Skip to content

Free Worldwide Shipping

Flexible Payment Options

↩️ 14 DAY FREE RETURN GUARANTEE

See It In Your Room with AI

Privacy policy

Privacy and Personal Data Protection Policy

Data controller: Halınet Halı Tekstil Ürünleri Pazarlama Sanayi ve Ticaret A.Ş.

Address: Bağlarbaşı Mahallesi, Halı Sokak No: 12, 34662 Üsküdar / İstanbul

Applications: info@hali.net · Registered electronic mail (KEP): halinethali@hs01.kep.tr

This text has been prepared in order to fulfil our duty to inform under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data (KVKK). Additional information applicable to persons residing in the European Union and the United Kingdom is set out in Section 8.

1. Personal Data We Process

  • Identity: first name, surname.
  • Contact: address, e-mail, telephone.
  • Customer transactions: order history, return and exchange records, requests and complaints.
  • Transaction security: IP address, cookie records, session information.
  • Financial: payment instrument information. Card numbers are not stored by us; payment is processed on the infrastructure of a licensed payment institution.
  • Marketing: shopping habits and preferences, subject to your explicit consent.

2. Method of Collection

Through website forms, the membership and order flow, cookies and similar technologies, and customer service correspondence; and also from third parties such as analytics providers and payment institutions, by automated and partly automated means.

3. Our Processing Purposes and the Legal Ground for Each Purpose

In accordance with Article 5 of the KVKK, the purposes and their legal grounds are set out separately:

  • Receiving, preparing and delivering the order. Legal ground: necessity for the establishment and performance of a contract (Art. 5/2-c).
  • Issuing invoices and keeping financial records. Legal ground: compliance with a legal obligation (Art. 5/2-ç).
  • Carrying out return, exchange and warranty processes. Legal ground: performance of a contract (Art. 5/2-c) and legal obligation (Art. 5/2-ç).
  • Responding to requests and complaints. Legal ground: legitimate interest (Art. 5/2-f).
  • Site security and the prevention of fraud. Legal ground: legitimate interest (Art. 5/2-f).
  • Sending commercial electronic messages. Legal ground: explicit consent (Art. 5/1). You may withdraw your consent at any time.
  • Personalised content and advertising. Legal ground: explicit consent, given through your cookie preferences.

For persons residing in the European Union and the United Kingdom, the Article 6 GDPR counterparts of these legal grounds are additionally set out in Section 8.1.

4. Transfers

Your data is transferred solely for the relevant purpose to the following parties:

  • Shipping companies — name, address and telephone, for delivery.
  • Payment institutions and banks — for the execution of payment.
  • The e-commerce infrastructure provider and the hosting service.
  • Analytics and advertising providers — subject to explicit consent.
  • Our financial adviser and legal counsel; and, upon request, judicial and administrative authorities.

Transfers abroad: The servers of the e-commerce infrastructure, analytics and marketing services we use are located abroad. The principal service providers to which we transfer data, and the purposes of those transfers, are as follows:

  • Shopify (Canada and the United States of America) — e-commerce infrastructure; hosting and processing of store, membership and order data.
  • Google (European Union and the United States of America) — Google Analytics and related measurement/advertising services; measurement of site usage and monitoring of advertising performance.
  • Microsoft Clarity (United States of America) — behavioural analytics regarding how pages are used.
  • Klaviyo (United States of America) — e-mail and message marketing; solely subject to your explicit consent.
  • Loox (abroad) — collection and publication of product reviews.

These transfers are made under Article 9 of the KVKK; where the transfer is to a country covered by an adequacy decision, on the basis of that decision, and otherwise on the basis of the appropriate safeguards provided for in the Law (including standard contracts) or your explicit consent. For the safeguards applied to transfers originating in the European Union and the United Kingdom, please see Section 8.4.

