Bu Kullanım Şartları (“Şartlar”), [Şirket Unvanı] (“İşletmeci”, “biz”) tarafından [alan adı] adresinde işletilen MercanPay kripto ödeme altyapısının (“Hizmet”) kullanımına ilişkin koşulları düzenler. İşletmeci bilgileri: adres [Adres], MERSİS No [MERSİS No], vergi dairesi ve numarası [Vergi Dairesi / No], iletişim [iletişim e-postası].
Satıcı hesabı oluşturarak, Hizmet’e API ile bağlanarak ya da Hizmet’i başka bir şekilde kullanarak bu Şartları, Gizlilik Politikası’nı ve Çerez Politikası’nı okuduğunuzu ve kabul ettiğinizi beyan edersiniz. Kabul ettiğiniz Şartlar sürümü ve kabul tarihi hesabınızda kayıt altına alınır.
Tanımlar
Satıcı: Hizmet’e kayıt olan ve onaylanan gerçek ya da tüzel kişi ile onun adına işlem yapmaya yetkili kişiler.
Müşteri: Satıcıya ödeme yapmak için ödeme sayfasını ya da ödeme adresini kullanan kişi.
Fatura: Satıcının panel ya da API aracılığıyla oluşturduğu, tutarı, coin’i ve geçerlilik süresi belirli ödeme talebi.
Bakiye: Onaylanan ödemelerden komisyon düşüldükten sonra Satıcı adına kaydedilen, çekilebilir tutar.
Çekim: Bakiyenin Satıcının belirttiği TRON adresine blokzincir işlemiyle gönderilmesi.
Ağ: Hizmet’in çalıştığı TRON ağı; gerçek değer taşıyan ana ağ (mainnet) ya da yalnızca deneme amaçlı test ağı (testnet, ör. Nile veya Shasta).
Ağ ücreti: Blokzincir işlemlerinin gerçekleştirilmesi için TRON ağında tüketilen enerji, bant genişliği ya da TRX bedeli.
Hizmetin tanımı
MercanPay; TRON blokzinciri üzerinde TRX ve USDT (TRC20) ile ödeme kabul etmeyi sağlayan, işletmecinin kendi sunucularında çalışan bir ödeme altyapısıdır. Hizmet kapsamında fatura ve ödeme linki oluşturma, barındırılan ödeme sayfası, REST API, imzalı webhook bildirimleri, satıcı paneli, bakiye takibi ve çekim işlemleri sunulur.
Ödemeler, Hizmet’in belirlediği sayıda blok onayı alındıktan sonra kesinleşmiş kabul edilir ve Bakiyenize yansıtılır. Hizmet bir banka hesabı, mevduat, yatırım ya da saklama (custody) ürünü değildir; Bakiyeye faiz ya da getiri işlemez. İşletmeci, Satıcı ile Müşteri arasındaki satış ilişkisinin tarafı değildir; ürün ya da hizmetin teslimi, iadesi ve tüketici hukukundan doğan yükümlülükler Satıcıya aittir.
Test ağı: Hizmet test ağında çalışıyorsa sayfalarda bu açıkça belirtilir. Test ağındaki varlıkların gerçek bir değeri yoktur, ana ağa aktarılamaz ve test işlemleri hiçbir alacak ya da hak doğurmaz.
Uygunluk ve satıcı onayı
Hizmet’i yalnızca 18 yaşını doldurmuş, fiil ehliyetine sahip kişiler ve tüzel kişileri temsile yetkili kişiler kullanabilir.
Kayıt sırasında verdiğiniz bilgilerin doğru, güncel ve eksiksiz olması gerekir. Bilgilerinizde değişiklik olursa panelden güncellemeniz ya da bize bildirmeniz gerekir.
Hesap açmak için kimlik doğrulaması (KYC) yapmanız ya da belge yüklemeniz istenmez; kayıt e-posta adresinizle tamamlanır ve başvurunuz kısa bir incelemenin ardından onaylanır.
Bununla birlikte İşletmeci; yasal yükümlülükleri, yetkili makamların talepleri, şüpheli işlem tespiti ya da risk değerlendirmesi gerektirdiğinde ek bilgi veya belge (ör. kimlik, vergi levhası, faaliyet belgesi, web sitesi bilgileri) talep etme ve başvuruyu gerekçe göstermeksizin reddetme hakkını saklı tutar.
Hesabınız onaylanmadan fatura oluşturma, API anahtarı üretme ve çekim gibi özellikler kullanılamaz.
Hesap güvenliği
Hesabınızın ve API anahtarlarınızın güvenliğinden siz sorumlusunuz. Hizmet, hesabınızı korumak için aşağıdaki önlemleri uygular; bu önlemleri devre dışı bırakmaya ya da atlatmaya çalışmamayı kabul edersiniz:
E-posta doğrulama kodları: Kayıt, giriş ve hassas işlemlerde e-posta adresinize tek kullanımlık kod gönderilebilir.
İki adımlı doğrulama (2FA): Authenticator uygulaması (TOTP) ile iki adımlı doğrulamayı etkinleştirebilir, girişte hangi yöntemlerin isteneceğini seçebilirsiniz. Çekimler e-posta kodu ve etkinse Authenticator kodu ile onaylanır.
Oturumlar: Oturumunuz en fazla 7 gün açık kalır. Şifreniz değiştirildiğinde ya da sıfırlandığında tüm açık oturumlar kapatılır.
Şifre sıfırlama sonrası çekim kilidi: Şifreniz sıfırlandığında ya da benzeri hassas güvenlik değişikliklerinden sonra, hesabınızın ele geçirilme riskine karşı çekimler 24 saat süreyle kilitlenir.
Kayıtlı adresler: Çekimlerin yalnızca kayıtlı adreslerinize yapılmasını zorunlu tutabilirsiniz; yeni adres eklendiğinde e-posta ile bilgilendirilirsiniz.
Yönetici incelemesi: Belirli tutarın üzerindeki ya da risk sinyali taşıyan çekimler, gönderilmeden önce İşletmeci tarafından incelenebilir, bekletilebilir ya da reddedilebilir.
Güvenlik bildirimleri: Şifre değişikliği, 2FA açma/kapama ve yeni adres ekleme gibi olaylar e-posta ile bildirilir.
Hesabınızın yetkisiz kullanıldığından şüphelenirseniz derhal şifrenizi değiştirmeli, API anahtarlarınızı iptal etmeli ve [iletişim e-postası] adresine bildirmelisiniz. Kimlik bilgilerinizin sizin kusurunuzla üçüncü kişilerin eline geçmesinden doğan zararlardan İşletmeci sorumlu değildir.
