The bracketed fields will be completed at launch.
In short
We process the data needed to keep your account open, hold the portfolio records you type in, and run the site. We use no advertising network, no tracking pixel, no tag manager and no analytics vendor. We do not sell any data and we do not share it for marketing. The only third-party embed on the site is the TradingView panels, and they do not load at all until you allow them.
1. Who we are
This policy applies to the mergen.finance site. You can reach us about anything to do with the site at info@mergen.finance.
The identity and address of the data controller under KVKK appear on the KVKK Aydınlatma Metni (KVKK information notice) page. They are there because the law requires them to be there.
2. What this policy covers
The site offers: market screens; news summaries written in our own words with a link to the source; readings of KAP disclosures; AI-generated analyst identities and commentary; a portfolio tracker into which you type your own records; and a credit system. The plans are Ücretsiz (free), Mergen and Mergen Pro.
Three things up front, because the rest of this text rests on them:
- There are no passwords. You sign in with a one-time link sent to your email address, or with “continue with Google”. There is no password field anywhere on the site. We store no passwords, because we use none.
- New sign-ups are currently closed. Registration is switched off at the authentication provider level; no new account can be created until launch.
- Payments are not open yet. There is no checkout step on the site and no payment provider is connected. No card or payment information is collected or stored.
3. The data we process
- Account data. Your email address and your display name. If you choose “continue with Google”, your account is matched to the email address Google verifies.
- Usage data the site needs to function. Keeping your session alive, your language and theme choice, and holding your plan and credit balance against your account; alongside that, the technical records that arise while serving requests, as on any web server.
- Portfolio records. Portfolio name, transaction date and type, asset class, symbol, quantity, unit price, currency, commission and your own notes. You enter these. We do not connect to any exchange, bank or wallet account of yours; we do not, and cannot, verify whether the records you enter correspond to real holdings.
- Credit and referral records. Which task you completed and when, the credit you earned, and your credit balance. If you arrived through an invite link, which invite brought you is held in a short-lived cookie in your browser; that cookie carries no identity.
- Newsletter preference. Whether you ticked the newsletter box while signing up. That preference is recorded; as of today no newsletter is being sent.
- Cookies and browser storage. The full list and the durations live on the Cookie Policy page (/cerez-politikasi). We do not copy the list into this text: a table kept in two places eventually drifts apart, and nobody checks the copy that went wrong. The one correct list is there.
What we do not process. No payment or card information is collected or stored. No location data is collected. No special categories of personal data (health, belief, biometrics and so on) are processed. No advertising profile is built. Your data is not sold and is not shared with third parties for marketing.
4. Why we process it, and on what legal basis
- Membership, sign-in, account management, the portfolio tracker, the credit and referral system — necessary for the conclusion and performance of the contract (KVKK art. 5/2-c).
- Security of the service, prevention of abuse and of the same task being credited twice — legitimate interest (KVKK art. 5/2-f).
- Analytics-class cookies and the loading of the TradingView panels — your explicit consent. That consent is given in the site’s cookie banner; without it those panels do not load at all.
- Preference-class cookies — your explicit consent, again through the cookie banner.
- Meeting legal obligations — legal obligation (KVKK art. 5/2-ç).
When newsletter sending begins, separate and explicit consent will be obtained for commercial electronic messages; because nothing is being sent today, this text describes no sending practice.
5. Cookies and cookie consent
The site has a live cookie consent banner, and that banner is the real mechanism for cookie choices. Three classes are defined:
- Zorunlu (strictly necessary) — session, language, security, and the settings you asked for directly. The site does not work without them, so they are not subject to consent.
- Analitik (analytics) — the TradingView panels’ own measurement, and nothing else. It is off until you allow it, and while it is off those panels do not load at all.
- Tercih (preferences) — remembering settings in your browser, such as your currency choice on the commodities page. This class too is genuinely gated on consent.
On the banner, Accept, Reject and the granular Preferences panel are equally reachable; refusing is no harder than accepting. Your choice is kept for 6 months and then we ask again. You can change your mind at any time: the “Cookie preferences” link at the foot of the page reopens the panel.
Which cookie is used for what, which class it belongs to and how long it lasts is set out row by row on the Cookie Policy page.
6. TradingView — the only third-party embed on the site
The chart and economic-calendar panels are provided by TradingView. This is the only third-party embed on the site.
- Those panels do not load at all unless you allow the analytics class. Before you allow it, your browser makes no connection to TradingView.
- If you do allow it, the panel loads directly in your browser. During that direct connection your IP address and browser information reach TradingView, and TradingView sets its own cookies on its own domain (including a Snowplow identifier).
- TradingView processes that data under its own privacy policy: https://www.tradingview.com/privacy-policy/
- If you withdraw your permission, the panels do not load again.
