
Cookie Policy
HeusMt2 uses necessary cookies (session and security) and two small preference cookies; no advertising or tracking cookies. Visit measurement is cookieless.
This English version is provided for information. If the two versions differ, the Turkish text prevails.
Last updated: October 4, 2026
This policy explains how HeusMt2 (heusmt2.com) uses cookies and browser storage. In short: our site uses only what it strictly needs in order to work, plus two preference cookies that remember your motion and intro choices on the home page; it does not use advertising or tracking cookies.
What is a cookie?
A cookie is a small text file that the sites you visit save in your browser. Cookies can be used for basic functions such as keeping your session open.
Cookies we use
- Session cookie (strictly necessary): Created only when needed: when you
open the login, sign-up or password reset page, when you tap the login box on the home page or
when you enter the shop. It is not written while you are only browsing pages. It keeps your
session open (PHP session cookie). It is used for security purposes only and is protected with
the
HttpOnlyandSameSiteflags; it is deleted when you close your browser. - Security / CSRF: The security check that prevents misuse of forms (sign-up, login, password change) is kept inside the session.
- Cloudflare security cookies: Cookies that may be needed during sign-up/login for bot and attack protection (Cloudflare Turnstile and traffic security). They are not for advertising; they are meant to protect the server and you. They are not written during normal browsing; they appear only if the protection layer puts you through a check.
- Preference cookies (motion and intro): They remember that you stopped the
animated scene on the home page, or chose to turn it on while data saving is on
(
h2_hareket), and that you have seen the intro curtain once (h2_intro). The script on the page writes and reads them; they delete themselves after 365 days. They serve no advertising or tracking purpose and contain no information that identifies you.
| Name | Party | Duration | Purpose |
|---|---|---|---|
PHPSESSID |
First party (heusmt2.com) | Session: deleted when you close the browser (carries no persistent duration) | Keeping the session open and form security (CSRF). There is no separate CSRF cookie; the check is kept inside this session. |
hm_cookie_ack(not a cookie but a localStorage key) |
First party (heusmt2.com) | Persistent: the browser does not delete it by itself; you need to clear it manually | Remembers that you closed the cookie notice. It is not sent to the server. |
h2_dil_oneri_kapali(not a cookie but a localStorage key) |
First party (heusmt2.com) | No duration is set: the browser does not delete it by itself; you need to clear it manually | Remembers that you closed the language suggestion bar; the bar is not shown again in this browser. It is not sent to the server. |
h2_hareket |
First party (heusmt2.com) | 365 days | Preference cookie. Remembers that you stopped the animated scene on the home page (0) or chose to turn motion on while data saving is on (1); it is written only when you press the button. The script on the page writes and reads it; even though the browser sends the cookie along with requests, the server does not read this value. |
h2_intro |
First party (heusmt2.com) | 365 days | Preference cookie. Remembers that you have seen the intro curtain once (value 1); the curtain is not shown again in this browser. The script on the page writes and reads it; the server does not read this value. |
__cf_bm, cf_clearance |
Third party (Cloudflare) | A short duration set by the provider | Bot/attack protection. Not written during normal browsing: it appears only if a security check is triggered. |
cf.turnstile.u(not a cookie but a localStorage key in Cloudflare's domain) |
Third party (Cloudflare Turnstile) | A duration set by the provider | The bot check on the sign-up and login forms (Cloudflare Turnstile). The check frame keeps this key in Cloudflare's own domain; heusmt2.com's code does not write it and cannot read it. |
Browser storage (localStorage)
Besides cookies, we keep two keys in your browser's own storage: a marker that remembers that you closed the cookie notice at the bottom of the page, and a second marker that remembers that you closed the language suggestion bar. This way you do not see the same notice or suggestion again every time a page loads.
- Name of the key:
hm_cookie_ack. - What is stored: only a value meaning "I have seen this notice".
- What is not stored: username, email, IP, browsing history or any information that identifies you.
- Where it goes: nowhere: this value is not sent to the server, it stays only in your browser.
- How long: it is persistent; the browser does not delete it by itself.
- How to delete it: clearing the site data in your browser settings is enough.
The second key is for the language bar that suggests the page's counterpart in another language:
- Name of the key:
h2_dil_oneri_kapali. - What is stored: only a value meaning "I closed the language suggestion bar".
- What is not stored: username, email, IP, browsing history or any information that identifies you.
- Where it goes: nowhere: this value is not sent to the server, it stays only in your browser.
- How long: no duration is set; the browser does not delete it by itself.
- How to delete it: clearing the site data in your browser settings is enough.
Cookies we do not use
We do not use advertising cookies, social media tracking pixels or behavioural profiling cookies. We measure visit statistics in aggregate with cookieless Cloudflare Web Analytics: this method does not write cookies to your browser and does not identify you individually (its legal ground and the transfer information are in the KVKK Privacy Notice).
Managing cookies
You can delete or block cookies in your browser settings. However, if you block strictly necessary cookies, basic functions such as logging in and account actions may not work.
Changes
This policy may be updated; the current version is always published on this page. For more information, you can see our Privacy Policy and KVKK Privacy Notice pages.
This English version is provided for information. If the two versions differ, the Turkish text prevails.