This policy explains which cookies and similar browser records merter.app uses, what each of them does, and how you can manage your choices. The general framework for the processing of personal data is on the Privacy Policy and Privacy Notice (KVKK) pages.
What this policy covers
A cookie is a small piece of text written to your browser when you visit a site and sent back to that site on later requests. Records kept in localStorage are technically not cookies, because the browser does not send them to the server on its own; this policy covers them as well, since they leave a trace on your device.
Scope: the marketing pages (merter.app, www.merter.app) and the business panel (hub.merter.app). Whatever happens inside the apps of the connected messaging platforms (WhatsApp, Instagram, Telegram) falls outside this policy; the rules of the platform concerned apply there.
The marketing pages write no cookies of their own. The only things that store anything here are the measurement script and the live support widget described below. Session cookies are used only in the panel and its API.
Strictly necessary cookies
These are required for the service to work; they are not an optional preference and they do not depend on consent. All three are signed by the server, marked HttpOnly (scripts on the page cannot read them), sent with SameSite=Lax, and written as Secure when the site is served over HTTPS.
| Cookie | What it does | Lifetime |
|---|---|---|
sp_session |
The panel session. This cookie carries who is signed in; it holds an account identifier and a session identifier — no name, e-mail address or password. | 30 days |
sp_admin_as |
The ticket that lets a platform administrator step into an account’s panel temporarily for support. It is created only when such a step-in happens, and it does not replace the session cookie. | 30 minutes |
sp_google_oauth |
Confirms that a sign-in with Google really originated from you (CSRF protection). It is valid only on the /api/auth/google path and is deleted as soon as the sign-in completes. |
10 minutes |
The lifetime written on a cookie is only a hint given to the browser; the validity of a session is verified again on the server with every request. When “sign out of all devices” is run for an account, or when the password of an account is reset, every session cookie belonging to that account becomes invalid immediately.
If these cookies are blocked, signing in to the panel is impossible: the session cannot be held in the browser, so every page reload returns to the sign-in screen.
Preferences kept in your browser
The records below are created in the panel, are kept in localStorage and are not sent to the server. They are not used for measurement and are not matched to your identity.
| Record | What it does | Lifetime |
|---|---|---|
app-theme |
The dark/light theme preference of the panel. | Until you delete it |
app-lang |
The language of the panel interface (tr / en). |
Until you delete it |
A whatsapp-theme record left over from earlier versions of the panel is read and deleted the next time the panel is opened.
Measurement and marketing cookies
Meta’s (Facebook, Instagram) measurement script — Meta Pixel, id 1597196545412819 — is used to measure advertising performance and for retargeting. The script runs both on the marketing pages and in the panel, and today it loads unconditionally when a page opens: merter.app has no cookie consent banner, so you are not asked for approval before it loads. When this changes, that is when a consent banner goes live, this section will be updated and the version number of this document will be raised.
The events the script reports to Meta:
- Page view — on every page load, both on the marketing pages and in the panel.
- Registration completed — when e-mail verification is passed and a new business account is opened.
- Search — when the availability of a store address is checked; the name searched for and whether it came back available are sent.
- Lead — when a showroom address is claimed, together with the address chosen.
On the marketing pages, if JavaScript is disabled in the browser, the same page view event is reported through a 1×1 pixel image request embedded in the page.
The script writes Meta’s own cookies to your browser; according to Meta’s documentation these are _fbp and — if you arrived through an advertising link — _fbc. Their contents, their lifetimes and how they are used on Meta’s side are a matter for Meta’s own cookie policy, not merter.app’s. Meta’s role in this relationship is set out in the subprocessor table in the Data Processing Addendum.
Live support widget
A live support widget runs on the marketing pages; its script is loaded from panel.appo.com.tr. The widget uses no cookies. When you start a chat it writes a single record whose name begins with chathub: into your browser’s localStorage; this is a visitor key that identifies your conversation and lets the chat continue where it left off when you move to another page or come back later. It stays in the browser until you clear it. The content of the messages you write is not held in that record but on the support system’s server.
Which group requires consent
- Strictly necessary cookies — no consent required. They are needed to deliver the service; they are created only when you sign in to the panel and are never used for measurement.
- Preferences kept in your browser — no consent required. They never leave your device and are not sent to the server.
- Measurement and marketing cookies — normally these do require consent. As things stand today, however, merter.app has no cookie consent banner, so the measurement script loads without prior approval. This gap is being closed; until the consent banner goes live you can stop the script yourself using the methods below.
We are stating this plainly rather than dressing it up: on marketing cookies, no choice is being offered at the moment.
How to manage your choices
- Browser settings. From the privacy settings of Chrome, Safari, Firefox and Edge you can block cookies per site and delete existing cookies and site data. A “delete site data” command also clears the
localStoragerecords (theme, language, live support key). - If you block the strictly necessary cookies you cannot sign in to the panel. That is not a fault but the direct consequence of blocking them; the marketing pages carry on displaying normally.
- To stop the measurement script, the browser’s tracking protection or a content blocker can be used. If the script does not load, no event reaches Meta and the rest of the site works normally.
- Advertising preferences. How the data Meta collects is used in advertising can be managed from the ad preferences section of your Facebook or Instagram account.
- For questions, write to [email protected].
Related documents
- Privacy Policy — which data is processed and why.
- Privacy Notice (KVKK) — the legal grounds for processing, retention periods and data subject rights.
- Data Processing Addendum — the full list of subprocessors the service uses.