This policy explains the current TripMate Turkiye v1 data model. It distinguishes account information handled through Firebase Authentication from TripMate information stored on your device.

1. Who operates TripMate Turkiye

TripMate Turkiye is operated by:

Bien Cappadocia Turizm Ticaret Limited Şirketi
Yeni Mah. Lale Cad. No: 6/5
50100 Merkez, Nevşehir, Türkiye
info@biencappadocia.com

In this policy, “TripMate,” “we,” “us,” and “our” refer to the operator above.

2. Scope of this policy

This policy applies to the TripMate Turkiye application and the TripMate Turkiye website at tripmateturkey.com. It does not govern third-party websites, widgets, bookings, or services that you access through TripMate. Those providers apply their own privacy notices and terms.

3. Firebase Authentication and account information

TripMate uses Firebase Authentication, a Google Firebase service, for optional account functionality. Depending on the action you take, account-related information can include your email address, Firebase UID or account identifier, email-verification status, authentication/session information, and information needed to deliver or complete a password-reset process.

TripMate does not store your password itself. Password authentication is handled by Firebase Authentication. Firebase and Google may process account information under their own terms and privacy documentation.

Signing in gives you a Firebase-authenticated identity. In the current v1 architecture, signing in does not turn on Firestore Sync, automatic account cloud sync, guest-to-account import, or guest migration.

4. TripMate data stored locally on your device

TripMate may store the working travel information you create in device or browser storage. Depending on the features you use, this can include saved places; trips and planner results; travel preferences; My Türkiye states; profile preferences; reservations you record in TripMate; wallet and travel records; journal entries and selected journal photos; saved activities and walks; expenses; and other locally persisted TripMate settings or state.

This local TripMate information is different from Firebase Authentication information. Under the current v1 architecture, TripMate does not automatically upload this local trip and profile information to Firestore or another TripMate account-sync service. Guest mode remains independently usable. Signing in does not automatically migrate or replace guest data.

If you choose a journal photo, TripMate processes it for the journal and stores the resulting photo data on your device. Avoid adding sensitive images or assuming that all image metadata has been removed. If you export or share a local backup, you control the resulting copy outside TripMate. Do not place passwords, payment-card details, passport numbers, or other credentials in notes, wallet references, booking links, or backups.

5. Current v1 architecture

FeatureCurrent v1 state
Firebase AuthenticationAvailable for email/password sign-up, verification, sign-in, sign-out, and password reset.
Firestore SyncOff.
Automatic account cloud syncOff.
Guest import and guest migrationOff.
Travel Together / collaborationOff.

6. Location and weather features

Some TripMate features can ask for device location only when you choose to use a location-related feature and grant the relevant permission. TripMate does not describe these features as continuous GPS tracking.

Where Weather Context is configured and used, the location coordinates used for a weather request are sent to the TripMate server and then to WeatherAPI to obtain weather context. TripMate uses a rounded coordinate cluster for weather context display and caching, but that cluster should not be understood as a promise that only rounded coordinates are sent in the provider request. Weather information can be unavailable, delayed, estimated, or forecast-based, and should be checked before you rely on it for travel decisions.

7. Third-party services and travel providers

TripMate can include or link to third-party services. Loading, opening, or interacting with those services may allow the provider to process information under its own privacy policy, including ordinary browser, device, network, or interaction information needed to provide its service. Provider cookies or browser storage may also be used. TripMate does not control those providers’ privacy practices.

Firebase Authentication / Google FirebaseProvides account authentication and related account flows.
Expedia — HotelsProvides hotel search through its widget or external pages. Hotel destination, dates, occupancy and related criteria that you enter may be sent to Expedia together with ordinary browser and network information. Expedia controls its inventory, booking, checkout and provider support.
Kiwi.com — FlightsProvides flight search using Travelpayouts affiliate infrastructure. Departure and arrival airports, travel dates, passenger details and related criteria that you enter may be sent to Kiwi.com and Travelpayouts as needed to provide the search, together with ordinary browser and network information. Those providers may use their own cookies or browser storage and control booking, checkout and provider support.
TravelpayoutsProvides affiliate and tracking infrastructure for the Kiwi.com flight-search integration and the existing Drive integration where applicable. It does not operate TripMate’s Expedia hotel widget.
Viator — ActivitiesMay provide activities and experiences through its partner widget or external pages.
Discover Cars — Car RentalMay provide car-rental search and booking services through an external affiliate link.
Breeze — eSIMMay provide eSIM-related travel services through an external affiliate link.
OpenStreetMap / LeafletMay provide map tiles and map presentation when you use map features.
WeatherAPIMay provide weather context where that optional integration is configured and used.

TripMate does not intentionally include your Firebase email or UID, precise GPS location, saved trips, or private account/profile information in requests to the Expedia hotel widget or the Kiwi.com/Travelpayouts flight widget. A provider may still infer an approximate location from ordinary network information such as an IP address. Optional tools may also request information from external sources, such as a currency-rate source or an official operational-information page. Those sources can receive ordinary connection information when requested.

Third-party providers may keep information according to their own retention rules. If you create an account, booking, or transaction with a provider, you must manage that relationship directly with that provider.

8. Affiliate disclosure

TripMate Turkiye may earn a commission when you make a qualifying purchase or booking after following certain third-party travel-service links or using eligible partner services, including Expedia Hotels, Kiwi.com Flights through Travelpayouts, Viator Activities, Discover Cars car rental, and Breeze eSIM services. This does not necessarily increase the price you pay. TripMate does not itself sell or fulfill those providers’ inventory; their prices, availability, checkout, payment, refunds, cancellations, support, and contractual terms are controlled by the relevant provider.

9. Account deletion and retention

You can delete a TripMate Firebase account from Me → Profile → Delete Account, then confirm deletion. The current deletion flow removes the Firebase Authentication account and local TripMate data on that device that is owned by that Firebase UID. It does not describe guest-owned local data or another Firebase account’s local data as deleted. If Firebase requires a recent sign-in, you may need to sign in again before retrying deletion.

Because local TripMate data is stored on your device or browser in the current v1 architecture, it can remain there until you delete it through the relevant feature, delete the account data owned by that UID, clear it from your device/browser, or uninstall the application, depending on the storage and platform. We do not publish a fixed retention period where the actual retention depends on your device, browser, Firebase, or a third-party provider. See Account Deletion for step-by-step information.

10. Security

We use reasonable technical and organizational measures appropriate to the current product design, including established third-party authentication services for account flows. No method of transmission, device storage, or online service is completely secure, and we cannot guarantee absolute security. Please protect access to your device and account credentials.

11. Children’s privacy

Children and their guardians should use TripMate only as permitted by applicable law and with appropriate supervision. If you believe a child has provided personal information in connection with TripMate, contact us so we can review the request under applicable law.

12. International processing

Firebase, Google, WeatherAPI, map providers, and travel partners may operate or process information in countries other than your own. The places and safeguards used by those providers are governed by their own policies and applicable law. We do not make claims about specific server locations that are not part of the current TripMate product configuration.

13. Your questions and rights

Depending on where you live, you may have rights or choices relating to your personal information. To ask a privacy question, request assistance, or contact the operator, email info@biencappadocia.com or write to the address in Section 1. We may need information necessary to verify and handle a request appropriately.

14. Changes to this policy

We may update this policy as TripMate changes or legal requirements evolve. We will post the updated version here and revise the effective date when appropriate.