Legal
Privacy Policy
Last updated: 31 July 2026
This policy explains what data the Bókun × BOG checkout integration processes, why it processes it, how long it is kept, and the rights you have over it. It is written to reflect the actual behaviour of the service and the data-handling expectations of the Bókun app platform and the GDPR.
1. What this service is
This website operates a private, single-vendor checkout integration (the “Service”) for one tour operator. The Service connects a tour selector embedded in the operator’s Duda website to a hosted checkout, reserves the selected tour in the operator’s Bókun account, collects payment through Bank of Georgia Payment Manager, and confirms the booking in Bókun once the payment is verified.
The Service is a technical connector. Bókun remains the authoritative system for products, availability, pricing, booking questions, reservations, confirmed bookings, and travel documents. Bank of Georgia is the payment processor.
2. Data we process
We process only the data needed to create and confirm a booking:
- Contact details you enter at checkout: full name, email address, and phone number.
- Booking selections: the tour product, date, start time, and passenger counts you choose in the selector.
- Answers to booking questions required by the tour operator, which are forwarded to Bókun as part of the reservation.
- Payment references: the Bank of Georgia order identifier, payment status, and the verified amount and currency (GEL).
- Operational records: booking status history, payment-provider callback events, and technical attempt logs used for auditing, recovery, and dispute investigation.
3. Data we deliberately do not collect
- Card numbers, card security codes, or bank account details. Payment card data is entered only on Bank of Georgia's hosted payment page and never touches this Service.
- User accounts or passwords. The checkout is session-based and requires no registration.
- Marketing profiles. We do not use your data for advertising, profiling, or automated decision-making, and we do not sell or rent personal data.
4. Cookies and tracking
The Service does not set tracking, analytics, or marketing cookies. Checkout sessions are identified by signed, expiring tokens carried in the page URL rather than by cookies.
5. How your data is used
- Creating a time-limited reservation in Bókun for your selected tour.
- Opening a payment order with Bank of Georgia for the exact server-verified amount and currency.
- Confirming your booking in Bókun only after the payment provider's callback signature and receipt have been verified.
- Delivering booking details and travel documents, which are issued by Bókun on behalf of the tour operator.
- Keeping an audit trail so that failed, duplicated, or interrupted payments can be recovered safely and investigated.
6. Who receives your data
- Bókun (a Tripadvisor company) — receives your contact details, booking selections, and question answers to create and manage the reservation and confirmed booking, and to issue travel documents.
- Bank of Georgia — receives the payment order details and processes your payment on its hosted page under its own terms and privacy policy.
- Duda — hosts the tour operator's website in which the tour selector is embedded; the selector itself only passes your tour selection, never your contact or payment data.
- Infrastructure providers that host this Service and its PostgreSQL database under contractual confidentiality obligations.
Data is shared with each provider only to the extent required to fulfil your booking. No other third parties receive your personal data unless required by law.
7. How we protect your data
- All traffic is served over HTTPS.
- Bókun installation credentials are stored encrypted at rest, and the encryption key is kept outside the database.
- Payment-provider callbacks are verified using RSA signature checks against the raw payload before any booking changes state.
- Provider and server modules are isolated so that secrets and tokens are never exposed to the browser.
- Access to operational records is restricted to authorised personnel operating the Service.
8. Data retention and deletion
- Payment-provider callback events and technical attempt logs are deleted after 90 days.
- Personal details (name, email, phone) on confirmed bookings are anonymised 365 days after the booking is created; booking records in Bókun are governed by the tour operator's own retention obligations.
- Interrupted or abandoned checkout sessions expire automatically and carry no payment obligation.
When the tour operator uninstalls the integration, API access is revoked and the stored Bókun credentials are deleted from this Service, in line with Bókun’s API Terms of Use.
9. Your rights
Depending on your jurisdiction (including the GDPR for EU/EEA travellers and the Law of Georgia on Personal Data Protection), you may have the right to:
- Request access to the personal data held about your booking.
- Request correction of inaccurate data.
- Request erasure of your data where retention is not legally required.
- Object to or restrict certain processing.
- Lodge a complaint with your data protection authority.
Because Bókun is the system of record for bookings, some requests will be fulfilled jointly with the tour operator’s Bókun account. To exercise any right, contact the tour operator using the contact details published on the main booking website.
10. Changes to this policy
If the data practices of this Service change, this page will be updated and the revision date above will change. Material changes will be communicated through the main booking website where appropriate.
11. Contact
For privacy questions or requests relating to a booking, contact the tour operator through the contact details published on the main booking website. For platform-level data concerns, you may also contact Bókun or Bank of Georgia under their respective privacy policies.