Last updated: 20 July 2026
This Privacy Policy explains what personal data NativeTravel (operated by Global Light Group LLP, BIN 231140022152, Kazakhstan) ("we", "us") collects, why we collect it, and the rights you have over it. It applies to our website, mobile apps, and API. We act as the data controller for the personal data described below.
Account data you provide at sign-up (email, username, display name, password — stored only as a bcrypt hash). Content you create (listings, bookings, orders, reviews, messages). Approximate location when you use map and search features. Images you upload. Messages you send to the AI assistant. Basic technical and usage data needed to operate and secure the service.
To provide the service and the account and transactions you request (performance of a contract, GDPR Art. 6(1)(b)); to keep the platform secure and prevent abuse (legitimate interests, Art. 6(1)(f)); and, where required, with your consent (Art. 6(1)(a)), which you can withdraw at any time.
We use a small set of vetted subprocessors strictly to run the service: Cloudinary (image hosting), Mapbox (maps and geocoding), and — only when AI features are enabled — Anthropic and OpenAI (assistant and search). Each processes data on our instructions under a data-processing agreement. We do not sell your personal data and do not use third-party advertising trackers.
Some processors are located outside the EEA. Where that is the case, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses (GDPR Art. 46).
We keep account and content data for as long as your account is active. Where records must be kept for legal or accounting reasons (for example transaction history), we retain them only for the period required and then delete or anonymise them.
If you are in the EEA/UK you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data (GDPR Art. 15–21). You can exercise most of these from your account settings; for erasure or export requests that cannot be completed automatically, contact us and we will respond within one month. You may also lodge a complaint with your supervisory authority.
We use only strictly-necessary cookies — chiefly the authentication cookie that keeps you signed in. We do not set advertising or cross-site tracking cookies.
Data is encrypted in transit (HTTPS), passwords are hashed with bcrypt, and access is scoped per tenant and role. No method of transmission or storage is perfectly secure, but we take reasonable measures appropriate to the risk (GDPR Art. 32).
Besides those named above we use: Resend (transactional email, US), Stripe and Kaspi (payment processing; we never store card numbers — only the provider’s payment reference), Expo (push delivery) and Vultr (server hosting, Frankfurt, EU).
Account data — until you delete the account. Page-view statistics — 400 days; search impressions — 180 days; speed metrics — 90 days; AI-assistant conversations — 180 days after the last message; translation cache — 365 days; business-ownership evidence documents — 90 days after the claim decision. Expired sign-in sessions are removed automatically.
The personal-data operator is Global Light Group LLP (BIN 231140022152). Our servers are located in Germany (EU): by creating an account you consent to the collection, processing and cross-border transfer of your personal data under Art. 16 of the Kazakhstan Law “On Personal Data and Their Protection” No. 94-V. You may withdraw consent by deleting your account or contacting us.
For any privacy request or question, contact us at roorsayan@gmail.com. This is a v1 policy for a limited launch and will be updated as the service grows.