Home

This English translation is provided for convenience. In case of any discrepancy, the Turkish version prevails.

Privacy and Cookie Policy.

Explains what information MEGAWATTRON stores in your browser, why it does not use third-party cookies or tracking tools, and how it protects your data.

Last updated: 27 September 2026

Contents · 8 sections

01Scope

This policy applies to the megawattron.com marketing site, the app.megawattron.com customer panel and the MEGAWATTRON REST API. It describes the information we store in your browser, the records we keep on the server side and the security measures we apply.

Which personal data we process, for which purpose and on which legal ground, to whom we transfer it and your rights under the KVKK (Law No. 6698 on the Protection of Personal Data) are set out in detail in the KVKK Privacy Notice.

02We do not use third-party cookies or tracking tools

Our site and our panel contain no analytics, advertising, retargeting or social media cookies. We do not load any third-party script that tracks visitor behaviour, such as Google Analytics, Google Tag Manager, the Meta (Facebook) pixel, heat-map or session-recording tools; we do not follow you across sites and we do not profile you.

Fonts are served from our own servers; when you open the pages, no request is sent to external font services such as Google Fonts. Our browser security policy (Content Security Policy) likewise allows our pages to connect only to our own servers and our API; the sole exception is the map tiles described below.

03Information we store in your browser

We use your browser's local storage (localStorage) so that the service works and your preferences are remembered. These entries belong to our domain only, cannot be read by other sites and, apart from the session token, are not sent to our server.

Session
aeth.refresh, aeth.user
The refresh token that keeps your session going after you sign in, and your account summary (name, e-mail, role). Strictly necessary; deleted when you sign out, and invalid once the session expires.
Sign-up flow
aeth.postVerify
Temporary storage of the cart you selected while signing up, so that you can continue where you left off after e-mail verification. Strictly necessary; deleted after verification.
Theme
theme
Your light, dark or automatic theme preference. Preference entry; kept until you change or delete it.
Panel view
forecasts.*, panel.*
The country and product you last selected; whether the sidebar is collapsed; notifications marked as read. Preference entry; kept until you delete it.
Language
aeth.locale (cookie)
The interface language you prefer, once you have made a language selection. Preference cookie; 1 year.

These entries are either strictly necessary for the service to work in the way you have requested, or merely remember a choice made by you; they serve no advertising or tracking purpose and are not shared with third parties. Your password is never stored in the browser; the session access token is held in memory only while the page is open.

04How you can delete this information

  • Sign out: when you sign out of the panel, the session tokens are deleted from your browser and the session is terminated on the server side.
  • Clear site data: in your browser's settings, under "Cookies and site data" (or "Privacy and security"), you can delete the data stored for megawattron.com. In that case your session is closed and your preferences return to their defaults.
  • Use a private window: entries created in a private/incognito window are deleted by your browser when the window is closed.

05Map tiles (OpenStreetMap)

The map shown on the panel screen where you select the plant location loads map images from the OpenStreetMap servers (tile.openstreetmap.org). When you open this screen, your browser connects directly to those servers in order to retrieve the map images, and in doing so your IP address and browser information are transmitted to the OpenStreetMap Foundation. The map is loaded on this screen only; no external connection is made on the marketing site or on the other panel pages. OpenStreetMap's processing of this data is governed by its own privacy policy.

06Records kept on the server side

To ensure security and prevent misuse, our servers keep the IP address, browser information (user agent), sign-in and session records, API key usage records and audit records of account/administration operations. These records are retained for a maximum of 2 years and are viewed only by authorised personnel, when a security review or a legal obligation so requires. For details, see the KVKK Privacy Notice.

07Data security measures

  • Encrypted connection: all site, panel and API traffic is encrypted with TLS (HTTPS); browsers are directed by HSTS to use secure connections only.
  • Passwords: stored only as an irreversible hash generated with the bcrypt algorithm; nobody, including our employees, can see your password.
  • API keys: shown only once, at the moment they are created; the system stores not the key itself but its hash (SHA-256) and a short prefix that helps you recognise it. If you lose the key it cannot be recovered; you revoke it in the panel and create a new one. Session refresh tokens are likewise stored as hashes.
  • Access records: sessions, API calls and administration operations are logged; unusual usage is detected by means of these records.
  • Least privilege: personnel and systems access only the data required for their duties; the customer panel and the administration panel are separate, and administration rights are granted to a limited number of people.
  • Against misuse: request limits (rate limits) are applied on all endpoints, with stricter limits on sign-in and password reset, together with browser security headers (CSP, framing protection).
  • No card data: as payments are made by bank transfer, card details are neither collected nor stored.

No system is entirely free of risk. In the event of a data breach, we will inform the data subjects concerned and the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) within the periods laid down in the legislation, pursuant to Article 12 of the KVKK. If you notice a suspicious operation on your account, please write to info@megawattron.com immediately.

08Changes and contact

We may update this policy as the technologies we use or the legislation change; the current version is always on this page, and the date at the top shows the latest change. Should we need to add a new third-party service or a cookie that requires permission, we will update this page before starting to use it and, where necessary, ask for your consent. For questions you can write to info@megawattron.com; to exercise your rights, see how to apply.