Privacy Policy

Privacy Policy

Read how Hot Air Balloon Göreme collects, uses, shares and protects booking, payment, passenger and website data under applicable privacy laws.

Last Updated: 30 July 2026

1. About This Privacy Policy

This Privacy Policy explains how Hot Air Balloon Göreme, operated by Tury Turizm Tic. Ltd. Şti., collects, uses, stores, shares and protects personal data when you:

  • Visit hotairballoongoreme.com
  • Create or use a customer account
  • Make an inquiry or submit a reservation request
  • Book a hot air balloon flight, tour, activity, transfer or travel service
  • Make or arrange a payment
  • Contact us by email, telephone, WhatsApp or another communication channel
  • Subscribe to our newsletter or marketing communications
  • Otherwise interact with our services

We process personal data primarily in accordance with Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”). Where the European Union General Data Protection Regulation (“GDPR”) or another applicable data protection law applies to a particular processing activity, we also process personal data in accordance with that law.

This Privacy Policy should be read together with our Terms & Conditions and the cookie information and preference controls made available on our website.

2. Data Controller

The data controller responsible for personal data processed through this website and our related booking and travel services is:

Tury Turizm Tic. Ltd. Şti.

Operating brand: Hot Air Balloon Göreme

TÜRSAB Licence Number: A-12113

Address: Avcılar Mahallesi, Ragıp Üner Caddesi, 50180 Göreme, Nevşehir, Türkiye

Email: info@hotairballoongoreme.com

Telephone: +90 546 271 21 81

Website: hotairballoongoreme.com

Tury Turizm Tic. Ltd. Şti. determines the purposes and means by which personal data covered by this Privacy Policy is processed.

Certain independent service providers, such as balloon operators, airlines, hotels, banks and payment service providers, may act as separate data controllers for the information they process under their own legal obligations and privacy policies.

3. Personal Data We May Collect

The personal data we collect depends on how you use our website and which services you request.

Identity Information

This may include:

  • Full name
  • Date of birth or age
  • Nationality
  • Gender, where operationally or legally required
  • Passport or identity document information
  • Names and details of other travellers included in your booking

Contact Information

This may include:

  • Email address
  • Telephone number
  • WhatsApp number
  • Postal or billing address
  • Preferred language and communication method

Booking and Travel Information

This may include:

  • Selected flight, tour, activity or transfer
  • Travel and service dates
  • Number of passengers
  • Hotel name, room number and accommodation details
  • Pick-up and drop-off location
  • Flight number, airport and arrival or departure information
  • Booking number, voucher and reservation status
  • Special requests
  • Dietary, accessibility or mobility requirements
  • Cancellation, amendment, rescheduling and refund information
  • Correspondence relating to the booked service

Passport and Identity Document Information

Where required for a particular service, we may collect:

  • Passport or identity document number
  • Nationality and issuing country
  • Date of birth
  • Passport issue and expiry dates
  • A photograph or copy of a passport or identity document
  • Other information required for passenger lists, insurance, transportation, accommodation or official travel arrangements

Payment and Transaction Information

Depending on the payment method, this may include:

  • Payment amount and currency
  • Deposit and outstanding balance
  • Transaction date and status
  • Billing information
  • Bank or payment reference
  • Refund and chargeback information
  • Information required to authorize or verify a payment

Certain payments are accepted through a secure, SSL-protected mail order payment form available on our website. Payment information submitted through this form may be retained until the booked service has been completed and the payment obligations connected with the reservation have ended.

Customer Account Information

If you create an account, we may process:

  • Username
  • Email address
  • Encrypted or hashed password
  • Account preferences
  • Saved traveller details
  • Wishlist information
  • Booking history
  • Account activity and security records

Communication Information

When you contact us, we may process:

  • The content of emails, messages and inquiries
  • WhatsApp and telephone communication details
  • Customer support requests
  • Complaints and feedback
  • Call or message dates and relevant operational notes

Technical and Website Usage Information

This may include:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Approximate location derived from IP address
  • Login and session information
  • Pages viewed and actions performed
  • Referring website
  • Date and time of visits
  • Website security and error logs
  • Cookie identifiers and preference information

Marketing Information

This may include:

  • Newsletter subscription status
  • Communication preferences
  • Records of marketing consent
  • Records of withdrawal or unsubscribe requests
  • Interaction with marketing emails, where permitted

Special Categories of Personal Data

Some requests may reveal health, disability, mobility, dietary or other sensitive information. Please provide such information only when it is necessary for the safe and appropriate delivery of the requested service.

