Last updated: 4 September 2026
This Privacy Policy explains what personal data NativeTravel — the platform provided by ТОО «Turismo» (БИН 200140007319, Republic of Kazakhstan) (“we”, “us”) — collects, why we collect it, and the rights you have over it. It applies to our website, mobile apps, and API. We act as the data controller for the personal data described below.
This site runs under the “Visit Almaty” brand, which belongs to our partner: ТОО «Бюро по туризму Алматы (Almaty Tourism Bureau)», БИН 120440000454. The platform itself is provided and operated by ТОО «Turismo» (NativeTravel), and it — not the brand owner — is the controller of your personal data. The partner receives neither accounts nor messages nor any other personal data in non-aggregated form: it only gets anonymised tourist-flow statistics.
Account data you provide at sign-up (email, username, display name, password — stored only as a bcrypt hash). Content you create (listings, bookings, orders, reviews, messages). Approximate location when you use map and search features. Images you upload. Messages you send to the AI assistant. Basic technical and usage data needed to operate and secure the service.
If you go through the identity check required to rent a vehicle, we process the data under strict minimisation: the document number and driving-licence number are kept only as an irreversible hash, and the date of birth is not stored at all — only the “is 18” and “is 21” flags remain. The document photo and selfie you upload are deleted as soon as the application is decided. The result is shared with a rental operator only with your separate consent, as a signed attestation and without copies of documents.
To provide the service and the account and transactions you request (performance of a contract, GDPR Art. 6(1)(b)); to keep the platform secure and prevent abuse (legitimate interests, Art. 6(1)(f)); and, where required, with your consent (Art. 6(1)(a)), which you can withdraw at any time.
We use a small set of vetted subprocessors strictly to run the service: Cloudinary (image hosting), Mapbox (maps and geocoding), and — only when AI features are enabled — Anthropic and OpenAI (assistant and search). Each processes data on our instructions under a data-processing agreement. We do not sell your personal data and do not use third-party advertising trackers.
Some processors are located outside the EEA. Where that is the case, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses (GDPR Art. 46).
We keep account and content data for as long as your account is active. Where records must be kept for legal or accounting reasons (for example transaction history), we retain them only for the period required and then delete or anonymise them.
If you are in the EEA/UK you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data (GDPR Art. 15–21). You can exercise most of these from your account settings; for erasure or export requests that cannot be completed automatically, contact us and we will respond within one month. You may also lodge a complaint with your supervisory authority.
We use only strictly-necessary cookies — chiefly the authentication cookie that keeps you signed in. We do not set advertising or cross-site tracking cookies.
Data is encrypted in transit (HTTPS), passwords are hashed with bcrypt, and access is scoped per tenant and role. No method of transmission or storage is perfectly secure, but we take reasonable measures appropriate to the risk (GDPR Art. 32).
Besides those named above we use: Resend (transactional email, US), Stripe and Kaspi (payment processing; we never store card numbers — only the provider’s payment reference), Expo (push delivery) and Vultr (server hosting, Frankfurt, EU).
Account data — until you delete the account. Page-view statistics — 400 days; search impressions — 180 days; speed metrics — 90 days; AI-assistant conversations — 180 days after the last message; translation cache — 365 days; business-ownership evidence documents — 90 days after the claim decision. Expired sign-in sessions are removed automatically.
The personal-data operator is ТОО «Turismo» (БИН 200140007319), 050000, Республика Казахстан, г. Алматы, Ауэзовский район, мкр. Сайран, д. 10, кв. 17. The servers are located in: Алматы, Казахстан. By creating an account you consent to the collection and processing of your personal data and — where the servers sit outside the Republic of Kazakhstan — to their cross-border transfer under Art. 16 of the Law of the RK “On Personal Data and Their Protection” No. 94-V. You can withdraw consent by deleting your account in settings or by writing to us.
For any privacy questions write to roorsayan@gmail.com. We reply within a reasonable time.