Google Analytics and cookie preferences
The Google Analytics 4 tag (Google; G-13R1XE9ZTL) loads by default when a web page opens. Before an analytics cookie choice, or when declined, analytics_storage=denied permits cookieless measurement signals; this does not mean that no data is sent to Google. Google may process page URLs/titles, referrers, device/browser information and the connection IP address. The connection may involve processing abroad. Account identifiers, portfolio amounts and calculator inputs are not sent as custom analytics parameters. Advertising storage, advertising user data, ad personalization and Google Signals are disabled.
Cookie Preferences shows necessary cookies as always active. The analytics cookie switch in Settings and Accept All allow _ga and _ga_* cookies for at most 180 days; Reject or switching off clears accessible GA cookies while cookieless measurement continues. GPC/DNT disables measurement; the tag file may still load. metrilume:analytics-consent:v1 stores only the choice and timestamp; the choice is requested again after 180 days. If saving fails, analytics cookies stay off in this tab. Earlier accept/decline records are preserved as cookie choices. Cookie Preferences in the footer reopens the panel. Previously received Google data is not retroactively erased; report retention is managed in Google property settings. Native applications and standalone Lume Embed iframes do not load this web tag. External chart providers’ storage controls are subject to their policies and browser settings.
1. Scope and responsible party
MetriLume is a product of AxelVira Teknoloji A.Ş. that provides financial information, comparison, calculation, and portfolio-tracking tools. AxelVira Teknoloji A.Ş. is the data controller for personal data it processes for purposes and by means it determines, and a processor in the limited circumstances in which it processes data on a business customer’s documented instructions.
This policy covers the metrilume.com domain, MetriLume mobile applications, support communications, and related account, membership, or administration interfaces. Independent third-party websites, data sources, and stores are governed by their own privacy notices.
2. Current service status
My watchlist and saved research views are held only on this device under metrilume:research-workspace:device:v1, using localStorage on the web and AsyncStorage in the mobile application. The store contains market type, fund code or US ticker, instrument name and time added, together with view identifiers, the view name you provide, supported research selections such as filters/search query, sorting and period, saved timestamps and the store version. Technical limits are up to 200 instrument references, 20 saved views and 256 KiB in total. Instrument references are not price histories or portfolio balances. These records have no MetriLume account or server synchronization, server backup or support recovery. Opening a saved view passes its supported filters and search query into the relevant page’s URL/query parameters and to the MetriLume API to retrieve results; on the web, the URL query string may reach the browser, network/edge layer and server. The view name you provide is not added to these queries and stays on the device. Records remain until you remove the relevant instrument/view in the product or clear browser site data or application storage. Losing or changing a device, changing browsers, uninstalling or reinstalling the application may cause record loss. Deleting an account does not automatically clear these local records.
Inputs that you do not save in general calculators, initial-public-offering and dividend tools, and financial widgets are processed only in the memory of the open page or iframe; they are not sent to persistent storage, a MetriLume server, the website publishing the Embed, or analytics. By contrast, scenarios you choose to save in Lume Scenario and records in Lume Journal and Lume Learn are held only in your browser’s localStorage under the keys described below; they are not synchronized with a server or your account. To measure service quality and research interest, limited first-party product events are processed without persistent visitor/session identifiers, Turkish fund codes, search text or financial-tool inputs; GPC/DNT signals suppress recording. US research records the module, public SEC CIK/ticker, filing family, chart symbol and buckets for search length, result count and duration as daily counters. The CIK and ticker identify a public issuer or fund class, not a visitor. Raw US events, IP addresses, user agents, referrers and client timestamps are not retained; daily counters are kept for 90 days. Public research trends use aggregate results after sufficient activity across multiple days; no unique-user counts are published. Your portfolio remains in browser or application storage. Selected fund codes are sent to the server for a current-price request; if you create a comparison-sharing link, the fund codes and period are written into the URL query string and transmitted to the browser, network/edge layer, and server when the link is opened.