Where this information constitutes special-category personal data, we process it only where permitted by applicable law, such as with your explicit consent or under another legally recognized processing condition.

4. How We Collect Personal Data

We may collect personal data:

  • Directly from you when you use our website
  • Through reservation, payment, contact and account forms
  • When you contact us by email, telephone or WhatsApp
  • When you subscribe to our newsletter
  • Through cookies and similar technologies
  • From the lead passenger or group organiser making a booking
  • From another traveller acting on your behalf
  • From hotels, travel agencies, tour operators or business partners
  • From balloon operators, airlines, transfer companies and other service providers
  • From payment providers, banks and financial institutions
  • From publicly available sources where permitted by law

If you provide personal data about another traveller, you must ensure that you are authorized to provide that information and that the traveller has been informed about this Privacy Policy.

5. Purposes and Legal Grounds for Processing

We process personal data only when we have a valid purpose and an appropriate legal ground.

Depending on the circumstances, processing may be necessary:

  • To take steps at your request before entering into a contract
  • To establish or perform a booking or service contract
  • To comply with a legal obligation
  • To establish, exercise or protect a legal right
  • For our legitimate interests, provided that your fundamental rights and freedoms are not harmed
  • Based on your explicit consent where consent is legally required

We may process personal data for the following purposes:

Reservations and Service Delivery

  • Receiving and evaluating reservation requests
  • Confirming availability and completing bookings
  • Preparing confirmations, vouchers, passenger lists and travel documents
  • Arranging balloon flights, tours, transfers and other travel services
  • Coordinating with balloon operators, guides, drivers, hotels and other suppliers
  • Organising hotel pick-up and drop-off
  • Communicating pick-up times, itinerary details and operational updates
  • Managing weather-related cancellations and rescheduling
  • Processing customer-requested changes and cancellations
  • Delivering the services you have purchased or requested

Payments and Financial Administration

  • Receiving and verifying payments
  • Collecting deposits and outstanding balances
  • Issuing invoices and receipts
  • Processing refunds
  • Managing payment disputes and chargebacks
  • Preventing fraudulent or unauthorized transactions
  • Meeting tax, accounting and financial record-keeping obligations

Customer Support and Communication

  • Responding to questions and inquiries
  • Providing information before, during and after a service
  • Handling complaints and service issues
  • Contacting customers in urgent or operationally necessary situations
  • Maintaining appropriate records of customer communication

Website and Account Management

  • Creating and managing customer accounts
  • Maintaining secure login sessions
  • Remembering user preferences
  • Providing booking history and account features
  • Diagnosing technical problems
  • Improving website functionality and user experience

Security and Legal Compliance

  • Protecting our customers, staff, website and systems
  • Detecting and preventing fraud, abuse and unauthorized access
  • Maintaining security logs
  • Responding to lawful requests from courts, regulators and public authorities
  • Complying with tourism, civil aviation, transportation, tax, accounting and consumer-protection obligations
  • Establishing, exercising or defending legal claims

Marketing

  • Sending newsletters, travel information and promotional offers where you have chosen to receive them
  • Managing marketing preferences
  • Recording and applying unsubscribe or withdrawal requests

Operational messages about an existing inquiry or booking are not considered marketing communications.

6. Booking Information Provided for Other Travellers

A lead passenger or group organiser may provide information about other travellers included in the same booking.

The person making the booking is responsible for:

  • Having permission to provide the other travellers’ information
  • Ensuring that the information is accurate
  • Informing the other travellers about this Privacy Policy
  • Communicating relevant booking and privacy information to the group

We use the information of accompanying travellers only for purposes connected with the reservation, service delivery, passenger safety, insurance and applicable legal obligations.

7. Passport and Identity Document Information

Passport or identity information may be required for certain services, including:

  • Balloon operator passenger lists
  • Passenger insurance arrangements
  • Domestic flight reservations
  • Hotel registration
  • Airport transfers
  • Services involving restricted or officially controlled locations
  • Other travel arrangements subject to identity requirements

Passport information may be provided through our website, email, WhatsApp or another agreed communication channel.