Faturalar, ödemeler ve bakiye
Faturalar belirli bir süre geçerlidir. USD olarak fiyatlandırılan faturalarda kur, Müşteri coin’i seçtiği anda sabitlenir.
Eksik ödemeler “kısmi”, fazla ödemeler “fazla ödendi” olarak işaretlenir; gelen tutarın tamamı Bakiyenize işlenir ve durum webhook ile bildirilir. Müşteriyle arasındaki fark ya da iade Satıcının sorumluluğundadır.
Fatura süresi dolduktan sonra, desteklenmeyen bir token ile ya da TRON dışı bir ağdan gönderilen ödemeler otomatik olarak işlenmeyebilir ve kurtarılamayabilir.
Webhook bildirimleri yeniden denenerek iletilir; ancak kesintisiz teslim garanti edilmez. Sipariş durumunu API üzerinden doğrulamanız ve webhook imzalarını kontrol etmeniz gerekir.
Hatalı ya da mükerrer kayıt tespit edilmesi hâlinde İşletmeci, Bakiyede gerekli düzeltmeyi yapma hakkını saklı tutar.
Ücretler
Platform komisyonu: Yalnızca onaylanan ödemelerden, fiyat sayfasında ya da panelinizde gösterilen yüzde oranında ([ör. %1]) kesilir. Size özel bir oran tanımlanmışsa o oran geçerlidir.
Çekim ve ağ ücretleri: Çekimlerde panelde gösterilen sabit ağ ücreti uygulanır. Müşterinin ödeme yaparken ödediği ağ ücretleri Müşteriye aittir.
Kurulum, aylık abonelik ya da gizli ücret alınmaz.
Ücretlerde yapılacak artışlar yürürlükten en az [30] gün önce e-posta ya da panel üzerinden bildirilir.
Satıcının gelirlerinden doğan vergi, harç ve diğer mali yükümlülükler Satıcıya aittir.
Çekimler
Bakiyenizi panelde belirtilen asgari tutar ve kurallar çerçevesinde TRON adresinize çekebilirsiniz. Alıcı adresin doğruluğundan, adresin TRON ağına ait olmasından ve adresin sizin kontrolünüzde bulunmasından yalnızca siz sorumlusunuz. Blokzincire gönderilmiş bir çekim geri alınamaz.
İşletmeci; hesap güvenliği, yasal yükümlülük, yetkili makam talebi, yaptırım taraması ya da Şartlara aykırılık şüphesi hâlinde bir çekimi inceleme süresince bekletebilir, ek bilgi isteyebilir ya da reddedebilir. Reddedilen çekimin tutarı Bakiyenize iade edilir.
Yasaklı faaliyetler
Hizmet aşağıdaki amaçlarla ya da aşağıdaki faaliyetlerle bağlantılı olarak kullanılamaz:
Suç gelirlerinin aklanması, terörün finansmanı ya da bu amaçlara yönelik işlemler (5549 sayılı Suç Gelirlerinin Aklanmasının Önlenmesi Hakkında Kanun ve ilgili mevzuat dahil);
Birleşmiş Milletler, Türkiye Cumhuriyeti, Avrupa Birliği ya da ABD (OFAC) yaptırım listelerinde yer alan kişi, kuruluş veya bölgelerle işlem;
Uyuşturucu, silah, patlayıcı, sahte ya da çalıntı ürün, kişisel veri ticareti, çocuk istismarı içeren ya da hukuka aykırı her türlü mal ve hizmet;
İzinsiz şans oyunları ve bahis, piramit/saadet zinciri, dolandırıcılık, kimlik avı ve yanıltıcı ticari uygulamalar;
Fikri mülkiyet haklarını ihlal eden ürünler, kaynağı belirsiz fonların karıştırılması (mixer/tumbler) hizmetleri;
Hizmet’in güvenliğini tehdit eden, aşırı yük oluşturan, tersine mühendislik yapan ya da sistemlere yetkisiz erişim sağlamaya çalışan her türlü girişim.
İşletmeci, şüpheli işlemleri yetkili mercilere bildirme, ilgili kayıtları saklama ve yetkili makamların hukuka uygun taleplerini yerine getirme hakkını ve yükümlülüğünü saklı tutar.
Kripto varlık riskleri
Geri alınamazlık: Blokzincir işlemleri onaylandıktan sonra geri alınamaz, iptal edilemez ve ters ibraz (chargeback) yapılamaz.
Yanlış adres ya da ağ: Yanlış adrese, farklı bir ağa (ör. ERC20, BEP20) ya da desteklenmeyen bir token ile yapılan gönderimler kalıcı olarak kaybolabilir.
Fiyat oynaklığı: TRX gibi kripto varlıkların değeri kısa sürede önemli ölçüde değişebilir. USDT gibi sabit değerli token’lar ihraççı ve piyasa risklerine tabidir.
Ağ riskleri: TRON ağındaki tıkanıklık, kesinti, çatallanma (fork), ücret değişiklikleri ya da protokol güncellemeleri işlemleri geciktirebilir veya maliyetini artırabilir.
Düzenleyici riskler: Kripto varlıklara ilişkin mevzuat değişebilir. Satıcı, kendi faaliyetine uygulanan mevzuata (6362 sayılı Sermaye Piyasası Kanunu’nda 7518 sayılı Kanun ile yapılan değişiklikler ve ilgili düzenlemeler dahil) uymaktan kendisi sorumludur.
Fikri mülkiyet
Hizmet’e ait yazılım, arayüz, tasarım, marka ve dokümantasyon üzerindeki haklar İşletmeciye ya da lisans verenlerine aittir. Size, bu Şartlar süresince Hizmet’i amacına uygun kullanmanız için sınırlı, devredilemez ve münhasır olmayan bir kullanım hakkı tanınır. Satıcı, kendi marka ve logosunu ödeme sayfasında gösterilmek üzere yüklediğinde, İşletmeciye bu amaçla sınırlı bir kullanım izni verir.
Kişisel veriler
Kişisel verileriniz Gizlilik Politikası uyarınca 6698 sayılı Kişisel Verilerin Korunması Kanunu’na uygun olarak işlenir. Satıcı, Müşterilerine ait verileri (ör. sipariş bilgileri) Hizmet’e aktarırken kendi aydınlatma ve hukuka uygunluk yükümlülüklerini yerine getirmekle sorumludur.
Sorumluluğun sınırlandırılması
Hizmet “olduğu gibi” ve “mevcut olduğu şekilde” sunulur. İşletmeci Hizmet’in kesintisiz, hatasız ya da belirli bir amaca uygun olacağını garanti etmez. Yürürlükteki mevzuatın izin verdiği ölçüde:
İşletmeci; kâr kaybı, veri kaybı, itibar kaybı ya da dolaylı zararlardan sorumlu değildir.
