Privacy and cookies

Privacy policy

This page explains what data is processed when you use Routavio, what that data is used for, and which third-party services the project relies on.

01

Who processes it

Routavio is not a separate legal entity. The project is run independently.

Requests about privacy and personal data can be sent to [email protected].

02

What we collect

Only the data the service needs in order to work is processed. Search works without an account.

  • Account: email address, an irreversible hash of the password and, if you gave them, your name, home city, passport nationality and currency preference. The password itself is stored nowhere.
  • Session: a hash of the session token, its expiry, your browser details and IP address. Kept so that someone else signing into your account can be noticed.
  • Usage: the searches you run (from, to, which date), the routes you save, the price alerts you set, and the moments you click through to a third-party provider.
  • Consent records: when marketing consent was given or withdrawn, with the IP address and browser details at that moment.
  • Pilot form: your answers, if you took part in the Sabancı University study. If you did not take part, no such record is created.
03

Why we process it

  • To compute the journey you searched for, joining flight, train, bus and ferry into one door-to-door result.
  • To keep your account open, keep your session secure and prevent automated request floods.
  • To send the emails the service cannot work without, such as email verification and password resets.
  • To send the price radar and the newsletter, if you consented. Without consent the service works exactly the same.
  • In the pilot study, and only where consent was given, to read the form answers alongside the matching search log.
04

On what basis

The data your account and your searches need in order to work is processed as part of the service relationship. Session security and the prevention of abuse rest on legitimate interest. Marketing email, non-essential cookies and the pilot study are processed on explicit consent alone; consent can be withdrawn at any time, and the service carries on working exactly the same.

05

Cookies

There are three groups. The first two need no consent: the essential cookies, and an anonymous measurement that leaves nothing behind once you close the tab. There are no ad-network cookies, no profiling and no cross-site tracking.

Essential
vrv_sid (anonymous session), routavio_session (only if you are signed in), vrv_locale and vrv_currency (language and currency preference). The site does not work without them, so no consent is asked for. The cookie preference itself is kept in the browser's localStorage under the key vrv:consent.
Measurement (consent only)
PostHog (EU servers) measures how often each page is opened, how long it takes to arrive and which controls are used; every form input is masked. It runs on every visit, but without your consent nothing it uses outlives the tab: no cookie, no permanent storage, only a temporary key the browser clears when the tab closes, so you are not recognised on a later visit. Accepting lets it remember this browser between visits; declining stops it running at all.
Referral attribution (consent only)
The referral attribution tag also loads only after you accept. If you click through to a third-party provider and book, it lets that referral be attributed. Decline it and the site works exactly the same.

You can change this at any time from the "Cookie settings" link at the bottom of the page: accept to be remembered between visits, or decline to stop the measurement and the referral scripts entirely, then and later.

06

The Routavio app

The mobile app uses the same account and the same servers as the website, and everything on this page applies to it. These points are specific to the app:

  • On the phone: your sign-in key, or a guest key if you have not signed in, is kept in the phone's secure storage. Recent searches, your last results, currency and home city are kept in the app's own storage and are removed when you uninstall the app.
  • Notifications: only if you are signed in and turn them on. The app then sends us a push token issued through Expo, and alerts reach the phone through Expo and Google Firebase Cloud Messaging (Android) or Apple Push Notification service (iOS). The token is deleted when you log out or delete your account.
  • Crash reports: when the app crashes, a report goes to Sentry with the error, the app version, the phone model and the operating system. Account details, tokens and the query part of web addresses are removed before it is sent.
  • Usage measurement: off until you turn it on in the Account tab. When it is on, the app sends search and booking events to PostHog (EU servers) under a random ID created on the phone; turning it off deletes that ID. Website pages opened inside the app are measured like the website, as described under Cookies.
  • The app does not ask for your location, contacts, camera or photos. A departure city may be suggested from the city of your internet connection.
  • Deleting your account: in the app, open the Account tab and choose Delete account. On the web, sign in at routavio.com/account, open Settings and choose Delete account, or write to the address below. Everything tied to the account is deleted with it, including push tokens.
07

Who else sees it

Personal data is not sold and is not opened to ad networks. These are the providers that keep the service running:

  • Hosting: Hetzner (Germany) runs the site, the background jobs and the database; Cloudflare sits in front as the CDN and DDoS shield.
  • Email: Resend delivers verification, password reset and, with consent, newsletter email.
  • Transport data sources: the flight, rail and bus providers asked for prices and departures on the route you searched. What goes to them is the search itself, not your identity.
  • Referral attribution networks: only when you click through to a third-party provider, and only to attribute that referral.
  • AI providers: text you write to the assistant is passed to a model to produce the answer. Your account details are not.
  • Maps: the map tiles on route maps come from CARTO, which sees your IP address and the part of the map being shown.
08

Where the data sits

The providers above run their servers outside Turkey, mostly in the European Union and the United States. Transfers are made under those providers' standard contractual clauses and data processing agreements. Without an account, search still works in full.

09

How long we keep it

Records with an expiry fall away by themselves; the rest is kept while the account is open.

Account data
While the account is open. Delete it from your account settings and every record attached to it is deleted with it.
Search logs
Kept to compute routes and to make repeated searches faster; they go when the account goes.
Session records
They become invalid when they expire and are cleared.
Consent records
Kept even after consent is withdrawn; the moment consent was given and the moment it was withdrawn both have to stay on record.
Pilot answers
Until the study is finished. Results are reported in aggregate and without names.
10

Security

Passwords are stored irreversibly with bcrypt; no plaintext password is kept anywhere. Traffic travels over TLS. What is stored is a hash of the session token, not the token itself.

11

Children

Routavio is not aimed at people under 18 and no data is knowingly collected from that age group. An account opened that way is deleted once it is reported.

12

Changes

When this text changes, the date at the bottom changes with it. For a substantive change, account holders are informed by email.

13

What you can ask for

Wherever you live, you can ask for any of these:

  • To learn what data is processed and to receive a copy of it.
  • To have wrong or incomplete data corrected.
  • To have the data erased.
  • To have the processing restricted.
  • To take the data in a machine-readable form and move it to another service.
  • To object to processing based on legitimate interest, and to withdraw marketing consent.
  • To complain to the data protection authority of the country you are in. In Turkey that is the Personal Data Protection Authority.

As far as your identity can be verified, requests are answered within thirty days at the latest: [email protected]

The notice under Law 6698 is also here: KVKK notice

Last updated: 29 September 2026.