We request only the information reasonably required for the relevant service. Access is limited to staff members and service providers who need the information to arrange or deliver that service.

Passport and identity information may be shared with the relevant balloon operator, airline, hotel, transfer company, insurance-related party or public authority when necessary.

Copies and photographs of identity documents are not retained longer than necessary for the service and applicable legal obligations. Where continued retention is not required, the information is deleted, destroyed or anonymized in accordance with our internal retention procedures.

Customers should avoid sending passport or identity information through public comments, social media posts or other unsecured public channels.

8. Payment and Mail Order Information

We accept certain payments through a secure, SSL-protected mail order payment form available on our website.

Depending on the applicable booking terms, the payment information submitted through this form may be used to:

  • Collect the required booking deposit
  • Verify and secure the reservation
  • Serve as security for the outstanding balance
  • Collect an amount that becomes payable under the accepted booking and cancellation conditions
  • Process an authorized remaining payment
  • Manage refunds, payment disputes and chargebacks
  • Meet applicable accounting and legal obligations

Card information submitted through the mail order form is transmitted through an SSL-protected connection and is treated as confidential. Access to this information is restricted to authorized personnel who require it for payment and reservation administration.

Where a booking includes an outstanding balance, the payment information may be retained until the booked service has been completed and all amounts connected with the reservation have been settled.

Full payment card information is deleted after the service has been completed and the payment obligation has ended, unless continued retention is specifically required by applicable law, a payment dispute, chargeback or another legally justified reason.

Transaction records, including the amount, currency, payment date, authorization status, refund information and accounting records, may be retained for the applicable legal retention period. These transaction records are separate from the full payment card information.

Payment information is not sold, rented or used for unrelated marketing purposes.

The submission of payment information does not by itself change the payment, cancellation or no-show conditions accepted during the booking process. Any charge made using the submitted payment information must be connected with the applicable reservation and the payment authorization and booking conditions accepted by the customer.

9. How We Share Personal Data

We do not sell, rent or trade personal data.

We may share limited personal data when necessary to provide a requested service, operate our business or comply with the law.

Recipients may include:

Travel Service Providers

  • Licensed balloon operators
  • Tour and activity providers
  • Hotels and accommodation providers
  • Airlines and ticketing providers
  • Transfer companies and drivers
  • Professional guides
  • Restaurants and other itinerary suppliers
  • Insurance-related service providers
  • Local partners involved in delivering the booked service

Payment and Business Service Providers

  • Banks and payment service providers
  • Accounting and financial advisers
  • Auditors
  • Legal advisers
  • Fraud-prevention and security providers

Technology Providers

  • Website hosting and server providers
  • Booking and customer account systems
  • Email and communication providers
  • Website maintenance and security providers
  • Newsletter and marketing platforms
  • Analytics, mapping, spam-prevention and website-functionality providers

Our website may use services provided by companies such as Google, including reCAPTCHA and Google Maps. If you subscribe to our newsletter, your information may be processed through our newsletter service provider. If you contact us through WhatsApp, Meta and WhatsApp may process communication and device information under their own privacy terms.

Authorities and Legal Recipients

We may disclose information to:

  • Courts and legal authorities
  • Law-enforcement bodies
  • Tax and regulatory authorities
  • Tourism and civil aviation authorities
  • TÜRSAB
  • Other public institutions where disclosure is legally required

We share only the information reasonably required for the relevant purpose.

10. International Transfers of Personal Data

Some of our technology, communication, hosting, analytics, marketing or travel-service providers may be located outside Türkiye or may process data using systems located in another country.

This may result in personal data being transferred internationally, including through services such as email, cloud hosting, newsletter platforms, Google services or WhatsApp.

Where personal data is transferred outside Türkiye, the transfer is carried out only where a condition or safeguard permitted under Article 9 of the KVKK and other applicable legislation is available. Depending on the circumstances, this may include:

  • A legally recognized adequacy decision
  • Appropriate safeguards
  • Standard contractual clauses
  • Binding corporate rules
  • A legally permitted exceptional transfer condition
  • Explicit consent where legally required and appropriate

Where the GDPR applies, international transfers are made using a mechanism recognized under the GDPR, where required.

