Privacy Policy
Last updated ·
This policy describes exactly what ByKaranteli collects, why, and what we do not collect. It is written against the running code rather than from a template, so it is specific and occasionally shorter than you may expect. Where we hold nothing, we say so.
Who operates this site
ByKaranteli is an independent crypto derivatives data platform operated from Türkiye. We are the controller of the personal data described here. You can reach a human at support@bykaranteli.com.
What we collect when you create an account
- Your email address. It is the account identifier and the only contact detail we require.
- A password hash, if you set a password. We store an argon2id hash, never the password itself. Accounts created through Google sign-in or a one-time email link have no usable password.
- Your interface language, so emails and pages arrive in the right one.
- Timestamps: when the account was created, when the email was verified, when you last signed in.
- Optional profile fields you enter yourself: a public handle, display name and short bio. These are only published if you switch the public profile on.
What we collect as you use the site
- Product events such as page views inside the member workspace and successful sign-ins. These records hold an opaque session identifier and a coarse device family such as ios, android or desktop. They do not hold your IP address.
- Security and audit records for account actions such as sign-in, password reset and email verification. These do hold the IP address the request came from, because an audit trail without it cannot answer the question it exists to answer.
- How you first arrived: the utm source, medium and campaign on your first visit, the landing page, and a referral code if a member referred you. These live in the bk_acq and bk_ref cookies and are attached to the account at signup.
- Standard server logs at our web server and at Cloudflare, which sits in front of the site. These contain IP addresses, requested paths and user agents, and exist for abuse prevention, rate limiting and debugging.
What we deliberately do not collect
- Exchange API keys. We never ask for them and there is nowhere in the product to enter one.
- Custody of any funds. We hold no assets on your behalf and cannot place a trade for you.
- Card or bank details. Subscriptions settle on chain, so no payment card ever reaches us.
- Your IP address inside product analytics. That table is deliberately IP-free.
- Cross-site advertising identifiers. We run no advertising pixels and no retargeting tags.
Payments
Subscriptions are paid in USDC or USDT on Solana. For each attempt we store the plan, the token, the expected amount, a unique on-chain reference key used to match your transfer, the status and the relevant timestamps. We do not store your private keys and we cannot move funds.
Blockchain transactions are public and permanent by design. Anything you send on chain is visible to anyone, independently of this site, and cannot be deleted by us or by you.
Cookies
- bk_session: your sign-in session. Strictly necessary. Without it you cannot stay signed in.
- bk_acq and bk_ref: first-touch attribution and referral credit, set on your first visit.
- bk_view_scope and bk_pending_watch: small interface preferences, such as the last view you chose.
- Google Analytics cookies beginning with _ga: see the next section.
Third parties that see data
- Cloudflare, as CDN and security layer in front of the site. It processes IP addresses and request metadata for every visit.
- Google Analytics 4, property G-VC79YWMSCT, for aggregate traffic measurement. It sets its own cookies and receives your IP address, which Google truncates. If you would rather not be measured, any standard content blocker or the Google Analytics opt-out add-on will stop it, and the site works normally without it.
- Google, if and only if you choose to sign in with Google. In that case Google tells us your Google account identifier, your email address and whether Google has verified it. We request no other permission and we never gain access to your Gmail, Drive or contacts.
- Our email provider, for verification, sign-in links, alerts and digests you have asked for.
- Market data sources such as exchanges and public data providers. These receive requests from our servers, not from your browser, so they do not see you.
How long we keep things
- Account records: while the account exists, then removed on deletion.
- Sign-in sessions: until they expire or you sign out, whichever comes first.
- One-time email tokens: they expire quickly and are single use, and the used ones are kept only as a record that they were spent.
- Product analytics and audit records: retained on a rolling window for operational and security purposes, then pruned.
- Billing records: retained as long as we are required to keep a record of the transaction.
Your rights
You can ask us for a copy of the personal data attached to your account, ask us to correct it, or ask us to delete the account entirely. Deletion removes the account and everything keyed to it. It cannot remove anything already published on a public blockchain, because that is outside our control.
Write to support@bykaranteli.com from the address on the account and we will act on it. If you are in a jurisdiction with a supervisory authority for data protection, you also have the right to complain to it.
Security
Passwords are stored as argon2id hashes. Session tokens are stored as SHA-256 hashes, so the value in your cookie does not exist anywhere in our database. API keys are stored the same way, as a hash plus a short display prefix, which is why we can never show you a key again after you create it. Transport is HTTPS only.
No system is perfectly secure. If you believe you have found a vulnerability, please write to support@bykaranteli.com before disclosing it publicly.
Children
This service is not intended for anyone under 18, and we do not knowingly collect data from anyone under 18.
Changes
If this policy changes in substance, we will change the date at the top of this page. Material changes affecting existing members will also be sent by email to the address on the account.
Contact
Questions about this policy, or a request about your data: support@bykaranteli.com.