1. Introduction
This Privacy & Cookie Policy explains how cealio (operated by Tavaktech LTD, Office 106, 9 Brewers Lane, Richmond, Surrey, TW9 1HH, UK, Company No. 16563260) collects, uses, shares, and protects personal data when you use our websites, apps, booking flows, accounts, and related services (the "Services").
Contact for privacy matters: hello@cealio.com.
This Policy is intended to meet requirements under the Turkish Personal Data Protection Law (KVKK), and, where applicable, the EU/UK GDPR and similar laws. For a Turkish-law focused notice, also see our Privacy Notice (Aydınlatma Metni). Business customers who appoint cealio as a processor should also review the Data Protection Addendum.
cealio Services are not directed to children under 18.
2. Data controller
Unless otherwise stated, the data controller for Platform account and booking data is:
Tavaktech LTD Office 106, 9 Brewers Lane, Richmond, Surrey, TW9 1HH, UK Email: hello@cealio.com
Where a Carrier processes passenger data to perform the ride, that Carrier may act as an independent controller or as a processor depending on the relationship and applicable law. We identify Carriers as needed for service delivery.
3. Categories of personal data we process
Depending on how you use the Services, we may process:
| Category | Examples |
|---|---|
| Identity & contact | Name, email, phone, company name, language preference |
| Account | Login identifiers, password hashes, roles, preferences |
| Booking & trip | Pickup/drop-off, dates/times, flight numbers, vehicle class, extras, passenger names, luggage notes, special requests |
| Payment | Tokenized card references, last4, brand, billing country, transaction IDs (card PAN is typically handled by payment processors) |
| Communications | Support chats, emails, SMS, call metadata, feedback/ratings |
| Device & usage | IP address, device type, browser, pages viewed, approximate location (if permitted), crash logs |
| Marketing (if consented) | Newsletter preferences, campaign interactions |
| Carrier partner data | Company details, driver/vehicle data shared for operations (see Carrier terms) |
We do not seek to collect special-category data (health, biometric, etc.) unless you voluntarily provide it for accessibility needs (e.g. wheelchair assistance). Provide only what is necessary.
4. Purposes and legal bases
We process personal data to:
- Provide the Services — create accounts, price journeys, confirm bookings, assign Carriers, send vouchers/updates (contract / steps prior to contract; KVKK Art. 5/2-c where applicable).
- Payments and fraud prevention — charge fares, detect abuse (legitimate interests / legal obligation / contract).
- Customer support — respond to requests and complaints (contract / legitimate interests).
- Safety and quality — investigate incidents, improve dispatch quality, process experience ratings (legitimate interests).
- Legal compliance — tax, accounting, regulatory requests (legal obligation).
- Marketing — only where you have consented or soft opt-in rules allow; you may withdraw anytime.
- Analytics & product improvement — aggregated or pseudonymized usage analysis (legitimate interests / consent for non-essential cookies).
Where GDPR applies, the corresponding Art. 6 bases are contract, legitimate interests, consent, and legal obligation.
5. Sources of data
- Directly from you (forms, account, checkout, support).
- From the person who books on your behalf (e.g. corporate booker naming a Guest).
- From Carriers/drivers during trip performance (status updates, incident reports).
- From payment providers and fraud tools.
- From publicly available flight/maps providers when you supply a flight number or address.
- From cookies and similar technologies (see Section 9).
6. Sharing and recipients
We may share data with:
- Carriers and drivers assigned to your Booking (name, contact, pickup details, flight, passenger count, special requests needed to perform the ride).
- Payment processors / acquirers / banks.
- IT and cloud providers, messaging/SMS/email providers, maps and flight-data providers, customer-support tools, acting as processors under contracts.
- Professional advisers (legal, accounting) under confidentiality.
- Authorities when required by law or to protect rights, safety, and security.
- Corporate successors in a merger or asset transfer, with notice where required.
We do not sell personal data.
7. International transfers
Data may be processed in Türkiye and in other countries where our providers operate. Where GDPR/KVKK transfer rules apply, we use appropriate safeguards (e.g. Standard Contractual Clauses, adequacy decisions, or other lawful mechanisms) and assess provider security.
8. Retention
We retain personal data only as long as needed for the purposes above, including:
- Account data: for the life of the account and a reasonable period thereafter.
- Booking and invoicing data: for statutory commercial/tax retention periods (often up to 10 years under Turkish commercial practice, or as otherwise required).
- Support records: typically up to 3 years after closure, unless a dispute requires longer.
- Marketing consents/preferences: until withdrawn plus evidence retention.
- Cookie/analytics data: per cookie lifetimes described in the CMP / Section 9.
When no longer needed, data is deleted or anonymized.
9. Cookies, pixels, and similar technologies
9.1 What we use
We use cookies and similar technologies that are:
- Strictly necessary — session, authentication, security, load balancing, cookie-consent storage, language.
- Functional — remembering preferences.
- Analytics — understanding traffic and funnel performance (where consented).
- Marketing — measuring campaigns (where consented).
9.2 Consent
Non-essential cookies are used only with your consent via our consent mechanism (where deployed). You can withdraw or change preferences at any time through cookie settings or browser controls. Blocking some cookies may affect Platform functionality.
9.3 Third-party cookies
Analytics or advertising partners may set their own cookies subject to their policies. We list major categories in our consent tool when active.
10. Security
We implement technical and organizational measures appropriate to risk, including access controls, encryption in transit (TLS), least-privilege access, logging, and vendor due diligence. No method of transmission or storage is 100% secure; please use strong unique passwords and protect your devices.
11. Your rights
Subject to applicable law (KVKK / GDPR), you may have rights to:
- access your personal data;
- rectify inaccurate data;
- erase data (“right to be forgotten”) where conditions are met;
- restrict or object to certain processing;
- data portability;
- withdraw consent without affecting prior lawful processing;
- lodge a complaint with a supervisory authority (in Türkiye: Kişisel Verileri Koruma Kurulu — kvkk.gov.tr; in the EU/UK: your local DPA).
To exercise rights, email hello@cealio.com. We may need to verify your identity. We respond within statutory timelines.
12. Automated decision-making
We may use automated and semi-automated checks for fraud, pricing eligibility, and dispatch. You may request human review of decisions that produce legal or similarly significant effects, where required by law.
13. Marketing communications
Transactional messages (booking confirmations, trip updates) are sent as part of the Service. Marketing messages require consent or another lawful basis; unsubscribe links are provided.
14. Updates to this Policy
We may update this Policy from time to time. The “Last updated” date at the top of the page will change. Material changes will be highlighted on the Platform or by email where appropriate.
15. Contact
Tavaktech LTD Office 106, 9 Brewers Lane, Richmond, Surrey, TW9 1HH, UK Email: hello@cealio.com