In US Markets search, the public-company name or symbol you enter is sent to the MetriLume API; SEC EDGAR data is fetched server-side, so your browser IP address is not sent directly to the SEC. Opening the US Markets Charts module or the BIST equities page on the web or mobile automatically loads the TradingView chart or stock screener through your browser or the in-app WebView. TradingView may process IP address, device/browser and network information, referring page if sent by the client, selected symbol, market and widget configuration, and provider cookie or analytics data under its own policies. These displays send no MetriLume account, portfolio or order data; external links open in the system browser.
3. Categories of information processed
| Category | Examples | Status and source |
|---|---|---|
| Basic request and security data | Request time, requested route, response status, error and abuse signals; IP address and protocol headers at the infrastructure layer | Generated automatically to deliver and protect the service. Product event logging is restricted so that it does not retain raw IP addresses, query strings, referring addresses, or user-agent strings. |
| US markets research and BIST display data | Company-name or symbol search, selected public SEC CIK and ticker; symbol, market and widget configuration and ordinary third-party network and device data in the US Markets Charts module and BIST equities page | The search reaches the MetriLume API, which fetches SEC EDGAR company and financial-statement data server-side. Opening the US Markets Charts module or BIST equities page on the web or mobile automatically connects to TradingView. |
| Language and device preferences | Turkish/English selection and interface preferences held only on the device | A necessary language cookie on the web; on-device application storage on mobile. |
| Portfolio and unsaved tool inputs | Fund code, transaction date, quantity, cost; fund codes and period of a saved comparison; amounts, rates, and terms entered into general calculators and initial-public-offering and dividend tools | The portfolio and up to five saved comparisons are stored on the device by default. In a sharing link, fund codes and the period are written into the URL query string and transmitted over the network when the link is opened; you should not add a confidential preference to that link. Unsaved inputs in general calculators and input-only initial-public-offering and dividend tools remain in page memory and are not written to persistent storage. Cloud sync operates only if the account feature is enabled and the user initiates it. |
| Lume Scenario on-device data | Scenario name; initial and recurring amounts, rates, duration, and the selected calculation or methodology | Written to browser localStorage under metrilume:lume-scenario:device:v1 only when you select “Save.” It is not synchronized with a server or account and cannot be viewed or recovered by support. |
| Lume Journal on-device data | Title, thesis/decision, expectation/assumption, and risk/signal; planned review time; review notes, outcome, and time; open/reviewed/archived status; record identifiers and created, decided, updated, and store-saved timestamps. The schema contains tag and portfolio/scenario-reference fields, but the current interface provides no input control for them | Held only in browser localStorage under metrilume:lume-journal:device:v1. It is not synchronized with a server or account and cannot be viewed or recovered by support. |
| Lume Learn on-device data | Lesson identifier, progress and completion status, score, and timestamps | Held only in browser localStorage under metrilume:lume-learn:progress:v1. It is not synchronized with a server or account and cannot be viewed or recovered by support. |
| Lume Embed request and configuration data | Requested iframe/asset path, request time, IP address and protocol headers at the infrastructure layer, the referring site’s origin if sent by the browser, and visible title, locale, and appearance configuration in the iframe URL | Transmitted to the network/edge layer as an ordinary technical request when the Embed loads. Financial inputs inside the widget remain in iframe memory and are not sent to MetriLume, the publishing site, or analytics. Do not place personal, special-category, or confidential information in a title or other configuration carried in the URL. |
| Mobile installation data | A random installation UUID generated by the application on the device | Held on-device in SecureStore to bind the mobile session vault to this installation; it may be created even while authentication is disabled and is not, by itself, a MetriLume account. |
| Support and request data | Name, contact information, message, attachments, request, and resolution record | Collected from you when you contact us by email or through another support channel. |
| Account and identity data | User identifier; Google/Apple provider identifier; masked or encrypted email address/phone number; session, passkey, and security records | Processed only when the account and relevant sign-in method are enabled. Passwords are not stored; biometric templates are not sent to a MetriLume server. |
| Order and membership data | Plan, price version, order and subscription status, invoice, and provider transaction reference | Processed only when paid services are enabled. Card numbers and CVVs do not enter or get recorded in MetriLume systems. |
| Accountability records | Consent version, security incident, account-deletion request, administrative action, and immutable payment-event summary | Retained for security, dispute resolution, and legal obligations when the relevant feature is enabled. |
Do not place identifying personal or confidential information in a Lume Scenario name or visible title/configuration in a Lume Embed URL. Lume Journal may be used for your own ordinary financial decision notes; do not add special-category data, account/access credentials, or unnecessary personal or confidential information about another person to Journal, support, or other free-text fields. Such information is not required to provide the service.