5. Retention Periods

  • Order, invoice and financial records: 10 years (as required by the Turkish Tax Procedure Law and the Turkish Commercial Code).
  • Membership record: for the duration of the membership and for 10 years following its termination (the limitation period).
  • Request and complaint records: 3 years.
  • Cookie records: between the duration of the session and 24 months, depending on the type of cookie.
  • Marketing consent records: 3 years following the withdrawal of consent (for the purpose of proof).

Data not separately listed above is retained until the relevant processing purpose ceases to exist and the statutory retention periods arising from legislation expire. Once the period has elapsed, the data is erased, destroyed or anonymised.

6. Cookies

Strictly necessary cookies are required for the site to function and cannot be switched off; they carry your session, your cart and security verifications. Preference cookies remember choices such as language and currency. Analytics cookies measure how pages are used in an aggregated and de-identified form. Marketing cookies are used to make the advertisements shown to you more relevant.

Analytics and marketing cookies operate only with your consent in regions where consent is mandatory under the applicable legislation. You can manage your preferences by category through the cookie consent notice; you can also delete or block non-essential cookies at any time from your browser settings (see 6.3). Withdrawing your consent does not invalidate processing lawfully carried out up to that point.

6.1 Cookie Inventory

The table below sets out the cookies used on hali.net in terms of name, provider, category, purpose and retention period. The categories are grouped under four headings: Strictly necessary, Functional, Analytics and Marketing.

Cookie Provider Category Purpose Duration
localization Shopify Functional Remembers the country, region and language preference you have selected. 2 weeks
cart_currency Shopify Strictly necessary Carries the currency in which the cart and the checkout flow are conducted. 2 weeks
_shopify_y Shopify Analytics Produces store analytics by distinguishing unique visitors. 1 year
_shopify_s Shopify Analytics Identifies a single visit session; session-based store analytics. 30 minutes
shopify_client_id Shopify Analytics Used as a client identifier in in-store event measurement. Determined by the provider
_ga Google (Google Analytics) Analytics Produces site usage statistics by distinguishing visitors from one another. 2 years
_ga_QHZ0R5D2Z5 Google (Google Analytics 4) Analytics Stores the session state for the relevant GA4 property. 2 years
_ga_BXHY73JNBY Google (Google Analytics 4) Analytics Stores the session state for the relevant GA4 property. 2 years
_ga_YC27T92YWT Google (Google Analytics 4) Analytics Stores the session state for the relevant GA4 property. 2 years
_gcl_au Google (Google Ads / conversion linker) Marketing Stores advertisement click information and thereby attributes conversions. 90 days
_fbp Meta (Facebook) Marketing Identifies the visitor for advertising measurement and retargeting. 90 days
_clck Microsoft Clarity Analytics Stores the unique user identifier for behavioural analytics. 1 year
_clsk Microsoft Clarity Analytics Combines the page views within the same session into a single record. 1 day
__kla_id Klaviyo Marketing Associates the visitor with an e-mail marketing profile; operates solely subject to explicit consent. 2 years
WISHLIST_TOTAL ScriptEngine (Live Wishlist app) Functional Carries the number of products on your wishlist. Determined by the provider
WISHLIST_PRODUCTS_IDS ScriptEngine (Live Wishlist app) Functional Stores the identifiers of the products you have added to your wishlist. Determined by the provider
WISHLIST_PRODUCTS_IDS_SET ScriptEngine (Live Wishlist app) Functional Marks whether a wishlist has been created. Determined by the provider
WISHLIST_UUID ScriptEngine (Live Wishlist app) Functional Assigns a unique identifier to the wishlist; ensures that the list is preserved between visits. Determined by the provider
WISHLIST_IP_ADDRESS ScriptEngine (Live Wishlist app) Functional Associates the IP address of the connection that created the wishlist with that list. Determined by the provider

The cookie names in the table were identified by an examination carried out on hali.net on 22 August 2026. Durations may be updated by the provider; moreover, cookie names and their number may change over time as a result of changes providers make to their own products. We review the current list regularly and update this section accordingly.

