Gizlilik Politikası
Bono Hotel mobil uygulaması · Son güncelleme: 13 Mayıs 2026
Bu gizlilik politikası, Bono Hotel Old Town (Marmaris, Türkiye) tarafından sunulan Bono Hotel mobil uygulamasının (bundan sonra "Uygulama") kişisel verileri nasıl topladığını, kullandığını ve koruduğunu açıklar. 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) ve AB Genel Veri Koruma Tüzüğü (GDPR) çerçevesinde hazırlanmıştır.
1. Veri Sorumlusu
Veri sorumlusu Bono Hotel Old Town'dur. İletişim bilgileri:
- Adres: Bono Hotel Old Town, Marmaris, Muğla, Türkiye
- Telefon: +90 507 173 00 48
- E-posta: info@bonohotel.net
2. Topladığımız Veriler
Uygulama, misafirler ve otel personeli olmak üzere iki tür kullanıcı için farklı veriler işler.
Misafir kullanıcılar için
- Aktivasyon kodu: Resepsiyondan aldığınız 6 haneli kod, mevcut konaklamanızla eşleştirilir.
- Oturum belirteci (session token): Aktivasyon kodu ile oluşturulan, cihazınıza özel kimliklendirme verisi. Cihazınızda
AsyncStorage içinde saklanır.
- İsim (isteğe bağlı): Konaklama sırasında belirttiğiniz isim. Hizmet kalitesinin kişiselleştirilmesi için kullanılır.
- Oda numarası ve otel adı: Aktivasyon koduyla ilişkilidir.
- Dil tercihi: Türkçe, İngilizce, Rusça veya Almanca.
- Sohbet mesajları: Yapay zekâ asistanına veya otel personeline gönderdiğiniz tüm metin mesajları.
- Hizmet talepleri: Oda servisi, kat hizmetleri ve diğer talep verileri ile ilgili durum güncellemeleri.
- Değerlendirme puanları: Çözülmüş taleplere verdiğiniz 1-5 yıldız puanları.
Personel kullanıcılar için
- E-posta ve şifre: Giriş kimlik doğrulaması amacıyla.
- JWT belirteci: Giriş sonrası oturum kimliği. Cihazda yerel olarak saklanır.
- İsim, rol, departman ve otel ID'si: Yetkilendirme ve görev yönlendirme amacıyla.
- Expo push bildirim belirteci: Anlık bildirim gönderebilmek için. Bu belirteç cihaz başına benzersizdir; rotasyona uğradığında otomatik olarak güncellenir, çıkış yapıldığında silinir.
Otomatik toplanan teknik veriler
- Uygulama hatası veya bağlantı kesilmesi durumunda standart React Native / Expo hata bilgileri (kişisel veri içermez).
- Push bildirim teslimat onayları (Apple APNs sunucusu tarafından).
Toplamadığımız veriler
Uygulama konum, kamera/fotoğraflar, rehber, sağlık verileri, finansal bilgiler, biyometrik veriler, tarayıcı geçmişi veya reklam tanımlayıcıları toplamaz. Uygulama içinde reklam veya üçüncü taraf izleme bulunmaz.
3. Verilerin Kullanım Amacı
- Aktif konaklamanız boyunca dijital konsiyerj hizmetinin sağlanması.
- Hizmet taleplerinizin işlenmesi ve durumlarının size bildirilmesi.
- Personelin gelen taleplere yanıt verebilmesi.
- Anlık bildirimlerle hizmet güncellemelerinin iletilmesi.
- Hizmet kalitesinin iyileştirilmesi (kişisel veri içermeyen, toplu istatistikler).
4. Hukuki Dayanak
Verileriniz aşağıdaki hukuki dayanaklarla işlenir:
- Sözleşmenin ifası: Konaklama süresince talep ettiğiniz hizmetlerin sağlanması.
- Açık rıza: İsim ve serbest metin sohbet içerikleri için.
- Meşru menfaat: Hizmet kalitesinin iyileştirilmesi.
