FlyVentis

Privacy Policy

Last updated: September 25, 2026

At FlyVentis, we care about your privacy. This page explains what data we collect, how we use it, and how you can exercise your rights.

Data controller and contact

For the purposes of this policy, FlyVentis acts as the data controller for the service it provides. You can contact us at [email protected] for privacy, personal-data, and data-protection requests.

To resolve a request securely, we may ask for identity or account verification only to the extent necessary.

1. Data we collect

When you sign in with Google, we collect only basic profile information:

  • Email address
  • Name / display name
  • Profile image (avatar)

We do not request access to sensitive Google services such as Gmail, Drive, Calendar, or Contacts. Your Google password is never shared with or visible to us.

Pseudonymous usage data collected when you allow analytics

If you enable the Analytics category in the cookie panel, we collect the following limited data to understand service usage and technical health:

  • Random pseudonymous visitor and session identifiers, which are one-way hashed on the server before being stored in the database.
  • The visited page path, page-view time, and count; URL query parameters are not stored.
  • Session start, last activity time, and interactive active-use duration.
  • FlyVentis API route, request method, response status, request count, and response duration; request and response bodies are not stored.
  • General device type (mobile, desktop, or tablet) and the approximate two-letter country code derived from the IP address by the network provider.

After the approximate country is determined, we do not store the IP address in first-party analytics records. We also do not store full device details, URL query parameters, account identifiers, or raw user content. Pseudonymous analytics data is not linked to your Google account, and access is restricted to authorized administrators.

Active time increases only while the page is visible and there has been a recent keyboard, touch, scroll, or pointer interaction. Tabs left open in the background or unused for a long period are not counted as active use.

We apply a 90-day retention policy to detailed page-view and API performance records, 13 months to pseudonymous session summaries, and 7 days to technical batch identifiers used to prevent duplicate ingestion, periodically deleting expired records.

Measurement begins only after you allow Analytics. If you withdraw permission in the Cookies panel, new collection stops and analytics identifiers are removed from your browser; previously collected pseudonymous records are periodically deleted under the retention policy above.

2. Community comments and reports

On artist pages you can sign in to write comments and report other comments. For this feature we process the comment text, when it was posted and edited, your public display name and your Google profile picture.

Comments are public. Your display name shows only your first name and the initial of your last name (for example "Ayşe K."); your full surname and email address are never shown. Please do not share phone numbers, addresses or other personal details in comments.

When you report a comment, the reason you choose and any optional explanation are stored with your account. This is not shown to the comment's author or other users; it is only reviewed by authorised administrators for moderation. Reported comments may be hidden or removed.

To prevent spam and abuse, your account identifier is used in short-lived counters kept in Redis on our own server for at most 24 hours. This processing is based on providing the feature you request (KVKK Art. 5/2(c); GDPR Art. 6(1)(b) where applicable) and our legitimate interest in keeping the service secure (KVKK Art. 5/2(f); GDPR Art. 6(1)(f) where applicable).

You can edit or delete your comment at any time; a deleted comment is removed from public view immediately. When you delete your account, all your comments and the reports you submitted are permanently deleted.

3. In-app data we store

  • Your favorites (events, flights, countries, and places to visit)
  • Your saved searches
  • Your search and display preferences
  • Session cookies managed by Supabase Auth

This data is associated only with your account. Row-Level Security is applied at database level, so other users cannot access it.

4. Service providers, recipient categories, and transfers

The following service providers and independent platforms may process limited data required to operate FlyVentis or provide a feature you request:

  • Database and sessions: a Supabase installation running on a virtual private server (VPS) rented by FlyVentis; Google sign-in, account sessions, in-app data and comments are processed there. The server hardware and network infrastructure are provided by our hosting provider.
  • Google: OAuth sign-in when requested; Google Analytics with Analytics consent; Google AdSense with Marketing consent.
  • Ticketmaster, PredictHQ, Travelpayouts/Aviasales and similar event or travel providers: fetching event and flight information (no personal data of yours is sent in these requests) and the searches, content and redirects you request.
  • Klook (accommodation) and Impact (Ticketmaster's affiliate network): redirects that open only when you click a ticket or hotel link; the provider's own privacy policy applies on those pages.
  • OpenFreeMap: when the tour map on an artist page comes into view, map tiles are loaded from this service, and your browser sends your IP address and standard request information to its servers. Your Google profile picture is also displayed on comments from Google's servers.

Cloudflare infrastructure and security services

FlyVentis uses Cloudflare for content delivery (CDN), traffic routing and reverse proxying, performance, DDoS mitigation, and malicious-traffic or bot protection. The site runs on our own server; when a visitor connects, traffic first passes through Cloudflare's network.

While providing these services, Cloudflare may process limited technical traffic data such as IP address, request time, requested hostname or page path, HTTP request information, approximate location, and security events. This essential network and security processing does not originate from cookies, so rejecting optional cookies does not prevent Cloudflare from technically processing the connection.

