Cimri MCP App Privacy Policy
This policy explains, specifically for the Cimri app used through ChatGPT, Claude, and other MCP-compatible AI assistants, what data is processed, why it is processed, who may receive it, how long it is retained, and the controls available to users.
Last updated: 22 July 2026
1. Scope and controller
This policy applies to the Cimri Model Context Protocol application and embedded interface (the “App”), operated by Cimri Bilgi Teknolojileri ve Sistemleri A.Ş. (“Cimri”, “we”, “us”). Cimri is the data controller for personal data it processes through the App under Türkiye’s Law No. 6698 on the Protection of Personal Data (“KVKK”).
This policy supplements the general Cimri Privacy Policy. Your AI assistant provider separately controls its account, conversation, and platform processing under its own terms.
2. How the App works
The assistant may call one of two read-only tools and sends only the applicable arguments to Cimri’s MCP server. Cimri queries its catalogue and returns the result to the assistant and embedded interface.
search_products: product search text plus optional minimum and maximum prices.get_product_details: a Cimri product ID, normally selected from a search result.
The App cannot place orders, process payments, create accounts, save favourites, send messages, publish content, or modify Cimri or merchant records. Server-side restricted-category filtering is applied to product search results.
3. Data processed, sources, and purposes
| Category | Data and source | Purpose |
|---|---|---|
| Tool inputs | Search text, optional minimum/maximum price, or selected product ID, sent by the assistant from your request. | Run the requested search, apply price and category filters, retrieve a selected product, and respond. |
| Tool outputs | The search response echoes the search term and may include product IDs, titles, URLs, category, images, prices, merchant/offer IDs and names, offer attributes, counts, badges, and specs. Detail responses may also include seller information, sponsored/authorised status, campaigns, instalments, shipping, price history, technical specifications, ratings/comments, and pros/cons. Data comes from Cimri catalogue services. | Display product comparisons, offers, and details in the conversation and interactive UI. |
| Referral and interaction data | Generated only when you open a store link: search term for list links; product, offer, merchant, ranking, price, count, sponsorship, filtering, campaign/instalment, platform and attribution fields; timestamp; and UTM parameters. | Open the selected offer through Cimri, attribute and measure the referral, and redirect to the relevant merchant. |
| Technical/security data | IP address, request time, route, HTTP status, user agent or similar network metadata, and error details, generated by hosting/network systems. | Deliver and secure the App, prevent abuse, investigate errors, maintain availability, and meet legal obligations. |
| Operational metrics | Tool/operation name, status, response duration, counts, and aggregate process health such as memory/event-loop data. Metrics exclude search text, product title, assistant account ID, and full responses. | Monitor reliability, latency, capacity, errors, and service health. |
| Support data | Email address and information you choose to provide when contacting Cimri. | Handle support, privacy, legal, or security requests. |
Data not requested by the App
The tool schemas do not request your name, email, phone, postal address, precise GPS location, assistant account details, payment data, government identifiers, health data, passwords, API keys, authentication secrets, files, contacts, or full conversation history. Free-text searches can nevertheless contain information you voluntarily type. Do not include personal, confidential, payment, health, identity, or authentication information in shopping queries.
4. Legal bases and uses
Cimri processes data where necessary to provide the requested service; for legitimate interests in operating, securing, measuring, debugging, and improving the App without overriding user rights; and to meet legal obligations or establish, exercise, or defend legal claims.
The App does not use tool inputs or outputs for direct marketing, cross-service behavioural advertising, credit scoring, or training Cimri AI models. Cimri does not sell personal data.
5. Recipients and transfers
- AI assistant provider: sends tool arguments and receives tool responses to display the result. The provider independently handles your account and full conversation.
- Cimri systems and authorised personnel: catalogue, API, security, operations, and support functions process data as needed to provide and protect the App.
- Infrastructure providers: hosting, network, CDN, monitoring, and security vendors may process limited request, image-delivery, log, and metrics data for Cimri under confidentiality and security obligations.
- Cimri.com and the merchant you choose: after your click, the referral fields listed above are sent to Cimri; Cimri redirects you to the merchant, which may receive ordinary referral, device, and network data under its own policy. No store link opens without your action.
- Authorities and advisers: where required by law, valid legal process, security needs, or protection of legal rights.
AI assistant and infrastructure providers may operate outside Türkiye. Where Cimri transfers personal data abroad, it uses safeguards and mechanisms required by Article 9 of the KVKK and applicable law. The assistant provider’s independent transfers are governed by its own policy.
6. Retention
| Data | Retention |
|---|---|
| Tool inputs and outputs | Processed transiently. The MCP application does not write them to a persistent application database after the response. They may remain in the assistant’s conversation history under provider settings and policies. |
| Referral and interaction data | Up to 18 months, then deleted or anonymised, unless longer retention is legally required or necessary for an active investigation or claim. |
| Technical, access, security, and error logs | Up to 18 months, then deleted or anonymised, subject to the same legal, security-incident, investigation, and claim exceptions. |
| Operational metrics | Up to 18 months, then deleted or aggregated/anonymised. |
| Support and rights requests | For resolution and applicable statutory limitation, evidence, and legal-compliance periods under Cimri’s general retention rules. |
7. Cookies and storage
The embedded App does not require a Cimri login and does not set Cimri advertising cookies or use local storage for product-search functions. The assistant host controls its own storage. Cimri.com or a merchant may use cookies under its own policy after you follow an external link.
8. Security
Cimri applies safeguards appropriate to the App, including minimised tool schemas, read-only permissions, server-side catalogue access, request timeouts, restricted UI network policies, access controls, monitoring, and security logging. No internet service can guarantee absolute security.
9. User controls
- Do not invoke the App, or ask your assistant not to use Cimri.
- Disconnect the App through assistant settings.
- Control what you include in free-text searches.
- Do not open a store link if you do not want referral data sent to Cimri and the merchant.
- Use assistant-provider controls to manage conversations and connected apps.
- Contact Cimri to exercise applicable data-protection rights.
10. KVKK rights
Under Article 11 of the KVKK, subject to applicable conditions, you may ask whether data is processed; request processing information; learn purposes and recipients in Türkiye or abroad; request correction, deletion, or destruction and notification to recipients; object to an adverse result based exclusively on automated analysis; and seek compensation for unlawful processing.
Requests must contain enough information to verify identity and locate records. Because the App creates no Cimri user account and does not persist tool inputs in an application database, Cimri may have limited ability to associate transient use or aggregated metrics with an individual.
11. Changes
We may update this policy when tool schemas, data practices, or legal requirements change. The current version will remain at this URL with a revised date.
12. Contact
Cimri Bilgi Teknolojileri ve Sistemleri A.Ş.
Kozyatağı Mah. Saniye Ermutlu Sok. No:6, Şaşmaz Plaza, Kat:7,
Kozyatağı – Kadıköy / İstanbul, Türkiye
Email: [email protected]
Telephone: +90 (216) 468 12 80