5. Üçüncü Taraflar ve Veri İşleyiciler
Hizmetimizi sunmak için aşağıdaki alt veri işleyicilerden destek alıyoruz:
| Hizmet | Amaç | İşlenen veri |
| Railway (Railway Corp., ABD) |
Uygulamanın bağlandığı API sunucusu |
Yukarıda listelenen tüm uygulama verileri |
| Supabase (Supabase Inc., AB / ABD) |
Veritabanı barındırma (yalnızca API üzerinden erişilir) |
Tüm uygulama verileri |
| Pusher (Pusher Ltd., Birleşik Krallık) |
Gerçek zamanlı mesajlaşma (WebSocket altyapısı) |
Sohbet mesajları, talep güncellemeleri (kanal yayını sırasında) |
| Expo / Apple APNs |
Push bildirim teslimi (yalnızca personel) |
Cihaz push belirteci, bildirim başlığı |
Verileriniz tanıtım, pazarlama veya reklam amacıyla üçüncü taraflara satılmaz veya paylaşılmaz.
6. Veri Saklama Süreleri
- Misafir oturumu: Çıkış işlemiyle (checkout) deaktive edilir. Çözülmemiş talepler iptal edilir.
- Sohbet ve talep geçmişi: Hizmet kalitesinin denetlenmesi amacıyla konaklamanızdan sonra en fazla 12 ay saklanır, ardından anonimleştirilir veya silinir.
- Personel JWT belirteci: Çıkış yaptığınızda hem cihazda hem de sunucuda geçersiz kılınır.
- Push belirteçleri: Çıkış işlemi sırasında veya bildirim teslim edilemediğinde otomatik olarak silinir.
7. Haklarınız
KVKK Madde 11 ve GDPR Madde 15-22 uyarınca, kişisel verilerinizle ilgili aşağıdaki haklara sahipsiniz:
- Verilerinizin işlenip işlenmediğini öğrenme
- İşlenen verilerinize erişme
- Eksik veya yanlış verilerin düzeltilmesini isteme
- Verilerinizin silinmesini veya yok edilmesini talep etme
- Aktarıldığı üçüncü kişileri öğrenme
- Otomatik sistemlerle analiz edilmesine itiraz etme
- Hukuka aykırı işlenmesi nedeniyle uğradığınız zararın giderilmesini talep etme
Bu haklarınızı kullanmak için info@bonohotel.net adresine yazılı olarak başvurabilirsiniz. Başvurularınız KVKK kapsamında en geç 30 gün içinde yanıtlanır.
8. Çocukların Gizliliği
Uygulama 13 yaşın altındaki çocukları hedeflemez ve bilerek 13 yaş altı bireylerden kişisel veri toplamayız. Çocuğunuzun bilgilerini bizimle paylaştığını düşünüyorsanız lütfen yukarıdaki iletişim bilgilerinden bize ulaşın.
9. Uluslararası Veri Transferi
Veri işleyicilerimizin bir kısmı (Railway, Supabase, Pusher) Türkiye dışında bulunabilir. Bu transferler standart sözleşme maddeleri ve hizmet sağlayıcıların kendi gizlilik politikaları kapsamında gerçekleştirilir.
10. Güvenlik
Verileriniz HTTPS/TLS şifrelemesiyle iletilir. Şifreler hash'lenmiş olarak saklanır; oturum belirteçleri yalnızca cihazın yerel güvenli depolamasında bulunur. Buna rağmen internet üzerinden tamamen güvenli iletim garanti edilemez.
11. Bu Politikadaki Değişiklikler
Bu politikayı zaman zaman güncelleyebiliriz. Önemli değişiklikler bu sayfada ve gerektiğinde uygulama içinde duyurulur. "Son güncelleme" tarihi her zaman sayfanın en üstünde gösterilir.
12. İletişim
Gizlilik uygulamalarımız hakkında sorularınız için: info@bonohotel.net · +90 507 173 00 48
Privacy Policy
Bono Hotel mobile app · Last updated: 13 May 2026
This privacy policy describes how the Bono Hotel mobile app (the "App"), operated by Bono Hotel Old Town (Marmaris, Türkiye), collects, uses, and safeguards personal data. It is written to comply with Türkiye's Personal Data Protection Law (KVKK, Law No. 6698) and the EU General Data Protection Regulation (GDPR).