Blokzincir ağından, üçüncü taraf cüzdan ve altyapı sağlayıcılarından, Satıcının ya da Müşterinin hatalı işleminden (yanlış adres, yanlış ağ vb.) kaynaklanan zararlardan sorumluluk kabul edilmez.
Her hâlükârda İşletmecinin toplam sorumluluğu, zarara yol açan olaydan önceki 12 ay içinde Satıcının İşletmeciye ödediği komisyon tutarıyla sınırlıdır.
Bu sınırlamalar, İşletmecinin kast ya da ağır ihmalinden doğan sorumluluğunu ve kanunen sınırlandırılamayan diğer sorumlulukları kapsamaz. Doğal afet, savaş, salgın, siber saldırı, enerji ya da iletişim altyapısındaki kesinti ve resmî makam kararları gibi mücbir sebep hâllerinde taraflar yükümlülüklerinden sorumlu tutulamaz.
Tazminat
Satıcı; bu Şartları, mevzuatı ya da üçüncü kişilerin haklarını ihlal etmesi nedeniyle İşletmeciye yöneltilecek talep, idari para cezası ve zararlardan doğan makul masrafları (avukatlık ücretleri dahil) İşletmeciye ödemeyi kabul eder.
Askıya alma ve fesih
Satıcı, hesabını dilediği zaman kapatma talebinde bulunabilir. Kapatmadan önce Bakiyesini çekmesi gerekir.
İşletmeci; Şartlara aykırılık, yasal zorunluluk, yetkili makam talebi, dolandırıcılık ya da güvenlik riski şüphesi hâllerinde hesabı, API anahtarlarını ya da çekimleri geçici olarak askıya alabilir veya sözleşmeyi feshedebilir.
Fesih hâlinde, hukuka aykırılık ya da yasal bir engel bulunmadıkça Bakiye, Satıcının doğrulanmış TRON adresine ağ ücreti düşülerek gönderilir.
Fesihten sonra da mevzuatın öngördüğü süreler boyunca kayıtlar saklanır; nitelikleri gereği fesihten sonra da geçerli olması gereken hükümler yürürlükte kalır.
Değişiklikler
İşletmeci bu Şartları güncelleyebilir. Güncel sürüm bu sayfada yürürlük tarihiyle yayımlanır. Haklarınızı esaslı şekilde etkileyen değişiklikler, yürürlüğe girmeden makul bir süre önce e-posta ya da panel üzerinden bildirilir ve gerektiğinde yeniden onayınız istenir. Değişiklikten sonra Hizmet’i kullanmaya devam etmeniz, güncel Şartları kabul ettiğiniz anlamına gelir.
Uygulanacak hukuk ve yetkili mahkeme
Bu Şartlar Türkiye Cumhuriyeti hukukuna tabidir. Şartlardan doğan uyuşmazlıklarda İstanbul (Çağlayan) Mahkemeleri ve İcra Daireleri yetkilidir. Satıcının tüketici sıfatını taşıdığı hâllerde 6502 sayılı Tüketicinin Korunması Hakkında Kanun’dan doğan haklar ve tüketici hakem heyetleri ile tüketici mahkemelerine başvuru hakkı saklıdır. İşletmecinin defter, kayıt ve sistem kayıtları, HMK md. 193 uyarınca kesin delil niteliğindedir.
İletişim
Bu Şartlarla ilgili sorularınız için: [Şirket Unvanı], [Adres], e-posta [iletişim e-postası].
Yürürlük tarihi: 28 Eylül 2026 · Sürüm 2026-09-28
Parties and scope
These Terms of Service (“Terms”) govern the use of the MercanPay crypto payment infrastructure (the “Service”) operated by [Company Name] (the “Operator”, “we”) at [domain]. Operator details: address [Address], MERSIS No. [MERSIS No], tax office and number [Tax Office / No], contact [contact email].
By creating a merchant account, connecting to the Service through the API or otherwise using the Service, you confirm that you have read and accept these Terms, the Privacy Policy and the Cookie Policy. The version of the Terms you accepted and the time of acceptance are recorded on your account.
This English version is provided for convenience. If there is any conflict, the Turkish version prevails.
Definitions
Merchant: an individual or legal entity that has registered and been approved for the Service, and anyone authorised to act on its behalf.
Customer: a person who uses the payment page or payment address to pay a Merchant.
Invoice: a payment request created by the Merchant through the panel or the API, with a set amount, coin and validity period.
Balance: the withdrawable amount recorded for the Merchant from confirmed payments, after fees.
Withdrawal: sending the Balance to a TRON address specified by the Merchant through a blockchain transaction.
Network: the TRON network the Service runs on: either the value-bearing main network (mainnet) or a test network used only for testing (testnet, e.g. Nile or Shasta).
Network fee: the energy, bandwidth or TRX consumed on the TRON network to carry out blockchain transactions.
The Service
MercanPay is a payment infrastructure running on the Operator’s own servers that lets merchants accept TRX and USDT (TRC20) on the TRON blockchain. The Service includes invoices and payment links, a hosted payment page, a REST API, signed webhook notifications, a merchant panel, balance tracking and withdrawals.
Payments are treated as final once the number of block confirmations set by the Service has been reached, and are then credited to your Balance. The Service is not a bank account, deposit, investment or custody product, and no interest or yield accrues on the Balance. The Operator is not a party to the sale between the Merchant and the Customer; delivery, refunds and any consumer-law obligations are the Merchant’s responsibility.
Testnet: when the Service runs on a test network, this is clearly shown on its pages. Testnet assets have no real value, cannot be moved to mainnet, and test transactions create no claims or rights.
Eligibility and merchant approval
Only persons aged 18 or over with full legal capacity, and persons authorised to represent a legal entity, may use the Service.
The information you give at sign-up must be accurate, current and complete. If it changes, you must update it in the panel or tell us.
No identity verification (KYC) or document upload is required to open an account; you sign up with your email address and your application is approved after a short review.
However, where its legal obligations, requests from competent authorities, the detection of suspicious activity or a risk assessment require it, the Operator reserves the right to request additional information or documents (e.g. ID, tax certificate, business registration, website details) and to decline an application without giving reasons.
Until your account is approved, features such as creating invoices, generating API keys and withdrawing are unavailable.
Account security
You are responsible for keeping your account and API keys secure. The Service applies the following safeguards, and you agree not to disable or try to bypass them:
Email verification codes: one-time codes may be sent to your email address at sign-up, log-in and for sensitive actions.