4. Collection methods
- Automatic technical transmission from your device and network connection when you use the website, application, or a Lume Embed iframe on another website.
- Information you provide directly when choosing a language, recording a portfolio, creating records held only on the device in Lume Scenario, Lume Journal, and Lume Learn, completing a form, creating an account, or placing an order.
- If enabled, verification and transaction results returned by providers such as Google, Apple, phone-verification services, payment providers, or application stores.
- Correspondence with you concerning security, support, objections, and legal requests.
- Market data obtained from public or licensed financial-data sources that, as a rule, does not identify you.
5. Processing purposes and principles
- To operate the requested page, financial tool, Lume module, Lume Embed iframe, price query, and language/device preference, and to remember the Lume Scenario, Lume Journal, and Lume Learn records you select only on your device.
- When enabled, to authenticate identity, protect the session, synchronize the cloud portfolio, and fulfil an order and membership entitlement.
- To prevent fraud, automated abuse, unauthorized access, data loss, and service interruption, and to investigate incidents.
- To provide support, respond to rights requests, resolve disputes, and satisfy legal record-keeping obligations.
- To measure service quality and research interest through daily aggregate counters without persistent identifiers or cookies, respect GPC/DNT signals and publish research trends only after sufficient activity thresholds are met.
- To apply optional communication or cookie preferences where the user has separately consented.
We process data for specified, explicit, and legitimate purposes, in a way that is relevant, limited, accurate, and, where necessary, kept up to date. If a new and incompatible purpose arises, the necessary notice and legal-basis assessment will be completed before processing begins.
7. International data transfers
Personal data may be accessible from outside Türkiye or your country because of global networking and security services, a TradingView chart or stock screener loaded automatically when the US Markets Charts module or BIST equities page opens, or international identity providers that may be enabled in the future. The provider connection is explained in the US Markets Charts module and BIST equities page. Before a transfer, we assess the data type, country, recipient role, and necessity of the transfer.
A transfer may occur only where there is a valid mechanism, such as an adequacy decision, a standard contract published by the Board, or another appropriate safeguard under the KVKK, or an adequacy decision, standard contractual clauses, and supplementary technical or organizational measures where necessary under the GDPR. Derogations are used only under the narrow statutory conditions. This page does not represent that a particular transfer instrument is in place for the current Cloudflare flow until its exact contracting party, countries, and mechanism are confirmed from verified operator records.
8. Retention and deletion
We do not apply a single general retention period; instead, retention depends on the processing purpose and record type. We consider continued service needs, security timeouts, backup cycles, request and claim limitation periods, tax, commercial, and consumer obligations, and regulatory directions.
| Record | Retention criterion | End-of-period action |
|---|---|---|
| Daily US Markets product-interest counters | 90 days; raw US product events are immediately converted into daily counters without being retained | Deletion of expired daily counters |
| On-device portfolio and language preference | Until you clear device data or uninstall the application; the web language cookie lasts no more than 12 months; saved comparisons are limited to no more than five records on the device | Deleted from your device or the preference is renewed |
| On-device Lume Scenario, Lume Journal, and Lume Learn records | Until you delete the relevant record or clear metrilume.com localStorage/site data; Lume Scenario holds up to 12 scenarios and Lume Journal up to 250 decision entries on the device; there is no automatic server-retention period | Deleted from the device through the in-product delete control or browser site-data clearing. Browser clearing, a device/browser change, or reinstallation may cause loss; deleting an account does not automatically clear browser localStorage, and support cannot recover these records |
| Account and cloud portfolio | While the account remains open and, after a deletion request, for applicable legal or defense periods | Deletion, anonymization, or legally required retention with restricted access |
| Session and authentication | The period required for session lifetime, the abuse window, and security review | Token invalidation; record deletion or irreversible dissociation |
| Order, invoice, and payment event | Applicable financial, consumer, and dispute record-keeping periods | Secure deletion or anonymization after the legal period ends |
| Support and rights request | Resolution of the request and the relevant rights or claims periods | Deletion or conversion into non-identifying statistics |
If the account feature is enabled, a deletion request stops the creation of new sessions and transactions. Records that must be retained by law are separated from the active product, access is restricted, and they are used only for the retention purpose. Where a flow uses backups, copies expire within the protected cycle documented before activation.