FlyVentis does not store IP addresses in its own analytics database, and IP addresses in Cloudflare logs are not combined with FlyVentis analytics identifiers. The scope and retention of Cloudflare records depend on the Cloudflare product, account plan, and configuration in use; access is restricted to authorized administrators.

Cloudflare Privacy Policy

For API security and abuse prevention, an IP address may be processed as a short-lived rate-limit key in Redis running on FlyVentis's own server. If Analytics consent is given, a temporary counter combining the IP address and event identifier may be kept for up to one hour to avoid counting the same event click repeatedly. These counters are not combined with an account or first-party analytics profile.

Cloudflare, Google, OpenFreeMap and some of the providers we redirect to may run infrastructure outside Türkiye or your country, so personal data may be transferred abroad. We base such transfers on the conditions in Article 9 of the Turkish KVKK and, where applicable, the GDPR (for example standard contracts and the provider's contractual and technical safeguards); for optional analytics and advertising services, the transfer only happens with the explicit consent you give in the cookie panel.

5. How we use data and legal bases

  • Create your account and keep your session active
  • Personalize your favorites, routes, and preferences
  • Run flight and event searches
  • Keep the service secure, including abuse and spam detection

We do not sell your data. Advertising scripts run only when you approve marketing cookies in the cookie panel. Ticket, flight, or hotel links you deliberately click may redirect to the relevant provider and contain an affiliate parameter; the provider's privacy policy then applies.

Depending on the processing activity, we rely on the following legal bases:

  • Your consent for analytics, advertising, and non-essential preference technologies (KVKK Art. 5/1; GDPR Art. 6(1)(a), where applicable).
  • Performance of or steps related to a contract for accounts, sessions, favorites, and features you request (KVKK Art. 5/2(c); GDPR Art. 6(1)(b), where applicable).
  • Compliance with applicable legal obligations (KVKK Art. 5/2(ç); GDPR Art. 6(1)(c), where applicable).
  • Legitimate interests that do not override your fundamental rights, for service security and preventing fraud or abuse (KVKK Art. 5/2(f); GDPR Art. 6(1)(f), where applicable).

6. Cookies and similar technologies

FlyVentis groups cookies and similar browser storage into four categories. Necessary cookies keep the site running; the other categories depend on your choice in the cookie panel.

  • Necessary: Supabase Auth session, sign-in, security, and remembering your cookie preference.
  • Preferences: Remembering language, region, theme, and similar user choices.
  • Analytics: Limited first-party measurement of pseudonymous visitors and sessions, page views, interactive active time, API performance, device type, and approximate country distribution, together with Google Analytics. If this category is off, these analytics measurements and event-click tracking are not performed.
  • Marketing and advertising: Advertising tools such as Google AdSense. If this category is off, these third-party scripts are not loaded. Affiliate redirects are not loaded as cookie scripts and open only when you click the relevant link.

You can change your choice at any time from the Cookies button at the lower left of the page.

Main browser-storage technologies

  • Necessary: Supabase session data and the flyventis-cookie-consent preference; for the session or until the preference is deleted or changed.
  • Preferences: flyventis-locale, theme, and region choices; until deleted by the user or consent is withdrawn.
  • Analytics: flyventis-analytics-visitor, session keys, and Google Analytics identifiers when allowed; FlyVentis detailed records follow the retention periods above, while Google technologies may apply their own periods.
  • Marketing: Google AdSense technologies only when allowed; retention periods are governed by the relevant Google policy.
  • Strictly necessary: flyventis_auth_next — kept for at most 10 minutes so you return to the page you were on after signing in with Google, and deleted right after sign-in.

Retention periods

  • Account details, favorites, saved searches and preferences: until you delete your account.
  • Comments and reports: until you delete them or your account; comments removed through moderation and resolved reports may be kept until your account is deleted to track abuse.
  • Security and rate-limit counters: at most 24 hours.

7. Your rights and data deletion

Subject to applicable law, you may exercise the following rights:

  • Learn whether your data is processed and obtain access to processed data
  • Request correction of incomplete or inaccurate data
  • Request deletion, destruction, or anonymization where the conditions are met
  • Request restriction of or object to processing where applicable
  • Request data portability where applicable
  • Lodge a complaint with the Turkish Personal Data Protection Authority under KVKK or the competent supervisory authority where GDPR applies

From your profile page, you can use the delete account option to immediately and irreversibly delete your account and all in-app data, including favorites, saved searches, activity history, preferences, the comments you wrote and the reports you submitted.

After you enter the confirmation text, the request runs server-side and also removes your auth record.

8. Security

  • Communication over HTTPS
  • Data isolation with Row-Level Security
  • Secret API keys are stored only on the server side
  • Your Google password is never received or viewed by FlyVentis

9. Children

FlyVentis is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has created an account, contact us and we will delete the account and its data.

10. Changes to this policy

We update this policy as our service changes. The date of the latest update is shown at the top of this page, and we announce updates that significantly change how we process data on the site.

11. Contact

You can contact us for privacy requests: [email protected]

We use cookies to give you a better experience

FlyVentis uses cookies and similar technologies to keep the site secure, measure usage, and personalize the experience around your interests. For more information, review our Cookie Policy .