Bosphorus Spa

Bosphorus Spa · Royal Bosphorus Hotel

Privacy Policy

This notice explains what information Bosphorus Spa receives when you browse the website or send a reservation request, why it is used, where it may travel and how you can contact us about it.

Last updated:

Who is responsible and how to contact us

Bosphorus Spa operates this website and the spa inside Royal Bosphorus Hotel at Hoca Paşa, Ebussuud Cd. No:6, 34110 Fatih/İstanbul, Türkiye. For privacy questions, corrections or deletion requests, call or use WhatsApp at +90 541 536 00 51, or visit the address above.

Information we receive

A reservation request may include your name, optional surname and email, phone or WhatsApp number, preferred contact method, selected package or massage, appointment date and time, number and type of guests, therapist or privacy preferences, message, and the booking or ticket identifier. The website may also receive ordinary technical information such as IP address, browser, device, language, requested page, time and security events.

Why we use it

We use the minimum information needed to answer you, check availability, confirm and prepare the requested visit, create your reservation ticket, avoid duplicate requests, provide customer service, protect the website and meet applicable operational or legal duties. Sending a request is not an automatic confirmation. No prepayment is required, and this website does not collect or store payment-card numbers.

Services involved in a request

Cloudflare provides website delivery and security. Reservation delivery may use Google Apps Script and Gmail. Cloudinary may host the generated ticket or PDF link. WhatsApp and Meta receive information only when you choose WhatsApp and send the prepared message; your email application receives it only when you choose email and send. Maps, video or other external links may receive technical data when you open them. Each provider applies its own terms and privacy practices.

Browser storage and cookies

The booking flow uses necessary storage in your browser to keep a draft for about 7 days and up to 10 recent booking records for up to 90 days on that device. This helps you recover or manage a ticket. You can remove it with the website reset controls or browser settings. Security, media or external services may set technically necessary identifiers; we do not use the booking form to sell personal data.

Retention, security and your choices

Local records expire according to the periods above. Messages and operational reservation records outside your device are kept only as long as reasonably needed for the visit, customer service, security and applicable legal duties; an exact period can vary by record. We limit access and use reasonable safeguards, but no internet transmission is risk-free. Subject to applicable law, you may ask to access, correct or delete your information, object to or restrict certain use, or raise a concern with the competent authority.

Children, changes and translations

An adult should submit a reservation and provide only the information needed for any child included in the visit. We may update this notice when the booking flow, providers or legal requirements change; the date at the top identifies the current version. Every language is intended to communicate the same policy. Contact us if any translated wording is unclear.

Privacy policy language