Cookie Policy
Last updated: 2026-09-08
This Cookie Policy explains how Cappadocia Balloon Flights, operated by Cappadocia Experience LLC (a Wyoming Limited Liability Company established in the State of Wyoming, United States, operating from Aydınlı-Orta Mah., Kağnı Yolu Sok. No: 1, 50180 Göreme — Nevşehir, Türkiye), uses cookies and similar local-storage technologies when you visit our website and book balloon flights and tours. We act as a booking intermediary and online marketplace: we let you discover and book, while the flights and tours themselves are operated by independent, licensed balloon operators and tour providers. This Cookie Policy covers only the storage our own website sets in your browser; it does not govern any separate sites or apps operated by those independent providers. We deliberately keep our use of these technologies minimal: there are no third-party advertising trackers, no remarketing and no ad pixels on this site, and we do not sell your data. For analytics we use our own first-party storage and, only if you opt in, Google Analytics 4 (a third-party service provided by Google). For our own Google Ads campaigns, only if you also consent to marketing, we use Google Ads conversion measurement (a first-party _gcl_au cookie) to see which ad led to a booking — never for remarketing or ad personalisation. This document is part of, and should be read together with, our Privacy Policy and our KVKK Disclosure Notice.
What cookies and local storage are
A "cookie" is a small text file that a website asks your browser to store on your device. When you return, the browser sends the cookie back, which lets the site remember things such as that you are signed in or which language you chose. "Local storage" (and the related "session storage") is a similar mechanism built into modern browsers that lets a site keep small pieces of information on your device without sending them with every request.
Throughout this policy we use "cookies" as a convenient shorthand for all of these similar technologies — browser cookies, local storage and session storage — because they raise the same privacy questions. We explain below exactly which ones we set, what each is for, and how long it lasts.
Our analytics — first-party plus Google Analytics (consent-based)
Most of what we set is first-party: our own site, for our own purposes. The only third-party service we load is Google Analytics 4 (provided by Google), and it loads solely after you opt in to analytics. We use no advertising network.
To be explicit about what we do NOT do:
- Google Analytics 4 is the only third-party analytics service we use, and it runs only if you opt in to analytics; we use no other third-party analytics service.
- No third-party advertising or remarketing cookies, and no advertising "pixels", web beacons or cross-site tracking tags. The only advertising tag we ever load is the Google Ads conversion tag, and only if you consent to marketing — it measures conversions of our own campaigns and sets the first-party _gcl_au cookie (see the Marketing sections).
- No sharing of your browsing behaviour with ad networks, data brokers or social platforms, and no selling of your personal data. Our Google Analytics integration denies advertising and personalisation signals (Google Consent Mode) and we keep Google's advertising features and Google Signals switched off, so your analytics data is not used for ad targeting.
- Our first-party analytics (an events log and listing-view counters) are run in-house, seen only by us and the hosting providers that run our site on our behalf (such as Supabase and Vercel) as our processors. Google Analytics data is, in addition, processed by Google LLC as our analytics processor to give us aggregate reports — see the inventory and the "Analytics cookies in detail" section below.
Session vs persistent storage
Cookies and local-storage items differ in how long they survive:
A session item is temporary: it lasts only while you are actively using the site (for example, the checkout state that holds your seat selection while you book) and is cleared when the session ends.
A persistent item stays on your device for a set period or until you delete it (for example, the record of your cookie choice, which we keep so you are not asked again on every visit). The inventory below states the duration of each item.
The three cookie categories
We group everything into three categories, matching the choices you see in our consent banner:
Strictly necessary — always on, because the site cannot function without them. These are exempt from consent.
Analytics — used only if you opt in. They help us understand and improve how the site is used.
Marketing — used only if you opt in. They support reminders about an unfinished booking and opt-in commercial messages.
Non-essential categories (analytics and marketing) are switched OFF by default and stay off until you actively turn them on. We never set them before you have given consent.
Cookie and storage inventory
The following is the complete list of the first-party cookies and local-storage items we use, with the purpose, category, type and duration of each.
Strictly necessary (always on):
- Supabase authentication / session — keeps you securely signed in to your account (including where you choose optional Google Sign-In) — strictly necessary — first-party — session and short-lived refresh tokens managed by Supabase.
- cookie_consent — remembers your cookie choices (and prevents the banner reappearing on every visit) — strictly necessary — first-party — persistent, 365 days (stored both as a cookie and in your browser's local storage).
- Checkout session — holds your seat/passenger selection and booking progress during checkout — strictly necessary — first-party — session (cleared when the booking session ends).
- Language preference — remembers your chosen interface language — strictly necessary — first-party — persistent.
- Display-currency preference — remembers the currency you chose to view prices in (the actual charge always settles in EUR) — strictly necessary — first-party — persistent.
- Analytics (only with consent): First-party analytics session/event identifier — links the page views and searches in a single visit so we can measure and improve the site; written to our first-party events log (analytics_events) and listing-view counters (listing_views) — analytics — first-party — the events themselves are deleted automatically after 180 days.
- Analytics (only with consent): Google Analytics 4 (_ga and _ga_<id>) — cookies set by Google's gtag.js to distinguish users and persist session state so Google can give us aggregate usage reports (unique users, sessions, pages viewed, approximate location and device type) — analytics — third-party (Google) — typically up to 2 years. Per Google, Google Analytics 4 does not store IP addresses.
- Marketing (only with consent): Abandoned-booking marketing record — if you start a booking and leave it unfinished, this lets us store your contact details so we can send you a reminder; used together with any opt-in commercial e-mail/SMS you have separately requested — marketing — first-party — kept only as long as needed for the reminder, then removed.