Two-factor authentication (2FA): you can enable 2FA with an authenticator app (TOTP) and choose which methods are required at log-in. Withdrawals are confirmed with an email code and, where enabled, an authenticator code.
Sessions: a session stays open for at most 7 days. When your password is changed or reset, all open sessions are signed out.
Withdrawal lock after a password reset: after a password reset or similar sensitive security change, withdrawals are locked for 24 hours to protect against account takeover.
Saved addresses: you can require withdrawals to go only to your saved addresses; you are notified by email whenever a new address is added.
Admin review: withdrawals above a certain amount or showing risk signals may be reviewed, held or rejected by the Operator before they are sent.
Security notifications: events such as password changes, enabling or disabling 2FA and adding new addresses are notified by email.
If you suspect unauthorised use of your account, change your password immediately, revoke your API keys and notify [contact email]. The Operator is not liable for losses caused by your credentials reaching third parties through your own fault.
Invoices, payments and balance
Invoices are valid for a limited time. For invoices priced in USD, the rate is locked when the Customer picks a coin.
Underpayments are marked “partial” and overpayments “overpaid”; everything received is credited to your Balance and the status is sent by webhook. Settling any difference or refund with the Customer is the Merchant’s responsibility.
Payments sent after an invoice has expired, with an unsupported token, or from a network other than TRON may not be processed automatically and may be unrecoverable.
Webhook notifications are retried, but uninterrupted delivery is not guaranteed. You should verify order status through the API and check webhook signatures.
If an erroneous or duplicate entry is found, the Operator reserves the right to correct the Balance accordingly.
Fees
Platform fee: charged only on confirmed payments, at the percentage shown on the pricing page or in your panel ([e.g. 1%]). If a custom rate is set for you, that rate applies.
Withdrawal and network fees: withdrawals carry the flat network fee shown in the panel. Network fees paid by the Customer when paying are borne by the Customer.
There are no setup, monthly subscription or hidden fees.
Fee increases are announced by email or in the panel at least [30] days before they take effect.
Taxes, duties and other fiscal obligations arising from the Merchant’s income are the Merchant’s responsibility.
Withdrawals
You may withdraw your Balance to your TRON address, subject to the minimum amounts and rules shown in the panel. You alone are responsible for the recipient address being correct, being a TRON address and being under your control. A withdrawal broadcast to the blockchain cannot be reversed.
For account security, legal obligations, requests from competent authorities, sanctions screening or suspected breaches of these Terms, the Operator may hold a withdrawal during review, request additional information or reject it. The amount of a rejected withdrawal is returned to your Balance.
Prohibited activities
The Service may not be used for, or in connection with:
money laundering, terrorist financing or transactions serving those purposes (including under Turkish Law No. 5549 on the Prevention of Laundering Proceeds of Crime and related legislation);
dealings with persons, entities or regions on United Nations, Republic of Türkiye, European Union or US (OFAC) sanctions lists;
drugs, weapons, explosives, counterfeit or stolen goods, trade in personal data, child abuse material, or any other unlawful goods and services;
unlicensed gambling and betting, pyramid or Ponzi schemes, fraud, phishing and misleading commercial practices;
products infringing intellectual property rights, or services that mix funds of unclear origin (mixers/tumblers);
any attempt to threaten the security of the Service, overload it, reverse-engineer it or gain unauthorised access to its systems.
The Operator reserves the right and the obligation to report suspicious transactions to the competent authorities, keep the relevant records and comply with lawful requests from authorities.
Crypto-asset risks
Irreversibility: once confirmed, blockchain transactions cannot be reversed, cancelled or charged back.
Wrong address or network: funds sent to a wrong address, over a different network (e.g. ERC20, BEP20) or with an unsupported token may be lost permanently.
Volatility: the value of crypto assets such as TRX can change significantly in a short time. Stablecoins such as USDT are subject to issuer and market risks.
Network risks: congestion, outages, forks, fee changes or protocol upgrades on the TRON network may delay transactions or make them more expensive.
Regulatory risks: crypto-asset legislation may change. The Merchant is responsible for complying with the rules that apply to its own business (including the amendments made to Capital Markets Law No. 6362 by Law No. 7518 and related regulations).
Intellectual property
All rights in the software, interface, design, trademarks and documentation of the Service belong to the Operator or its licensors. For the term of these Terms you receive a limited, non-transferable, non-exclusive right to use the Service for its intended purpose. When a Merchant uploads its own brand name and logo for display on the payment page, it grants the Operator a limited licence for that purpose.
Personal data
Your personal data is processed under the Privacy Policy in accordance with Turkish Personal Data Protection Law No. 6698 (KVKK). When a Merchant passes its Customers’ data (e.g. order details) to the Service, the Merchant is responsible for meeting its own notice and lawfulness obligations.
Limitation of liability
The Service is provided “as is” and “as available”. The Operator does not warrant that the Service will be uninterrupted, error-free or fit for a particular purpose. To the extent permitted by applicable law:
the Operator is not liable for loss of profit, data or reputation, or for indirect damages;
no liability is accepted for losses caused by the blockchain network, third-party wallet or infrastructure providers, or by mistakes of the Merchant or Customer (wrong address, wrong network, etc.);
in any case, the Operator’s total liability is limited to the fees the Merchant paid to the Operator in the 12 months before the event giving rise to the claim.
These limitations do not cover liability for the Operator’s intent or gross negligence, or any other liability that cannot be limited by law. Neither party is liable for failures caused by force majeure, such as natural disasters, war, pandemics, cyber-attacks, power or telecommunications outages and decisions of public authorities.
Indemnity
The Merchant agrees to reimburse the Operator for reasonable costs (including legal fees) arising from claims, administrative fines and damages brought against the Operator because the Merchant breached these Terms, the law or the rights of third parties.
Suspension and termination
The Merchant may ask to close its account at any time and should withdraw its Balance before doing so.
The Operator may temporarily suspend the account, API keys or withdrawals, or terminate the agreement, in the event of a breach of these Terms, a legal requirement, a request from a competent authority, or suspected fraud or security risk.
On termination, unless there is unlawfulness or a legal impediment, the Balance is sent to the Merchant’s verified TRON address less the network fee.
Records are kept after termination for the periods required by law; provisions that by their nature should survive termination remain in force.
Changes
The Operator may update these Terms. The current version is published on this page with its effective date. Changes that materially affect your rights are announced by email or in the panel a reasonable time before they take effect and, where required, your renewed acceptance is requested. Continuing to use the Service after a change means you accept the updated Terms.