6.2 Third-Party Resources Running on Our Pages

In addition to cookies, scripts, fonts, images or measurement resources are loaded on our site from the following third-party domains. When these resources run, your connection information (including your IP address and browser information) may be transmitted to the relevant provider:

  • cdn.shopify.com — Shopify; distribution of store images, fonts and theme files. Strictly necessary.
  • shop.app — Shopify; Shop Pay accelerated checkout and order tracking components. Strictly necessary / functional.
  • www.googletagmanager.com — Google; loading of analytics and advertising measurement codes via tag management. Analytics / marketing.
  • connect.facebook.net — Meta; advertising measurement and retargeting code. Marketing.
  • scripts.clarity.ms and www.clarity.ms — Microsoft Clarity; behavioural analytics code and data transmission. Analytics.
  • static.klaviyo.com and static-tracking.klaviyo.com — Klaviyo; e-mail marketing forms and visit tracking. Marketing.
  • loox.io — Loox; display of product reviews. Functional.
  • cdn.jsdelivr.net — the content delivery network from which open-source JavaScript libraries are distributed. Functional.
  • www.gstatic.com — Google; static resources such as fonts, images and security verification. Strictly necessary / functional.
  • api.orsis.net — Orsis; the service endpoint that enables the distance sales agreement text to be displayed within the order flow. Strictly necessary / functional.
  • uw-egcr.s3.eu-west-2.amazonaws.com — a badge/mark display file specific to our store, hosted on Amazon S3 (London region). Functional.

6.3 How to Manage Your Cookie Preferences

You can delete or block cookies other than strictly necessary cookies from your browser settings. Our site uses a cookie consent notice that offers consent management by category (analytics, marketing, preference, sale of data). This notice is displayed automatically on the first visit to visitors coming from regions where cookie consent is mandatory under the applicable legislation, such as the European Union and the United Kingdom; from there you can give or refuse consent by category and change the consent you have given at a later time. Apart from this, you can also use the provider-based opt-out options set out below. Strictly necessary cookies cannot be switched off, as they are required for the site to function.

In addition, you can view cookies from your browser settings, delete them individually or in bulk, and prevent cookies from being placed in the future. The relevant settings are located under the “Privacy and security” heading in Chrome, Safari, Edge and Firefox; on mobile browsers the same settings are managed from within the application settings. If you block cookies entirely, functions such as the cart, membership and language/currency preferences may not work as expected.

As regards advertising cookies, you may also use the providers' own preference tools; providers such as Google and Meta offer the option of switching off advertising personalisation through your own account settings.

Provider-based opt-out:

  • Google Analytics / Google Ads: Google Analytics Opt-out Add-on and the Ad Settings in your Google Account
  • Meta (Facebook): the Ad Preferences section in your Facebook account
  • Microsoft Clarity: browser-level tracking prevention and cookie deletion
  • Klaviyo: the unsubscribe link in marketing e-mails and browser cookie deletion
  • All browsers: deleting cookies, blocking third-party cookies or enabling “Tracking” protection from the settings section

7. Your Rights under Article 11 of the KVKK

  • To learn whether your personal data is being processed.
  • To request information about it if it has been processed.
  • To learn the purpose of processing and whether the data is used in accordance with that purpose.
  • To know the third parties to whom the data has been transferred, in Turkey or abroad.
  • To request rectification if the data has been processed incompletely or inaccurately.
  • To request erasure or destruction of the data.
  • To request that rectification and erasure operations be notified to the third parties to whom the data has been transferred.
  • To object to a result arising against you as a consequence of analysis carried out exclusively by automated systems.
  • To claim compensation for damage suffered as a result of unlawful processing.

You may submit your applications in writing or by registered electronic mail, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller. We conclude your request within 30 days at the latest.