- Marketing (only with consent): Google Ads conversion linker (_gcl_au) — set by Google's tag, only if you consent to marketing and only while we run Google Ads, so we can measure which ad click led to your booking (conversion attribution) — marketing — first-party — typically up to 90 days.
- For analytics we do not store your raw IP address; only an approximate country derived from it, plus your device type added on our server, are recorded. (Separately, when you actually make a booking, we do record your IP address and browser/user-agent at that moment for fraud-prevention and security; that is part of the booking process and is described in our Privacy Policy, not analytics storage.)
Analytics cookies in detail
If you allow analytics, two things run. First, our own first-party analytics: an event log of actions such as pages viewed and searches made, tied to a first-party session identifier, used only to understand and improve the site. Second, Google Analytics 4 (Google's gtag.js), which sets the _ga and _ga_<id> cookies and sends usage data to Google — acting as our analytics processor — to give us aggregate audience and traffic reports.
We keep this privacy-protective. For our first-party analytics your raw IP address is not stored — we derive only an approximate country — and your device type is added on our server; these events are deleted automatically after 180 days. Google states that Google Analytics 4 does not log or store IP addresses either (your IP reaches Google only to derive an approximate location, then is discarded). Our integration denies Google's advertising and personalisation signals (Consent Mode) and we keep Google's advertising features, Google Signals and ads data-sharing switched off — so neither analytics stream is ever used for advertising. You can also opt out of Google Analytics in any browser with Google's opt-out add-on (tools.google.com/dlpage/gaoptout).
Marketing cookies in detail
If you allow marketing, and you begin a booking but do not complete it, we may store your contact details so we can send you a reminder e-mail (an "abandoned-cart" recovery message) through our e-mail provider, Resend.
Separately, we send commercial e-mail or SMS only where you have specifically opted in. Every such message includes a way to unsubscribe. Transactional messages that are necessary to perform your booking — such as your confirmation, cancellation or refund notices — are sent regardless of your marketing choice, because they are part of the service you asked for, not marketing.
If you consent to marketing and we are running Google Ads, we also load Google's advertising tag to measure conversions — that is, to see which ad click led to a booking. This uses the first-party _gcl_au cookie (up to 90 days) and sends conversion data to Google, acting as our processor. We use it only for conversion measurement of our own campaigns: we do NOT enable Google Ads remarketing, Google Signals or ad personalisation. Ad signals stay denied (Google Consent Mode) until you accept marketing.
How to manage your choices on our site
When you first visit, a banner lets you Accept all, Reject all (keep only strictly necessary), or Customize by category with separate toggles for Analytics and Marketing. Strictly necessary items are shown as always on and cannot be switched off, because the site needs them to work.
You can review or change your decision at any time by selecting "Cookie settings" in the website footer, which reopens the banner with your current choices.
Withdrawing consent is as easy as giving it: turning a category off in "Cookie settings" takes the same single step as turning it on, and takes effect immediately. Withdrawing consent does not affect the lawfulness of anything we processed while consent was in place.
How to manage cookies in your browser
Independently of our banner, you can control cookies through your browser settings. Most browsers let you view and delete existing cookies, block or limit new ones, and clear local storage. The exact steps vary by browser (Chrome, Safari, Firefox, Edge and others each have a privacy or cookies section in their settings).
Please note that if you block or delete strictly necessary items, parts of the site will not work properly — for example you may be unable to sign in, complete a booking, or keep your language and currency preferences. Because these items are strictly necessary, they are exempt from consent and are required for the service. Deleting the cookie_consent record will simply cause the consent banner to appear again on your next visit.
Do Not Track and Global Privacy Control
Some browsers can send a "Do Not Track" (DNT) signal or a Global Privacy Control (GPC) preference. Because our non-essential cookies are already off by default and are only ever set after you opt in, visitors who use these signals — or who simply do nothing — already receive no analytics or marketing cookies from us.
In other words, our opt-in design honours the spirit of a no-tracking preference automatically: if you never opt in, we never run analytics or marketing storage, regardless of whether your browser sends a DNT or GPC signal.
Hosting, processors and international transfers
The storage described here is operated through service providers that host and run our site on our behalf — principally Supabase (database and authentication) and Vercel (application hosting), with Stripe handling payments and Resend handling e-mail. If you consent to analytics, Google additionally processes your usage data through Google Analytics 4 as our analytics provider. These providers act as our processors and may only use the data to provide their service to us.
Some of these providers, or their infrastructure, are located outside Türkiye and the EEA. Where data is transferred abroad, we rely on appropriate safeguards (such as standard contractual clauses) in line with the KVKK and, for EU visitors, the GDPR. Our Privacy Policy and KVKK Disclosure Notice describe these transfers and your related rights in more detail.
Changes to this policy
We may update this Cookie Policy from time to time — for example if we add a feature or change a processor. When we do, we will revise the "last updated" date at the top, and for significant changes we may also highlight them on the site. We encourage you to review this page periodically.
Contact
If you have questions about this policy or about how we use cookies, contact us at fly@cappadociaballoonflights.com. For requests relating to your personal data under Türkiye's KVKK (Law No. 6698), you can also reach us at fly@cappadociaballoonflights.com, and for general enquiries at fly@cappadociaballoonflights.com or +90 384 271 23 88. This Cookie Policy should be read together with our Privacy Policy and our KVKK Disclosure Notice.
Dokumentversion: 2026-09-08