Cookie Policy
Last updated: 29 September 2026
This is an English translation provided for convenience. If it differs from the Turkish original, the Turkish version prevails.
In short
Tapiko uses only strictly necessary cookies and browser storage. We do not use analytics, advertising, retargeting or social media tracking cookies; there is no tool that follows your visit across other sites. We count how often the public pages are opened with a counter that uses no cookies (section 3a). What we do use is essential for things you asked for, such as signing in and showing your card, so it does not require separate permission — which is why we show no cookie consent banner.
1. Scope and data controller
This policy covers tapiko.app, the Tapiko card customers open in their browser (My cards) and the business dashboard. The data controller is Cevdet Aslan (Pendik V.D. 0870214606), registered at Kurtköy Mah. Ankara Cad. Yelken Plaza No: 289 İç Kapı No: 21, Pendik / İstanbul. How personal data is processed in general is explained in the Privacy Policy.
2. What are cookies and similar technologies?
A cookie is a small text file a site leaves in your browser and reads back on later requests. Browser storage (localStorage), the service worker cache and a push subscription likewise keep information on your device; this policy covers all of them.
3. The strictly necessary technologies we use
| What | Why | How long |
|---|---|---|
Session cookies (Clerk: __session, __client_uat and a session cookie on the sign-in provider's own domain) | Remembering that you are signed in and stopping anyone else from using your account. Set by Clerk, our authentication provider. | For the session; deleted when you sign out |
QR key (browser storage, yinegel.qrKey.v1) | Showing your QR code and cards without an internet connection. | Until you sign out or clear your browser data |
My cards cache (service worker, yinegel-wallet-v1) | Opening the My cards page where there is no signal. Only the My cards pages and the site's own files are cached; the business dashboard and account data are not. | Until you sign out or clear your browser data |
| Push subscription | Only if you allow notifications; delivering businesses' announcements to you. | Until you turn the permission off |
| Security cookie (our hosting provider Vercel) | Set only when unusual traffic is detected and a check is requested; confirms the request comes from a real browser rather than a bot. | Short-lived |
3a. Cookieless visit counting
On the public pages, the sign-in and sign-up pages and business setup we use Web Analytics from our hosting provider Vercel. It sets no cookie and stores nothing on your device; it shows us only totals, such as how often a page was opened, which site a visitor came from and the type of device, never individual people. Query parameters in the address bar are removed before anything is sent. My cards and the business dashboard are not measured with it.
4. Are the stamper and the QR code cookies?
No. When you tap your phone on a stamper, your phone simply opens a link; scanning a QR code does the same. The stamp is recorded on your account, not in a cookie. The location read at the moment of a stamp is not saved to your device or your account (see the Privacy Policy).
5. Third-party cookies
We do not place third parties' advertising code on our pages; our only measurement tool is the cookieless visit counting in section 3a. When you sign in with Apple, Google or your phone, or add your card to Apple Wallet or Google Wallet, that service's own cookie policy applies to what happens on its own pages. A site opened from a business's social media link applies its own rules too.
6. How to manage your preferences
- Signing out (Profile › Sign out) deletes the session cookies, the QR key and the My cards cache from this browser.
- In your browser settings you can delete or block cookies and site data. If you block strictly necessary cookies you will not be able to sign in, and your card will not open offline.
- Notifications can be turned off at any time in your browser's or phone's site settings.
7. Transfer abroad
Session cookies belong to Clerk, whose servers are abroad; this transfer rests on the explicit consent you gave when opening your account (see Privacy Policy, section 10).
8. Your rights
Your rights under Article 11 of the KVKK and how to apply are set out in the Privacy Policy. Questions: info@tapiko.app
9. Changes
If we ever start using a cookie that is not strictly necessary, we will first update this policy, and run that cookie only after you give explicit consent through a preferences window that is off by default.