Privacy
Privacy Policy
What is stored in your browser when you visit this site, what is recorded on the server side, and who else is in the path of your request.
Last updated:
Scope
This policy covers only the pages published under the dantemuzik.com domain. The legal basis on which personal data submitted through the forms is processed, who it is shared with and how long it is kept are set out separately in the Data Protection Notice. Once you leave this site for a third-party address, that address's own policy applies.
Cookies
No advertising, measurement or tracking cookies are used. There are exactly two cookies and both are functional:
- NEXT_LOCALE — remembers which language you are browsing in. It is a session cookie set by the site's multilingual layer: it carries no expiry date, is deleted when you close your browser, and holds nothing that identifies you — only “tr” or “en”.
- dm_admin — created only when a member of Dante Müzik staff signs in to the admin panel. It is never present in a visitor's browser. It is marked HttpOnly, so no script on the page can read it, is signed, and expires after seven days.
Server records and abuse control
The hosting provider keeps technical request records in order to operate the infrastructure. Alongside those, a counter is kept in our own database to limit automated form submissions. That counter does not hold your IP address as such: it holds a SHA-256 digest of the address taken together with a secret key, and because the key never leaves the server environment the digest on its own cannot be turned back into an address. The record is deleted within twenty-four hours.
Service providers
The site runs on the providers below. Each processes only the data needed to deliver its own service:
- Vercel Inc. — hosting the site and running its server-side code.
- Neon Inc. — the database holding the product catalogue and form submissions.
- Resend — delivering form submissions to Dante Müzik's company email address.
No analytics, no advertising trackers
This is not a statement of intent but a technically verifiable property of the site. Each page's content security policy restricts script execution and outbound network requests to the site's own domain, so a third-party measurement tool added later would be blocked by the browser.
- No Google Analytics, Google Ads, Meta pixel or any comparable analytics or advertising tool is loaded.
- No heatmaps, session recording or mouse-movement tracking.
- Typefaces are served from our own server rather than a third-party font service.
- Product images are served through our own image-processing endpoint; your browser makes no request to another company's server to fetch them.
Security
The site is served over HTTPS only and sends a transport security header instructing the browser to keep the connection secure. Pages carry a content security policy that blocks framing, execution of externally sourced scripts and form submission to any domain but its own. The admin panel is password protected and its session is carried in a signed cookie. No technical measure provides absolute security, so we suggest not typing sensitive information into the forms unless you need to send it.
Changes
Because this policy describes what the site actually does, the text changes when the behaviour does. The date at the top of the page shows when it was last updated.
Contact
For any question or request about this policy or your personal data, write to info@dantemuzik.com or by post to Yavuz Sinan Mah. Atatürk Blv. 6431, Fatih / Istanbul, Türkiye.