Last updated: 13 August 2026

Privacy Policy

This policy explains which personal data we process when you use Arkman Travel AI (assistant.arkman.com.tr), why and for how long we keep it, who we share it with, and what rights you have.

01In short

  • You sign in with a username and password; your password is stored only as an irreversible hash.
  • We use a single cookie, strictly necessary to keep you signed in. No advertising, tracking or third-party analytics.
  • The travel request you write is sent to our AI provider so the plan can be generated.
  • Payment card details are never stored in our database.

02Data controller

Your personal data is processed by [Şirketin tam ticari unvanı] as data controller.

Address: [Şirket açık adresi] · Registry: [MERSİS / ticaret sicil numarası]

03Data we process

Depending on which parts of the service you use, we process:

  • Account details: your username, a hash of your password, your role, when the account was created and whether it is active.
  • Session data: a signed session cookie (ta_session) set in your browser. It is HttpOnly and cannot be read by JavaScript.
  • Usage records: the search text you write (first 500 characters), the detected destination and number of nights, the time of the request, how long it took, and the IP address you connected from.
  • Credit activity: grants, spending, refunds and end-of-period records, each with its date, amount and which search engine it relates to.
  • Sign-in attempts: failed attempts are counted temporarily per IP and username to protect accounts against brute-force attacks.
  • Booking details (only if you use the booking flow): first and last name, date of birth, nationality, passport or ID details, email address and phone number.
  • Payment details: card number, cardholder and expiry are validated solely to carry out the transaction and passed to the payment provider; they are not stored in our database. Only the last four digits may appear in the transaction record.
  • Calendar integration: if you authorise adding events to Google Calendar, the access token is held in server memory for the duration of the operation only and is not persisted.

04Why we process it, and on what basis

  • Performance of a contract: creating your account, authenticating you, generating the travel plan, running your credit balance and, if you ask for it, carrying out booking operations.
  • Legitimate interests: keeping the service secure, preventing abuse and automated attacks, diagnosing faults, and planning capacity and cost.
  • Legal obligation: retaining records we are required to keep under financial and other applicable regulations.
  • Consent: running optional integrations such as Google Calendar only when you authorise them.

05Transfer to the AI provider

To generate your plan, the request text you write and the travel details extracted from it (destination, dates, number of travellers, your preferences) are sent to our AI provider.

For that reason we recommend not writing special categories of personal data (health, beliefs, political views and similar) or other people's details into your request.

06Who we share data with

We do not sell your data. To operate the service we share it with the following providers, limited to what each operation requires:

  • AI providers (Anthropic, OpenAI) — generating plans and interpreting your request.
  • Google (Places, Maps, Geocoding, Directions, Calendar) — place information, maps, routing and the optional calendar integration.
  • Ticketmaster — listing events taking place on your dates.
  • Open-Meteo, NASA EONET, OpenStreetMap/Nominatim — weather, natural-event warnings and location lookup.
  • Our travel supplier — flight, accommodation, transfer and car-hire searches, bookings and payments.
  • Our hosting and infrastructure providers.
  • Competent public authorities, where legally required.

07International transfers

Some of the providers above operate servers outside Türkiye. Relevant data may therefore be transferred abroad in order to provide the service. Such transfers are carried out in line with the conditions set out in applicable law.

08Retention

  • Account and credit records: [hesabınız açık kaldığı sürece].
  • Usage and search records: [12 ay].
  • Booking and payment records: [ilgili mevzuat gereği 10 yıl].
  • Once the period ends, records are deleted or irreversibly anonymised.

09Cookies

We use a single cookie (ta_session), strictly necessary to keep your session alive. It is signed, set as HttpOnly, and becomes invalid when it expires.

We use no advertising, profiling or third-party analytics cookies. This landing page makes no requests to external services.

10Security

  • Passwords are never held in plain text; they are stored as irreversible hashes.
  • The session cookie is signed server-side and has a limited lifetime.
  • Administrative and credit endpoints pass an additional authorisation check.
  • Failed sign-in attempts are rate-limited.

11Your rights

Under Article 11 of Turkish Law No. 6698 on the Protection of Personal Data you have the right to learn whether your personal data is processed, to request information if it is, to learn the purpose of processing and whether it is used accordingly, to request correction of incomplete or inaccurate data, to request erasure or destruction where the conditions are met, to request that such actions be notified to third parties the data was transferred to, to object to a result drawn against you through automated analysis, and to claim compensation for damage arising from unlawful processing.

You can send your requests to the contact address below. We respond within 30 days at the latest.

12Changes and contact

We may update this policy as the service changes. The current version is always published on this page and the date above is refreshed.

Please get in touch with any questions or data protection requests.