

Last updated: July 21, 2026
Effective Date: July 21, 2026
Last Updated: July 21, 2026
Penyu OÜ (“Penyu”, “we”, “our”, or “us”) respects your privacy and is committed to processing personal data lawfully, fairly, transparently, and securely.
This Privacy Policy explains how we collect, use, disclose, store, transfer, retain, and otherwise process personal data when you use the Penyu website, mobile applications, APIs, customer support channels, and related products or services collectively referred to as the “Services”.
Penyu operates a digital travel marketplace and intermediary platform. Through the Services, users may discover, purchase, manage, and receive travel-related products and services, including eSIM packages, hotel bookings, flights, airport transfers, transportation services, travel assistance, digital vouchers, and other travel products.
Unless expressly stated otherwise, Penyu does not directly provide telecommunications, hotel, airline, transfer, transportation, or similar travel services. These services are provided by independent third-party suppliers.
By using the Services, you acknowledge that you have read and understood this Privacy Policy.
Penyu OÜ
Registry Code: 16093920
Registered Office:
Harju maakond
Tallinn
Kesklinna linnaosa
Viru väljak 2
10111
Estonia
Website: https://penyu.io
Email: info@penyu.io
This Privacy Policy applies when you:
visit the Penyu website;
use a Penyu mobile application;
create or manage an account;
sign in using email, Google, or Apple;
purchase an eSIM or travel service;
make or manage a reservation;
communicate with customer support;
subscribe to marketing communications;
participate in surveys or promotions;
use any future Penyu service referring to this Privacy Policy.
Account means a registered Penyu user profile.
Controller means the entity determining the purposes and means of processing personal data.
Customer or User means an individual using the Services.
GDPR means Regulation (EU) 2016/679.
KVKK means Turkish Personal Data Protection Law No. 6698.
Personal Data means information relating to an identified or identifiable natural person.
Processing includes collecting, storing, using, sharing, updating, anonymizing, restricting, or deleting personal data.
Service Provider means an independent supplier offering products or services through Penyu, including eSIM providers, mobile operators, hotels, airlines, transfer companies, and other travel suppliers.
Penyu generally acts as an independent data controller for personal data processed to:
operate the platform;
manage user accounts;
process orders;
provide customer support;
prevent fraud;
comply with legal obligations;
communicate with users;
improve and secure the Services.
Independent Service Providers may act as separate data controllers for personal data they receive to fulfill a booking, activate an eSIM, provide accommodation, operate a flight, arrange a transfer, or deliver another service.
In limited circumstances, Penyu may process data on behalf of another party as a processor. Where this occurs, the processing will be subject to appropriate contractual arrangements.
We may collect:
full name;
email address;
phone number;
country;
preferred language;
account credentials;
profile image;
account preferences.
Users may sign in using:
email and password;
Google Sign-In;
Sign in with Apple.
Depending on the provider, we may receive:
name;
verified email address;
profile image;
provider identifier;
authentication tokens required for login.
We do not receive your Google or Apple password.
We may process:
order numbers;
purchased products;
booking identifiers;
reservation references;
passenger or guest information;
travel dates;
destination details;
eSIM activation identifiers;
ICCID or similar technical identifiers;
service provider references;
order status;
refund status;
purchase history;
support history.
Payments are processed by Stripe.
Penyu does not store complete card numbers, CVV or CVC codes, or sensitive card authentication information.
We may receive limited payment metadata, including:
payment identifier;
transaction identifier;
payment status;
transaction amount;
currency;
billing country;
card brand;
last four digits of the card;
refund status;
dispute or chargeback status;
fraud prevention indicators.
Stripe processes payment information under its own privacy and security policies.
We may automatically collect:
IP address;
browser type and version;
operating system;
device model;
device language;
time zone;
screen resolution;
session identifiers;
device identifiers;
referral URLs;
network information;
API request logs;
authentication logs;
crash reports;
performance metrics;
error logs.
We may process:
country;
region;
time zone;
IP-based approximate location;
selected destination country.
We do not continuously track precise GPS location unless you explicitly authorize a feature requiring such access.
When you contact us, we may process:
emails;
support tickets;
chat messages;
attachments;
screenshots;
diagnostic data;
device information;
order references;
booking references;
complaint and dispute information.
We may process:
newsletter subscriptions;
marketing consent;
communication preferences;
promotional participation;
coupon usage;
survey responses;
product feedback.
You may withdraw marketing consent at any time.
Penyu may use cookies, local storage, SDKs, pixels, tags, and similar technologies.