Governing law and jurisdiction
These Terms are governed by the laws of the Republic of Türkiye. The Courts and Enforcement Offices of İstanbul (Çağlayan) have jurisdiction over disputes arising from these Terms. Where the Merchant is a consumer, its rights under Consumer Protection Law No. 6502, including applying to consumer arbitration committees and consumer courts, are reserved. The Operator’s books, records and system logs constitute conclusive evidence under Article 193 of the Turkish Code of Civil Procedure.
Contact
For questions about these Terms: [Company Name], [Address], email [contact email].
Effective date: 28 September 2026 · Version 2026-09-28
Veri sorumlusu
Bu Gizlilik Politikası ve Kişisel Verilerin İşlenmesine İlişkin Aydınlatma Metni, 6698 sayılı Kişisel Verilerin Korunması Kanunu (“KVKK”) md. 10 ve Aydınlatma Yükümlülüğünün Yerine Getirilmesinde Uyulacak Usul ve Esaslar Hakkında Tebliğ uyarınca hazırlanmıştır.
Veri sorumlusu
[Şirket Unvanı]
Adres
[Adres]
MERSİS No
[MERSİS No]
E-posta
[iletişim e-postası]
KEP adresi
[KEP adresi]
VERBİS kaydı
[VERBİS kayıt bilgisi / muafiyet durumu]
Kapsam
Bu metin; MercanPay satıcıları ve yetkilileri, ödeme sayfasını kullanan müşteriler, API ve webhook entegrasyonları üzerinden verisi iletilen kişiler ile web sitemizi ziyaret eden kişilerin kişisel verilerinin nasıl işlendiğini açıklar. Satıcının kendi müşterilerine karşı yükümlülükleri bakımından Satıcı ayrıca kendi aydınlatma metnini sunmakla sorumludur.
İşlenen kişisel veriler
Kategori
Veriler
İlgili kişi
Kimlik
Ad soyad, işletme adı, (gerekirse) kimlik ve vergi bilgileri
Satıcı / yetkili
İletişim
E-posta adresi, yazışma içerikleri
Satıcı / yetkili
Müşteri işlem
Fatura tutarı, coin, sipariş numarası, açıklama, dönüş adresleri, ödeme durumu, webhook teslim kayıtları
Satıcı, müşteri
Finansal / blokzincir
Ödeme ve çekim cüzdan adresleri, kayıtlı adresler, işlem özetleri (txid), tutarlar, bakiye hareketleri, blokzincirden okunan herkese açık işlem verileri
Satıcı, müşteri
İşlem güvenliği
IP adresi, cihaz ve tarayıcı bilgisi (user-agent), oturum ve giriş kayıtları, başarısız giriş denemeleri, 2FA durumu, şifrelenmiş Authenticator anahtarı, denetim (audit) kayıtları, bot koruma doğrulama sonuçları
Tüm kullanıcılar
Hukuki işlem
Kabul edilen şartların sürümü ve tarihi, talepler, şikâyetler ve bunlara ilişkin yazışmalar
Satıcı / yetkili
Görsel
Satıcının yüklediği logo (kişisel veri içermesi hâlinde)
Satıcı
Blokzincir verileri hakkında: TRON ağına kaydedilen adresler, tutarlar ve işlem özetleri herkese açıktır ve niteliği gereği blokzincirden silinemez ya da değiştirilemez. Bu veriler kimliğinizle ilişkilendirilebildiği ölçüde kişisel veri sayılır; biz yalnızca kendi sistemlerimizdeki kayıtları silebilir ya da anonim hâle getirebiliriz.
Özel nitelikli kişisel veri (sağlık, biyometrik vb.) talep etmiyor ve işlemiyoruz. Pazarlama amaçlı profil oluşturmuyor, verilerinizi satmıyoruz.
İşleme amaçları
Satıcı başvurusunun alınması, değerlendirilmesi ve hesabın oluşturulması;
Fatura, ödeme sayfası, API, webhook, bakiye ve çekim hizmetlerinin sunulması;
Ödemelerin blokzincirde izlenmesi, doğrulanması ve kayıt altına alınması;
Hesap güvenliğinin sağlanması: kimlik doğrulama, iki adımlı doğrulama, oturum yönetimi, şüpheli giriş ve işlemlerin tespiti, çekim incelemesi;
Dolandırıcılık, kara para aklama ve terörün finansmanının önlenmesi, yaptırım taraması;
Hizmete ilişkin bildirimlerin (güvenlik uyarıları, ödeme ve çekim bildirimleri, şart değişiklikleri) gönderilmesi;
Talep ve şikâyetlerin yanıtlanması, destek sağlanması;
Muhasebe, faturalama ve yasal saklama yükümlülüklerinin yerine getirilmesi; yetkili kurum ve kuruluşlara bilgi verilmesi;
Hukuki uyuşmazlıklarda hakların tesisi, kullanılması ve korunması.
Hukuki sebepler
Kişisel verileriniz KVKK md. 5/2 kapsamında aşağıdaki hukuki sebeplere dayanılarak işlenir:
(c) Sözleşmenin kurulması veya ifası: hesap açma, ödeme ve çekim işlemleri, bildirimler;
(ç) Hukuki yükümlülüğün yerine getirilmesi: 5549 sayılı Kanun, 213 sayılı Vergi Usul Kanunu, 6102 sayılı Türk Ticaret Kanunu ve ilgili mevzuattan doğan kayıt ve bildirim yükümlülükleri;
(d) İlgili kişinin kendisi tarafından alenileştirilmiş olması: blokzincire yazılmış herkese açık işlem verileri;
(e) Bir hakkın tesisi, kullanılması veya korunması: uyuşmazlık, şikâyet ve denetim süreçleri;
(f) Meşru menfaat: sistem ve hesap güvenliği, dolandırıcılığın önlenmesi, denetim kayıtları, hizmetin iyileştirilmesi — temel hak ve özgürlüklerinize zarar vermemek kaydıyla.
Tema ve dil tercihinizin cihazınızda kalıcı olarak saklanması gibi zorunlu olmayan işlemler için onayınıza başvururuz (bkz. Çerez Politikası).
Toplama yöntemi
Verileriniz; kayıt ve giriş formları, satıcı paneli, API istekleri, ödeme sayfası, e-posta yazışmaları, çerezler ve benzeri teknolojiler aracılığıyla otomatik ya da kısmen otomatik yollarla; blokzincir verileri ise TRON ağından (doğrudan ya da blokzincir API sağlayıcıları aracılığıyla) elde edilir.
