Privacy Policy
In short
We ask for little more than your email address. We do not sell data to advertising networks and we run no third-party analytics on this site.
This page explains what we collect, why, and how to have it deleted.
Data controller
Your personal data is processed by Levent EREN, operating under the Markuda brand, as the data controller. Address: Çınarlı Mah. Onaran Sok. No 17 Derince/Kocaeli. Contact: info@markuda.com. This page is the privacy notice required by art. 10 of Turkish Personal Data Protection Law no. 6698 and the related regulation: the controller, the purposes and legal grounds, the way data is collected, the parties it is passed to, and your rights are read together.
Purposes and legal grounds
Membership and sign-in (email, optional name, session): to open the account and provide the service. Necessary for forming and performing the contract (Law art. 5/2-c).
The service itself (watchlist, portfolio, drawings, layouts, strategies, notification and market preferences): to carry your own screen across devices. Performance of the contract (art. 5/2-c).
Security and prevention of abuse (one-way digest of the network the terminal connects from, browser identity cookie, session record): to see from how many places an account is used and to diagnose account sharing and server load. Legitimate interest (art. 5/2-f); without storing the raw address and without harming your fundamental rights and freedoms.
Counters (visitor count, page totals): to watch that the site is running. Legitimate interest (art. 5/2-f); one-way hashes that cannot be traced back to a person, and totals.
Agreement acceptance, deletion request and email-permission history: establishing, exercising or protecting a right (art. 5/2-e). The permission you give to receive product updates by email rests on your explicit consent (art. 5/1) and can be withdrawn at any time.
Legal obligation: at the lawful request of competent public authorities, to the extent the legislation requires (art. 5/2-ç).
We do not process your data for advertising or profiling.
How the data is collected
We collect data directly from you (account creation, settings, saving lists and drawings, the support and contact forms), automatically while the terminal and the site are used (session, server record, cookies), and from Google (email address and name) if you choose sign-in with Google. Collection takes place electronically, by automatic or partly automatic means.
What we process
Account: your email address, your name if you provide one, and your sign-up and last sign-in times.
Preferences: your watchlist, notification settings, language and market selection.
Your portfolio: the positions you enter (symbol, quantity, cost, purchase date). This is shown only to you and is never exposed to other users or third parties.
What you create: the drawings you place on a chart. We keep these with your account so that the same screen is waiting for you when you change computers or open the web version. We do not look inside them; to us each one is a named piece of text. They are shown only to you and are never exposed to other users or third parties.
Your strategy library: if you use the web version, the names and the code of the indicators and strategies you write in CodeScript are kept with your account. Browser storage is not permanent — clearing the browser erases it — so this is the only way to keep your work on the web. We do not read it, do not run it and do not show it to anyone else; when you delete it from your account it goes from our servers too.
Usage record: which pages you visit and your last activity time, used to measure service health.
Visitor counting: for signed-out visitors we combine IP address, browser information and a daily rotating salt into a one-way hash. Your raw IP address is not stored and the record cannot be traced back to you.
The network your terminal connects from: When your desktop terminal verifies your subscription, a one-way digest of the network address you connect from is recorded; the raw address is not stored and the address cannot be recovered from the digest. We keep this digest for two purposes: to see how many separate networks an account is used from (account sharing and abuse) and to diagnose where server load comes from. On the administration side the digest can be matched to your account; it is not exposed to any other user or third party.
Your acceptance of the agreement: When you accept the user agreement we record the time of acceptance, the version you accepted, a digest of that version's text, your account number and your terminal identifier. The terminal identifier is a number we generate for that installed copy of the application; it is not read from your device. This record is kept even if you delete your account, because its purpose is the protection of a legal right and deleting the account does not remove that purpose. Once your account is deleted the record holds neither your name nor your e-mail address, only your account number. Your device name and local network addresses are never sent to us; they stay on your own computer.
Your email permission: Whether you want product updates by email is kept not only in its latest state but with its history: when you gave the permission, when you withdrew it, and where you did so (the acceptance screen, your settings, or the unsubscribe link in an email). The one reason for this is to be able to prove that every message we sent you was permitted on the day it was sent. The record holds no identifier beyond your account number; your interests, which email you opened and what you clicked are not kept. You can withdraw the permission at any time from Settings > Account in the terminal, from the Email permission section of your account page on this site, or from the unsubscribe link at the bottom of any email we send — giving and withdrawing sit in the same place.
What you create
The drawings you place on a chart, your watchlists and the strategies you write belong to you. We store them; they remain yours.
Why they sit on our servers. In the web version there is nowhere to keep them but the browser's own storage, which belongs to that browser and disappears when it is cleared. For a drawing you saved to still be there tomorrow, it has to be kept on the server. In the desktop version your records always remain on your own computer as well; the copy on our side does not replace it — it lets you find the same screen on a second device.
What we carry: your drawings, your watchlists, your language choice, and the code of the strategies you write on the web. Layouts, indicator settings and alerts will join this set later; this section will be updated when they do.
What we do not carry: your exchange key and secret, your bot settings, preferences tied to your screen size (panel widths, column layout) and the price copy kept for speed. Those stay on your own computer.
