Gizlilik Bildirimi
Hangi kişisel verileri, neden ve ne kadar süreyle kullandığımız; haklarınız.
Bu belge İngilizcedir ve bağlayıcı olan İngilizce metindir. Türkçe çevirisi hazırlanmaktadır.
Who is responsible
Hubonex Technology Ltd, company number MS 235712, incorporated in the Turkish Republic of Northern Cyprus, with its principal place of business at Hubonex Building, Kyrenia, Northern Cyprus, is the data controller for GoKibris. Contact our privacy team at [email protected].
When you book with a Provider, the Provider also becomes responsible for the data it receives to deliver your service, under its own privacy notice.
How we treat your data
- We collect only what a service needs, for a purpose we have told you.
- Optional uses — like keeping your location history — are off until you turn them on, and you can turn them off at any time.
- Precise location goes only to the service that needs it, for as long as it needs it.
- We do not sell your personal data.
- Every kind of data has a fixed retention period. When it ends, the data is deleted.
What we collect
| Category | Examples | Source |
|---|---|---|
| Account | Name, email, phone, language, sign-in methods | You |
| Security | Sessions, devices, sign-in events | Your use of the Platform |
| Saved details | Addresses, travellers, saved places and routes | You |
| Bookings and trips | What you booked, when, where, status and receipts | You and Providers |
| Location | Pick-up and drop-off, live position during an active trip | Your device, with your permission |
| Payments | Amounts, currency, references and outcomes — never full card details | You and the payment provider |
| Verification | Identity documents where a regulated service requires them | You |
| Communications | Messages with Providers and support | You and Providers |
Why we use it, and on what basis
| Purpose | Legal basis |
|---|---|
| Running your account and the services you use | Our contract with you |
| Keeping accounts and payments secure, preventing fraud | Our legitimate interest, and legal obligations |
| Financial records, tax and regulatory duties | Legal obligation |
| Optional location history and personalisation | Your consent, which you can withdraw |
| Service messages about your bookings and account | Our contract with you |
| Marketing messages | Your consent, which you can withdraw |
How long we keep it
Each kind of data has its own period. Deletion happens at the end of it, and earlier if you ask and no legal duty requires us to keep it.
| Data | Kept for |
|---|---|
| Account and profile | While your account is open; optional profile details deleted within 30 days of closure |
| Ended sessions | 90 days, without any sign-in secret |
| Saved addresses and places | Until you remove them or close your account |
| Optional location history | Rolling 90 days, or less if you delete it |
| Trip and order records | 2 years after completion; precise movement and contact details removed after 90 days |
| Financial records | Up to 7 years from the end of the financial year, as financial law requires |
| Private messages | Rolling 1 year |
| Support cases | 2 years after closure |
| Consent records | While relied on, then 3 years |
| Backups | Deleted data leaves backups within 35 days |
Your rights
You can ask to access, correct, delete or receive a copy of your data, object to or restrict a use of it, and withdraw consent at any time. Most of this is available directly in Account → Privacy; you can also write to us.
We acknowledge a request within 2 business days and aim to complete it within 20 calendar days. We tell you exactly what was done — and if something must be kept, what and why.
If you are not satisfied, write to [email protected]. You may also complain to the data-protection authority where you live or work.
Security
Access is limited to people whose role needs it, and recorded. Sign-in secrets are never stored in readable form. Payment card data stays with the payment provider. No system is perfectly secure; if a breach affects you, we will tell you as the law requires.
Children
Accounts are for adults. A child’s journeys and data are managed by a verified guardian or institution, and visible only to them for the agreed purpose.
Changes
We publish each new version here with its date, and announce material changes on the Service Notices page and in the app. The English version governs.