Sencé
Privacy Policy
1. Introduction
Sencé is a mobile travel application operated by Malik Cingöz (bireysel geliştirici / individual developer, Türkiye) ("Sencé", "we", "us"). This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our mobile application and the associated website (sencetravel.com).
For Turkish KVKK detailed disclosure, please see our KVKK Aydınlatma Metni.
2. Data We Collect
2.1 Provided by You
- Account info: name, email, phone, profile photo
- Booking info: passenger names, IDs (TC kimlik for invoicing), travel preferences
- Payment info: handled by Stripe (we never see card numbers)
- User-generated content: posts, photos, comments, reviews
2.2 Automatically Collected
- Device info: device type, OS version, unique device ID
- Usage data: pages viewed, features used, errors
- Location data: precise (GPS, with permission), approximate (IP-based)
- Crash reports: stack traces (PII redacted)
2.3 From Third Parties
- OAuth providers: Apple Sign-in, Google Sign-in (basic profile)
- Booking providers: confirmation IDs, voucher status
3. How We Use Your Data
| Purpose | Legal Basis |
|---|---|
| Provide booking services | Contract performance (GDPR Art. 6.1.b) |
| Process payments | Contract + Legal obligation |
| Customer support | Legitimate interest (Art. 6.1.f) |
| Analytics (anonymous) | Consent (Art. 6.1.a) |
| Marketing communications | Opt-in consent |
| Fraud prevention | Legitimate interest |
| Legal compliance | Legal obligation |
4. Data Sharing
4.1 Service Providers (Data Processors)
- Stripe (USA): payment processing
- Hotelbeds (Spain): hotel + car + activity bookings
- Duffel (UK): flight bookings
- Viator (USA): tour bookings
- Ticketmaster (USA): event tickets
- FlixBus / Obilet: bus tickets
- Supabase (USA, EU option): cloud infrastructure
- Sentry (EU Frankfurt): crash reporting
- PostHog (EU Frankfurt): analytics
All providers signed Data Processing Agreements (DPA) with Sencé where required.
4.2 Legal Authorities
- Court order or subpoena
- Tax authorities (Turkish VUK Mad. 253 — 10-year invoice retention)
- Law enforcement (for fraud / criminal investigation)
4.3 Sale of Data
We DO NOT sell your personal data to third parties.
5. International Transfers
Some providers (Stripe, Viator, Ticketmaster) are based in the USA. We rely on Standard Contractual Clauses (SCCs) approved by EU Commission, adequacy decisions where applicable, and your explicit consent for non-essential transfers. You can withdraw consent for non-essential transfers via app settings → KVKK preferences.
6. Your Rights
6.1 GDPR (EU residents)
- Access, Rectification, Erasure, Restriction, Portability, Object, Automated decisions
6.2 CCPA (California residents)
- Right to know, delete, opt-out (we don't sell, so N/A), non-discrimination
6.3 KVKK (Turkish residents)
See KVKK Aydınlatma Metni Section 6 for the detailed list.
6.4 How to Exercise Rights
- In-app: Profile → Settings → Privacy → Data Request
- Email: fredcakmaktas@gmail.com
- Web: sencetravel.com/privacy/request
We respond within 30 days (GDPR), 45 days (CCPA), 30 days (KVKK).
7. Data Retention
| Category | Retention | Reason |
|---|---|---|
| Account data | Active + 1 year after deletion | KVKK + GDPR |
| Booking records | 10 years | Turkish Tax Law (VUK) |
| Payment records | 10 years | Tax + AML |
| Location data | 30 days post-trip | Operational + legitimate interest |
| Anonymous analytics | Indefinite (anonymized) | Out of scope |
| Crash reports | 90 days | Engineering need |
| Marketing opt-in records | While active | Consent proof |
Account deletion: Settings → "Delete My Account" → 30-day grace period, then hard delete (PII erased; financial records anonymized but kept 10y for tax).
8. Security
Technical: TLS 1.3, Keychain/Keystore auth tokens, Row Level Security, Stripe Vault (card data never on Sencé servers), rate limiting, input validation, PII redaction in Sentry, regular security review.
Organizational: sole-operator KVKK/GDPR awareness (annual refresh), data processing policy + incident response plan, 72-hour breach notification (GDPR Art. 33 + KVKK Art. 12.5).
9. Children's Privacy
Sencé is intended for users 18+. We do not knowingly collect data from children under 13 (COPPA), 16 (GDPR), or 18 (KVKK). If we learn we have, we delete it immediately. Parents can contact fredcakmaktas@gmail.com.
10. Cookies and Similar Technologies
Mobile app: no traditional cookies. We use AsyncStorage/SecureStorage for auth tokens (essential), expo-image cache (essential), PostHog (analytics, opt-in). Web (sencetravel.com): see Cookie Policy.
11. Changes to This Policy
We may update this Privacy Policy. Material changes trigger email notification, in-app modal requesting renewed consent, and version history on sencetravel.com/privacy/versions.
Last updated: 2026-07-22
12. Contact
- Operator / Data Controller: Malik Cingöz (bireysel geliştirici, Türkiye)
- Email: fredcakmaktas@gmail.com
- EU Representative: not appointed (below GDPR Art. 27 threshold for a sole-operator, non-EU-established service; will be appointed if EU user thresholds require it).
Postal correspondence and phone support are not available. Please use the email above for all privacy-related requests.