Contents
This page lists the cookies and similar technologies used on utkusakallioglu.com, on both the Turkish and the English pages. For each one it explains what it does, how long it lasts and who receives the data. It also explains how you can accept, refuse or change your choices.
Who is responsible
I am Utku Sakallıoğlu, a freelance sole trader (serbest çalışan) based in Ankara, Türkiye, and I run this website. I am the controller for the processing described here. Where I name another company as an independent controller, or as joint controller with me, that company is also responsible for its own part of the processing, as explained below. You can contact me about anything in this policy at [email protected].
This policy covers only cookies and similar technologies. My GDPR privacy notice explains in full how I process the personal data of people in the EU/EEA and the UK, including your rights and how to complain. My Privacy policy gives an overview of all processing on this site. If Turkish law applies to you, please see the Turkish Çerez politikası and KVKK aydınlatma metni.
Cookies and similar technologies
A cookie is a small text file that a website stores in your browser and that your browser sends back with later requests. A first-party cookie belongs to this site’s own domain. A third-party cookie is set on another company’s domain, such as doubleclick.net or facebook.com.
Similar technologies work differently but fall under the same rules:
- localStorage keeps small values in your browser, with no expiry date, until you clear this site’s data. The values are not sent to a server automatically.
- sessionStorage works the same way, but its values are deleted when you close the tab.
- Scripts and pixels read information in your browser, such as page-load timings or cookie values, and send it to a server.
In this policy, “cookies” includes all of these unless I say otherwise.
When I ask for consent
Article 5(3) of the EU ePrivacy Directive, as implemented in each Member State, and the UK Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025, allow a website to store information on your device, or to read information from it, only with your consent. The exceptions are storage or access whose sole purpose is to carry out the transmission of a communication, and storage or access that is strictly necessary to provide a service you have explicitly asked for. UK law also allows a few narrow exceptions, for example for statistics and for the appearance of a site, where you are given a simple way to object. I do not rely on those UK exceptions.
The rule covers cookies, localStorage, sessionStorage and scripts that read information from your device, whether or not the information is personal data. Where it is personal data, the GDPR or the UK GDPR applies as well. In this policy, references to GDPR articles also mean the corresponding articles of the UK GDPR for visitors in the UK.
I use four categories and apply the same rules to every visitor, including visitors in the UK:
- Strictly necessary: always on. I do not ask for consent, because these items are needed to deliver the site securely, in the language, appearance and currency you use, and to respect your choices. Where personal data is involved, I rely on my legitimate interests (Article 6(1)(f) GDPR), which I explain below the table.
- Functional: off until you switch it on. It covers counters that apply the display rules of pop-ups.
- Analytics: off until you switch it on. It covers Cloudflare Web Analytics and Google Analytics 4.
- Marketing: off until you switch it on. It covers Google Ads conversion tracking and remarketing, and the Meta Pixel.
For the functional, analytics and marketing categories, your consent is the basis both for storing or reading information on your device and for any related processing of personal data (Article 6(1)(a) GDPR).
Giving, refusing and changing consent
On your first visit a banner asks for your choice. It has three buttons of equal weight: Accept all, Reject all and Preferences. Under Preferences you can switch each category on or off separately. No category is switched on in advance, and strictly necessary items are shown as always on.
Until you choose, only strictly necessary items are used. Continuing to browse without choosing is not consent. Refusing does not block your access to the site or to any of my services.
You can change your choice at any time through the Cookie settings link in the footer of every page. Withdrawing consent is as easy as giving it. From that point on, the tools concerned no longer run on this site, and items of that category already stored in your browser are no longer read here. They stay in your browser until they expire or until you delete them, as explained below. My site cannot remove cookies that Google or Meta have set on their own domains, such as IDE and fr. Withdrawal does not affect the lawfulness of processing that took place before it (Article 7(3) GDPR).