Right to lodge a complaint with the Personal Data Protection Board: If your application is rejected, if you find our response insufficient, or if your application is not answered within the applicable time limit, you have the right to lodge a complaint with the Personal Data Protection Board within 30 days from the date on which you learned of the response and, in any event, within 60 days from the date of the application (Art. 14 of the KVKK). You can find the Board's application channels and current contact details at kvkk.gov.tr. The complaint route to the Board does not remove your right to have recourse to the courts.

8. For Persons Residing in the European Union and the United Kingdom (GDPR / UK GDPR)

Our company is established in Turkey. Because we offer goods to persons located in the European Union, the General Data Protection Regulation (GDPR) applies to those persons' data pursuant to Article 3(2) GDPR. For persons located in the United Kingdom, the UK GDPR and the relevant provisions of the Data Protection Act 2018 apply. The information and rights in this section apply in addition to those listed above under the KVKK.

8.1 Legal Bases for Processing (Article 6 GDPR)

The Article 6 GDPR counterparts of the legal grounds set out in Section 3 under Article 5 of the KVKK are as follows:

  • Receiving, preparing and delivering the order — performance of a contract (Art. 6(1)(b)).
  • Issuing invoices and keeping financial records — compliance with a legal obligation (Art. 6(1)(c)).
  • Carrying out return, exchange and warranty processes — performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
  • Responding to requests and complaints — legitimate interest (Art. 6(1)(f)).
  • Site security and the prevention of fraud — legitimate interest (Art. 6(1)(f)).
  • Sending commercial electronic messages — explicit consent (Art. 6(1)(a)).
  • Personalised content and advertising — explicit consent (Art. 6(1)(a)), obtained through cookie preferences.

Where we rely on legitimate interest, we carry out a balancing assessment between our interest and your rights and freedoms; we will share a summary of that assessment with you upon request.

8.2 Your Rights as a Data Subject (Articles 15-22 GDPR)

  • Right of access (Art. 15): to access the personal data we process about you and information relating to the processing, and to request a copy thereof.
  • Right to rectification (Art. 16): to request the rectification and completion of incomplete or inaccurate personal data concerning you.
  • Right to erasure (Art. 17): to request the erasure of your data where we have no statutory retention obligation (the “right to be forgotten”).
  • Right to restriction of processing (Art. 18): to request that processing be restricted during the period in which you contest the accuracy of the data or your objection to the processing is being assessed.
  • Right to data portability (Art. 20): to receive the data we process by automated means on the basis of your consent or a contract in a structured, commonly used and machine-readable format; and to request that it be transmitted directly to another controller where technically feasible.
  • Right to object (Art. 21): to object, on grounds relating to your particular situation, to processing based on legitimate interest; and to object to processing for direct marketing purposes at any time and without giving reasons.
  • Right not to be subject to automated decision-making and profiling (Art. 22): not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you; and, where such a decision is involved, to request human intervention, to express your point of view and to contest the decision.
  • Right to withdraw consent (Art. 7(3)): to withdraw your consent at any time in processing based on explicit consent. Withdrawal does not affect the lawfulness of processing carried out up to that point.

As a rule, we conclude your requests within one month. This period may be extended by a further two months owing to the complexity or the number of requests; in the event of an extension we will inform you together with the reasons (Art. 12(3) GDPR). Your requests are, as a rule, free of charge.

Advertising and content personalisation may involve profiling; however, this processing does not produce a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you. Should such a process be introduced, this policy will be updated and your right to request human intervention will be stated separately.

8.3 How to Contact Us

If you are located in the European Union or the United Kingdom, you may submit requests arising from data protection legislation directly to us. Your applications are assessed and answered in accordance with the time limits under the GDPR and the UK GDPR.

  • E-mail: info@hali.net
  • Post: Halınet Halı Tekstil Ürünleri Pazarlama Sanayi ve Ticaret A.Ş., Bağlarbaşı Mahallesi, Halı Sokak No: 12, 34662 Üsküdar / İstanbul, Turkey

Contacting us does not in any way remove your right to lodge a complaint with the competent supervisory authority (see 8.5).

