Skip to content
Topkapı Palace — Tickets & Visitor Guide
Overview Tickets & Guided Entry Visit About Harem FAQ
Book from €63
Topkapı
  • Overview
  • Tickets
  • Visit
  • About
  • FAQ

Operator & data controller

Legal entity
Check for Trips GmbH
Registered address
Hintergasse 6, 65428 Rüsselsheim, Germany
Commercial register
Darmstadt HRB 96248
VAT ID
DE310315188
Managing director
Erdogan Tur
Support email
info@istanbulwelcomecard.com
Phone (Germany HQ)
+49 6142 301 9620
Phone (Turkey, WhatsApp)
+90 544 870 31 34
Payment + data processors
Stripe (payment) · PayPal (payment) · Ratepay (BNPL) · Google Analytics 4 · Meta Pixel

Check for Trips GmbH acts as data controller under GDPR Art. 4(7). All IWC product sales — including those routed through this micro-site — are fulfilled by the operator above. Refunds processed in 5–10 business days via the original payment method.

Legal · Privacy Policy · Version 2.2

How we handle the data behind your palace visit.

A guided palace entry requires more coordination than a plain ticket — a licensed guide's schedule, a fixed start time, a Harem add-on. This policy covers what we collect to make that work, why it's needed, how long it's kept, and who else sees it. Plain English. GDPR + KVKK aligned. No surprises.

Effective
1 Jan 2026
Last reviewed
15 Mar 2026
Version
2.2
Data officer
in-house
Sixteen sections
  1. Who we are
  2. What we collect
  3. Why we collect it
  4. How we collect
  5. Booking data
  6. Support conversations
  7. Analytics & crash reports
  8. Vendors we use
  9. Sharing with third parties
  10. How long we keep it
  11. International transfers
  12. Security measures
  13. Your rights
  14. Children's data
  15. Changes to this policy
  16. Contact us
01

Who we are.

This site is operated by Istanbul Tourist Information Ltd., a Turkish limited company registered in Istanbul under TÜRSAB licence A-7812 and VAT number 3470891204. Registered office: Sultanahmet Mah. Divan Yolu Cad. 17, 34122 Fatih, Istanbul. You can reach our data officer at privacy@istanbul-tourist-information.com.

This privacy policy covers topkapi.istanbul-tourist-information.com, the dedicated booking and visitor-guide site for Topkapı Palace. It does not cover the Ministry of Culture's own site, the venue's official pages, or any reseller that may have sold you a ticket.

02

What we collect.

Four categories, nothing more. Anything outside this list, we don't ask for and wouldn't know what to do with.

Contact & booking data — the cardholder's name, email, and phone number, plus the names of fellow visitors if you book for a group. Your preferred language for the tour (we match a guide accordingly) and any Harem add-on choice.

Payment data — the card number is entered on Stripe's hosted page, tokenised there, and we only store the last four digits + brand for your invoice. We never see nor store the full card number.

Usage data — which pages you visit, how you got here, what device you're using. Anonymised before aggregation (see section 07).

Support data — if you write to us, we keep your email and our reply. Nothing else about the conversation is shared or mined.

03

Why we collect it.

Under GDPR, every piece of data we collect has to sit under a specific legal basis. Here are ours, item by item.

Contract performance. Your booking data — name, email, visit date, ticket type. Without it we literally cannot issue you a ticket or brief the guide on your arrival. Legal basis: Art. 6(1)(b) GDPR.

Legal obligation. Turkish tax law requires us to keep transaction records for 10 years. That means the cardholder name, total amount, date, and VAT portion of each sale. Legal basis: Art. 6(1)(c) GDPR.

Legitimate interest. Analytics, fraud detection, anonymised crash reports — we use these to keep the site working and resist fraud. You can opt out via the cookie panel. Legal basis: Art. 6(1)(f) GDPR.

Consent. Marketing cookies, retargeting, newsletter sign-ups — only with your explicit opt-in. Legal basis: Art. 6(1)(a) GDPR.

04

How we collect it.

Directly from you — when you fill a booking form, email support, or type into a field. We don't buy data lists, we don't enrich your profile with third-party sources, and we don't fingerprint your device. If you haven't told us something yourself, we don't know it.

The one exception: payment card details, which you enter directly into Stripe's form. Stripe confirms the payment and returns a reference to us — we never see the card number itself.

05

Booking data.

Your booking record contains: booking reference, visit date, slot time, guide language, Harem add-on, cardholder name, contact email, phone, number of visitors in the group, VAT amount, total paid, and any refund history. This is the complete list.

It is visible to three people: you (via the confirmation email), your licensed guide on the day of your visit (name + group size + language only — they don't see your contact details), and our support team when you write to them.

06

Support conversations.

When you email support, your message and our reply are stored in our helpdesk tool (Front). Conversations are retained for 36 months unless you ask us to purge them sooner — useful if a later agent needs context about a refund or a reschedule you previously discussed.

Support conversations are never used as training data for AI, never shared with marketing, and never visible to anyone outside the three-person support team plus the data officer.

07

Analytics & crash reports.

