Privacy Statement — Plugins
Last updated: 31 August 2026
Applicable to: the WordPress plugins listed below, in their free and Pro editions. For this website and the customer account area, see the Website Privacy Policy / KVKK.
1. Who this is for
These plugins run on your own WordPress site. For the data your visitors leave on that site, the data controller is you, not us. This page describes only one thing: what — if anything — each plugin sends OUT of your site, and to whom.
The short answer: in the free editions, nothing leaves your site except where you switch it on yourself or where the plugin's own job requires it (MevvPos talks to your bank). The Pro editions check their licence against our server.
2. Controller
Mev E-Ticaret Limited Company ("Mevvsoft")
Address: Fenerbahçe Mah. İğrip Sok. No:13 Kadıköy / İstanbul 34726
MERSIS: 0620166247200001
Tax ID: 6201662472
E-mail: iletisim@mevvsoft.com
3. Licence verification (Pro editions only)
MevvPos Pro, MevvCart Pro, MevvBlocks Pro and MevvLegal Pro verify their licence against mevvsoft.com. The request carries exactly four fields:
license_key— the key you enteredsite_url— your site address, so the seat count can be enforcedplugin,version— which product and which version is asking
No visitor data, no order data, no content is sent. The answer is cached for twelve hours, so the request is made about twice a day and only in the admin area — never on a page your visitors see.
Free editions never make this request. The licence client ships inside the Pro package; if Pro is not installed, the code is not on your site at all.
4. Product by product
MevvPos
MevvPos is a payment plugin, so sending data out is its job: at checkout it talks to the bank or payment provider YOU configured (İşbank, Akbank, Garanti BBVA, iyzico, PayTR, Craftgate, Sipay and others). Card number, expiry and CVV travel from the shopper's browser to that provider under 3D Secure and are never written to your database or ours.
Those providers are separate controllers with their own policies. Which one receives the data is your choice, made in the plugin settings.
Separately, MevvPos has a form for requesting a new POS definition or support from us. It is sent only when you press the button, and it carries the contact details you type (name, e-mail, phone), your site address and the message itself.
MevvCart
MevvCart stores abandoned carts and the e-mail address entered at checkout in your own database, and sends reminders through your own site. That data does not reach us.
It also has an optional usage-statistics setting. It is OFF by default and nothing is sent unless you turn it on. When on, it sends version numbers, your locale, theme name, which features you enabled, the number of recorded carts, your site address and a hash of your site address together with the admin e-mail. It contains no visitor and no order data.
Measured on 31 August 2026: the address this setting posts to does not currently resolve, so even when switched on the request fails and no data arrives anywhere. We are stating this because a privacy statement should describe what actually happens, not what the code intends.
MevvBridge
MevvBridge sends nothing out of your site. It reads your existing pages, converts what it recognises into blocks and freezes the rest. The only network request it makes is to your own site — it fetches one of your own pages to compare the result before and after the conversion. MevvBridge has no Pro edition, so it never checks a licence either.
MevvBlocks
The free edition makes no external requests at all — not one. Blocks are rendered on your server and the style CSS is produced there too.
Two things can send data out, and both are things you set up yourself: the Pro form engine can post a submission to a webhook address you enter, and the map block loads a map frame from OpenStreetMap. The map is described below.
The map block asks first. A third-party map frame reveals your visitor's IP address to that service. By default the frame is not loaded until the visitor agrees. If MevvLegal is installed, the frame is handed to its consent mechanism; if not, the block asks on its own.
MevvLegal
MevvLegal is the plugin that stops other scripts from running without consent, so it holds itself to the same rule: the free edition sends nothing out of your site.
- The consent record stays on the visitor's device. It is written to browser storage, not to a cookie, and it never reaches a server.
- The consent log on your server is anonymous. It counts (day, policy version, choice) triples. No IP address, no visitor identifier, no personal data — deliberately, because proving consent per person would require giving the visitor a durable identifier, which is a new processing operation nobody consented to.
- The cookie scanner reads names, never values. Only the part before the equals sign is ever read, and it never leaves your site. A session cookie's value is an identity token; collecting it in order to measure cookie consent would open the very channel this product exists to close.
- Geographic rules use no IP lookup. The region is derived from the browser's own time-zone setting. No request is made to any geolocation service and no IP address is sent anywhere.
- Google Consent Mode is off unless you turn it on. When you do turn it on, Google's tag runs on your pages and a request reaches Google even for a visitor who refused — carrying the refusal itself. That is a step back from the default behaviour, it is your decision to make, and the plugin says so on the screen where you make it.
5. What we never do
- We do not collect your visitors' personal data on our own servers through these plugins.
- We do not send anyone's IP address to a third-party service in order to determine their location.
- We do not read cookie values, session tokens or passwords.
- We do not sell or share data with advertising networks.
6. Your rights
For the licence records we hold (your key, your site address, your e-mail as the customer), you may ask us to show, correct or delete them under Article 11 of the Turkish Data Protection Law and Articles 15–22 GDPR. Write to iletisim@mevvsoft.com. Deleting a licence record ends the licence.
For data your own visitors leave on your own site, the request belongs to you, not to us — you are the controller there.
7. Changes
If a plugin starts sending something it did not send before, this page changes on the same day and the date at the top is updated. Each statement here was checked against the code on the date shown.
Documentation
- MevvPos — Multibank virtual POS for WooCommerce
- MevvCart — Sales funnels and cart recovery
- MevvBridge — Migration away from a page builder
- MevvBlocks — Blocks and templates for the block editor
- MevvLegal — Cookie consent and legal pages