The use of an international website or communication platform does not mean that personal data is made publicly available.

11. Cookies and Similar Technologies

Our website uses cookies and similar technologies to:

  • Keep the website functioning
  • Maintain secure sessions
  • Remember language and user preferences
  • Support account and booking features
  • Prevent spam and misuse
  • Analyse website performance and traffic
  • Improve website content and user experience
  • Support embedded maps, videos and third-party features

Strictly necessary cookies may operate without consent where they are required to provide a service requested by the user or to maintain website security.

Analytics, advertising, marketing and other non-essential cookies are used only where permitted by applicable law and, where required, after the user has provided consent.

Where a cookie preference or control panel is made available, users may use it to manage non-essential cookie preferences. Users may also control cookies using their browser settings. However, disabling necessary cookies may prevent parts of the website from functioning correctly.

12. Marketing Communications

We send newsletters, travel news or promotional offers only where we have an appropriate legal basis and, where required, your prior consent.

Marketing consent:

  • Is optional
  • Is not a condition of making a reservation
  • Must be given separately from accepting the Terms & Conditions
  • Can be withdrawn at any time

You can unsubscribe by:

  • Selecting the unsubscribe link in a marketing email
  • Updating your communication preferences, where available
  • Contacting us at info@hotairballoongoreme.com
  • Using another legally available opt-out method

Withdrawing marketing consent does not prevent us from sending service-related messages concerning an active inquiry, reservation, payment, cancellation, refund or operational update.

13. Data Retention and Deletion

We retain personal data only for as long as necessary for the purpose for which it was collected and for any additional period required by applicable law.

Retention periods are determined according to:

  • The nature and sensitivity of the information
  • The service requested or purchased
  • Operational requirements
  • Tax, accounting, tourism and consumer-protection obligations
  • Possible complaints, disputes and legal claims
  • Security and fraud-prevention requirements
  • Applicable limitation periods

In general:

  • Booking and transaction records are retained for the applicable legal and accounting periods
  • Passport and identity document information is retained only for the operational and legal period for which it is required
  • Full payment card information submitted through the mail order form is retained until the booked service has been completed and all connected payment obligations have ended, unless continued retention is legally justified
  • Customer communications are retained for a reasonable period to provide support and manage possible disputes
  • Marketing information is retained until consent is withdrawn or the person unsubscribes, subject to keeping a limited suppression record
  • Customer account information is retained while the account remains active and for a reasonable period afterward, unless deletion is requested or longer retention is legally required
  • Technical and security logs are retained according to security, fraud-prevention and hosting requirements
  • Backup copies are removed in accordance with the applicable backup rotation schedule

When continued retention is no longer required, personal data is securely deleted, destroyed or anonymized.

A deletion request does not require us to erase information that must be retained to comply with a legal obligation or establish, exercise or defend a legal claim.

14. Data Security

We take reasonable administrative, technical and organizational measures to protect personal data against:

  • Unauthorized access
  • Accidental loss
  • Improper use
  • Unauthorized alteration
  • Unlawful disclosure
  • Destruction

Depending on the system and type of information, these measures may include:

  • TLS/SSL encryption during transmission
  • Access controls and role-based permissions
  • Password protection
  • Security monitoring
  • Firewall and malware protection
  • Restricted access to sensitive records
  • Backup and recovery procedures
  • Confidentiality obligations for staff and contractors
  • Periodic review of systems and access rights

No internet transmission or storage method can be guaranteed to be completely secure. We therefore cannot promise absolute security, but we continuously take proportionate measures to reduce foreseeable risks.

Where a personal data breach must be reported under applicable law, we will notify the competent authority and affected individuals within the legally required period.

15. Children’s Personal Data

Our website and booking services are intended to be used by adults.

Children may participate in certain travel services where permitted by the applicable service conditions. In such cases, the reservation must be made or authorized by a parent, legal guardian or responsible adult.

We process only the information reasonably required to:

  • Confirm the child’s eligibility for the service
  • Arrange the booking
  • Meet passenger safety and insurance requirements
  • Comply with legal or operational obligations

We do not knowingly use children’s personal data for direct marketing.

If you believe that a child’s information has been provided without appropriate authorization, please contact us so that we can review and, where appropriate, delete it.