1. Data Controller
The data controller is Bono Hotel Old Town. Contact:
- Address: Bono Hotel Old Town, Marmaris, Muğla, Türkiye
- Phone: +90 507 173 00 48
- Email: info@bonohotel.net
2. Data We Collect
The App processes different data for two user types: hotel guests and hotel staff.
Guests
- Activation code: A 6-digit code issued at reception, matched to your active check-in.
- Session token: A device-specific identifier created when you enter your activation code, stored locally on your device in
AsyncStorage.
- Name (optional): Used to personalize the concierge experience.
- Room number and hotel name: Linked to your activation code.
- Language preference: Turkish, English, Russian, or German.
- Chat messages: All text you send to the AI assistant or hotel staff.
- Service requests: Room service, housekeeping and other request data, plus status updates.
- Ratings: 1–5 star ratings you submit on resolved tickets.
Staff
- Email address and password: For login authentication.
- JWT session token: A login session identifier stored locally on the device.
- Name, role, department, and hotel ID: For authorization and task routing.
- Expo push notification token: Per-device identifier used to deliver push alerts. Rotates automatically; cleared on logout.
Automatically collected technical data
- Standard React Native / Expo error information on crash or network failure (no personal data).
- Push notification delivery receipts (from Apple APNs).
What we do not collect
The App does not collect location, camera/photos, contacts, health data, financial information, biometric data, browsing history, or advertising identifiers. The App contains no advertising and no third-party trackers.
3. How We Use Your Data
- To provide the digital concierge service during your active stay.
- To process service requests and notify you of their status.
- To enable staff to respond to your requests.
- To deliver push notifications about service updates.
- To improve service quality via aggregate, non-personal statistics.
4. Legal Basis
- Contract performance: Providing the services you request during your stay.
- Explicit consent: For optional name and free-form chat content.
- Legitimate interest: Improving service quality.
5. Third-Party Sub-Processors
We rely on the following sub-processors to deliver the service:
| Service | Purpose | Data processed |
| Railway (Railway Corp., USA) |
Hosts the API server the app connects to |
All app data listed above |
| Supabase (Supabase Inc., EU / USA) |
Database hosting (accessed only via the API) |
All app data |
| Pusher (Pusher Ltd., UK) |
Real-time messaging (WebSocket infrastructure) |
Chat messages, ticket updates (during channel broadcast) |
| Expo / Apple APNs |
Push notification delivery (staff only) |
Device push token, notification title |
We do not sell or share your data with third parties for advertising or marketing purposes.
6. Data Retention
- Guest session: Deactivated at checkout. Unresolved tickets are cancelled.
- Chat and ticket history: Retained for up to 12 months after your stay for service-quality auditing, then anonymized or deleted.
- Staff JWT: Invalidated on logout, both on device and on the server.
- Push tokens: Deleted on logout or when a notification fails to deliver.
7. Your Rights
Under KVKK Article 11 and GDPR Articles 15–22, you have the right to:
- Know whether your personal data is being processed
- Access your personal data
- Request correction of incomplete or inaccurate data
- Request erasure of your data
- Know to whom your data has been transferred
- Object to automated processing
- Seek compensation for damages caused by unlawful processing
To exercise these rights, contact info@bonohotel.net in writing. We respond within 30 days as required by KVKK.
8. Children's Privacy
The App is not directed at children under 13 and we do not knowingly collect personal data from anyone under 13. If you believe your child has provided us with personal data, please contact us at the address above.
9. International Data Transfers
Some of our sub-processors (Railway, Supabase, Pusher) may be located outside Türkiye. Such transfers are performed under standard contractual clauses and the privacy policies of the respective providers.
10. Security
All data is transmitted over HTTPS/TLS. Passwords are stored as hashes; session tokens reside only in the device's local secure storage. Despite this, no method of internet transmission can be guaranteed 100% secure.
11. Changes to This Policy
We may update this policy from time to time. Significant changes will be announced on this page and, where appropriate, in the App itself. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact
For questions about our privacy practices: info@bonohotel.net · +90 507 173 00 48