본문으로 건너뛰기

Privacy Policy

Last updated: 2026-09-08

This Privacy Policy explains how Cappadocia Experience LLC ("we", "us", "our"), operating the "Cappadocia Balloon Flights" platform, collects, uses, shares and protects your personal data when you browse our site, create an account or book a hot-air balloon flight or tour in Cappadocia. We are the seller you contract with and an online marketplace: we let you discover and book, while the flight or tour itself is performed by independent licensed operators in Cappadocia. We are established in the State of Wyoming, United States and offer our services to visitors worldwide, so we handle your data under the EU General Data Protection Regulation ("GDPR") and the UK GDPR where they apply to you, and under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") where it applies. It works alongside our Cookie Policy, our Terms of Service and our KVKK Clarification Notice (Aydinlatma Metni).

1. At a glance

The short version of this policy. The full detail follows in the sections below.

  • What we collect: your account and contact details, the booking and passenger details needed to fly or run a tour, payment confirmation from our payment service provider (never your full card number), reviews you write, and limited technical data.
  • Why: to take and fulfil your booking, to meet legal and aviation obligations, to prevent fraud, and — only with your consent — for analytics (our own first-party analytics and Google Analytics 4) and marketing.
  • Who we share with: the independent operator performing your flight or tour, a short list of named service providers (Stripe, Resend, Supabase, Vercel, and — only with your analytics consent — Google for Google Analytics), and public authorities where the law requires it.
  • What we do NOT do: we do not sell your data, we show no advertising and set no ad pixels or ad-targeting cookies. The only analytics we run — our own first-party analytics and Google Analytics 4 — load solely if you opt in, and are never used for advertising.
  • Your choices: non-essential tracking is OFF until you opt in; you can withdraw consent any time via the footer "Cookie settings" link and unsubscribe from marketing in every message.
  • Your rights: access, correction, deletion and more under KVKK (and GDPR for EU/EEA visitors), exercised via fly@cappadociaballoonflights.com.

2. Who we are — the data controller

The data controller (veri sorumlusu) responsible for your personal data is:

  • Legal entity: Cappadocia Experience LLC, a Wyoming Limited Liability Company (State of Wyoming, United States, filing ID 2026-002075110)
  • Brand: "Cappadocia Balloon Flights"
  • Registered office: 30 N Gould St, Ste R, Sheridan, WY 82801, United States
  • Operational address: Aydınlı-Orta Mah., Kağnı Yolu Sok. No: 1, 50180 Göreme — Nevşehir, Türkiye
  • General contact: fly@cappadociaballoonflights.com / +90 384 271 23 88
  • Privacy matters: fly@cappadociaballoonflights.com
  • Data-subject requests (GDPR / UK GDPR / KVKK): fly@cappadociaballoonflights.com
  • Important: we are the booking intermediary and, for tours, the seller. The independent licensed operator that performs your flight or tour is a separate data controller for the data it needs to carry you safely (manifests, pickup, insurance). It processes that data under its own responsibility — see section 5.
  • Where a TÜRSAB-licensed Turkish agency takes part in delivering a service, it is TURTLE TUR TURİZM SEY. TİC. LTD. ŞTİ. (brand "Turtle Tours", TÜRSAB licence no. 4551), a separate company under common ownership and a separate controller for its own purposes.

3. What personal data we collect, and where it comes from

We only collect what we need for the purposes described in this policy. We group it as follows.

