BOARDIGO
Privacy Notice
Last updated: September 2026
Boardigo is operated by Muhammet İbrahim Özsağlam. This notice explains how Boardigo processes personal information when you use the website, mobile application and reservation wallet.
Information we process
We process the account information you provide, reservation details, uploaded ticket or booking documents, reminder preferences, device information needed for notifications, support correspondence and security activity. Boardigo does not store payment-card numbers.
Why we process it
Information is used to provide and synchronise your reservation wallet, display original documents, deliver reminders, open provider check-in pages, protect accounts, respond to support requests and comply with applicable legal obligations.
Optional anonymous document learning
If you expressly enable this setting in the application, Boardigo may receive only a public provider fingerprint, fixed layout labels such as Departure, Arrival, Date or Booking reference, and value-free relative layout information describing where a value normally appears around a label. The ticket or PDF, OCR text, example value, passenger name, booking code, route, date and time are not sent as learning data. A contribution is stored under a server-keyed pseudonymous hash and a layout is shared with other users only after at least five independent accounts confirm the same structure. Ten different contributions that are subsequently approved may activate a one-time, one-month Premium community reward. The reward is recorded on the account, while the learning votes remain pseudonymous. You can disable the setting at any time; pending contributions and your server-side vote are then withdrawn.
Service providers and transfers
Hosting, e-mail delivery, app-store, notification and optional Google or Apple sign-in providers may process limited information on our behalf. They receive only what is needed for their service. Boardigo does not sell personal information. Processing may occur outside your country subject to applicable contractual and legal safeguards.
Security
Connections use HTTPS. Passwords are one-way hashed, access sessions expire, sensitive configuration is encrypted, documents require an authenticated owner and administrative access requires two-factor authentication. No internet service can guarantee absolute security.
Retention
Active account content is kept while the account is in use. After a confirmed account-deletion request, access is disabled immediately and personal account content is scheduled for deletion within 30 days. Expired authentication records are routinely removed, security logs are normally retained for up to 180 days and protected backups for up to 30 days unless a longer period is legally required.
Your choices
You may correct profile or reservation information, delete individual reservations, download a copy of your Boardigo data and request complete account deletion. Depending on your location, additional access, correction, objection or restriction rights may apply.
Contact
Privacy enquiries and rights requests can be sent to privacy@boardigo.app. General product support is available at boardigo.app/support.