← All legal documents

Sencé

Privacy Policy

Effective Date: July 22, 2026 · Version v1.1 · Applicable Law: GDPR (EU), CCPA (California), KVKK (Turkey)

1. Introduction

Sencé is a mobile travel application operated by Malik Cingöz (bireysel geliştirici / individual developer, Türkiye) ("Sencé", "we", "us"). This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our mobile application and the associated website (sencetravel.com).

For Turkish KVKK detailed disclosure, please see our KVKK Aydınlatma Metni.

2. Data We Collect

2.1 Provided by You

2.2 Automatically Collected

2.3 From Third Parties

3. How We Use Your Data

PurposeLegal Basis
Provide booking servicesContract performance (GDPR Art. 6.1.b)
Process paymentsContract + Legal obligation
Customer supportLegitimate interest (Art. 6.1.f)
Analytics (anonymous)Consent (Art. 6.1.a)
Marketing communicationsOpt-in consent
Fraud preventionLegitimate interest
Legal complianceLegal obligation

4. Data Sharing

4.1 Service Providers (Data Processors)

All providers signed Data Processing Agreements (DPA) with Sencé where required.

4.2 Legal Authorities

4.3 Sale of Data

We DO NOT sell your personal data to third parties.

5. International Transfers

Some providers (Stripe, Viator, Ticketmaster) are based in the USA. We rely on Standard Contractual Clauses (SCCs) approved by EU Commission, adequacy decisions where applicable, and your explicit consent for non-essential transfers. You can withdraw consent for non-essential transfers via app settings → KVKK preferences.

6. Your Rights

6.1 GDPR (EU residents)

6.2 CCPA (California residents)

6.3 KVKK (Turkish residents)

See KVKK Aydınlatma Metni Section 6 for the detailed list.

6.4 How to Exercise Rights

We respond within 30 days (GDPR), 45 days (CCPA), 30 days (KVKK).

7. Data Retention

CategoryRetentionReason
Account dataActive + 1 year after deletionKVKK + GDPR
Booking records10 yearsTurkish Tax Law (VUK)
Payment records10 yearsTax + AML
Location data30 days post-tripOperational + legitimate interest
Anonymous analyticsIndefinite (anonymized)Out of scope
Crash reports90 daysEngineering need
Marketing opt-in recordsWhile activeConsent proof

Account deletion: Settings → "Delete My Account" → 30-day grace period, then hard delete (PII erased; financial records anonymized but kept 10y for tax).

8. Security

Technical: TLS 1.3, Keychain/Keystore auth tokens, Row Level Security, Stripe Vault (card data never on Sencé servers), rate limiting, input validation, PII redaction in Sentry, regular security review.

Organizational: sole-operator KVKK/GDPR awareness (annual refresh), data processing policy + incident response plan, 72-hour breach notification (GDPR Art. 33 + KVKK Art. 12.5).

9. Children's Privacy

Sencé is intended for users 18+. We do not knowingly collect data from children under 13 (COPPA), 16 (GDPR), or 18 (KVKK). If we learn we have, we delete it immediately. Parents can contact fredcakmaktas@gmail.com.

10. Cookies and Similar Technologies

Mobile app: no traditional cookies. We use AsyncStorage/SecureStorage for auth tokens (essential), expo-image cache (essential), PostHog (analytics, opt-in). Web (sencetravel.com): see Cookie Policy.

11. Changes to This Policy

We may update this Privacy Policy. Material changes trigger email notification, in-app modal requesting renewed consent, and version history on sencetravel.com/privacy/versions.

Last updated: 2026-07-22

12. Contact

Postal correspondence and phone support are not available. Please use the email above for all privacy-related requests.