  • Account and profile data — name, email, password (stored securely by our auth provider), and, if you choose Google Sign-In / One Tap, the basic profile Google shares to authenticate you. Guest checkout is also available without an account.
  • Booking and passenger (manifest) data — the details required to fly or run a tour safely: lead booker and passenger names, nationality, weight where the operator asks for it (for balloon balance/safety), number of guests, date/time, hotel or pickup point, and a reachable phone and email.
  • Co-passenger data — where you book for others, you provide their details. By doing so you confirm you are allowed to share them and that you have informed them of this policy.
  • Payment data — we use Stripe to process payments. Balloon flights can be booked with a deposit, with the balance collected as shown at checkout; tours require full payment or a deposit depending on the product. We receive a payment confirmation and limited transaction data; we NEVER store your full card number. Prices are shown in a display currency you choose, but the actual charge settles in EUR. Where you use a discount or promo code, we record its use against your booking.
  • Communications and support — messages you send us, and the transactional emails we send you (confirmation, cancellation, refund).
  • Reviews and user content (UGC) — reviews you submit, which we store and may display.
  • Technical and fraud-prevention data — your IP address and browser/user-agent captured at the time of booking, used to help prevent fraud. For first-party analytics we do NOT store your raw IP address; we keep only an approximate country derived from it (via our hosting provider), a device type added on our server, and a salted, irreversible hash of the IP used solely for same-day de-duplication and abuse limiting.
  • Sources: most data comes directly from you. We also receive payment confirmation from our payment service provider, authentication data from our auth provider (and Google if you use Google Sign-In), and operational data from the operator performing your booking.

4. Why we use your data and our legal bases

We map each purpose to a lawful basis under KVKK (Law 6698, Art. 5 and Art. 6) and, for EU/EEA visitors, the equivalent GDPR Article 6 basis.

  • Take and fulfil your booking; send confirmations, changes, cancellations and refunds — Basis: performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6(1)(b)).
  • Share passenger/manifest data with operators and, where legally required, with public authorities (e.g. civil-aviation passenger manifests to SHGM/DHMI); keep tax and accounting records — Basis: legal obligation (KVKK Art. 5/2-ç; GDPR Art. 6(1)(c)).
  • Prevent and investigate fraud and secure the platform (using IP + user-agent at booking) — Basis: legitimate interest (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)).
  • Analytics to understand and improve the site — our first-party analytics (analytics_events log and listing-view counters) and Google Analytics 4 — Basis: your consent (KVKK explicit consent; GDPR Art. 6(1)(a)).
  • Marketing — abandoned-cart recovery email, opt-in commercial email/SMS, and Google Ads conversion tracking for our own ad campaigns — Basis: your consent (KVKK explicit consent and the opt-in rule under E-Commerce Law No. 6563; GDPR Art. 6(1)(a)).
  • Health-adjacent eligibility information (e.g. a condition that may make a flight unsuitable, pregnancy) is handled with care as it may be special-category data; we minimise it and rely on explicit consent and flight-safety grounds.
  • Transactional booking emails (confirmation, cancellation, refund) are sent regardless of marketing consent because they are necessary to perform your contract.

5. Who we share your data with

We share your data only with the parties below, and only as needed. We do not sell your personal data, and we do not share it with advertising networks. The one third-party analytics partner we use is Google (Google Analytics 4), and only if you consent to analytics.

  • The operator performing your booking — we pass the booking and passenger details the independent licensed operator needs to perform and insure your flight or tour (manifest, contact, pickup). The operator is a separate, independent data controller for that data.
  • Stripe — payment processing. Stripe operates as a PCI-DSS-compliant processor; we never receive or store your full card number. Stripe processes payment data outside Türkiye (see the international-transfer section below).
  • Resend — sending transactional emails and, with your consent, opt-in marketing email.
  • Supabase — database and authentication hosting (your account, sessions and booking records).
  • Vercel — hosting our application.
  • Upstash — a hosted Redis service we use to rate-limit abusive requests and to cache search results. Rate limiting uses your IP address as the key; these entries are short-lived and are not linked to your account or booking.
  • Arcjet — abuse and bot protection on our API endpoints. It receives your IP address and basic request metadata (such as the requested path, method and user-agent) to decide whether a request is automated or abusive.
  • Google (Maps Places) — only on the booking form, and only when you start typing a hotel name for pickup: the characters you type are sent to Google so it can suggest matching hotels. If you skip the hotel field, nothing is sent.
  • Google (Sign-In) — only if you choose to sign in with Google, so Google can authenticate you and return your name and e-mail address to us.
  • Google (Google Analytics 4) — only if you consent to analytics, Google LLC provides our third-party audience measurement. Google processes usage data (such as pages viewed, an approximate location derived from your IP, and device/browser type) as our processor to give us aggregate reports. Google states that Google Analytics 4 does not log or store IP addresses (your IP is transmitted to Google only to derive an approximate location, then discarded). Our integration applies Google Consent Mode to deny advertising and personalisation signals, and we keep Google's advertising features and Google Signals switched off, so this is never used for advertising. It runs only after you opt in.
  • Google (Google Ads) — only if you consent to marketing and we are running Google Ads, Google LLC receives conversion data (that a booking occurred, its reference, value and currency) to attribute it to an ad click, acting as our processor. This is conversion measurement of our own campaigns only — no remarketing, Google Signals or ad personalisation. It runs only after you opt in to marketing.
  • Public authorities — where the law requires, for example civil-aviation passenger manifests to SHGM/DHMI, or tax and regulatory disclosures.
  • We do NOT: sell your data, run remarketing or ad personalisation, deploy ad-targeting cookies, or use ad pixels. We use Google Analytics 4 (with analytics consent) and — for our own campaigns — Google Ads conversion tracking (with marketing consent) for measurement only.