16. Your Rights Under Turkish Data Protection Law

Under Article 11 of the KVKK, you may have the right to:

  • Learn whether your personal data is being processed
  • Request information about the processing of your personal data
  • Learn the purpose of processing and whether the data is being used in accordance with that purpose
  • Learn the third parties in Türkiye or abroad to whom personal data has been transferred
  • Request correction of incomplete or inaccurate personal data
  • Request deletion or destruction of personal data where the legal conditions are met
  • Request notification of correction, deletion or destruction to third parties to whom the data was transferred
  • Object to a result arising against you through the analysis of personal data exclusively by automated systems
  • Claim compensation if you suffer damage because your personal data has been processed unlawfully

These rights are subject to the conditions and limitations provided by applicable law.

17. Additional Rights Where the GDPR Applies

Where the GDPR applies to the relevant processing activity, you may also have the right to:

  • Access your personal data
  • Correct inaccurate or incomplete data
  • Request erasure of eligible data
  • Request restriction of processing
  • Receive eligible data in a structured, commonly used and machine-readable format
  • Object to processing based on legitimate interests
  • Object to direct marketing
  • Withdraw consent at any time
  • Lodge a complaint with the competent data protection authority

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

These rights may be limited where continued processing is required by law, necessary for a contract, or required for the establishment, exercise or defence of legal claims.

18. How to Submit a Privacy Request

You may submit a privacy request using the contact details below:

Tury Turizm Tic. Ltd. Şti.

Avcılar Mahallesi, Ragıp Üner Caddesi

50180 Göreme, Nevşehir, Türkiye

Email: info@hotairballoongoreme.com

Your request should include sufficient information to identify you and clearly explain which right you wish to exercise.

We may request additional information to verify your identity and protect personal data from unauthorized access or deletion.

Requests made under the KVKK are answered as soon as possible and no later than 30 days, unless a different period applies under another relevant law.

Requests are generally handled without charge. Where applicable law permits a fee because a request creates additional costs or is manifestly unfounded or excessive, we may charge only the legally permitted amount.

You may also submit a complaint to the Turkish Personal Data Protection Authority in accordance with the procedures and time limits established by law.

19. Account Correction and Deletion

You may request:

  • Correction of inaccurate account information
  • Closure of your customer account
  • Deletion of personal data that is no longer required
  • Removal of saved traveller information, subject to legal and operational restrictions

Closing an account does not automatically delete booking, invoice, payment or legal records that we are required to retain.

To make an account-related privacy request, contact us at info@hotairballoongoreme.com.

20. Automated Decision-Making

We do not currently use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects on customers.

We may use automated tools for routine website security, spam prevention, availability display, fraud detection and booking administration. Where necessary, decisions affecting a reservation are reviewed by an authorized team member.

21. External Links, Embedded Content and Social Media

Our website may contain links to third-party websites and embedded services, including:

  • Hotels and travel providers
  • Balloon and tour operators
  • Payment providers
  • Google Maps
  • YouTube
  • Social media platforms
  • WhatsApp
  • Review websites

Third-party websites and platforms process personal data under their own privacy policies. We do not control and are not responsible for their independent privacy practices.

Social sharing buttons, embedded content or external links may allow the relevant platform to collect information about your device, account or interaction. You should review the privacy settings and policies of those platforms before using them.

We will not ask you to publish passport, payment or other sensitive information in a public social media comment.

22. Changes to This Privacy Policy

We may update this Privacy Policy when:

  • Our services or business processes change
  • We introduce a new service provider or technology
  • Legal or regulatory requirements change
  • We improve our privacy and security procedures

The “Last Updated” date at the top of the page shows the latest revision.

If a material change significantly affects how we process personal data, we may provide additional notice through the website, customer account or an appropriate communication channel.

Changes apply from the date the revised policy is published, unless another effective date is stated.

23. Contact Us

For questions about this Privacy Policy or the processing of your personal data, please contact:

Tury Turizm Tic. Ltd. Şti.

Operating brand: Hot Air Balloon Göreme

TÜRSAB Licence Number: A-12113

Address: Avcılar Mahallesi, Ragıp Üner Caddesi, 50180 Göreme, Nevşehir, Türkiye

Email: info@hotairballoongoreme.com

Telephone: +90 546 271 21 81

Website: hotairballoongoreme.com