Numeric or event-triggered retention periods for current edge/origin security records, limited product events, and email infrastructure must be established from the data inventory and supplier contracts examined during operator fact verification. This version does not promise an unverified exact period; new persistent flows such as accounts, payments, or server portfolios cannot be enabled until their retention and deletion controls are documented.
9. Security measures
- TLS in transit, security headers, and network/edge protection in the current public service.
- Input validation, rate limiting, and abuse controls in the current public service; limited product events omit raw IP addresses, query strings, referrers, user agents, fund codes, Lume content, and financial-tool inputs.
- Independent feature gates for identity, administration, and payments that enable only verified capabilities in production.
- Risk-appropriate field-level encryption, purpose-separated HMAC, masking, short-lived verification, session rotation, CSRF, and replay protections only if account/identity features are enabled.
- A verified hosted-provider approach that keeps card data outside the MetriLume environment, with secret/data masking in payment logs, only if payments are enabled.
- Backup/restoration, retention/deletion, vulnerability, incident-response, and supplier controls that must be documented and tested before any new feature using persistent server data is activated; this public list does not represent that they are currently deployed for every disabled feature.
No system can guarantee absolute security. If we identify a breach that requires notification because of risks to your rights and freedoms, we will notify the competent authorities and affected individuals in accordance with applicable timing and content rules.
10. Your choices and rights
- You can clear local portfolio, language, Lume Scenario, Lume Journal, and Lume Learn data through your browser or device settings. Deleting an account does not automatically clear browser localStorage records; you must separately use the in-product delete control or clear browser site data.
- You may use the necessary portion of the service without accepting them and may change your preference later.
- When the account feature is enabled, the account center will provide tools to close sessions, manage the portfolio, and initiate an account-deletion request.
- You may submit requests to access, correct, or erase your personal data, or to restrict or object to processing, in accordance with applicable KVKK/GDPR rights.
- If marketing communications are enabled, you may unsubscribe using the method provided in each communication.
Details of these rights, identity-verification methods, and application channels are set out in the KVKK + GDPR Privacy Notice. We request only enough information to verify the person making a request.
11. Children’s privacy
MetriLume is generally intended for adults capable of making financial decisions and does not knowingly seek to collect account data from children. A user who requires parental or guardian consent under applicable law may use an account feature only when that consent and an appropriate age assurance are in place. No account or paid feature launches until the operator has documented the target countries, minimum age, required guardian flow, and storefront scope. Please notify us if you believe a child’s data has been processed inappropriately.
12. Changes and contact
If there is a material change to a purpose, data category, recipient, or right, we will publish the text with a new version and effective date and, where necessary, provide an in-product or direct notice and renewed consent. This does not retroactively alter the lawfulness of earlier processing.
For privacy questions, contact [email protected]; for KVKK applications, contact [email protected]. In postal applications, identify yourself and your request clearly, and do not send unnecessary special-category data or identity documents.
Contact and data controller
- AxelVira Teknoloji A.Ş.
- İzmir Trade Registry 271455
- Address
- Adalet Mah. Manas Blv. No:47/B Folkart Plaza D:3509, Bayraklı/İzmir, Türkiye
- Tax identification number
- 0991410303
- MERSİS
- 0099141030300001
- Support
- [email protected] · +90 (850) 840 20 83
- Privacy and data requests
- [email protected] · [email protected]