6. International data transfers

Some of our service providers (Stripe, Resend, Supabase, Vercel, Upstash, Arcjet, and — where you consent to analytics or marketing, or if you use Google Sign-In or the hotel search — Google) operate partly outside Turkiye and the EU/EEA, so your data may be transferred abroad. These are recurring, structural transfers, so we rely on appropriate safeguards rather than one-off consent.

Under KVKK Art. 9, we rely on appropriate safeguards such as the Board-published standard contract (standart sozlesme / SCC-type mechanism) and, where it exists, an adequacy decision. For EU/EEA visitors under GDPR, transfers outside the EEA rely on Standard Contractual Clauses or another valid safeguard. Sharing passenger manifests with SHGM/DHMI is a domestic disclosure under a legal obligation, not a foreign transfer. You can ask us for a copy of the relevant safeguard at fly@cappadociaballoonflights.com.

Because we are established in the State of Wyoming, United States, personal data you give us is processed by us there. Where you are in the EU/EEA or the UK, this is a transfer to a third country: we rely on the appropriate safeguards permitted under Chapter V GDPR (standard contractual clauses with our processors, and your explicit consent or contractual necessity where that is the lawful route), and the operator performing your flight processes its share of the data in Türkiye.

7. How long we keep your data

We keep personal data only as long as needed for the purpose we collected it for, then delete or anonymise it. Concretely:

  • Analytics events (analytics_events) are automatically deleted after 180 days.
  • Google Analytics 4 data (only if you consent to analytics) is retained by Google according to the retention period we configure in GA4; Google states that Google Analytics 4 does not store IP addresses.
  • For our first-party analytics we do not store your raw IP address; we keep only an approximate country derived from it, a server-side device type, and a salted, irreversible hash used solely for same-day de-duplication.
  • Booking, payment and accounting records are kept for the period required by Turkish tax, commercial and tourism law, then deleted or anonymised.
  • Fraud-prevention signals (IP + user-agent captured at booking) are kept only as long as needed for fraud defence.
  • Account data is kept while your account is active; reviews remain while published unless you ask us to remove them or we moderate them.
  • Marketing-consent records are kept to evidence your consent for as long as required.

8. Cookies and similar technologies

We use a small, honest set of cookies and local storage, in three categories, described fully in our Cookie Policy.

Our analytics run only if you opt in, and cover both our own first-party analytics and Google Analytics 4. We use NO third-party advertising or ad-targeting cookies and NO ad pixels, and analytics is never used for advertising. The only advertising-related cookie we may set is the first-party Google Ads conversion linker (_gcl_au), and only if you also consent to marketing (see the Marketing section).

