Privacy Policy

Last updated: 26 July 2026

Overview

We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

Scope of this Policy

This Privacy Policy applies to the Ziyara.io website (ziyara.io), the Ziyara.io mobile application available on Google Play and the Apple App Store, and any related services (collectively, the "Services"). By using our Services you agree to the collection and use of information as described in this policy.

Who is responsible for your data (controller vs. processor)

Ziyara.io is the data controller for the personal data of our own customers and website visitors (agency accounts, staff users, billing, support, website usage). For pilgrim data entered by travel agencies (names, passports, travel documents, payments), the agency is the controller and Ziyara.io acts as a data processor on the agency's instructions under our Data Processing Agreement. If you are a pilgrim, please direct privacy requests to your travel agency first — we assist agencies in fulfilling them. See our GDPR & Data Protection page for details.

Information we collect

We may collect the following types of information:

Mobile application & device permissions

Our mobile application may request the following device permissions:

You can revoke any permission at any time through your device's settings. Revoking the camera permission disables QR scanning, passport scanning and photo capture; revoking location disables the SOS feature; revoking notifications stops announcements and emergency alerts from reaching you. Other functionality is unaffected.

How we use your information

We use collected information to provide and improve our Services, process bookings and payments, communicate with you, ensure security, and comply with legal obligations. We do not sell your personal information to third parties.

Payment processing

We use Paddle for payment processing. Paddle handles billing, invoices and payment authorization on our behalf. We do not store full payment card details on our servers. For more information, see Paddle's Privacy Policy and Paddle's Terms.

Where we store your data

The application and database are hosted in the European Union — Hetzner Online GmbH, Germany. Uploaded files (documents, passport scans, photos) are stored on Amazon Web Services S3 in the EU region (Frankfurt, eu-central-1). Access to stored files is restricted and short-lived signed URLs are used for temporary access when necessary. Backups are encrypted and kept with a defined retention period.

Data retention

We retain personal data as long as necessary to provide our services or as required by law. If you wish to request deletion of your data, contact us at info@ziyara.io.

Your rights

You have rights to access, correct, or request deletion of your personal data. To exercise these rights contact us at info@ziyara.io.

International transfers & processors

We use a small number of vetted service providers to operate the Services:

The full list, including the data each provider processes, its location and the applicable transfer safeguard, is published at ziyara.io/subprocessors. Where a provider processes personal data outside the EEA/UK/Türkiye, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, adequacy decisions where applicable, or the EU–US Data Privacy Framework.

GDPR / UK GDPR (EU & UK residents)

If you are located in the EU or the UK, you have the rights listed above and the right to lodge a complaint with your local supervisory authority. The legal bases for processing personal data include contract performance, legitimate interests, and consent where required (for example for non-essential cookies).

CCPA / CPRA (California residents)

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), including the right to request disclosure of categories of personal information collected, the purposes for which it is used, and the right to request deletion. We do not sell personal information. To exercise your rights under CCPA/CPRA, contact info@ziyara.io and specify your request.

KVKK (Türkiye)

If you are a resident of Türkiye, you have rights under the Turkish Data Protection Law (KVKK) including access, correction, deletion, and objection. To exercise those rights, contact info@ziyara.io. For international transfers from Türkiye, we will rely on appropriate safeguards and provide information upon request.

Security measures

Note that we do not offer end-to-end encryption: to operate the Service, our systems and the sub-processors listed above necessarily process data in a readable form.

Data Protection Officer / Contact

If you have data protection concerns you may contact info@ziyara.io. We are not required to appoint a Data Protection Officer under Art. 37 GDPR; privacy requests are handled at the contact address above.

Contact

If you have questions about this policy, please contact: info@ziyara.io


See also: GDPR & Data Protection · Data Processing Agreement · Sub-processors · Cookie Policy