Aller au contenu
Topkapı Palace — Tickets & Visitor Guide
Aperçu Billets et entrée guidée Visite À propos Harem FAQ
Réservez à partir de €63 FR
Topkapı
  • Aperçu
  • Billets
  • Visite
  • À propos
  • FAQ

Opérateur & responsable du traitement

Entité juridique
Check for Trips GmbH
Siège social
Hintergasse 6, 65428 Rüsselsheim, Germany
Registre du commerce
Darmstadt HRB 96248
N° TVA
DE310315188
Directeur général
Erdogan Tur
E-mail de support
info@istanbulwelcomecard.com
Téléphone (siège Allemagne)
+49 6142 301 9620
Téléphone (Turquie, WhatsApp)
+90 544 870 31 34
Processeurs de paiement et de données
Stripe (payment) · PayPal (payment) · Ratepay (BNPL) · Google Analytics 4 · Meta Pixel

Check for Trips GmbH agit en tant que responsable du traitement au sens de l'Art. 4(7) du RGPD. Toutes les ventes de produits IWC — y compris celles passées via ce micro-site — sont exécutées par l'opérateur ci-dessus. Les remboursements sont traités en 5–10 jours ouvrables via le moyen de paiement initial.

Mentions légales · Politique de confidentialité · Version 2.2

Comment nous traitons les données derrière votre visite du palais.

Une entrée guidée au palais nécessite plus de coordination qu'un simple billet — l'horaire d'un guide agréé, une heure de début fixe, un supplément Harem. Cette politique explique ce que nous collectons pour que cela fonctionne, pourquoi c'est nécessaire, combien de temps nous le conservons et qui d'autre le voit. Langage clair. Conforme RGPD + KVKK. Sans surprise.

Entrée en vigueur
1er janv. 2026
Dernière révision
15 mars 2026
Version
2.2
Responsable des données
en interne
Seize sections
  1. Qui nous sommes
  2. Ce que nous collectons
  3. Pourquoi nous le collectons
  4. Comment nous collectons
  5. Données de réservation
  6. Conversations support
  7. Analyses et rapports de plantage
  8. Fournisseurs utilisés
  9. Partage avec des tiers
  10. Durée de conservation
  11. Transferts internationaux
  12. Mesures de sécurité
  13. Vos droits
  14. Données des enfants
  15. Modifications de cette politique
  16. Nous contacter
01

Qui nous sommes.

Ce site est exploité par Istanbul Tourist Information Ltd., une société turque à responsabilité limitée enregistrée à Istanbul sous licence TÜRSAB A-7812 and VAT number 3470891204. Siège social : Sultanahmet Mah. Divan Yolu Cad. 17, 34122 Fatih, Istanbul. Vous pouvez joindre notre responsable des données à privacy@istanbul-tourist-information.com.

This privacy policy covers topkapi.istanbul-tourist-information.com, the dedicated booking and visitor-guide site for Topkapı Palace. It does not cover the Ministry of Culture's own site, the venue's official pages, or any reseller that may have sold you a ticket.

02

Ce que nous collectons.

Quatre catégories, rien de plus. Tout ce qui ne figure pas dans cette liste, nous ne le demandons pas et nous ne saurions qu'en faire.

Données de contact et de réservation — the cardholder's name, email, and phone number, plus the names of fellow visitors if you book for a group. Your preferred language for the tour (we match a guide accordingly) and any Harem add-on choice.

Données de paiement — the card number is entered on Stripe's hosted page, tokenised there, and we only store the last four digits + brand for your invoice. We never see nor store the full card number.

Données d'utilisation — which pages you visit, how you got here, what device you're using. Anonymised before aggregation (see section 07).

Données de support — if you write to us, we keep your email and our reply. Nothing else about the conversation is shared or mined.

03

Pourquoi nous le collectons.

Under GDPR, every piece of data we collect has to sit under a specific legal basis. Here are ours, item by item.

Contract performance. Your booking data — name, email, visit date, ticket type. Without it we literally cannot issue you a ticket or brief the guide on your arrival. Legal basis: Art. 6(1)(b) GDPR.

Legal obligation. Turkish tax law requires us to keep transaction records for 10 years. That means the cardholder name, total amount, date, and VAT portion of each sale. Legal basis: Art. 6(1)(c) GDPR.

Legitimate interest. Analytics, fraud detection, anonymised crash reports — we use these to keep the site working and resist fraud. You can opt out via the cookie panel. Legal basis: Art. 6(1)(f) GDPR.

Consent. Marketing cookies, retargeting, newsletter sign-ups — only with your explicit opt-in. Legal basis: Art. 6(1)(a) GDPR.

04

How we collect it.

Directly from you — when you fill a booking form, email support, or type into a field. We don't buy data lists, we don't enrich your profile with third-party sources, and we don't fingerprint your device. If you haven't told us something yourself, we don't know it.

The one exception: payment card details, which you enter directly into Stripe's form. Stripe confirms the payment and returns a reference to us — we never see the card number itself.

05

Données de réservation.

Your booking record contains: booking reference, visit date, slot time, guide language, Harem add-on, cardholder name, contact email, phone, number of visitors in the group, VAT amount, total paid, and any refund history. This is the complete list.

It is visible to three people: you (via the confirmation email), your licensed guide on the day of your visit (name + group size + language only — they don't see your contact details), and our support team when you write to them.

06

Conversations support.

