Skip to content

Legal

Privacy Notice

This notice describes the information the product actually processes. It is not a consent form and it is not a compliance certificate.

Effective date:
Pending approval
Last updated:
10 October 2026

Back to Legal Overview

Status of this notice

Pending legal review. This page is a draft prepared for SaaSInvader. It is not a claim that the platform is certified or compliant with KVKK, GDPR, or any other law.

Draft date: 10 October 2026. An approved effective date has not been set.

The registered legal name of the operator has not been verified. MHT Software is the trading name shown by the user and on https://www.mhtsoftware.net/. Do not treat that website name as a confirmed registered entity.

The address published on the MHT Software website is Gazi Mustafa Kemalpaşa, Öztrak Cd. No:38 Kat:2 Daire:2, 59500 Çerkezköy/Tekirdağ, Türkiye. It has not been confirmed as the registered office or as the address for legal notices.

Until a dedicated legal, privacy, copyright, or security mailbox is confirmed, notices can be sent to info@mhtsoftware.net. That address is the contact shown on the MHT Software website and has not been separately verified as the official notice address for SaaSInvader.

1. Controller and scope

This notice covers people who visit the site, people with accounts, founders who submit listings, and people who email support. If another organization decides why and how a particular integration works, that organization's notice may also apply. Google and GitHub do that for a sign-in you start with them.

2. Information and where it comes from

Depending on what you use, the product may process:

  • Account identifiers, email address, username, display name, profile picture, biography, and a password hash or an identifier from Google or GitHub.
  • Public posts, comments, uploaded images and videos, SaaS listings, votes, follows, bookmarks, and other community activity you choose to perform.
  • Notification preferences, cookie choices stored in your browser, Terms acceptance records, optional marketing preference, and email you send us.
  • Technical logs needed to run and protect the service, which can include IP address, browser details, timestamps, and security events. A published retention period for those logs has not been audited.
  • Public website information you ask the product to read when you start a listing from a domain.

We do not collect card or payment data. There is no checkout. We do not sell personal information, and this notice does not claim that information is never shared with service providers.

3. Purposes

Registration and sign-in information is used to create and protect accounts and to provide the features you ask for. Posts and listings are published because you submit them. Logs and abuse signals are used to protect accounts and investigate incidents. Consent records remember the Terms version you accepted and, separately, whether you asked for marketing email.

Optional marketing email is sent only if you opt in. Support email is used to answer that request. The precise legal condition for each activity, including the KVKK condition and any GDPR basis, still has to be confirmed. Do not read this notice as saying that every activity is based on consent.

4. Public information

Public profile fields, posts, comments, SaaS listings, images, and other content you place in public areas can be seen without an account and may be indexed by search engines. Vote counts are public. Deleting something on SaaSInvader does not erase copies that other people or search engines already made.

5. Service providers

The application database and uploaded media are stored with Supabase. Transactional email, including verification and password reset, is sent through an SMTP service configured for the operator. The SMTP vendor, the Supabase region, and the transfer paperwork for those providers have not been confirmed in this notice.

Google or GitHub receive the sign-in request only when you choose that provider. Staff can see reports and account records they need in order to moderate or support the product. We may disclose information when the law requires it, to defend rights, or to prevent imminent harm when that is lawful. A corporate transaction is not currently announced.

A complete processor list, with countries and agreements, is pending review. Google Analytics receives page measurements only after a visitor accepts analytics in Cookie settings. No advertising network is connected to the public site.

6. Cross-border transfers

Countries, recipient categories, and the KVKK Article 9 or GDPR Chapter V mechanism are pending a data-mapping review. Accepting the Terms does not make a foreign transfer lawful by itself.

7. Retention

Information is kept while it is needed for the purpose or for a legal obligation, and then deleted, anonymized, or archived. Public content stays until you delete it, a moderator removes it, or the account-closure process changes how it is shown.

Specific periods for application logs, support mail, and backups are not published because they have not been matched to the live jobs and providers. Invented numbers would be misleading.

8. Security

The product uses access control, encrypted transport in production, hashed passwords, HttpOnly session cookies, and database row restrictions. No system is free of incidents. Suspected vulnerabilities can be reported as described on the Security page. Legally required breach notices will be made to the people and authorities the law names. This section does not certify a security standard.

9. Your rights

Depending on the law that applies, you can ask whether your information is processed, ask for access or correction, ask for deletion or anonymization where the conditions are met, learn about recipients, object to certain processing, and withdraw optional consent without undoing processing that was already lawful. KVKK Article 11 and, where it applies, GDPR rights such as portability and restriction are not waived by this notice.

Write to info@mhtsoftware.net from the email on your account, and say which right you are using. A self-service download of your data is not available yet. Account deletion is requested through the Account Deletion page, not by a button that erases the database immediately. You can also contact the supervisory authority that the law gives you.

10. Cookies, children, and automation

Storage and tracking technologies are described in the Cookie Policy. The product is not designed to collect children's information beyond the unsettled age rule in the Terms. If you believe a child has an account, email the contact above.

Discussion and product lists can be ordered with vote counts, recency, and similar engagement signals. Those signals do not, by themselves, suspend an account. Reports are queued for a person to review. No solely automated decision with a legal or similarly significant effect is documented in the current product.

11. Changes

Material changes will be announced in a reasonable way. This page shows the draft date. Older versions should be kept when a version is actually approved and replaced.

Privacy Notice · SaaSInvader