These technologies may be used to:
maintain sessions;
authenticate users;
remember preferences;
secure accounts;
prevent fraud;
operate shopping carts;
analyze usage;
measure performance;
diagnose technical problems;
evaluate campaigns.
These are necessary for platform operation, security, authentication, checkout, fraud prevention, and session management.
These remember preferences such as language, currency, accessibility settings, and recently viewed products.
These help us understand traffic, usage patterns, navigation paths, feature usage, conversion events, performance, and errors.
These may be used to measure advertising performance, campaign effectiveness, and promotional engagement.
Where legally required, non-essential technologies are used only after consent.
We may process personal data to:
create and manage accounts;
authenticate users;
process orders and payments;
deliver digital products;
activate and manage eSIM services;
create and manage reservations;
communicate with Service Providers;
provide customer support;
process refunds;
investigate disputes;
detect and prevent fraud;
protect accounts and systems;
enforce our Terms of Service;
provide transactional communications;
send marketing communications where permitted;
personalize the Services;
perform analytics;
improve products and features;
comply with tax, accounting, regulatory, and legal obligations;
establish, exercise, or defend legal claims.
Penyu does not sell personal data to data brokers or unrelated third parties.
Where GDPR applies, processing may be based on:
Processing may be necessary to create an account, process an order, deliver a product, manage a reservation, provide support, or process a refund.
Processing may be necessary for accounting, taxation, regulatory compliance, fraud prevention, court orders, or lawful government requests.
We may process personal data for legitimate interests such as:
platform security;
fraud prevention;
service improvement;
troubleshooting;
customer support;
dispute management;
analytics;
protection of legal rights.
Consent may be used for:
optional cookies;
marketing communications;
surveys;
promotional activities.
Consent may be withdrawn at any time without affecting previous lawful processing.
We may share personal data with the following categories of recipients.
Depending on the service, data may be shared with:
eSIM providers;
mobile network operators;
hotels;
accommodation providers;
airlines;
airport transfer companies;
transportation providers;
travel assistance providers;
booking and reservation partners.
Only information reasonably necessary to fulfill the purchased service is shared.
Payment-related information may be shared with Stripe and other parties involved in payment processing, fraud prevention, refunds, or disputes.
Where you use Google or Apple login, information is exchanged as necessary to complete authentication.
We may use providers for:
hosting;
cloud storage;
content delivery;
security;
logging;
monitoring;
email delivery;
analytics;
error tracking;
customer support;
fraud prevention.
We may disclose information to accountants, auditors, lawyers, insurers, and other professional advisers where necessary.
We may disclose information where required to:
comply with law;
respond to lawful requests;
comply with court orders;
prevent fraud;
protect users or the public;
enforce our rights.
When you purchase or use an eSIM, Penyu and the relevant eSIM provider or network operator may process:
order identifiers;
activation identifiers;
ICCID or similar identifiers;
package details;
destination and validity information;
activation status;
usage status;
connection diagnostics;
network-related technical data;
device compatibility information;
support and error logs.
Mobile network operators independently operate their networks and may process connection, routing, usage, device, and traffic information under their own legal obligations and privacy notices.
Penyu does not ordinarily receive the content of your communications.
For hotel, flight, transfer, and similar bookings, Penyu may transmit information necessary to create, confirm, modify, support, or refund the reservation.
The relevant provider may request additional data, including:
identity document information;
passenger information;
guest information;
arrival details;
special assistance requests;
information required by local law.
Users should avoid submitting unnecessary sensitive information.
Penyu serves users internationally. Personal data may therefore be processed outside the country in which it was collected.
Where required, Penyu may use safeguards including:
European Commission Standard Contractual Clauses;
contractual confidentiality obligations;
access controls;
encryption;
data minimization;
organizational safeguards;
legally recognized transfer mechanisms.
Penyu retains personal data only for as long as necessary for the purposes described in this Privacy Policy.
Indicative retention periods include:
Data Category | Indicative Retention |
|---|---|
Account information | Until account deletion, followed by deletion or anonymization within a reasonable operational period |
Order and transaction records | Generally up to 10 years where required for tax, accounting, or legal purposes |
Payment metadata | Generally up to 10 years where required by law |
Customer support communications | Generally up to 5 years after closure |
Security and authentication logs | Generally up to 24 months |
Cookie and consent records | As long as necessary to demonstrate consent or objection |
Marketing preferences | Until withdrawal, with limited suppression records retained afterward |
Anonymized data | May be retained indefinitely |
Retention periods may be extended where necessary for disputes, investigations, fraud prevention, regulatory obligations, or legal claims.