When you email support, your message and our reply are stored in our helpdesk tool (Front). Conversations are retained for 36 months unless you ask us to purge them sooner — useful if a later agent needs context about a refund or a reschedule you previously discussed.

Support conversations are never used as training data for AI, never shared with marketing, and never visible to anyone outside the three-person support team plus the data officer.

07

Analyses et rapports de plantage.

We use Google Analytics 4 with IP anonymisation, ad-signals disabled, and demographics off. We see how many visitors arrive, which page they land on, and where they drop off — not who they are, what device model they use, or what else they look at across the web.

Sentry captures crash reports (JavaScript errors, server exceptions) with a scrubbed version of the page — any form field, cookie, or URL parameter that might carry personal data is stripped before the report leaves your browser. We use these to know what broke; we don't use them to identify people.

08

Fournisseurs utilisés.

Seven third parties touch data on this site. Here they are, what they do, and where they hold the data.

VendorPurposeData heldRegion
StripePayment processingCard details (tokenised)EU + US
External sales APIMinistry of Culture ticket issuanceVisit date, group sizeTürkiye
Transactional emailConfirmation + voucher deliveryEmail address, booking summaryEU
Google Analytics 4Anonymised usage statsAnonymised session IDEU + US
Meta PixelAd attribution (opt-in only)Opaque retargeting IDEU + US
SentryCrash reports (scrubbed)Error trace, no PIIEU
Hosting & CDNServing the siteIP, user-agent (transient)EU

Each vendor has signed a Data Processing Agreement with us and is audited annually. If you want a copy of the list, email the data officer.

09

Sharing with third parties.

We do not sell your data. We do not rent it. We do not share it with partners for their own marketing. The only third parties that touch your data are the vendors listed in section 08, all of whom act as data processors under our instructions.

Exception: if a Turkish court, a tax authority, or the Ministry of Culture issues a valid legal order, we will comply. You will be notified unless the order specifically forbids that disclosure. This has not happened in the history of the site.

10

Durée de conservation.

Booking records — 10 years (Turkish tax law requires the financial record for this duration).

Conversations support — 36 months from last message, or until you ask for deletion.

Analytics data — 24 months in GA4, aggregated after that (no individual records).

Crash reports — 14 days (Sentry automatically purges beyond that).

Marketing cookies — 90 days or until you revoke consent, whichever comes first.

11

Transferts internationaux.

Our primary infrastructure is EU-based (Frankfurt and Amsterdam). Two vendors — Stripe and Google — route a portion of data through US infrastructure. Both rely on the EU-US Data Privacy Framework and Standard Contractual Clauses under GDPR Art. 46 for lawful transfer.

If you are booking from Türkiye, data stays within the country to the extent the Ministry of Culture's external sales API is concerned — that transfer sits under KVKK equivalent safeguards.

12

Mesures de sécurité.

TLS 1.3 on every connection. Database encryption at rest. Two-factor authentication required for every staff account. Quarterly penetration tests by an independent Turkish security firm. A documented incident-response playbook with a 72-hour notification commitment (shorter than GDPR requires).

No system is perfectly secure. If a breach happens that affects you, we will notify you within 72 hours of detection with the specific data involved, the potential impact, and the steps we've taken — regardless of what the regulatory minimum requires.

13

Vos droits.

Under GDPR (if you're in the EU) and KVKK (if you're in Türkiye), you have eight rights over your data. Here they are, plus how to exercise each one.

01

Access

Request a copy of every piece of data we hold on you. Delivered within 30 days as a downloadable archive.

02

Rectification

Fix anything that's wrong — a typo in your name, an outdated email address. Same-day turnaround.

03

Erasure

Delete your data outside the 10-year tax retention. For post-retention records, we can pseudonymise.

04

Restriction

Freeze your data — we keep it, but stop processing, usually during a rectification dispute.

05

Portability

Export your booking history in JSON or CSV — machine-readable, usable in another system.

06

Objection

Object to any legitimate-interest processing. We stop unless we can demonstrate a compelling legal reason.

07

Automated decisions

We don't make any automated decisions about you. No scoring, no profiling, no algorithmic calls.

08

Complain

Complain to KVKK (in Türkiye) or your EU country's DPA. You don't need to tell us first.

14

Données des enfants.

We do not knowingly collect data about children under 16. A parent can book palace entry for a child — in that case the cardholder's name is the parent's, and only first names of children appear on the voucher. No contact details are requested for minors.

15

Changes to this policy.

We may update this policy. When a change affects your rights materially, you will be emailed at the address on your most recent booking at least 30 days before the change takes effect. Minor edits (typo fixes, clarifications) are posted without notification, but the version number in the header increments either way.

Privacy & data questions

Write to our data officer — not a generic privacy inbox.

One in-house person reads every privacy request. First reply in eight business hours, resolution in under fifteen business days for 98% of cases. No chatbot, no ticketing system, no external vendor reading your message first.

Data protection officer privacy@istanbul-tourist-information.com
Related policies & tools
Terms of Booking Refund Policy Cookie Preferences Contact support
Topkapı Palace — Tickets & Visitor Guide

A dedicated booking and visitor-guide site for the Ottoman imperial palace. Part of the Istanbul Tourist Information portfolio.

Visite

  • Billets
  • Visite
  • À propos
  • FAQ

Support

  • Contact & support
  • Accessibilité
  • Plan du site
  • Politique de remboursement

Mentions légales

  • Privacy
  • Conditions générales
  • Cookie settings
© Istanbul Tourist Information · TÜRSAB A-7812Powered by istanbul-tourist-information.com