Fonts are served from our own origin; no request goes to Google Fonts or to any other font provider. There is no other measurement tool, pixel, advertising network or tag manager on the site.
7. Service providers and where the data physically sits
We use the following providers to deliver the service. This is the whole list.
- Hetzner Online GmbH — web and API servers. The servers are in Nuremberg, Germany.
- Supabase — membership, database and authentication. Hosted on AWS infrastructure inside the European Union; region: [to be completed at launch]. Your account, portfolio, credit and referral records are held here.
- Resend (over Amazon SES) — sending transactional email such as the sign-in link. The sending infrastructure is in Ireland. Your email address is passed to the provider for this.
- Cloudflare — the edge network in front of the Supabase API endpoint; global.
- Google LLC — only if you choose “continue with Google”, for authentication. Google operates globally, including in the USA.
- TradingView — only if you allow the analytics class (see section 6).
There is no analytics vendor, advertising network, pixel or tag manager on this list, because we use none.
8. Transfers abroad (KVKK art. 9)
Let us be plain: our servers being in Germany and in the EU is itself a transfer abroad under KVKK. Data resting in Europe does not make it data kept inside Türkiye; our old text did not present this as a transfer, and this text does.
- Hosting, membership infrastructure and transactional email (Hetzner, Supabase, Resend/Amazon SES, Cloudflare) — the transfer is necessary for the contractual performance of the service we provide to you (KVKK art. 5/2-c). Without these providers your account cannot exist.
- The analytics class (TradingView) — this transfer rests solely on the explicit consent you give in the cookie banner. If you do not allow it, the transfer never happens.
- Sign in with Google — happens only if you choose that method yourself; Google operates globally, including in the USA.
There is no separate consent checkbox at sign-up for transfers abroad. In reality there are two acts: creating your account, and your choice in the cookie banner. This text relies on those two and nothing else.
You will find the detailed breakdown in the KVKK Aydınlatma Metni; the two texts use the same legal bases.
9. Retention periods
- Account data (email, display name, plan): for as long as your account exists.
- Portfolio records: until you delete them or your account is closed.
- Credit ledger and referral records: for as long as your account exists — they are needed to stop the same task being credited a second time.
- Newsletter preference: for as long as your account exists, or until you withdraw it.
- Server access logs (IP address, browser information, requested address): 14 days. That period was measured on the server itself rather than read off a configuration file: the nginx logs are rotated daily and 14 copies are kept, and as of 30 August 2026 the oldest surviving file is dated 16 August 2026. Application logs are additionally written to journald; those are bounded by size rather than by time (1 GB at most). That bound is currently full and its oldest entry is also 16 August 2026 — so, today, the same 14-day window. If the volume of logging rises that window shortens; if it falls, it lengthens.
- Cookies and browser storage: the duration written next to each row in the Cookie Policy applies. We do not repeat those durations here; the one correct list is there.
Let us be plain: there is not yet an automated job that deletes data when its period expires. The principle we apply is this — data is deleted when the purpose of processing has fallen away and any statutory retention obligation has ended. This text will be updated when automated deletion is in place.
If you want your account and records deleted, writing to info@mergen.finance is enough. There is currently no self-service delete button on the site, so the request is carried out by hand. When an account is deleted, the records attached to it (portfolio, credit ledger, referral record) are deleted with it.
10. Your rights
Under KVKK art. 11 you have the right to learn whether your data is being processed, to request information about it, to have it corrected, to request its deletion, to know the third parties it has been transferred to, to withdraw your explicit consent, and to complain to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurulu).
The full list of rights and how to make an application are on the KVKK Aydınlatma Metni page. For requests: info@mergen.finance. Your application is concluded within thirty days at the latest.
You do not need to make an application to take back your cookie choice: the “Cookie preferences” link at the foot of the page is enough.
11. Security
Without overstating it:
- We use no passwords, so there is no password database of ours to leak. Sign-in is by one-time email link or with Google.
- Site and API traffic is encrypted in transit with TLS.
- Row-level access rules apply in the database: you cannot read anyone’s records but your own.
- The security of your account depends largely on the security of your mailbox; the sign-in link goes there.
Absolute security cannot be promised for any system, and we do not promise it.
12. Children
The site is not aimed at anyone under 18, and we do not knowingly collect data from anyone under that age.
13. Changes to this text
This text is updated when the data we process, the providers we use or the cookie classes change. If the scope of the cookie classes changes, the question in the cookie banner is asked again — we do not add something new without asking.
14. Contact
info@mergen.finance
15. Governing text
The Turkish version of this policy governs. The English translation is provided for convenience only; if the two differ, the Turkish text prevails.