DerLeng FreeDerLengFree
Legal · Privacy Policy

Privacy Policy

What DerLeng Free collects, why we collect it, who we share it with, and the rights you have over it.

Last updated 4 September 2026 · v1.1
Operator
Derleng Free Travel LLC
Company ID
405880177
Incorporated in
Georgia
Registered address
Georgia, Tbilisi, Vake district, Vazha-Pshavela avenue, block II, building 1, entrance 1, floor 1
01

Who controls your data

Derleng Free Travel LLC — company identification number 405880177, registered at Georgia, Tbilisi, Vake district, Vazha-Pshavela avenue, block II, building 1, entrance 1, floor 1 — is the data controller for personal data collected through https://www.derlengfree.com. That means we decide what is collected and why, and we are the party you hold responsible for it.

For any privacy question or to exercise a right described on this page, write to chhaya@derlengfree.com. That is our single published address; there is no separate privacy mailbox.

Booking confirmations and vouchers are sent from bookings@derlengfree.com. Replies to that address reach the same team, so you can answer a confirmation email directly; chhaya@derlengfree.com remains the address for privacy requests and formal notices.

02

What we collect

Account data

Email address, password credentials (stored hashed — we never see your password), display name, and any profile or contact details you choose to add. If you sign in through a third-party provider, the identifier that provider returns to us.

Booking data

Search criteria and dates, the property and rate you select, occupancy, stay dates, the booking reference, and the status and history of the booking including any cancellation or refund.

For each booking we also store the details you give us for the lead guest at checkout: first name, last name, email address, phone number, country of residence, any special requests you add, and whether you told us the booking is for someone other than yourself.

Where you book for someone else, you are giving us another person’s personal data, and you confirm you have their permission to do so. We use it only to make and fulfil that booking.

Payment data

The amount, currency, method and status of each payment, and a reference issued by the payment processor or, on a local bank transfer, the short reference we asked you to quote.

We never receive your card number

DerLeng Free does not collect, receive, transmit or store card numbers, expiry dates or security codes — in any system, at any point. Where you pay by card, the card form is hosted by our accommodation supplier and your details are entered on that supplier’s own page. What reaches us is a payment reference and an outcome.

Where you use crypto rails, we hold the wallet address associated with your account, deposit and payout references, and on-chain transaction identifiers.

Cashback and wallet data

Your LENG and BOUN balances, the cashback credited against each booking, its pending or available state, conversions, redemptions and withdrawals.

Content you submit

Receipts, photographs, activity claims and supporting evidence you upload for verification, together with any message you send us.

Device and usage data

IP address, browser and device type, operating system, referring page, the pages you view, and the actions you take on them. Collected automatically when you use the site.

03

Why we process it, and on what legal basis

  • To provide the service — creating your account, taking payment, placing and managing your reservation, issuing confirmations and receipts, calculating and crediting cashback, processing withdrawals. Legal basis: performance of a contract with you.
  • To support you — answering questions, handling cancellations, refunds, complaints and disputes. Legal basis: performance of a contract, and our legitimate interest in running a service people can get help with.
  • To keep the platform honest — detecting fraud, abuse of cashback and referral mechanics, duplicate accounts, and payment risk. Legal basis: legitimate interest in protecting the platform and other users, and in some cases legal obligation.
  • To improve the product — analytics, heatmaps and session replay showing where the interface fails people. Legal basis: consent where required, otherwise legitimate interest.
  • To comply with the law — accounting, tax and financial-record obligations, and responding to lawful requests. Legal basis: legal obligation.
  • To send you messages — transactional messages about your bookings and wallet are part of the service. Marketing messages, where we send them, are sent on consent and every one carries an unsubscribe link. Unsubscribing from marketing does not stop booking confirmations.
04

Who we share it with

We do not sell your personal data. We share it with the accommodation provider you book — they need the guest name and stay details to hold your room — and with the service providers below, who process data on our instructions for the stated purpose and nothing else.

