Skip to content
Basilica CisternTickets & Visitor Guide
Overview Tickets Visit About What to See FAQ
Book €42
  1. Home
  2. /
  3. Privacy policy
Basilica Cistern
  • Overview
  • Tickets
  • Visit
  • About
  • FAQ

Operator & data controller

Legal entity
Check for Trips GmbH
Registered address
Hintergasse 6, 65428 Rüsselsheim, Germany
Commercial register
Darmstadt HRB 96248
VAT ID
TR-3470891204
Managing director
Erdogan Tur
Support email
info@istanbulwelcomecard.com
Phone (Germany HQ)
+49 6142 301 9620
Phone (Turkey, WhatsApp)
+90 544 870 31 34
Payment + data processors
Stripe (payment) · PayPal (payment) · Ratepay (BNPL) · Google Analytics 4 · Meta Pixel

Check for Trips GmbH acts as data controller under GDPR Art. 4(7). All IWC product sales — including those routed through this micro-site — are fulfilled by the operator above. Refunds processed in 5–10 business days via the original payment method.

Legal · Privacy Policy · Version 2.2

The data behind a thirty-minute underground visit.

The cistern admits 85 people per 15-minute slot. That's why we ask for your slot time on the booking form, and almost nothing else. This policy covers what we do collect, why we need it, how long it stays, and who else sees it. Plain English. GDPR + KVKK aligned. No surprises.

Effective
1 Jan 2026
Last reviewed
15 Mar 2026
Version
2.2
Data officer
in-house
Sixteen sections
  1. Who we are
  2. What we collect
  3. Why we collect it
  4. How we collect
  5. Booking data
  6. Support conversations
  7. Analytics & crash reports
  8. Vendors we use
  9. Sharing with third parties
  10. How long we keep it
  11. International transfers
  12. Security measures
  13. Your rights
  14. Children's data
  15. Changes
  16. Contact us
01

Who we are.

This site is operated by Istanbul Tourist Information Ltd., a Turkish limited company registered in Istanbul under TÜRSAB licence A-7812 and VAT number 3470891204. Registered office: Sultanahmet Mah. Divan Yolu Cad. 17, 34122 Fatih, Istanbul. Data officer: privacy@istanbul-tourist-information.com.

This privacy policy covers basilicacistern.istanbul-tourist-information.com, the dedicated booking and visitor-guide site for the Basilica Cistern. It does not cover the Municipality of Istanbul's own cistern operator site, nor any reseller.

02

What we collect.

Four categories. Nothing more.

Contact & booking data — cardholder name, email, phone, chosen slot time, ticket quantity, optional audio-guide language.

Payment data — card entered on Stripe's hosted page. We keep only last four digits + brand for your invoice.

Usage data — which pages you visit, referrer, device class. Anonymised before aggregation.

Support data — if you write to us, your email and our reply. Kept in our helpdesk for 36 months.

03

Why we collect it.

Each item sits under a specific GDPR legal basis.

Contract performance. Booking data — we can't issue a ticket without it. Art. 6(1)(b) GDPR.

Legal obligation. Turkish tax law — 10-year retention of transaction records. Art. 6(1)(c) GDPR.

Legitimate interest. Analytics, fraud detection, crash reports. Opt-out via cookie panel. Art. 6(1)(f) GDPR.

Consent. Marketing cookies and newsletters — explicit opt-in only. Art. 6(1)(a) GDPR.

04

How we collect it.

Directly from you, in the booking form or a support email. We don't buy data lists, don't enrich with third-party sources, don't fingerprint your device. One exception: card details go directly to Stripe, which returns a token we use to reference the payment.

05

Booking data.

Your booking record: reference (BC- prefix), slot time, cardholder name, contact email, phone, ticket count, audio-guide language, VAT amount, total paid, refund history. Complete list.

Visible to you (via confirmation email) and our support team when you write in. The cistern gate attendant only sees a scanned QR code with quantity — no contact details.

06

Support conversations.

Helpdesk tool: Front. Retention: 36 months. Not used for AI training. Not shared with marketing. Seen only by the support team + data officer.

07

Analytics & crash reports.

GA4 with IP anonymisation, ad-signals disabled, demographics off. We see how many people arrive, where they drop off — not who they are. Sentry for crash reports with PII scrubbing before leaving your browser.

08

Vendors we use.

VendorPurposeData heldRegion
StripePaymentsCard tokensEU + US
External sales APICistern slot inventorySlot time, quantityTürkiye
Transactional emailConfirmation & voucherEmail, booking summaryEU
Google Analytics 4Anonymised usageAnonymised session IDEU + US
Meta PixelAd attribution (opt-in)Opaque retargeting IDEU + US
SentryCrash reports (scrubbed)Error trace, no PIIEU
Hosting & CDNServing the siteIP, user-agent (transient)EU

Each vendor has a signed DPA with us. Audited annually.

09

Sharing with third parties.

We don't sell, rent, or share data with partners for their own marketing. The vendors in section 08 are the only third parties, all acting as processors under our instructions.

Exception: valid Turkish court or tax-authority order. You will be notified unless forbidden by the order. Never happened in the history of the site.

10

How long we keep it.

Booking records — 10 years (Turkish tax law).

Support conversations — 36 months from last message, or until erasure requested.

Analytics — 24 months in GA4, aggregated after.

Crash reports — 14 days in Sentry.

Marketing cookies — 90 days or until revoked.

11

International transfers.

Primary infrastructure is EU-based (Frankfurt, Amsterdam). Stripe and Google route some data through US infrastructure under the EU-US Data Privacy Framework + SCCs (GDPR Art. 46).

12

Security measures.

TLS 1.3 everywhere. DB encryption at rest. 2FA required for all staff accounts. Quarterly pen-tests by a Turkish security firm. 72-hour breach notification commitment (tighter than GDPR's baseline).

13

Your rights.

Eight rights under GDPR (EU) and KVKK (Türkiye).

01

Access

Copy of all data we hold on you. 30-day SLA.

02

Rectification

Fix anything wrong. Same-day turnaround.

03

Erasure

Delete outside 10-year tax retention.

04

Restriction

Freeze processing during disputes.

05

Portability

Export as JSON or CSV.

06

Objection

Object to legitimate-interest processing.

07

Automated decisions

We don't make any. No profiling, no scoring.

08

Complain

To KVKK or your EU DPA directly.

14

Children's data.

We do not knowingly collect data about under-16s. A parent can book a child's entry — cardholder is the parent's name, and only first names of children appear on the voucher.

15

Changes to this policy.

Material changes: 30-day email notice before taking effect. Minor edits: posted without notification, version number increments in the header.

Privacy & data questions

Write to our data officer directly.

One in-house person reads every privacy request. First reply in eight business hours, resolution in fifteen business days for 98% of cases.

Data protection officer privacy@istanbul-tourist-information.com
Related policies & tools
Terms of Booking Refund Policy Cookie Preferences Contact support
Basilica CisternTickets & Visitor Guide

A dedicated booking and visitor-guide site for the Basilica Cistern. Part of the Istanbul Tourist Information portfolio.

Visit

  • Tickets
  • Visit
  • About
  • FAQ

Support

  • Contact & support
  • Accessibility
  • Sitemap
  • Refund policy

Legal

  • Privacy
  • Terms
  • Cookie settings
© Istanbul Tourist Information · TÜRSAB A-7812Powered by istanbul-tourist-information.com