We use Google Analytics 4 with IP anonymisation, ad-signals disabled, and demographics off. We see how many visitors arrive, which page they land on, and where they drop off — not who they are, what device model they use, or what else they look at across the web.

Sentry captures crash reports (JavaScript errors, server exceptions) with a scrubbed version of the page — any form field, cookie, or URL parameter that might carry personal data is stripped before the report leaves your browser. We use these to know what broke; we don't use them to identify people.

08

Vendors we use.

Seven third parties touch data on this site. Here they are, what they do, and where they hold the data.

VendorPurposeData heldRegion
StripePayment processingCard details (tokenised)EU + US
External sales APIMinistry of Culture ticket issuanceVisit date, group sizeTürkiye
Transactional emailConfirmation + voucher deliveryEmail address, booking summaryEU
Google Analytics 4Anonymised usage statsAnonymised session IDEU + US
Meta PixelAd attribution (opt-in only)Opaque retargeting IDEU + US
SentryCrash reports (scrubbed)Error trace, no PIIEU
Hosting & CDNServing the siteIP, user-agent (transient)EU

Each vendor has signed a Data Processing Agreement with us and is audited annually. If you want a copy of the list, email the data officer.

09

Sharing with third parties.

We do not sell your data. We do not rent it. We do not share it with partners for their own marketing. The only third parties that touch your data are the vendors listed in section 08, all of whom act as data processors under our instructions.

Exception: if a Turkish court, a tax authority, or the Ministry of Culture issues a valid legal order, we will comply. You will be notified unless the order specifically forbids that disclosure. This has not happened in the history of the site.

10

How long we keep it.

Booking records — 10 years (Turkish tax law requires the financial record for this duration).

Support conversations — 36 months from last message, or until you ask for deletion.

Analytics data — 24 months in GA4, aggregated after that (no individual records).

Crash reports — 14 days (Sentry automatically purges beyond that).

Marketing cookies — 90 days or until you revoke consent, whichever comes first.

11

International transfers.

Our primary infrastructure is EU-based (Frankfurt and Amsterdam). Two vendors — Stripe and Google — route a portion of data through US infrastructure. Both rely on the EU-US Data Privacy Framework and Standard Contractual Clauses under GDPR Art. 46 for lawful transfer.

If you are booking from Türkiye, data stays within the country to the extent the Ministry of Culture's external sales API is concerned — that transfer sits under KVKK equivalent safeguards.

12

Security measures.

TLS 1.3 on every connection. Database encryption at rest. Two-factor authentication required for every staff account. Quarterly penetration tests by an independent Turkish security firm. A documented incident-response playbook with a 72-hour notification commitment (shorter than GDPR requires).

No system is perfectly secure. If a breach happens that affects you, we will notify you within 72 hours of detection with the specific data involved, the potential impact, and the steps we've taken — regardless of what the regulatory minimum requires.

13

Your rights.

Under GDPR (if you're in the EU) and KVKK (if you're in Türkiye), you have eight rights over your data. Here they are, plus how to exercise each one.

01

Access

Request a copy of every piece of data we hold on you. Delivered within 30 days as a downloadable archive.

02

Rectification

Fix anything that's wrong — a typo in your name, an outdated email address. Same-day turnaround.

03

Erasure

Delete your data outside the 10-year tax retention. For post-retention records, we can pseudonymise.

04

Restriction

Freeze your data — we keep it, but stop processing, usually during a rectification dispute.

05

Portability

Export your booking history in JSON or CSV — machine-readable, usable in another system.

06

Objection

Object to any legitimate-interest processing. We stop unless we can demonstrate a compelling legal reason.

07

Automated decisions

We don't make any automated decisions about you. No scoring, no profiling, no algorithmic calls.

08

Complain

Complain to KVKK (in Türkiye) or your EU country's DPA. You don't need to tell us first.

14

Children's data.

We do not knowingly collect data about children under 16. A parent can book palace entry for a child — in that case the cardholder's name is the parent's, and only first names of children appear on the voucher. No contact details are requested for minors.

15

Changes to this policy.

We may update this policy. When a change affects your rights materially, you will be emailed at the address on your most recent booking at least 30 days before the change takes effect. Minor edits (typo fixes, clarifications) are posted without notification, but the version number in the header increments either way.

Privacy & data questions

Write to our data officer — not a generic privacy inbox.

One in-house person reads every privacy request. First reply in eight business hours, resolution in under fifteen business days for 98% of cases. No chatbot, no ticketing system, no external vendor reading your message first.

Data protection officer privacy@istanbul-tourist-information.com
Related policies & tools
Terms of Booking Refund Policy Cookie Preferences Contact support
Topkapı Palace — Tickets & Visitor Guide

A dedicated booking and visitor-guide site for the Ottoman imperial palace. Part of the Istanbul Tourist Information portfolio.

Visit

  • Tickets
  • Visit
  • About
  • FAQ

Support

  • Contact & support
  • Accessibility
  • Sitemap
  • Refund policy

Legal

  • Privacy
  • Terms
  • Cookie settings
© Istanbul Tourist Information · TÜRSAB A-7812Powered by istanbul-tourist-information.com