Privacy Policy
Last updated: 11 October 2026
Yuanly (缘旅) helps travellers discover experiences in Türkiye and send booking requests to the operators that run them. This policy explains what personal data we process, why, and the choices you have. It applies to the Yuanly mobile app, the yuanly.app website and the Yuanly operator and pilot panels.
1. Who we are and how to reach us
Yuanly is responsible for the personal data described here. For any privacy question or request, write to support@yuanly.app. We answer within 30 days.
2. Data we collect
- Account: your name, email address, password (stored only as a one-way hash), preferred language and, if you add it, your phone number. If you sign in with Apple, we receive an Apple user identifier and the email address Apple shares with us (which may be a private relay address).
- Booking requests: the experience, date and time, number of guests, the contact name, phone number, hotel and note you enter, the status of the request and your e-ticket code.
- AI Concierge: your message is used only to produce the answer. We do not store the text of your messages; we keep the language and which experiences were recommended, so we can improve suggestions.
- Notifications: messages about your bookings shown in the app.
- Operators and pilots: business name, contact details, team membership, panel permissions and pilot profile information.
- Technical data: IP address, time of request and app version in short-lived server logs, used for security and troubleshooting.
We do not collect your precise location, contacts, photos, microphone recordings or advertising identifiers, and we do not use third-party analytics or advertising trackers.
3. Why we use it
- To create and secure your account and to let you sign in (performance of our agreement with you).
- To send your booking request to the operator, let the operator confirm it and show it in your trips (performance of the agreement).
- To answer your questions through the AI Concierge (performance of the agreement).
- To keep the service secure and prevent abuse (our legitimate interest).
- To meet legal obligations, for example record keeping (legal obligation).
We do not sell your personal data and we do not use it for advertising.
4. Who we share it with
- The operator you book with: your name, contact details, note and booking details, so they can serve you. Operators see only their own customers' bookings.
- Service providers that run Yuanly for us: hosting and database (Railway, servers in Singapore), network and email routing (Cloudflare) and Apple for Sign in with Apple. If an external AI model provider is used, the text of your question is sent to it only to generate the answer.
- Authorities, when required by law.
5. International transfers
Our servers are located in Singapore, so your data is transferred outside Türkiye, the European Union and the People's Republic of China. We use providers that apply appropriate security measures, and we rely on the transfer mechanisms required by applicable law, including the Turkish Personal Data Protection Law (KVKK), the EU GDPR and China's Personal Information Protection Law (PIPL). Where your consent is required for a transfer, we ask for it.
6. How long we keep it
- Account data: until you delete your account.
- Booking records: after account deletion they are kept in anonymised form (without your name, contact details or notes) so operators can keep their accounting records.
- Server logs: a short period, normally no longer than 30 days.
7. Your rights
You can access, correct and delete your data, object to processing, ask for a copy of your data and withdraw consent at any time. You can edit your profile in the app and delete your account in Me → Delete account: your profile and personal data are erased and open bookings are cancelled. For other requests write to support@yuanly.app.
Depending on where you live, you also have the rights given by KVKK (Article 11), the GDPR or PIPL, and you may complain to your data protection authority, such as the Turkish Personal Data Protection Authority (KVKK Kurumu).
8. Security
Passwords are stored as one-way hashes, all connections are encrypted (HTTPS), and access to customer data is limited to the two Yuanly administrators and, for their own bookings, to the operators. Invitation links for operator and administrator accounts are single-use and expire after 7 days.
9. Children
Yuanly is not intended for children under 16, and we do not knowingly collect their data.
10. Changes
We will update this page when our practices change and show the date of the latest version at the top. Significant changes will also be announced in the app.