Your choice is remembered for 6 months. After that, or earlier if I add or change a category, the banner asks you again.
Records of your choice
To apply your choice and to be able to show that consent was given (Article 7(1) GDPR), I keep a record of each choice. It holds the categories you accepted or refused, the date and time, the version of the banner and policy, and a random consent ID. It does not contain your full IP address. The record is kept in a first-party cookie in your browser and in a consent log in the WordPress database on my hosting server in Türkiye. I keep each log entry for 3 years. The legal basis is my legitimate interest in respecting your choices and in demonstrating consent (Article 6(1)(f) GDPR).
What is used on this site
The tables below list every item by category. The durations show how long each item stays in your browser unless you delete it earlier.
Strictly necessary (always on)
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| cf_clearance | Cloudflare, Inc., on this site’s domain (first-party cookie, HttpOnly, Secure) | Records that your browser passed a Cloudflare security check, so the check is not shown again while the cookie is valid. It is set only after such a check. | 30 minutes, the period set in my Cloudflare security settings |
| __cf_bm | Cloudflare, Inc., on this site’s domain (first-party cookie) | Holds encrypted bot-score data so that Cloudflare’s bot management can tell people from automated traffic. It is not linked to any user ID on the site, and it is set only while bot management is active. | 30 minutes after your last activity |
| Consent choice cookie | This site’s own consent tool (first-party cookie) | Stores the choices you made in the banner (consent or refusal per category, date, text version), so they are respected and the banner does not appear on every visit. | 6 months |
| pll_language | Polylang, the site’s multilingual plugin (first-party cookie, SameSite=Lax, Secure) | Remembers the language of the page you are viewing (“tr” or “en”), so that later requests that do not carry the language in their address, such as redirects and background requests, are answered in the same language. | 1 year, set on the first page you view |
| site_theme | This site’s own script (localStorage) | Remembers the light or dark appearance you pick with the theme toggle. It is stored only when you use the toggle; until then the site follows your device’s appearance setting and stores nothing. | No expiry; kept until you clear this site’s data |
| site_currency | This site’s own script (localStorage) | Remembers the currency (euro or US dollar) you pick in the English pricing sections. It is written only when you pick a currency. | No expiry; kept until you clear this site’s data |
| site_lang_switch | This site’s own script (sessionStorage) | Holds the time at which you clicked a language link, so the language-switch transition can play on the next page. | Removed within about 10 seconds; at most until you close the tab |
Security. Cloudflare, Inc. delivers and protects every page of this site. To do so, it processes your IP address and request data on every visit, as my privacy notices explain. cf_clearance and __cf_bm protect the site and its forms against attacks, malicious bots and abuse. My legitimate interest is the security and availability of the site (Article 6(1)(f) and Recital 49 GDPR).
Language, appearance and currency. Polylang sets pll_language on the first page you view, and the cookie lasts 1 year. It holds only the language code. Page addresses already carry the language, but background requests and some redirects do not, and the cookie tells the server which language to use for them. I use it only for that, not to recognize you or for any other purpose. It is sent to my hosting server with each request. site_theme holds only “dark” or “light”, site_currency only the currency code, and site_lang_switch only a timestamp. None of them contains an identifier, and none is sent to any server. My legitimate interest is to show you the site in the language, appearance and currency you use.
Your choice. The consent choice cookie is needed to respect the choice you made in the banner.
Functional (only with your consent)
Some pop-ups on this site, such as info tips and panels, are built with the Elementor Pro site builder. To apply their display rules, Elementor Pro keeps counters in your browser: how often a pop-up appears, and that a pop-up you closed is not shown again. These items are stored only if you switch on the functional category. The data stays in your browser and is not sent to any server.