Supabase
Database, authentication and file storage
Shares Account data, bookings, wallet and cashback records, uploaded evidence
Vercel
Website hosting and content delivery
Shares Request metadata — IP address, user agent, requested URL, timestamps
Resend
Transactional email — booking confirmations and vouchers, sent from bookings@derlengfree.com
Shares Recipient email address, guest name, and the booking details printed in the message
LiteAPI / Nuitée
Accommodation supply — search, rates and reservations — and the hosted card payment page
Shares Search criteria, dates, occupancy, lead guest name, email and phone, the reservation itself, and the card details you enter on their page (which never pass through us)
Accommodation providers
Fulfilling your stay at properties we contract with directly
Shares Lead guest name, contact details, stay dates and any special requests — what the property needs to hold and honour your room
NOWPayments
Cryptocurrency payments for bookings and account top-ups
Shares Payment amount, currency, deposit reference and transaction status
Local bank / QR transfer
Manually confirmed bank and QR payments
Shares The payment reference you quote, matched against our bank records by a member of our team
Openfort
Wallet provider — creates and signs for the blockchain address on your account
Shares Account identifier and wallet address
Thirdweb
Blockchain reads and on-chain LENG/USDC transactions
Shares Wallet addresses, balances and transaction data — see the note on public ledgers
Telegram
Notifications to property operators and our own staff
Shares Booking reference, stay dates and the lead guest’s name and phone number, sent to the operator of the property you booked
Microsoft Clarity
Product analytics, heatmaps and session replay
Shares Pseudonymous interaction and device data. Page text is masked, and /admin, /operator and /claim are never recorded — see below
Anthropic
Automated verification of receipts and claims you upload
Shares The content you submit for verification — receipt images and claim text
Travelpayouts
Affiliate tracking on partner links you click
Shares Click event, the link clicked, and a sub-identifier for attribution
OpenStreetMap
The map embedded on a property page
Shares Loading the map sends your IP address and browser details to openstreetmap.org

We may also disclose data to professional advisers, to a successor in the event of a sale or reorganisation of the business, and to authorities where we are legally required to.

On-chain data is public and permanent

LENG and USDC transactions settle on a public blockchain. Wallet addresses, amounts and timestamps written there are visible to anyone and cannot be edited, retracted or erased by us or by anyone else— not on request, and not by a court order.

That is a property of the technology, not a choice in our policy. It is why the right to erasure described below cannot extend to on-chain records, and why you should treat a wallet address as permanently public once it has transacted.

05

Cookies, analytics and session replay

Cookies

We use cookies and similar browser storage that are strictly necessary to run the site — keeping you signed in, holding your session, remembering a search in progress, and security. These cannot be switched off without breaking the service.

We also use analytics storage, described below. You can clear or block cookies in your browser settings; blocking the necessary ones will prevent you from signing in or booking.

Microsoft Clarity

We use Microsoft Clarity to understand how the interface is actually used — which controls people reach for, where they get stuck, which steps they abandon. Clarity records interaction and device data, and can replay a reconstruction of a session: clicks, scrolls and navigation.

What session replay cannot see

This is a financial product, so recording is masked by default across the entire site, in code rather than in a dashboard setting. Page text is redacted before it leaves your browser, and values typed into form fields are never captured by Clarity in any configuration.

The administrative console, the operator console and property-claim links (/admin, /operator and /claim) are excluded from recording entirely. What we receive is a pseudonymous picture of behaviour — where a cursor went, what was clicked — not a readable copy of your balances, addresses or personal details.

Clarity data is processed by Microsoft as our processor. If you would rather not be included, blocking the Clarity script in your browser or using a tracker-blocking extension prevents collection, and the site continues to work normally.

Affiliate links

Some accommodation links take you to a partner site through a Travelpayouts tracking redirect, which records the click so a booking you make there can be attributed to us. Once you land on the partner’s site, that partner’s own privacy policy governs what it collects.

06

International transfers

We operate internationally and so do our processors. Your data may be transferred to, stored in, and processed in countries outside Georgia and outside your own country — including the United States and the European Union — where our hosting, database, analytics and payment providers operate infrastructure.

