Privacy Policy
Last updated: April 6, 2026
Overview
This Privacy Policy explains how Tolga Cagin ("I", "me", "my") collects, uses, and protects your personal information when you visit tolgacagin.com or use my services. I am committed to protecting your privacy and handling your data responsibly.
Information I Collect
Account Information
When you register for the Client Portal, I collect your full name, email address, and password. Passwords are stored in hashed form and are never accessible in plain text.
Payment Information
Payment processing is handled by iyzico, a PCI-compliant payment gateway. Your credit card details (card number, expiry date, CVV) are sent directly to iyzico and are never stored on my servers. iyzico may store tokenized card information for recurring billing purposes. Your IP address is shared with iyzico as required by their payment verification process.
Newsletter
If you subscribe to my newsletter, I collect your email address. You can unsubscribe at any time by contacting me directly.
Analytics Data
I use Google Analytics to understand how visitors interact with my website. This collects anonymized data such as pages visited, time spent on site, device type, and approximate location. I also use Vercel Speed Insights to monitor site performance.
Meeting Scheduling
My contact page uses Calendly for booking meetings. When you schedule a meeting, Calendly collects your name, email, and scheduling preferences under their own privacy policy.
How I Use Your Information
- To provide and manage your subscription services
- To process payments and manage recurring billing
- To communicate with you about your account or projects
- To send newsletter updates (if you opted in)
- To improve website performance and user experience
- To comply with legal obligations
Cookies
My website uses the following cookies:
- Authentication cookie (portal_token) — a secure, HTTP-only cookie used to keep you signed in to the Client Portal. It expires after 7 days.
- Google Analytics cookies — used to collect anonymous usage statistics.
Third-Party Services
I share your information with the following third-party services, each of which has their own privacy policy:
- iyzico — payment processing and card storage
- Google Analytics — website analytics
- Vercel — website hosting and performance monitoring
- Calendly — meeting scheduling
I do not sell, rent, or trade your personal information to any other third parties.
Data Security
I take reasonable measures to protect your personal information, including using HTTPS encryption for all data transmission, secure HTTP-only cookies for authentication, and 3D Secure verification for card payments. However, no method of electronic transmission or storage is 100% secure.
Data Retention
I retain your account information for as long as your account is active or as needed to provide services. Newsletter email addresses are retained until you unsubscribe. Analytics data is retained according to Google Analytics' standard retention policies. Payment records are retained as required by applicable tax and accounting regulations.
Your Rights
You have the right to:
- Access the personal data I hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Withdraw consent for newsletter communications
- Request a copy of your data in a portable format
To exercise any of these rights, please contact me at the email address below.
International Data Transfers
Your data may be processed in different countries depending on the service provider. Vercel and Google operate infrastructure globally, and iyzico is based in Turkey (a PayU company). By using my services, you consent to the transfer of your information to these providers.
Changes to This Policy
I may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
Contact
If you have any questions about this Privacy Policy, please contact me at tolga.cagin@gmail.com.