8.4 Transfers Abroad and the Safeguards Applied

Transfers to the service providers listed in Section 4 are based on data processing agreements containing the Standard Contractual Clauses (SCC) adopted by the European Commission pursuant to Article 46(2)(c) GDPR. For transfers originating in the United Kingdom, the International Data Transfer Addendum (UK Addendum) or the International Data Transfer Agreement (IDTA) published by the Information Commissioner's Office (ICO) additionally applies.

In addition to the appropriate safeguards, we carry out a transfer impact assessment where necessary and apply supplementary technical and organisational measures such as encrypted communication, restriction of access rights and contractual undertakings. You may request a copy of the safeguards applied from info@hali.net.

8.5 Right to Lodge a Complaint with a Supervisory Authority

If you have a concern about the way your data is processed, we kindly ask you to contact us first; however, your right to lodge a complaint directly with a competent supervisory authority is reserved in any event.

  • European Union (Art. 77 GDPR): you may lodge a complaint with the data protection authority of the Member State of your residence, place of work or of the alleged infringement. Each Member State has its own supervisory authority. In Germany there is both a federal authority (BfDI) and a data protection authority for each federal state; for complaints concerning the private sector, the competent authority is as a rule the relevant state authority. You can find the current list of Member State authorities on the website of the European Data Protection Board (EDPB).
  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk.
  • Turkey: Personal Data Protection Authority — kvkk.gov.tr. For details and time limits, please see Section 7.

8.6 Our Application Channels

To exercise the rights in this section you may send an e-mail to info@hali.net, send a registered electronic mail to halinethali@hs01.kep.tr, apply in writing to our postal address stated above, or contact us using the details set out in 8.3. In order to process your request, we may ask for reasonably limited additional information to verify your identity.

9. Data Security and Data Minimisation

We apply organisational and technical measures to protect your personal data against unauthorised access, loss and unlawful processing; these include an authorisation matrix, encrypted communication, the keeping of access logs and employee confidentiality undertakings. Your payment card details never enter our systems and are processed directly on the infrastructure of a licensed payment institution.

We collect only the data that is genuinely necessary for the relevant purpose. We do not request identity documents, dates of birth or similar additional data in order to complete an order; if you encounter such a request, assume that it does not come from us and verify it via info@hali.net.

10. Personal Data Breach Notification

Should personal data, despite the measures we take, be unlawfully obtained by others, lost, altered or disclosed without authorisation, the notification obligations we apply are set out below.

10.1 Turkey — Article 12/5 of the KVKK

When we determine that personal data has been obtained by others by unlawful means, we notify the Personal Data Protection Board. Pursuant to the relevant decision of the Personal Data Protection Board, this notification is made within 72 hours of becoming aware of the breach. If, for a justified reason, notification cannot be made within 72 hours, the reasons for the delay are explained to the Board together with the notification.

The data subjects affected by the breach are informed, following their identification, within the shortest reasonable time, by appropriate means (by way of an announcement published on our website if direct contact is not possible). The notification states when the breach occurred, which categories of personal data were affected, its likely consequences, the measures taken and recommended, and the contact channels through which information can be obtained.

10.2 European Union and the United Kingdom — Articles 33 and 34 GDPR

  • Notification to the supervisory authority (Art. 33): we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Notification may be omitted if the breach is unlikely to result in a risk to the rights and freedoms of natural persons; that assessment and its reasoning are documented. If notification exceeds 72 hours, the reasons for the delay are appended to it.
  • Communication to the data subject (Art. 34): where the breach is likely to result in a high risk to the rights and freedoms of natural persons, we inform the persons concerned without undue delay in clear and plain language. If the affected data had been rendered unintelligible prior to the breach (for example by means of encryption), or if subsequent measures eliminating the high risk have been taken, a public communication may be made instead of individual notification.