Where personal data protected by the GDPR or UK GDPR is transferred outside those areas, we rely on the European Commission’s Standard Contractual Clauses, on an adequacy decision where one applies, or on another lawful transfer mechanism, and we contract with our processors on terms requiring them to protect the data to that standard.

Booking with an accommodation provider necessarily transfers your guest details to the country where the property is located. That transfer is required to deliver the stay you asked for.

07

How long we keep it

We keep personal data only as long as we need it for the purpose it was collected, or as long as the law requires — whichever is longer.

  • Account data — while your account is open, and for up to 12 months after you close it, so that a late dispute or refund can be resolved.
  • Booking and payment records — retained for 7 years from the date of the transaction to meet accounting, tax and financial record-keeping obligations. This period is a legal requirement and a deletion request does not shorten it.
  • Cashback and wallet records — for as long as a balance or an unresolved entitlement exists, and then under the booking-record period above.
  • Submitted evidence — receipts and claim images are kept while the claim is open and for 24 months after it is decided, so a reversed or disputed decision can be reviewed.
  • Analytics and session replay — retained by Microsoft Clarity under its own retention schedule, currently up to 13 months.
  • Server and security logs — up to 12 months.
  • On-chain transactions — permanent, and outside anyone’s control. See the callout above.

When a retention period ends we delete the data or irreversibly anonymise it so it can no longer identify you.

08

Your rights, and how to use them

Depending on where you live, you have some or all of the following rights over your personal data:

  • Access — a copy of the personal data we hold about you, and an explanation of what we do with it.
  • Correction — to have inaccurate or incomplete data fixed. Much of this you can do yourself in your account settings.
  • Deletion — to have your data erased, subject to the retention periods above. We cannot delete records we are legally required to keep, and we cannot delete anything written to a public blockchain.
  • Portability — to receive the data you gave us in a structured, machine-readable format, or to have it sent to another provider where technically feasible.
  • Objection — to object to processing we carry out on the basis of legitimate interest, including profiling for fraud detection, and to object to direct marketing at any time.
  • Restriction — to have processing paused while an accuracy or objection question is being resolved.
  • Withdraw consent — where processing rests on consent, you can withdraw it at any time. That does not affect processing already carried out.

How to exercise them

Email chhaya@derlengfree.com from the address on your account and say which right you are using. We may need to verify your identity before acting, so that nobody can obtain or delete your data by pretending to be you.

We respond within 30 days. There is no charge, unless a request is manifestly unfounded or repetitive. If you are unhappy with our response you have the right to complain to your local data protection authority, and we would ask that you tell us first so we can try to put it right.

09

How we protect it

Data is encrypted in transit. Access to production data is restricted to the people who need it, database access is governed by row-level security so an account can only reach its own records, and administrative consoles are separately gated and excluded from session recording.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant authority as the law requires. Keep your account credentials to yourself and tell us at chhaya@derlengfree.com if you suspect unauthorised access.

10

Children

DerLeng Free is not directed at children. You must be 18 or older to hold an account, and we do not knowingly collect personal data from anyone under 18.

Children’s names may appear in a booking as accompanying guests. That information is provided by the adult making the booking, is used only to hold the reservation, and is shared only with the accommodation provider.

If you believe a child has given us personal data, write to chhaya@derlengfree.com and we will delete it.

11

Changes to this policy

We update this policy when what we do with data changes — a new processor, a new feature, a change in the law. The current version and its effective date are always published at https://www.derlengfree.com/privacy.

Where a change materially affects how we use data you have already given us, we will make reasonable efforts to notify account holders directly rather than relying on this page alone.

Questions about this page

Write to chhaya@derlengfree.com and we will respond to the address on your account. Postal notices go to Derleng Free Travel LLC, Georgia, Tbilisi, Vake district, Vazha-Pshavela avenue, block II, building 1, entrance 1, floor 1.

Last updated 4 September 2026 · v1.1