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| elementor (localStorage) | Elementor Pro (first-party, localStorage) | Counts page views and sessions, and how often each pop-up was shown or closed, so that pop-up display rules can be applied. | Page-view and session counters: no expiry, kept until you clear this site’s data. Entries for a single pop-up may expire earlier, as set in that pop-up’s rules. |
| elementor (sessionStorage) | Elementor Pro (first-party, sessionStorage) | Marks the browser session as active so that sessions are counted correctly. | Until the end of the browser session |
Analytics (only with your consent)
With your consent I use two tools to understand how the site is used: which pages and services attract interest, where visitors come from and how fast pages load. I work mainly with aggregated reports, and I do not use analytics data for advertising.
Cloudflare Web Analytics uses no cookies and no browser storage. After the page loads, a script from static.cloudflareinsights.com reads page-load performance timings in your browser. It sends them to Cloudflare with the page address (without the query string), the referring page and a timestamp. As with any web request, your IP address and browser information reach Cloudflare with it, and Cloudflare derives your country from the IP address. Cloudflare states that it does not fingerprint visitors. I see only aggregated figures in my Cloudflare dashboard. Because the script reads information from your device and sends it to a server, I load it only after you consent to analytics.
Google Analytics 4 also loads only after you consent to analytics. It records page views, the events I have configured, the referring site and campaign parameters, your device, browser, operating system, screen size and language, and your approximate location (city, region, country). Google uses your IP address to work out the location but does not log or store it. For visitors in the EU, Switzerland and the UK, data is collected through regional servers and the IP address is dropped before logging. No names, email addresses or form contents are sent to Google Analytics. Google signals is switched off, and my Analytics property is not linked to Google Ads.
User-level and event-level data in Google Analytics is deleted after 14 months. This limit applies to detailed analyses (explorations and funnel reports); standard aggregated reports are not affected by it. Google explains how it uses this data in How Google uses information from sites or apps that use our services.
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| Cloudflare Web Analytics script | Cloudflare, Inc. (script from a third-party domain; stores nothing) | Aggregated statistics on page views, visits, referring sites and page-load speed. | Nothing is stored on your device |
| _ga | Google LLC, through the Google tag on this site’s domain (first-party cookie) | Stores a random ID that Google Analytics uses to distinguish visitors. | 14 months from your last visit |
| _ga_ followed by my Google Analytics measurement ID | Google LLC, through the Google tag on this site’s domain (first-party cookie) | Keeps the session state: session ID and count, and timestamps. | 14 months from your last visit |
Although these two cookies belong to this site’s domain, the Google tag sends their values to Google.
Marketing (only with your consent)
With your consent I use Google Ads and the Meta Pixel to measure which ads lead to inquiries, to show my ads to people who have visited the site (remarketing) and to let Meta optimize how it delivers my ads. Inquiries are recorded as events, such as “quote form submitted”, without the content of the form. I do not use Google’s enhanced conversions or Customer Match, or Meta’s advanced matching, and I do not send your email address or phone number to Google or Meta.
Google Ads. The Google tag loads only after you consent to marketing. It records the pages you visit and conversion events, together with your IP address, browser information, the referring page, a timestamp, ad-click IDs and your consent signals. Google Ireland Limited receives this data as an independent controller (Google LLC for visitors in the UK) and uses it under the Google Privacy Policy. I am responsible for collecting the data on my site and passing it to Google through the tag.
Meta Pixel. Meta offers no equivalent of Google’s consent mode, so the Pixel script does not load at all until you consent to marketing. It then records page views and events such as a submitted inquiry (without the form content), together with your IP address, browser information, the referring page, a timestamp and the IDs in the cookies below.
For visitors in the EU/EEA, Meta Platforms Ireland Limited and I are joint controllers for collecting this data on my site and transmitting it to Meta (Article 26 GDPR). In essence, I give you this information and obtain your consent. Meta Platforms Ireland Limited handles requests under Articles 15 to 20 GDPR for the data it has received, and it is responsible for its own processing from then on. It also acts as my processor when it matches and measures these events. You may exercise your rights against either of us. You can read the arrangement in Meta’s Controller Addendum, and how Meta uses the data in its Privacy Policy. For visitors in the UK, Meta Platforms, Inc. acts as my processor. For other visitors, including those in Türkiye, Meta Platforms, Inc. acts as a processor or as an independent controller under Meta’s Business Tools Terms.