Users may request account deletion.
Following deletion:
name, email address, and phone number will be deleted or anonymized where reasonably possible;
authentication credentials will be invalidated;
active sessions will be terminated;
marketing preferences will be removed;
profile information will be deleted or anonymized.
Penyu may retain transaction, accounting, tax, security, fraud prevention, regulatory, and dispute-related records where legally required or reasonably necessary.
Anonymized data that no longer identifies an individual may continue to be used.
Penyu uses reasonable technical and organizational safeguards, which may include:
encryption in transit;
encryption at rest where appropriate;
role-based access controls;
least-privilege access;
authentication controls;
administrative security;
logging and monitoring;
software updates;
backup procedures;
incident response processes;
security testing.
No online system can be guaranteed to be completely secure.
Penyu maintains procedures to identify, assess, contain, investigate, and remediate security incidents.
Where required by law, Penyu will notify the relevant supervisory authority and affected individuals within the applicable legal timeframe.
Notifications may describe:
the nature of the incident;
affected data categories;
likely consequences;
protective measures;
recommended actions.
Penyu may use automated tools for:
fraud detection;
payment risk assessment;
account security;
operational monitoring;
service personalization.
Penyu does not intend to make decisions producing legal or similarly significant effects solely through automated processing without legally required safeguards.
Penyu may use artificial intelligence or machine-assisted tools to:
categorize support requests;
translate content;
detect fraud or abuse;
summarize technical information;
improve search;
assist support personnel.
Penyu applies reasonable data minimization, access controls, contractual protections, and human oversight.
Private customer communications are not intentionally used to train public AI models unless users are clearly informed and a valid legal basis exists.
Depending on applicable law, you may have the right to:
access your personal data;
correct inaccurate data;
request deletion;
restrict processing;
object to processing;
withdraw consent;
request portability;
object to certain automated decisions;
lodge a complaint with a supervisory authority.
Penyu may verify your identity before processing a request.
Requests may be refused or limited where permitted by law, including where they are manifestly unfounded, excessive, conflict with another person’s rights, or concern data Penyu must legally retain.
Users in the European Economic Area may complain to the supervisory authority in their country of residence, place of work, or place of the alleged infringement.
Where applicable, Penyu’s lead supervisory authority may be the Estonian Data Protection Inspectorate.
Requests may be submitted to:
Where KVKK applies, Penyu may process personal data based on legally recognized grounds, including:
explicit legal authorization;
necessity for contract performance;
compliance with a legal obligation;
establishment, exercise, or protection of a right;
legitimate interests, provided fundamental rights are not harmed;
explicit consent where required.
Users may have the right to:
learn whether personal data is processed;
request information about processing;
learn the purpose of processing;
learn recipients of personal data;
request correction;
request deletion or destruction;
request notification of corrections or deletion to third parties;
object to certain automated processing;
request compensation where legally available.
International transfers subject to KVKK will be performed only where a lawful transfer mechanism and other applicable conditions are satisfied.
Requests may be submitted to:
The Services are not intentionally directed to children who cannot legally consent to data processing or enter into contracts under applicable law.
If Penyu learns that personal data was unlawfully collected from a child, reasonable steps will be taken to delete or anonymize it.
The Services may contain links to third-party websites, applications, or services.
Penyu is not responsible for the privacy practices, security, availability, or content of independent third parties.
Users should review the relevant third-party privacy notices.
If Penyu is involved in a merger, acquisition, financing, restructuring, sale of assets, insolvency, or transfer of business, personal data may be transferred as part of that transaction.
Any recipient must process the data in accordance with applicable law.
Some browsers transmit “Do Not Track” or similar signals.
Because no single universal standard applies to every signal, Penyu may not respond uniformly to all browser signals.
Where applicable law requires recognition of a legally valid browser-based opt-out signal, Penyu will take reasonable steps to honor it.
Penyu may update this Privacy Policy to reflect:
legal developments;
regulatory requirements;
product changes;
operational changes;
security improvements;
new Service Providers;
business developments.
Material changes will be published with an updated “Last Updated” date.
Version | Date | Description |
|---|---|---|
1.0 | July 21, 2026 | Initial publication |
For privacy questions or requests, contact:
Penyu OÜ
Registry Code: 16093920
Harju maakond
Tallinn
Kesklinna linnaosa
Viru väljak 2
10111
Estonia
Website: https://penyu.io
Email: info@penyu.io
If you have questions about this policy, you can reach us at destek@penyu.io .