BookNow.one
GuidesManage Booking

Privacy Policy

Last updated: May 2026

1. Data Controller

This privacy policy describes how personal data collected through the booknow.one platform — operated by ŞEREF TURİZM VE TİCARET LTD. ŞTİ. (the "Company", "we") — is handled.

  • Trade Name: ŞEREF TURİZM VE TİCARET LTD. ŞTİ.
  • Address: İnönü Mah. Cumhuriyet Cad. Ulumaç Apt. No.93 İç Kapı No.10 Şişli / İSTANBUL
  • Tax Office / No: Beyoğlu V.D. / 810 003 1613
  • MERSİS No: 0810003161300014
  • Email: [email protected]

2. Personal Data Collected

The following personal data is processed in the course of reservations and service delivery:

  • Identity information: First name, last name, nationality
  • Contact information: Email address, phone number
  • Reservation details: Tour date, number of guests, pickup point, special requests
  • Payment information: Chosen payment method (card data is processed exclusively through the iyzico infrastructure; the Company does not store card numbers)
  • Technical data: IP address, browser type, session data

3. Purposes of Processing

  • Creating, confirming and managing reservations
  • Tour operations and logistics coordination (guide and vehicle assignment)
  • Communicating with the customer via WhatsApp, email or phone
  • Fulfilling legal obligations (TÜRSAB, tax, e-invoice)
  • Ensuring the security and integrity of the platform
  • Measuring and improving service quality

4. Legal Grounds

Your personal data is processed under the following legal grounds set out in 6698 sayılı Kişisel Verilerin Korunması Kanunu (Personal Data Protection Law No. 6698, "KVKK"):

  • Establishment and performance of a contract (KVKK art. 5/2-c)
  • Compliance with a legal obligation (KVKK art. 5/2-ç)
  • Legitimate interest (KVKK art. 5/2-f)
  • Explicit consent — used only for non-mandatory marketing communications (KVKK art. 5/1)

5. Transfer of Personal Data

Your data may be shared with the following parties as part of service delivery:

  • Tour guides and transport providers: Name, phone and reservation details, for operational coordination
  • Payment infrastructure (iyzico): Information strictly required to process the transaction, when card payment is selected
  • Legal authorities: In response to requests from courts, tax offices, TÜRSAB or other competent bodies
  • Analytics and advertising providers (international transfer): When you consent to optional cookies, technical and usage data is shared with Google (Google Ireland Ltd. / Google LLC) and Meta (Meta Platforms Ireland Ltd.) as our processors, which may involve transfer of data outside Türkiye / the EEA, including to the United States

Other than the cases listed above, your data is not shared with, sold to or rented to any third party.

6. Data Retention Periods

  • Reservation and guest data: 10 years from the service date (as required by the Turkish Commercial Code)
  • Payment records: 10 years
  • Technical log records: 2 years
  • Marketing consent: Until consent is withdrawn
  • Analytics and marketing cookie data: Retained per each provider's retention policy, or until you withdraw consent

7. Cookies

With your consent, the platform uses cookies and similar technologies in two categories: (1) strictly necessary cookies for session management and security, which are always active; and (2) optional analytics and marketing cookies, active only after you accept them via our consent banner. You can change or withdraw your choice at any time through the banner.

When enabled, we use Google Analytics 4 and Google Tag Manager (Google Ireland Ltd. / Google LLC), Google Ads conversion tracking, and the Meta Pixel (Meta Platforms Ireland Ltd.) to measure traffic and advertising performance. These providers process technical and usage data (including IP address, device and browser data, and on-site interactions) as our processors. Where this involves transfer of data outside Türkiye / the EEA — including to the United States — such transfers rely on the provider's Standard Contractual Clauses and your explicit consent (KVKK art. 9, GDPR art. 49).

8. Your Rights Under KVKK

Under Article 11 of KVKK, you have the right to:

  • Learn whether your personal data is being processed
  • Request information if it has been processed
  • Learn the purpose of processing and whether your data is used in line with that purpose
  • Know the third parties to whom your data is transferred, inside or outside Türkiye
  • Request correction if your data is incomplete or inaccurate
  • Request erasure or destruction under the conditions set out in the law
  • Object to outcomes adverse to you that result from automated processing of your data
  • Claim compensation for damages caused by unlawful processing

You may submit your requests in writing to [email protected]. Applications are answered within 30 days.

9. Security

Your personal data is protected against unauthorized access, alteration, disclosure or destruction by appropriate technical and administrative measures. Card payments are handled through the PCI-DSS compliant iyzico service, and no card data is stored on the Company's servers.

10. Policy Updates

This policy may be updated from time to time. Material changes will be announced on the platform. The current version is always available on this page.

11. Referral & QR Code Tracking

When you reach our platform through a partner hotel's QR code or referral link, we use referral-attribution technology to credit the referring partner for your booking. This is a non-essential, marketing-category technology and is activated only with your consent via our cookie banner. When enabled, it involves the following:

  • Referral code: a partner code captured when you scan a hotel's QR code or open a referral link (a web address that begins with /r/ followed by the partner code).
  • Referral cookie (bn_ref): stores that referral code in your browser for up to 90 days on a last-touch basis, so a booking you make later can still be attributed to the referring partner.
  • Session key cookie (bn_ref_sk): a random, non-identifying value used only to tell referral sessions apart; it does not identify you personally.
  • Pseudonymized technical data: on our servers we store only a hashed (pseudonymized) form of your IP address and browser/user-agent, used to detect abuse and duplicate scans. Your raw IP address and user-agent are not retained.

Purpose: this information is used solely to attribute your booking to the referring hotel so that the correct partner commission can be calculated. It is not used to build advertising profiles about you.

Retention: the bn_ref referral cookie lasts up to 90 days from your last qualifying visit; the related server-side scan record is retained for up to 90 days as well.

Legal basis and consent: because this is a non-essential, marketing-category technology, it runs only after you accept the marketing category in our cookie banner (explicit consent — KVKK art. 5/1, GDPR art. 6/1(a)). You can change or withdraw your consent at any time through the banner.

Questions: [email protected] · Contact Page →