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| _gcl_au | Google Ads, through the Google tag on this site’s domain (first-party cookie) | Conversion linker: stores an ID used to match ad clicks with conversions on the site, such as a form submission. | 90 days |
| _gcl_aw | Google Ads, through the Google tag on this site’s domain (first-party cookie) | Stores the ad-click information (GCLID) when you arrive from a Google ad, so I can measure which ad led to a conversion. | 90 days |
| _gcl_dc, _gcl_gb, _gcl_gs | Google Ads, through the Google tag on this site’s domain (first-party cookies) | Store additional information for measuring Google ad clicks and conversions. Set only if the related feature is active. | 90 days each |
| IDE | Google Ads, on doubleclick.net (third-party cookie) | Used on Google’s ad network to serve ads, for remarketing and to measure ad performance. | 13 months in the EEA and UK; 24 months elsewhere |
| test_cookie | Google Ads, on doubleclick.net (third-party cookie) | Checks whether your browser accepts cookies. | 15 minutes |
| ar_debug | Google Ads, on doubleclick.net (third-party cookie) | Used to debug attribution reporting in Google’s ad measurement. Set only in some cases. | 90 days |
| _fbp | Meta Pixel, on this site’s domain (first-party cookie) | Stores an ID that identifies your browser for Meta’s advertising and measurement services. | 90 days |
| _fbc | Meta Pixel, on this site’s domain (first-party cookie) | Stores the click ID (fbclid) when you arrive by clicking a Facebook or Instagram ad. | 90 days |
| fr | Meta, on facebook.com (third-party cookie) | Used to deliver and measure ads and to make them more relevant. Present only if your browser holds cookies from Meta, for example because you use Facebook or Instagram. | 90 days |
The first-party marketing cookies belong to this site’s domain, but the Google tag and the Meta Pixel send their values to Google and Meta. Google and Meta set and read the third-party cookies on their own domains. Google and Meta keep the data they receive under their own retention policies.
Comment form and newsletter box
The comment form on blog and personal posts and the newsletter box at the end of each post set no cookies. WordPress’s comment cookies, which would remember a commenter’s name and email address for the next comment (names beginning with comment_author_), are switched off on this site. Avatars are switched off on the whole site, so pages make no requests to Gravatar and your email address is not sent to it. The hidden field and timestamp used for spam protection are sent with the form and are not stored in your browser. My GDPR privacy notice explains how I process comment and newsletter data.
How the tags are loaded
I use Google Consent Mode v2 in its basic form. Until you consent, no Google tag loads and no data is sent to Google, not even cookieless measurement pings. Consent to analytics lets Google Analytics run. Consent to marketing lets Google Ads run and grants the ad_storage, ad_user_data and ad_personalization signals; if you refuse marketing, remarketing stays off. The consent tool loads the Meta Pixel and Cloudflare Web Analytics only after you give the matching consent.
Third parties and transfers outside the EU and UK
I am based in Türkiye. This site is hosted by my processor Veridyen Bilişim Teknolojileri San. ve Tic. Ltd. Şti. on a server in İstanbul, Türkiye. The server receives the pll_language cookie with each request and stores the consent log. Türkiye has no adequacy decision from the European Commission or under UK law; my GDPR privacy notice explains what this means for your data. All traffic to the site passes through Cloudflare’s global network. So although the site and its data are stored on a server in Türkiye, requests are also processed outside Türkiye.
