Privacy and Cookie Policy

1. Purpose and Scope

This Privacy and Cookie Policy has been prepared to explain which information is processed through cookies and similar technologies used on the atolira.com (“Atolira”) platform owned by Kalkan Dijital Platform E-Ticaret Limited Şirketi, acting as an Intermediary Service Provider; the purposes for which these technologies are used; the circumstances in which they are based on user preference or explicit consent; the third-party providers; and how users can manage their preferences.

2. What Are Cookies and Similar Technologies?

Cookies are small text files that may be stored on a browser or device when a website is visited. Local storage, pixels, tags, SDKs, and similar technologies may also be used for similar purposes. Unless otherwise stated, the term “cookie” in this Policy also covers these similar technologies.

3. Classification of Cookies

Category

Purpose

Legal Approach

Example Use

Strictly Necessary Cookies

The basic operation of the Site, cart, secure session, booking, reservation, and payment flow

May operate independently of user preference to the extent necessary for the provision of the service

Session, security, cart, fraud prevention

Functional / Preference Cookies

Remembering language, preferences, live support, or user experience features

Service request where necessary according to the specific function; otherwise preference/explicit consent

Language preference, preferred display, support tool

Analytics / Performance Cookies

Measuring Site usage and analyzing performance and user flows

User preference/explicit consent to the extent required

Visits, page views, conversion analysis

Marketing / Advertising Cookies

Advertising measurement, retargeting, campaign performance, and interest-based advertising

As a rule, user preference/explicit consent

Advertising pixels, conversion tags

4. First-Party and Third-Party Cookies

Cookies may be first-party cookies placed by Atolira or third-party cookies placed by third-party providers from which services are obtained. The data processing and cross-border transfer practices of the relevant provider are also taken into account regarding third-party cookies.

5. Session and Persistent Cookies

Session cookies are deleted when the browser session ends. Persistent cookies may remain on the device for the specified retention period. The maximum retention period of each cookie is shown separately in the final cookie inventory.

6. Cookie Preferences and Explicit Consent Management

Analytics, functional, or marketing cookies that are not strictly necessary are subject to the user’s preference. Accept and reject options are presented to the user clearly, understandably, and equally in the cookie preference panel. Preferences may subsequently be changed or withdrawn. The Information Notice and explicit consent are not combined within the same transaction or a single checkbox.

7. Types of Data Processed Through Cookies

  • IP address and approximate location information
  • Browser and device characteristics
  • Session and security identifiers
  • Page view, click, and browsing data
  • Cart, preference, and language information
  • Campaign and advertising interaction data
  • Cookie or advertising identifiers
  • Analytics and performance measurement data

8. Purposes of Using Cookies

  • Ensuring Site and account security
  • Maintaining the cart, booking, and payment flow
  • Remembering user preferences and sessions
  • Operating live support and customer communication features
  • Measuring Site performance and error rates
  • Statistically analyzing visitor behavior
  • Measuring advertising and campaign performance to the extent permitted by the user
  • Preventing fraud and misuse attempts
  • Verifying and tracking requests submitted by users through support/communication channels and forms and operating customer communication features.

9. Cookies and Cross-Border Data Transfers

Personal data may be transferred abroad through cookies if third-party analytics, advertising, cloud, or customer communication providers are located abroad or process data in data centers located abroad. In such cases, the transfer is based on a transfer mechanism compliant with the current Article 9 of the KVKK. For cookies based on the user’s explicit consent, the necessary information regarding the nature of the cross-border transfer is also provided during the explicit consent process.

10. Cookie Inventory

Cookie / Technology Provider Category Purpose Duration Legal Basis Cross-Border Transfer
_shopify_essential, _shopify_test Shopify Necessary Ensuring the correct operation of the store, session, and checkout security; checking the browser’s cookie support 1 minute–1 year KVKK Art. 5/2-c and Art. 5/2-f Yes – Shopify infrastructure and its subprocessors located abroad
_tracking_consent Shopify Necessary Recording the user’s cookie and privacy preferences 1 year KVKK Art. 5/2-ç and Art. 5/2-f Yes – Shopify infrastructure and its subprocessors located abroad
cart, cart_currency, localization, discount_code Shopify Necessary Remembering the cart, currency, country/language preference, and any discount code Session duration–1 year KVKK Art. 5/2-c and Art. 5/2-f Yes – Shopify infrastructure and its subprocessors located abroad
_landing_page, _orig_referrer, _shopify_analytics, _shopify_s, _shopify_y, shop_analytics Shopify Analytics Measuring the source of visits, store usage, and Site performance 30 minutes–1 year Explicit consent under KVKK Art. 5/1 Yes – Shopify infrastructure and its subprocessors located abroad
_shopify_marketing Shopify Marketing Measuring marketing activities and campaign interactions 1 year Explicit consent under KVKK Art. 5/1 Yes – Shopify infrastructure and its subprocessors located abroad
Tidio sohbet bileşeni yerel tarayıcı depolaması (localStorage) Tidio Personalization / Functional Remembering the status of the chat window, user preferences, and the ongoing chat session Until browser data is deleted or updated by the service Fulfillment of the chat request and explicit consent where necessary Yes – data may be processed through Tidio’s infrastructure in the EEA
Payment Security Cookies Virtual POS / Bank Necessary 3D Secure verification and fraud prevention control Session Duration KVKK Art. 5/2-f and Art. 5/2-c Depending on the Bank/Payment Institution

11. Cookie Management Through the Browser

In addition to the cookie preference panel, users may view, delete, or block cookies through the settings of the browser they use. However, if strictly necessary cookies are blocked, some parts of the cart, account, booking/reservation, or payment flow may not function.

12. Third-Party Services and Links

Atolira may use third-party providers for payment, booking/reservation, analytics, advertising, live support, email, or similar services. Third-party websites and services may be subject to their own privacy and cookie policies. To the extent possible, Atolira informs the user about the role of these providers and data transfers.

13. Payment Security

Sensitive payment card data (Credit card number, expiration date, CVC/CVV security code) is processed with 3D Secure through the PCI-DSS-compliant secure infrastructures of BDDK-licensed payment institutions and/or authorized virtual POS providers. Atolira does not retain, directly process, or store full card data, including the card number, expiration date, and CVC, on its own servers under any circumstances. Tracking the payment flow through cookies and session information is limited solely to matching order and verification codes.

14. Personal Data Breach and Incident Management

If Atolira becomes aware of a personal data breach, it conducts the necessary investigations in accordance with the applicable KVKK provisions and Board decisions; notifications required to be submitted to the Board are made without delay and within the applicable periods, and affected data subjects are informed through appropriate methods as soon as required by the circumstances.

15. Data Subject Rights and Contact

Requests under the KVKK concerning personal data processed through cookies may be submitted through the application procedures specified in the Atolira KVKK Information Notice. Cookie preferences may also be managed through the cookie preference panel on the Site.

  • Email: info@atolira.com
  • Address: Yakuplu Mah. Hürriyet Bul. Skyport Sitesi Skyport Residence No: 1, Interior Door No: 151, Beylikdüzü 34520 İstanbul, Türkiye

16. Updating the Policy

This Policy may be updated in accordance with changes in legislation, Board decisions, technologies used, cookies, or third-party service providers. The current version shall enter into force on the date it is published on atolira.com.