawal of your consent or unsubscription.
  • Cookie and session data is processed for the periods specified in our Cookie Policy.

Upon expiry of the applicable retention period or once the purpose for processing no longer exists, your personal data is securely deleted, destroyed, or anonymised in accordance with our internal data retention procedures and applicable law.

9. Your Rights as a Data Subject

Under Articles 15–22 of the GDPR, you have the following rights in relation to your personal data:

  1. Right of access (Art. 15): The right to obtain confirmation as to whether your personal data is being processed and, if so, to receive a copy of that data together with related information.
  2. Right to rectification (Art. 16): The right to have inaccurate or incomplete personal data corrected without undue delay.
  3. Right to erasure / "right to be forgotten" (Art. 17): The right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent and there is no other legal basis for processing.
  4. Right to restriction of processing (Art. 18): The right to request that we restrict the processing of your personal data in certain circumstances.
  5. Right to data portability (Art. 20): The right to receive personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
  6. Right to object (Art. 21): The right to object to processing based on legitimate interests or carried out for direct marketing purposes, including profiling.
  7. Right to withdraw consent (Art. 7(3)): Where processing is based on your consent, the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
  8. Right not to be subject to automated decision-making (Art. 22): The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects.
  9. Right to lodge a complaint (Art. 77): The right to lodge a complaint with the supervisory authority in your country of residence, place of work, or the place of the alleged infringement. In the EU/EEA this is your national data protection authority; in the UK it is the Information Commissioner's Office (ICO).

10. How to Exercise Your Rights

To exercise any of the rights set out above, or to ask questions about how we handle your personal data, please contact us using one of the following methods:

  • By e-mail: info@mytinygarden.com — please include sufficient information to verify your identity and describe your request clearly.
  • By post: STARTUP CREATIVE TEKNOLOJİ VE DANIŞMANLIK LİMİTED ŞİRKETİ, Eğitim Mah. Poyraz Sok. No:1/68, Kadıköy, İstanbul, Türkiye.

We will respond to your request without undue delay and in any event within one (1) month of receipt, in accordance with Article 12 GDPR. Where requests are complex or numerous, this period may be extended by a further two months; we will notify you of any such extension within the initial one-month period. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive.

If you are not satisfied with our response, or if we fail to respond within the prescribed period, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction.

11. Cookies

Our website uses cookies and similar tracking technologies to enhance user experience, ensure website functionality, and support analytical purposes. For detailed information about the cookies we use and how to manage your preferences, please refer to our Cookie Policy available on our website.

12. Data Security

The Company implements appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure, in accordance with Article 32 GDPR. All payment transactions are processed through a secure payment infrastructure using SSL/TLS encryption. Card details are not stored by the Company at any point.

13. Updates to This Privacy Notice

This Privacy Notice may be revised from time to time to reflect changes in applicable law or in our data processing practices. The most current version will always be available on our website. Where changes are material, we will make reasonable efforts to inform you prior to the changes taking effect.

Last updated: The date on which this notice was published on our website shall serve as the effective date.

Discover KitsCall Me