Aktarım
Kişisel verileriniz, yukarıdaki amaçlarla sınırlı ve ölçülü olarak şu alıcı gruplarına aktarılabilir:
Yetkili kamu kurum ve kuruluşları: Mali Suçları Araştırma Kurulu (MASAK), mahkemeler, savcılıklar, vergi daireleri ve diğer yetkili merciler — hukuki yükümlülük kapsamında;
Hizmet sağlayıcılar: sunucu barındırma ([barındırma sağlayıcısı ve ülkesi]), e-posta gönderimi ([e-posta sağlayıcısı]), blokzincir veri/API sağlayıcıları (ör. TronGrid) ve etkinse Cloudflare Turnstile bot koruması;
Danışmanlar: hukuk, mali müşavirlik ve denetim hizmeti aldığımız kişiler — sır saklama yükümlülüğü altında;
Satıcılar: ödeme sayfasında müşterinin gerçekleştirdiği ödemeye ilişkin bilgiler, ilgili Satıcıyla paylaşılır.
Yurt dışında yerleşik hizmet sağlayıcılara aktarım, KVKK md. 9’da öngörülen şartlara (yeterlilik kararı, standart sözleşme gibi uygun güvenceler ya da arızi aktarım hâlleri) uygun olarak yapılır. Standart sözleşme kullanılması hâlinde Kişisel Verileri Koruma Kurumu’na süresi içinde bildirim yapılır.
Saklama süreleri
Veri
Süre
Hesap ve iletişim bilgileri
Sözleşme süresince ve sona ermesinden itibaren 10 yıl (genel zamanaşımı)
Ödeme, çekim ve bakiye kayıtları
İşlem tarihinden itibaren en az 8 yıl (5549 sayılı Kanun) ve 10 yıl (6102 sayılı TTK) — hangisi uzunsa
Güvenlik ve denetim kayıtları (IP, cihaz, giriş)
[2 yıl]; bir uyuşmazlık ya da inceleme varsa sonuçlanana kadar
Oturum çerezi (zp_session)
En fazla 7 gün ya da çıkış yapana kadar
E-posta doğrulama kodları
Kısa süreli (dakikalar); kullanıldıktan ya da süresi dolduktan sonra geçersiz
Reddedilen başvurular
[1 yıl]
Süre sonunda kişisel veriler, Kişisel Verilerin Silinmesi, Yok Edilmesi veya Anonim Hale Getirilmesi Hakkında Yönetmelik uyarınca en geç 6 aylık periyodik imha dönemlerinde silinir, yok edilir ya da anonim hâle getirilir. Blokzincire yazılmış veriler bu kapsamın dışındadır.
Veri güvenliği
Verilerinizi korumak için teknik ve idari tedbirler uygularız: şifrelerin tek yönlü özet (hash) ile saklanması, Authenticator anahtarlarının AES-256-GCM ile şifrelenmesi, iletimde TLS şifrelemesi, oturum çerezlerinin HttpOnly ve SameSite=Strict olarak ayarlanması, yetki bazlı erişim, hassas işlemler için iki adımlı doğrulama, değiştirilemez denetim kayıtları ve cüzdan özel anahtarlarının yalnızca sunucuda tutulması. Veri ihlali hâlinde KVKK md. 12/5 uyarınca Kurul’a ve ilgili kişilere bildirim yapılır.
Otomatik işleme
Hakkınızda yalnızca otomatik işlemeye dayalı, hukuki sonuç doğuran bir karar vermiyoruz. Güvenlik kuralları (ör. tutar eşiği, yeni adres) bazı çekimleri otomatik olarak yönetici incelemesine yönlendirebilir; nihai karar bir yetkili tarafından verilir.
İlgili kişi hakları
KVKK md. 11 uyarınca veri sorumlusuna başvurarak:
Kişisel verilerinizin işlenip işlenmediğini öğrenme,
İşlenmişse buna ilişkin bilgi talep etme,
İşlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme,
Yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme,
Eksik veya yanlış işlenmişse düzeltilmesini isteme,
KVKK md. 7’deki şartlar çerçevesinde silinmesini veya yok edilmesini isteme,
(d) ve (e) bentleri uyarınca yapılan işlemlerin, verilerin aktarıldığı üçüncü kişilere bildirilmesini isteme,
İşlenen verilerin münhasıran otomatik sistemler vasıtasıyla analiz edilmesi suretiyle aleyhinize bir sonucun ortaya çıkmasına itiraz etme,
Kanuna aykırı işlenmesi sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme
haklarına sahipsiniz.
Başvuru yolu
Haklarınıza ilişkin taleplerinizi, Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ’e uygun olarak; kimliğinizi tespit etmeye yarayan bilgilerle birlikte
ıslak imzalı dilekçe ile [Adres] adresine şahsen ya da noter aracılığıyla,
güvenli elektronik imza ile [KEP adresi] KEP adresine,
iletebilirsiniz. Başvurunuz en geç 30 gün içinde ücretsiz olarak sonuçlandırılır; işlemin ayrıca bir maliyet gerektirmesi hâlinde Kurul’ca belirlenen tarifedeki ücret alınabilir. Başvurunuzun reddedilmesi, cevabın yetersiz bulunması ya da süresinde cevap verilmemesi hâlinde KVKK md. 14 uyarınca Kişisel Verileri Koruma Kurulu’na şikâyette bulunabilirsiniz.
Çocuklar
Satıcı hesapları 18 yaşından küçüklere açık değildir. 18 yaşından küçük bir kişiye ait verileri istemeden işlediğimizi fark edersek bu verileri sileriz.
Değişiklikler
Bu metni güncelleyebiliriz. Güncel sürüm yürürlük tarihiyle bu sayfada yayımlanır; önemli değişiklikler e-posta ya da panel üzerinden duyurulur.
Yürürlük tarihi: 28 Eylül 2026 · Sürüm 2026-09-28
Data controller
This Privacy Policy and Privacy Notice has been prepared under Article 10 of Turkish Personal Data Protection Law No. 6698 (“KVKK”) and the Communiqué on the Procedures and Principles for Fulfilling the Obligation to Inform.
Data controller
[Company Name]
Address
[Address]
MERSIS No.
[MERSIS No]
Email
[contact email]
Registered e-mail (KEP)
[KEP address]
VERBIS registration
[VERBIS registration / exemption status]
This English version is provided for convenience. If there is any conflict, the Turkish version prevails.
Scope
This notice explains how we process the personal data of MercanPay merchants and their representatives, customers using the payment page, people whose data is sent to us through API and webhook integrations, and visitors to our website. Merchants remain responsible for giving their own customers a privacy notice for their own processing.