10.3 Our Internal Process

Where a breach is suspected, we apply the following steps:

  • Detection and containment: confirming the incident, isolating the affected systems and stopping ongoing access.
  • Documentation: the nature of the breach, the categories of data affected and the approximate number of persons concerned, its likely consequences and the measures taken are recorded in our internal breach register, irrespective of the outcome.
  • Impact and risk assessment: the likely effect of the breach on the data subjects is assessed in order to determine whether the notification threshold has been exceeded.
  • Notification: notification is made to the competent authority and, where necessary, to the data subjects in accordance with the periods set out above; our service providers acting as processors are also contractually obliged to notify us without undue delay.
  • Corrective measures: remedying the root cause, taking technical and organisational measures to prevent recurrence, and reviewing the process.

11. Children's Personal Data

hali.net is not a service directed at children. Our site and services are not designed, offered or marketed to persons under the age of 18. We do not knowingly and willingly collect personal data from children.

11.1 Turkey

Under Turkish law, the processing of the personal data of persons under the age of 18 is as a rule subject to the consent of a parent or legal guardian. You must have reached the age of 18 in order to create a membership, place an order or give consent to commercial electronic messages. If a transaction is to be carried out on behalf of a person under the age of 18, that transaction must be performed by the parent or legal guardian using their own details.

11.2 European Union and the United Kingdom (Article 8 GDPR)

Pursuant to Article 8 GDPR, in relation to information society services offered directly to a child and processing based on explicit consent, the child's consent is valid where the child is at least 16 years old; Member States may lower this age limit in their own legislation, provided that it is not below 13 years. For children below the age determined, processing is lawful only where consent is given or authorised by the holder of parental responsibility. In the United Kingdom this age limit is 13 under the UK GDPR.

Notwithstanding this, hali.net is, as stated above, directed solely at persons who have reached the age of 18; accordingly, none of our processing activities, including cookie consent, is designed to be offered directly to children.

11.3 If We Become Aware

If we learn that we have collected personal data belonging to a child without the necessary consent, we erase that data without undue delay or destroy it; where the data has been transferred to third parties, we also communicate our erasure request to them. In respect of records that cannot be erased owing to a statutory retention obligation, access is restricted and the data is kept solely for the duration of that obligation.

Application channel for parents and guardians: If you believe that personal data belonging to a child in your custody or guardianship is being processed by us, you may apply to info@hali.net or, if you prefer, to the registered electronic mail address halinethali@hs01.kep.tr. In order to assess your application, we may request reasonably limited information to verify the family relationship and your identity.

12. Our Registry and Registration Details

VERBİS (Turkish Data Controllers' Registry): Pursuant to Article 16 of the KVKK, data controllers processing personal data are as a rule obliged to register with the Data Controllers' Registry Information System (VERBİS). The Personal Data Protection Board has introduced an exemption from this obligation based on the criteria of annual number of employees and annual total financial balance sheet. As our company remains below these thresholds, we have no obligation to register with VERBİS. Being exempt from the registration obligation does not remove our responsibility to maintain a personal data processing inventory and to comply with the other obligations of the KVKK; we comply with those obligations in full. Should the thresholds be exceeded, we will complete our registration within the period prescribed by the legislation.

ETBİS (Turkish Ministry of Trade's Electronic Commerce Information System): Pursuant to Law No. 6563 on the Regulation of Electronic Commerce and the related regulation, we are registered with the ETBİS system of the Turkish Ministry of Trade. ETBİS registration ensures that the identifying information of electronic commerce service providers is centrally recorded and can be verified. For our registration details and identifying particulars, please see our Legal Notice and Company Particulars page.

You may send any questions about our registry and registration status to info@hali.net.

13. Changes to This Policy

We may revise this text from time to time owing to legislative changes or updates to our services. The current version is always published on this page and the effective date is stated below. In the event of a change that materially affects the scope of our duty to inform, we will also notify our registered users separately.

14. Contact

For questions about this policy: info@hali.net · 0216 629 10 55 · 0532 429 59 00

Last updated: 22 August 2026