Privacy and cookies

Privacy policy

This page explains what data is processed when you use Routavio, what that data is used for, and which third-party services the project relies on.

01

Who processes it

Routavio is not a separate legal entity. The project is run independently by Halil Çınar.

Requests about privacy and personal data can be sent to [email protected].

02

What we collect

Only the data the service needs in order to work is processed. Search works without an account.

  • Account: email address, an irreversible hash of the password and, if you gave them, your name, home city, passport nationality and currency preference. The password itself is stored nowhere.
  • Session: a hash of the session token, its expiry, your browser details and IP address. Kept so that someone else signing into your account can be noticed.
  • Usage: the searches you run (from, to, which date), the routes you save, the price alerts you set, and the moments you click through to a third-party provider.
  • Consent records: when marketing consent was given or withdrawn, with the IP address and browser details at that moment.
  • Pilot form: your answers, if you took part in the Sabancı University study. If you did not take part, no such record is created.
03

Why we process it

  • To compute the journey you searched for, joining flight, train, bus and ferry into one door-to-door result.
  • To keep your account open, keep your session secure and prevent automated request floods.
  • To send the emails the service cannot work without, such as email verification and password resets.
  • To send the price radar and the newsletter, if you consented. Without consent the service works exactly the same.
  • In the pilot study, and only where consent was given, to read the form answers alongside the matching search log.
04

On what basis

The data your account and your searches need in order to work is processed as part of the service relationship. Session security and the prevention of abuse rest on legitimate interest. Marketing email, non-essential cookies and the pilot study are processed on explicit consent alone; consent can be withdrawn at any time, and the service carries on working exactly the same.

05

Cookies

There are three groups of cookies, and only the first runs without consent. There are no ad-network cookies, no profiling and no cross-site tracking.

Essential
vrv_sid (anonymous session), routavio_session (only if you are signed in), vrv_locale and vrv_currency (language and currency preference). The site does not work without them, so no consent is asked for. The cookie preference itself is kept in the browser's localStorage under the key vrv:consent.
Measurement (consent only)
Vercel Analytics and Vercel Speed Insights load only after you accept in the cookie banner. They measure how many times each page is opened and how long a page takes to arrive. They are gated behind consent because they are third-party scripts.
Referral attribution (consent only)
The referral attribution tag also loads only after you accept. If you click through to a third-party provider and book, it lets that referral be attributed. Decline it and the site works exactly the same.

You can change your preference at any time: the "Cookie settings" link at the bottom of the page reopens the banner. If you decline, the measurement and referral scripts never load, then or later.

06

Who else sees it

Personal data is not sold and is not opened to ad networks. These are the providers that keep the service running:

  • Hosting: Vercel runs the site, Railway runs the background jobs and the database.
  • Email: Resend delivers verification, password reset and, with consent, newsletter email.
  • Transport data sources: the flight, rail and bus providers asked for prices and departures on the route you searched. What goes to them is the search itself, not your identity.
  • Referral attribution networks: only when you click through to a third-party provider, and only to attribute that referral.
  • AI providers: text you write to the assistant is passed to a model to produce the answer. Your account details are not.
07

Where the data sits

The providers above run their servers outside Turkey, mostly in the European Union and the United States. Transfers are made under those providers' standard contractual clauses and data processing agreements. Without an account, search still works in full.

08

How long we keep it

Records with an expiry fall away by themselves; the rest is kept while the account is open.

Account data
While the account is open. Delete it from your account settings and every record attached to it is deleted with it.
Search logs
Kept to compute routes and to make repeated searches faster; they go when the account goes.
Session records
They become invalid when they expire and are cleared.
Consent records
Kept even after consent is withdrawn; the moment consent was given and the moment it was withdrawn both have to stay on record.
Pilot answers
Until the study is finished. Results are reported in aggregate and without names.
09

Security

Passwords are stored irreversibly with bcrypt; no plaintext password is kept anywhere. Traffic travels over TLS. What is stored is a hash of the session token, not the token itself.

10

Children

Routavio is not aimed at people under 18 and no data is knowingly collected from that age group. An account opened that way is deleted once it is reported.

11

Changes

When this text changes, the date at the bottom changes with it. For a substantive change, account holders are informed by email.

12

What you can ask for

Wherever you live, you can ask for any of these:

  • To learn what data is processed and to receive a copy of it.
  • To have wrong or incomplete data corrected.
  • To have the data erased.
  • To have the processing restricted.
  • To take the data in a machine-readable form and move it to another service.
  • To object to processing based on legitimate interest, and to withdraw marketing consent.
  • To complain to the data protection authority of the country you are in. In Turkey that is the Personal Data Protection Authority.

As far as your identity can be verified, requests are answered within thirty days at the latest: [email protected]

The notice under Law 6698 is also here: KVKK notice

Last updated: 22 August 2026.