Personal data we process
Category
Data
Data subject
Identity
Name, business name, and (where needed) ID and tax details
Payment and withdrawal wallet addresses, saved addresses, transaction hashes (txid), amounts, balance movements, public transaction data read from the blockchain
Merchant, customer
Security
IP address, device and browser information (user-agent), session and log-in records, failed log-in attempts, 2FA status, encrypted authenticator key, audit logs, bot-protection results
All users
Legal
Version and date of the accepted terms, requests, complaints and related correspondence
Merchant / representative
Visual
Logo uploaded by the merchant (where it contains personal data)
Merchant
About blockchain data: addresses, amounts and transaction hashes recorded on the TRON network are public and, by their nature, cannot be deleted or changed on the blockchain. They count as personal data to the extent they can be linked to you; we can only delete or anonymise the records held in our own systems.
We do not request or process special categories of personal data (health, biometrics, etc.). We do not build marketing profiles or sell your data.
Purposes
Receiving and reviewing merchant applications and creating accounts;
providing invoices, the payment page, the API, webhooks, balances and withdrawals;
monitoring, verifying and recording payments on the blockchain;
preventing fraud, money laundering and terrorist financing, and sanctions screening;
sending service notifications (security alerts, payment and withdrawal notices, changes to terms);
responding to requests and complaints and providing support;
meeting accounting, invoicing and statutory retention obligations and providing information to competent authorities;
establishing, exercising and defending legal claims.
Legal bases
We process your personal data on the following legal bases under Article 5(2) KVKK:
(c) Formation or performance of a contract: account opening, payments and withdrawals, notifications;
(ç) Compliance with a legal obligation: record-keeping and reporting duties under Law No. 5549, Tax Procedure Law No. 213, Turkish Commercial Code No. 6102 and related legislation;
(d) Data made public by the data subject: public transaction data written to the blockchain;
(e) Establishing, exercising or defending a right: disputes, complaints and audits;
(f) Legitimate interest: system and account security, fraud prevention, audit logs and improving the service — provided this does not harm your fundamental rights and freedoms.
For non-essential processing, such as remembering your theme and language on your device, we ask for your consent (see the Cookie Policy).
How we collect data
We collect data by automated or partly automated means through sign-up and log-in forms, the merchant panel, API requests, the payment page, email correspondence, cookies and similar technologies; blockchain data is obtained from the TRON network (directly or through blockchain API providers).
Transfers
Your personal data may be shared, only as far as necessary for the purposes above, with:
competent public authorities: the Financial Crimes Investigation Board (MASAK), courts, prosecutors, tax offices and other competent bodies — to meet legal obligations;
service providers: server hosting ([hosting provider and country]), email delivery ([email provider]), blockchain data/API providers (e.g. TronGrid) and, when enabled, Cloudflare Turnstile bot protection;
advisers: legal, accounting and audit advisers — under a duty of confidentiality;
merchants: details of a payment a customer makes on the payment page are shared with the relevant merchant.
Transfers to service providers located abroad are made in line with Article 9 KVKK (adequacy decisions, appropriate safeguards such as standard contracts, or occasional transfers). Where standard contracts are used, the Personal Data Protection Authority is notified within the required period.
Retention
Data
Period
Account and contact details
For the term of the contract and 10 years after it ends (general limitation period)
Payment, withdrawal and balance records
At least 8 years (Law No. 5549) and 10 years (Commercial Code No. 6102) from the transaction — whichever is longer
Security and audit logs (IP, device, log-ins)
[2 years]; longer if needed for an ongoing dispute or investigation
Session cookie (zp_session)
Up to 7 days or until you log out
Email verification codes
Short-lived (minutes); invalid once used or expired
Rejected applications
[1 year]
At the end of the period, personal data is deleted, destroyed or anonymised under the Regulation on the Deletion, Destruction or Anonymisation of Personal Data, at the latest in periodic destruction cycles of 6 months. Data written to the blockchain falls outside this scope.
Security
We apply technical and organisational measures to protect your data: passwords stored as one-way hashes, authenticator keys encrypted with AES-256-GCM, TLS in transit, HttpOnly and SameSite=Strict session cookies, role-based access, two-factor authentication for sensitive actions, tamper-evident audit logs, and wallet private keys that never leave the server. In the event of a data breach, the Board and the affected persons are notified under Article 12(5) KVKK.
Automated processing
We do not take decisions with legal effects about you based solely on automated processing. Security rules (e.g. amount thresholds, new addresses) may automatically route some withdrawals to manual review; the final decision is made by an authorised person.
Your rights
Under Article 11 KVKK, you may apply to the data controller to:
learn whether your personal data is processed,
request information about it if it is,
learn the purpose of processing and whether it is used accordingly,
know the third parties in Türkiye or abroad to whom it is transferred,
request correction if it is incomplete or inaccurate,
request deletion or destruction under the conditions of Article 7 KVKK,
request that third parties to whom the data was transferred be notified of actions under (d) and (e),
object to an outcome against you arising from analysis exclusively by automated systems,
claim compensation if you suffer damage due to unlawful processing.
How to apply
You can send requests about your rights, in line with the Communiqué on the Procedures and Principles of Application to the Data Controller and with information identifying you:
by a wet-signed letter delivered in person or through a notary to [Address],
with a secure electronic signature to our registered e-mail (KEP) address [KEP address],
from the email address registered in our system to [contact email].
We will conclude your request free of charge within 30 days at the latest; if the action requires an additional cost, the fee set by the Board’s tariff may be charged. If your request is rejected, the answer is insufficient or we do not answer in time, you may complain to the Personal Data Protection Board under Article 14 KVKK.
Children
Merchant accounts are not available to anyone under 18. If we learn that we have unintentionally processed the data of a person under 18, we will delete it.
Changes
We may update this notice. The current version is published on this page with its effective date; significant changes are announced by email or in the panel.
Effective date: 28 September 2026 · Version 2026-09-28
Çerez nedir?
Çerezler, ziyaret ettiğiniz sitenin tarayıcınıza kaydettiği küçük metin dosyalarıdır. Tarayıcı depolama alanları (localStorage, sessionStorage) da benzer amaçla kullanılan teknolojilerdir. Bu politika, MercanPay’in bu teknolojileri hangi amaçlarla ve ne kadar süreyle kullandığını açıklar.
Kısaca
MercanPay yalnızca zorunlu bir oturum çerezi kullanır. Tema ve dil tercihiniz, izin verirseniz cihazınızda saklanır. Analiz, reklam, sosyal medya ya da izleme çerezi kullanmıyoruz; tarayıcı parmak izi çıkarmıyoruz.
—Seçiminizi dilediğiniz zaman değiştirebilirsiniz.
