Privacy Policy
Last updated: 26 July 2026
Overview
We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
Scope of this Policy
This Privacy Policy applies to the Ziyara.io website (ziyara.io), the Ziyara.io mobile application available on Google Play and the Apple App Store, and any related services (collectively, the "Services"). By using our Services you agree to the collection and use of information as described in this policy.
Who is responsible for your data (controller vs. processor)
Ziyara.io is the data controller for the personal data of our own customers and website visitors (agency accounts, staff users, billing, support, website usage). For pilgrim data entered by travel agencies (names, passports, travel documents, payments), the agency is the controller and Ziyara.io acts as a data processor on the agency's instructions under our Data Processing Agreement. If you are a pilgrim, please direct privacy requests to your travel agency first — we assist agencies in fulfilling them. See our GDPR & Data Protection page for details.
Information we collect
We may collect the following types of information:
- Account information – name, email address, phone number, and organization details provided during registration.
- Pilgrim data – personal details, passport information, travel documents, and related data entered by authorized agency users.
- Camera & photos – images captured or selected when you use in-app features such as passport scanning or profile photo uploads (see "Mobile Application & Device Permissions" below).
- Location data – your GPS coordinates at the moment you trigger the emergency (SOS) feature in the mobile app. Collected only at that moment, never in the background (see "Mobile Application & Device Permissions" below).
- Usage data – device type, operating system, browser, IP address, and interaction logs collected automatically.
- Registration IP address – the IP address used when an account is created, stored for up to 12 months to detect fraudulent or duplicate free-trial sign-ups (legitimate interest, Art. 6(1)(f) GDPR). It is never used on its own to make an automated decision about your account.
- Payment data – processed securely by our payment provider (see below); we do not store full card details.
Mobile application & device permissions
Our mobile application may request the following device permissions:
- Camera (android.permission.CAMERA) – Used to scan QR codes and to capture passport pages and profile photos within the app. Images are uploaded to our servers over an encrypted connection and stored privately on AWS S3. The camera is activated only when you explicitly choose to scan or take a photo; we do not access the camera in the background.
- Storage / Media – Used to allow you to select existing photos or documents from your device for upload.
- Location (approximate and precise) – Used solely by the emergency (SOS) feature. When you press the SOS button, the app reads your current GPS coordinates once and sends them, together with your name, to your travel agency and to the guide assigned to your group so that they can reach you. Location is never collected in the background and is never used for tracking, advertising or analytics.
- Notifications (android.permission.POST_NOTIFICATIONS) – Used to deliver announcements from your travel agency and emergency alerts. Notifications are delivered through Google Firebase Cloud Messaging; for SOS alerts the message payload contains the pilgrim's name and GPS coordinates.
- Internet – Required to communicate with our servers and synchronize data.
You can revoke any permission at any time through your device's settings. Revoking the camera permission disables QR scanning, passport scanning and photo capture; revoking location disables the SOS feature; revoking notifications stops announcements and emergency alerts from reaching you. Other functionality is unaffected.
How we use your information
We use collected information to provide and improve our Services, process bookings and payments, communicate with you, ensure security, and comply with legal obligations. We do not sell your personal information to third parties.
Payment processing
We use Paddle for payment processing. Paddle handles billing, invoices and payment authorization on our behalf. We do not store full payment card details on our servers. For more information, see Paddle's Privacy Policy and Paddle's Terms.
Where we store your data
The application and database are hosted in the European Union — Hetzner Online GmbH, Germany. Uploaded files (documents, passport scans, photos) are stored on Amazon Web Services S3 in the EU region (Frankfurt, eu-central-1). Access to stored files is restricted and short-lived signed URLs are used for temporary access when necessary. Backups are encrypted and kept with a defined retention period.
Data retention
We retain personal data as long as necessary to provide our services or as required by law. If you wish to request deletion of your data, contact us at info@ziyara.io.
Your rights
You have rights to access, correct, or request deletion of your personal data. To exercise these rights contact us at info@ziyara.io.
International transfers & processors
We use a small number of vetted service providers to operate the Services:
- Hetzner Online GmbH — application and database hosting (Germany, EU)
- Amazon Web Services — file storage on S3 (Frankfurt, EU)
- Brevo (Sendinblue SAS) — transactional and campaign e-mail (France, EU)
- Infobip Ltd. — SMS and WhatsApp delivery (EU, with a global carrier network)
- Google Ireland Ltd. — push notifications via Firebase Cloud Messaging, and website analytics via Google Analytics (loaded only after cookie consent)
- Functional Software, Inc. (Sentry) — error monitoring (US)
- Cloudflare, Inc. — bot protection on public forms (Turnstile)
- Paddle.com Market Limited — payments, acting as an independent controller (Paddle never receives pilgrim data)
The full list, including the data each provider processes, its location and the applicable transfer safeguard, is published at ziyara.io/subprocessors. Where a provider processes personal data outside the EEA/UK/Türkiye, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, adequacy decisions where applicable, or the EU–US Data Privacy Framework.
GDPR / UK GDPR (EU & UK residents)
If you are located in the EU or the UK, you have the rights listed above and the right to lodge a complaint with your local supervisory authority. The legal bases for processing personal data include contract performance, legitimate interests, and consent where required (for example for non-essential cookies).
CCPA / CPRA (California residents)
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), including the right to request disclosure of categories of personal information collected, the purposes for which it is used, and the right to request deletion. We do not sell personal information. To exercise your rights under CCPA/CPRA, contact info@ziyara.io and specify your request.
KVKK (Türkiye)
If you are a resident of Türkiye, you have rights under the Turkish Data Protection Law (KVKK) including access, correction, deletion, and objection. To exercise those rights, contact info@ziyara.io. For international transfers from Türkiye, we will rely on appropriate safeguards and provide information upon request.
Security measures
- Encryption in transit (TLS) for all connections; sensitive identity fields such as passport numbers and national IDs are encrypted at rest with AES-256.
- Files stored privately on AWS S3, retrieved through short-lived signed URLs.
- Strict multi-tenant isolation: each agency's data is scoped to that agency.
- Role-based access control, two-factor authentication, and audit logging of data changes.
- Encrypted backups with a defined retention period and a documented restore procedure.
Note that we do not offer end-to-end encryption: to operate the Service, our systems and the sub-processors listed above necessarily process data in a readable form.
Data Protection Officer / Contact
If you have data protection concerns you may contact info@ziyara.io. We are not required to appoint a Data Protection Officer under Art. 37 GDPR; privacy requests are handled at the contact address above.
Contact
If you have questions about this policy, please contact: info@ziyara.io
See also: GDPR & Data Protection · Data Processing Agreement · Sub-processors · Cookie Policy