Rug N’ TravelJourneys · Stories
Legal

Privacy Policy

Last updated · June 2026

1. Overview

RUGN Turizm ve Seyahat A.Ş. (“RUGN”, “we”, “our”) values the privacy of every guest. This policy describes what we collect, why we collect it, and how we protect it under the General Data Protection Regulation (GDPR), Türkiye’s KVKK (Law No. 6698) and applicable international privacy frameworks.

2. Data We Collect

  • Contact details: name, email, phone, WhatsApp.
  • Travel preferences: destinations, dates, travelers, dietary, mobility.
  • Booking and payment metadata (tokenised; we never store card numbers).
  • Site analytics: pages visited, referrer, anonymised IP.

3. How We Use Data

Strictly to design, deliver, and improve your journey. We do not sell your information. Sharing is limited to vetted partners necessary for fulfillment — hotels, airlines, drivers, insurance providers — under contractual confidentiality.

4. Retention

Active client data is retained for the duration of our relationship plus ten years for fiscal/regulatory compliance. You may request erasure at any time, subject to our legal obligations.

5. Your Rights

You may request access, correction, deletion, or portability of your data by writing to privacy@rugntravel.com. We respond within thirty days.

6. Security

Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Payment flows are handled through PCI-DSS Level 1 gateways. Access is restricted to designated staff under least-privilege principles.

7. Contact

Data Protection Officer · RUGN Turizm ve Seyahat A.Ş. · Teşvikiye Cad. No: 42, Nişantaşı, Istanbul · privacy@rugntravel.com