Kullandığımız çerezler ve depolama
Ad
Tür
Amaç
Süre
Kategori
zp_session
Birinci taraf çerez · HttpOnly, SameSite=Strict, HTTPS’te Secure
Satıcı paneline girişinizi güvenle sürdürür; JavaScript tarafından okunamaz.
7 gün ya da çıkış yapana kadar
Zorunlu
zp_cookie_consent
localStorage
Çerez tercihinizi (sürüm, tercih izni, tarih) hatırlar; banner’ın tekrar gösterilmemesini sağlar.
Siz silene kadar
Zorunlu
Geçici sekme verileri
sessionStorage
Panelin ve sayfaların çalışması için gereken geçici durum bilgileri.
Sekme kapanınca silinir
Zorunlu
zp_theme
localStorage (izin yoksa sessionStorage)
Açık/koyu tema seçiminiz.
İzin verdiyseniz siz silene kadar; aksi hâlde sekme kapanınca
Tercihler
zp_lang
localStorage (izin yoksa sessionStorage)
Türkçe/İngilizce dil seçiminiz.
İzin verdiyseniz siz silene kadar; aksi hâlde sekme kapanınca
Tercihler
Cloudflare Turnstile
Üçüncü taraf (challenges.cloudflare.com)
Etkinleştirilmişse kayıt ve giriş formlarında bot koruması için kendi çerezlerini ve teknik verilerini kullanabilir.
Cloudflare’in belirlediği süre
Zorunlu (güvenlik)
Müşterilerin kullandığı barındırılan ödeme sayfası da tema ve dil seçiminizi yalnızca cihazınızda (zp_theme, zp_lang) saklayabilir; bu veriler sunucumuza gönderilmez.
Kullanmadıklarımız
Google Analytics ya da benzeri ziyaretçi analizi araçları,
reklam, yeniden hedefleme ve sosyal medya piksel/çerezleri,
siteler arası izleme ve tarayıcı parmak izi teknikleri.
Sayfalarımız, Cloudflare Turnstile dışında harici betik yüklemez; bu durum içerik güvenlik politikasıyla (CSP) teknik olarak da sınırlandırılmıştır.
Tercihlerinizi yönetme
İlk ziyaretinizde gösterilen bannerdan “Kabul et” seçeneğiyle tercih depolamaya izin verebilir, “Yalnızca zorunlu” seçeneğiyle reddedebilir ya da “Ayarlar” üzerinden seçiminizi ayrıntılı olarak yapabilirsiniz. Seçiminizi her sayfanın alt kısmındaki “Çerez tercihleri” bağlantısından değiştirebilirsiniz. Tercihleri reddettiğinizde tema ve dil seçiminiz yalnızca açık sekme süresince hatırlanır ve daha önce cihazınıza kaydedilmiş tercihler silinir.
Tarayıcınızın ayarlarından da çerezleri ve site verilerini silebilir veya engelleyebilirsiniz. Zorunlu oturum çerezini engellerseniz satıcı paneline giriş yapamazsınız.
Hukuki dayanak
Zorunlu çerezler, sözleşmenin ifası ve hizmet güvenliğine ilişkin meşru menfaatimiz (KVKK md. 5/2-c ve f) kapsamında kullanılır. Tercih depolama yalnızca onayınızla kalıcı hâle getirilir. Kişisel verilerinizin işlenmesine ilişkin ayrıntılar ve haklarınız için Gizlilik Politikası’na bakabilirsiniz.
Değişiklikler ve iletişim
Yeni bir çerez ya da benzeri teknoloji kullanmaya başlarsak bu politikayı güncelleriz ve gerekiyorsa onayınızı yeniden isteriz. Sorularınız için: [iletişim e-postası].
Yürürlük tarihi: 28 Eylül 2026 · Sürüm 2026-09-28
What are cookies?
Cookies are small text files that a website stores in your browser. Browser storage (localStorage, sessionStorage) is a similar technology used for comparable purposes. This policy explains why and for how long MercanPay uses these technologies.
In short
MercanPay uses only one strictly necessary session cookie. Your theme and language are stored on your device if you allow it. We use no analytics, advertising, social-media or tracking cookies, and no browser fingerprinting.
—You can change your choice at any time.
Cookies and storage we use
Name
Type
Purpose
Duration
Category
zp_session
First-party cookie · HttpOnly, SameSite=Strict, Secure over HTTPS
Keeps you securely signed in to the merchant panel; cannot be read by JavaScript.
7 days or until you log out
Strictly necessary
zp_cookie_consent
localStorage
Remembers your cookie choice (version, preferences permission, date) so the banner is not shown again.
Until you delete it
Strictly necessary
Temporary tab data
sessionStorage
Temporary state needed for the panel and pages to work.
Deleted when the tab closes
Strictly necessary
zp_theme
localStorage (sessionStorage without permission)
Your light/dark theme choice.
Until you delete it if allowed; otherwise until the tab closes
Preferences
zp_lang
localStorage (sessionStorage without permission)
Your Turkish/English language choice.
Until you delete it if allowed; otherwise until the tab closes
Preferences
Cloudflare Turnstile
Third party (challenges.cloudflare.com)
When enabled, may use its own cookies and technical data for bot protection on sign-up and log-in forms.
As set by Cloudflare
Strictly necessary (security)
The hosted payment page used by customers may also keep your theme and language (zp_theme, zp_lang) on your device only; this data is not sent to our server.
What we don’t use
Google Analytics or similar visitor analytics tools,
advertising, retargeting and social-media pixels or cookies,
cross-site tracking or browser fingerprinting.
Apart from Cloudflare Turnstile, our pages load no external scripts; this is also technically enforced by our Content Security Policy (CSP).
Managing your choice
In the banner shown on your first visit you can allow preference storage with “Accept”, decline it with “Necessary only”, or choose in detail under “Settings”. You can change your choice at any time from the “Cookie preferences” link at the bottom of every page. If you decline preferences, your theme and language are remembered only while the tab is open, and preferences saved earlier on your device are removed.
You can also delete or block cookies and site data in your browser settings. If you block the strictly necessary session cookie, you will not be able to sign in to the merchant panel.
Legal basis
Strictly necessary cookies are used to perform our contract with you and for our legitimate interest in keeping the service secure (Article 5(2)(c) and (f) KVKK). Preference storage is made persistent only with your permission. See the Privacy Policy for details on how we process personal data and your rights.
Changes and contact
If we start using a new cookie or similar technology, we will update this policy and ask for your consent again where needed. Questions: [contact email].
Effective date: 28 September 2026 · Version 2026-09-28