  • Necessary (always on, no consent) — authentication/session, your cookie-consent choice, the checkout session, and your language and currency preferences. These are strictly necessary to log in, book and keep the site working.
  • Analytics (consent) — our first-party analytics_events log and listing-view counters, plus Google Analytics 4 (the _ga and _ga_* cookies), loaded only after you opt in.
  • Marketing (consent) — abandoned-cart recovery email, opt-in email/SMS, and Google Ads conversion tracking (the _gcl_au conversion-linker cookie) for our own ad campaigns.
  • Non-essential categories are OFF until you opt in via the cookie banner, and you can withdraw consent any time via the footer "Cookie settings" link without losing essential functionality.

9. Marketing and how to unsubscribe

We only send marketing when you have opted in. Marketing consists of abandoned-cart recovery emails (sent only if you gave marketing consent) and opt-in commercial email/SMS, delivered through Resend.

Every marketing message includes an unsubscribe link, and you can withdraw consent any time via the footer "Cookie settings" link. Withdrawing consent does not affect processing carried out before withdrawal, and does not stop transactional booking emails, which we must send to perform your contract.

10. Automated processing and fraud screening

We use rule-based, automated checks to help screen bookings for fraud (for example signals derived from your IP and browser/user-agent at the time of booking). We may also use automated weather/forecast scoring to inform flight planning.

We do not make decisions that produce legal or similarly significant effects on you based solely on automated processing without human involvement. Where a booking is flagged, a person reviews it before any consequential action. This reflects your rights under KVKK Art. 11 and GDPR Art. 22.

11. Security

We apply technical and organisational measures appropriate to the risk.

  • Payments are handled by Stripe (a PCI-DSS-compliant processor); we never store full card numbers.
  • Authentication and sessions are handled by Supabase, with optional Google Sign-In / One Tap.
  • Data is encrypted in transit (TLS), and access to personal data is restricted to those who need it.
  • If a personal-data breach occurs that requires notification, we will inform affected individuals and the competent authority (the Turkish Data Protection Authority / KVKK Kurumu) within the legally required time.

12. Children and minimum age

Our accounts, bookings and the platform are intended for adults. A minor may take part in a flight or tour only as part of a booking made by a responsible adult and subject to the operator's age and safety rules.

We do not knowingly create accounts for children without proper authority. If we learn that an account or data of a minor was provided without the necessary authority, we will delete it. We collect minor passenger details only to the extent needed for the safety manifest.

13. Your rights and how to exercise them

Under KVKK Art. 11, as a data subject you have the right to: learn whether your data is processed; request information about the processing; learn its purpose and whether it is used accordingly; learn the domestic and foreign recipients; request correction of incomplete or inaccurate data; request deletion or destruction; request that correction/deletion be notified to recipients; object to results arising solely from automated analysis; and claim compensation for damage caused by unlawful processing.

For visitors in the EU/EEA, GDPR provides parallel rights: access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent.

How to exercise: contact us at fly@cappadociaballoonflights.com or fly@cappadociaballoonflights.com, through your account settings, or by post to Aydınlı-Orta Mah., Kağnı Yolu Sok. No: 1, 50180 Göreme — Nevşehir, Türkiye. We may verify your identity before acting. We respond to KVKK applications within 30 days at the latest.

14. Complaints to a supervisory authority

If you are not satisfied with our response, you can complain to a supervisory authority.

In Turkiye, you may first apply to us; if we reject your request, our answer is unsatisfactory, or we do not respond in time, you may complain to the Turkish Data Protection Authority (Kisisel Verileri Koruma Kurumu / KVKK Kurumu) within 30 days of our response and in any case within 60 days of your application. Visitors in the EU/EEA may complain to their local EU data protection supervisory authority.

15. Changes to this policy and contact

We may update this Privacy Policy from time to time, for example when our practices, providers or the law change. We will post the updated version with a new "last updated" date, and where required we will seek fresh consent.

Questions about this policy or your data? Contact us at fly@cappadociaballoonflights.com (privacy), fly@cappadociaballoonflights.com (KVKK applications), fly@cappadociaballoonflights.com / +90 384 271 23 88 (general), or by post at Aydınlı-Orta Mah., Kağnı Yolu Sok. No: 1, 50180 Göreme — Nevşehir, Türkiye.

문서 버전: 2026-09-08