We do not access the contents. To us a record is a piece of text with a name, a body and a change marker. We do not read it, analyse it, use it in the product, train anything on it, or show it to anyone. An indicator you drew or a strategy you wrote is yours; the only thing we can do with it is give it back to you.
How much space it takes. At most 256 KB per piece and 2,000 pieces per account.
If you change the same record on two devices we delete neither. Both are kept, and you choose which one to keep.
Content you share
When you create a link to share a list (and other content that may become shareable later), anyone who knows the link can see that content; they do not need to sign in. Only the content itself is shown (for example the list name and its symbols); your name, email address and any other account detail are not shown.
You can close the link at any time. A closed link stops working and the content is no longer visible. If you delete your account, your open links are deleted too. You decide who receives the link; we cannot stop a person you gave it to from passing it on, so do not share anything you consider sensitive.
Your exchange key
The key and secret you use to reach your exchange account stay on your own computer alone. They are held encrypted in your operating system's credential store; they are not sent to our servers, not written to log files, and not included in syncing. Your orders do not pass through us — they go straight to the exchange, and we have no access to your assets. We suggest keeping withdrawal permission disabled on the key; that setting lives at the exchange and the choice is yours.
Cookies
Today only essential cookies run: the security cookie that keeps you signed in (session); a browser identity cookie that counts how many different browsers an account is used from (mkd_trm: it carries only a random number, nothing else, and lasts 1 year); your language and market preference (lang and mkd_mkt, 1 year); your cookie choice (cerez_onay); and a short-lived entry permit that recognises a visitor waiting in the queue under heavy load (mkd_izin, 30 minutes). Without these cookies you cannot sign in and your preferences are not remembered.
We run no measurement or advertising cookies. The banner at the bottom of the page asks for your consent to advertising cookies; granting it changes nothing today, because advertising is not live yet.
When it is, we will name the network here, list the cookies it sets and say how long they last. If you decline you keep full use of the product, and you can withdraw your consent at any time from the same banner.
Who we share with
We do not sell your personal data and do not share it for marketing.
Fonts: page fonts load from our own server; no connection is made to a third-party font server when you view a page.
Sign in with Google: if you choose this method, authentication is performed through Google and your email address and name come to us from Google; unless you choose it, no data is exchanged with Google.
Email: notification and sign-in emails are sent from our own mail server; no third-party email service is used.
Requests to the exchanges that supply our market data originate from our server; your IP address is not passed to them.
Transfers abroad — as they are
Sign in with Google: authentication happens at Google only if you choose this method. If you do not, no data is exchanged with Google.
Orders placed from the desktop terminal go from your own computer directly to the exchange and do not pass through us; your exchange key stays on your computer. We make no transfer for those orders.
We do not sell your personal data in any of these transfers.
How long we keep it
Account data is kept while your account is open.
Support requests: Your support requests are kept for 12 months after they are closed; they are deleted together with your account when you delete it.
You can delete your account yourself: use the Delete my account link at the bottom of your account page, with a two-step confirmation. When you do, your e-mail address, name, watchlist, portfolio, preferences, subscription entitlements and open sessions are deleted. Three records remain: your acceptance of the agreement (described above), the history of your email permission, and the record of your deletion request — the time of the request, your account number and your reason for leaving if you wrote one. None of them holds your name or your e-mail address. A "permission withdrawn" line is added to the permission history at the moment of deletion; we send you nothing once your account is closed. Giving a reason is not required; if you leave it empty, the record simply notes that no reason was given. The records we hold for your account are deleted as well: your drawings, your watchlists, your strategy library and your preferences. Your bot settings and your exchange key never reach our servers in the first place; they stay on your own computer.
The counters we keep
To see that the site is working we keep counters: traces that count how many visitors arrive, day-by-day totals of how often each page was opened, when a member last signed in, and a record of terminal sessions. None of your own content is in these counters — your drawings, your strategies and your watchlists never go there.
What they are for: when a fault is reported we can see when it started, and we can count how many people came to the site. The visitor trace holds a number that cannot be reversed, not your raw address.
Counters older than 90 days are deleted. For either purpose a record that old is of no use. The deletion is carried out by an automated clean-up task that runs every night. What remains is only totals that cannot be linked to anyone — such as how many pages were viewed on a given day; those are not personal data.
How long your own records stay
There is no time limit on your drawings, your watchlists, your strategies, your layout or your alerts.
The nightly cleanup above never touches them. They stay until you delete them; if you close your account they are deleted with it. Nothing else removes them.
Your rights (Law art. 11) and how to apply
By applying to the data controller you may ask: whether your data is processed; for information if it is; the purpose and whether it is used accordingly; who it has been passed to at home or abroad; for correction if incomplete or wrong; for deletion or destruction within the conditions of art. 7 of the Law; for correction and deletion to be notified to those it was passed to; to object to a result against you arising from analysis solely by automatic systems; and compensation if you suffer loss from unlawful processing.
Send your request through the Contact us form in your account.
If you cannot sign in, you may write to info@markuda.com from the email address registered to your account (to verify who you are).
We respond to your application free of charge within 30 days at the latest.