These companies receive data through the cookies and tools described above:
| Recipient | Role | Location | Transfer safeguard |
|---|---|---|---|
| Veridyen Bilişim Teknolojileri San. ve Tic. Ltd. Şti. (hosting, consent log) | Processor | İstanbul, Türkiye | Türkiye has no adequacy decision. My GDPR privacy notice explains how I handle this. |
| Cloudflare, Inc. (delivery and security of every page, security cookies, Web Analytics) | Processor | USA, and the data center nearest to you on Cloudflare’s global network | EU Standard Contractual Clauses (Modules 2 and 3) and the UK Addendum in Cloudflare’s Customer Data Processing Addendum. Cloudflare, Inc. is also certified under the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Data Privacy Framework. |
| Google LLC (Google Analytics 4) | Processor | USA and other countries where Google has facilities | Standard Contractual Clauses in Google’s data processing terms for processor products, where they are required. Google LLC is also certified under the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Data Privacy Framework. |
| Google Ireland Limited; Google LLC for visitors in the UK (Google Ads) | Independent controller | Ireland; data is processed in the USA and other countries | For EU/EEA visitors the recipient is in the EEA, and Google is responsible for its own onward transfers. For UK visitors, the transfer terms in Google’s Controller-Controller Data Protection Terms; in addition, Google LLC’s certification under the UK Extension to the EU-US Data Privacy Framework. |
| Meta Platforms Ireland Limited (Meta Pixel, EU/EEA visitors) | Joint controller with me for collection and transmission; processor for matching and measurement; responsible for its own processing afterwards | Ireland; data is processed in the USA and elsewhere | The recipient is in the EEA. Meta’s onward transfers to Meta Platforms, Inc. rely on that company’s certification under the EU-US Data Privacy Framework. |
| Meta Platforms, Inc. (Meta Pixel, UK and other visitors) | Processor for UK visitors; processor or independent controller for other visitors | USA | For UK visitors, I have not been able to confirm which transfer safeguard applies, so I do not name one here. |
The Standard Contractual Clauses, the UK Addendum and the Data Privacy Framework were designed for transfers from the EEA and the UK. Because I am established in Türkiye, it is not settled whether they apply formally to my transfers. I rely on them as the safeguards that are available.
You can read Cloudflare’s terms at cloudflare.com/cloudflare-customer-dpa and Google’s processor terms at business.safety.google/processorterms. You can check the certifications at dataprivacyframework.gov. I can also send you a copy of the relevant clauses if you ask.
Opting out with Google and Meta
These settings work alongside your choices on this site, not instead of them:
- Google: you can manage ad personalization in My Ad Center, and you can block Google Analytics on all websites with the Google Analytics opt-out browser add-on.
- Meta: if you use Facebook or Instagram, you can control how Meta uses information from other websites for ads in your ad preferences.
Managing cookies in your browser
You can also block or delete cookies and site data in your browser settings. Most browsers let you block third-party cookies, delete the cookies of a single site, and clear a site’s stored data, which also removes the localStorage and sessionStorage items listed above. Your browser’s help pages explain how.
If you block all cookies, Cloudflare’s security check may be shown repeatedly and some parts of the site may not work as expected. Deleting cookies also deletes your consent choice, so the banner will ask you again on your next visit.
Your rights
Right to object. Where I rely on legitimate interests, for the security cookies, the preference items and the consent log, you have the right to object at any time on grounds relating to your particular situation (Article 21(1) GDPR). If you ask, I will send you my assessment of those interests.
You can withdraw your consent at any time through the Cookie settings link. You also have the rights of access, rectification, erasure, restriction and portability. You can also complain to a data protection supervisory authority, in particular in the EU Member State where you live or work or where the alleged infringement took place, or, in the UK, to the Information Commissioner’s Office (ICO). My GDPR privacy notice explains these rights and how to use them. Many of the items in this policy stay in your browser, and you can delete them yourself at any time.
Changes to this policy
I update this policy when I add, remove or change a cookie or a tool. If a change needs your consent again, the banner will ask you. The date below shows the current version.
Last updated: October 3, 2026