Privacy Policy
What DerLeng Free collects, why we collect it, who we share it with, and the rights you have over it.
Who controls your data
Derleng Free Travel LLC — company identification number 405880177, registered at Georgia, Tbilisi, Vake district, Vazha-Pshavela avenue, block II, building 1, entrance 1, floor 1 — is the data controller for personal data collected through https://www.derlengfree.com. That means we decide what is collected and why, and we are the party you hold responsible for it.
For any privacy question or to exercise a right described on this page, write to chhaya@derlengfree.com. That is our single published address; there is no separate privacy mailbox.
Booking confirmations and vouchers are sent from bookings@derlengfree.com. Replies to that address reach the same team, so you can answer a confirmation email directly; chhaya@derlengfree.com remains the address for privacy requests and formal notices.
What we collect
Account data
Email address, password credentials (stored hashed — we never see your password), display name, and any profile or contact details you choose to add. If you sign in through a third-party provider, the identifier that provider returns to us.
Booking data
Search criteria and dates, the property and rate you select, occupancy, stay dates, the booking reference, and the status and history of the booking including any cancellation or refund.
For each booking we also store the details you give us for the lead guest at checkout: first name, last name, email address, phone number, country of residence, any special requests you add, and whether you told us the booking is for someone other than yourself.
Where you book for someone else, you are giving us another person’s personal data, and you confirm you have their permission to do so. We use it only to make and fulfil that booking.
Payment data
The amount, currency, method and status of each payment, and a reference issued by the payment processor or, on a local bank transfer, the short reference we asked you to quote.
DerLeng Free does not collect, receive, transmit or store card numbers, expiry dates or security codes — in any system, at any point. Where you pay by card, the card form is hosted by our accommodation supplier and your details are entered on that supplier’s own page. What reaches us is a payment reference and an outcome.
Where you use crypto rails, we hold the wallet address associated with your account, deposit and payout references, and on-chain transaction identifiers.
Cashback and wallet data
Your LENG and BOUN balances, the cashback credited against each booking, its pending or available state, conversions, redemptions and withdrawals.
Content you submit
Receipts, photographs, activity claims and supporting evidence you upload for verification, together with any message you send us.
Device and usage data
IP address, browser and device type, operating system, referring page, the pages you view, and the actions you take on them. Collected automatically when you use the site.
Why we process it, and on what legal basis
- To provide the service — creating your account, taking payment, placing and managing your reservation, issuing confirmations and receipts, calculating and crediting cashback, processing withdrawals. Legal basis: performance of a contract with you.
- To support you — answering questions, handling cancellations, refunds, complaints and disputes. Legal basis: performance of a contract, and our legitimate interest in running a service people can get help with.
- To keep the platform honest — detecting fraud, abuse of cashback and referral mechanics, duplicate accounts, and payment risk. Legal basis: legitimate interest in protecting the platform and other users, and in some cases legal obligation.
- To improve the product — analytics, heatmaps and session replay showing where the interface fails people. Legal basis: consent where required, otherwise legitimate interest.
- To comply with the law — accounting, tax and financial-record obligations, and responding to lawful requests. Legal basis: legal obligation.
- To send you messages — transactional messages about your bookings and wallet are part of the service. Marketing messages, where we send them, are sent on consent and every one carries an unsubscribe link. Unsubscribing from marketing does not stop booking confirmations.
Who we share it with
We do not sell your personal data. We share it with the accommodation provider you book — they need the guest name and stay details to hold your room — and with the service providers below, who process data on our instructions for the stated purpose and nothing else.
| Processor | Purpose | What we share |
|---|---|---|
| Supabase | Database, authentication and file storage | Account data, bookings, wallet and cashback records, uploaded evidence |
| Vercel | Website hosting and content delivery | Request metadata — IP address, user agent, requested URL, timestamps |
| Resend | Transactional email — booking confirmations and vouchers, sent from bookings@derlengfree.com | Recipient email address, guest name, and the booking details printed in the message |
| LiteAPI / Nuitée | Accommodation supply — search, rates and reservations — and the hosted card payment page | Search criteria, dates, occupancy, lead guest name, email and phone, the reservation itself, and the card details you enter on their page (which never pass through us) |
| Accommodation providers | Fulfilling your stay at properties we contract with directly | Lead guest name, contact details, stay dates and any special requests — what the property needs to hold and honour your room |
| NOWPayments | Cryptocurrency payments for bookings and account top-ups | Payment amount, currency, deposit reference and transaction status |
| Local bank / QR transfer | Manually confirmed bank and QR payments | The payment reference you quote, matched against our bank records by a member of our team |
| Openfort | Wallet provider — creates and signs for the blockchain address on your account | Account identifier and wallet address |
| Thirdweb | Blockchain reads and on-chain LENG/USDC transactions | Wallet addresses, balances and transaction data — see the note on public ledgers |
| Telegram | Notifications to property operators and our own staff | Booking reference, stay dates and the lead guest’s name and phone number, sent to the operator of the property you booked |
| Microsoft Clarity | Product analytics, heatmaps and session replay | Pseudonymous interaction and device data. Page text is masked, and /admin, /operator and /claim are never recorded — see below |
| Anthropic | Automated verification of receipts and claims you upload | The content you submit for verification — receipt images and claim text |
| Travelpayouts | Affiliate tracking on partner links you click | Click event, the link clicked, and a sub-identifier for attribution |
| OpenStreetMap | The map embedded on a property page | Loading the map sends your IP address and browser details to openstreetmap.org |
We may also disclose data to professional advisers, to a successor in the event of a sale or reorganisation of the business, and to authorities where we are legally required to.
LENG and USDC transactions settle on a public blockchain. Wallet addresses, amounts and timestamps written there are visible to anyone and cannot be edited, retracted or erased by us or by anyone else— not on request, and not by a court order.
That is a property of the technology, not a choice in our policy. It is why the right to erasure described below cannot extend to on-chain records, and why you should treat a wallet address as permanently public once it has transacted.
International transfers
We operate internationally and so do our processors. Your data may be transferred to, stored in, and processed in countries outside Georgia and outside your own country — including the United States and the European Union — where our hosting, database, analytics and payment providers operate infrastructure.
Where personal data protected by the GDPR or UK GDPR is transferred outside those areas, we rely on the European Commission’s Standard Contractual Clauses, on an adequacy decision where one applies, or on another lawful transfer mechanism, and we contract with our processors on terms requiring them to protect the data to that standard.
Booking with an accommodation provider necessarily transfers your guest details to the country where the property is located. That transfer is required to deliver the stay you asked for.
How long we keep it
We keep personal data only as long as we need it for the purpose it was collected, or as long as the law requires — whichever is longer.
- Account data — while your account is open, and for up to 12 months after you close it, so that a late dispute or refund can be resolved.
- Booking and payment records — retained for 7 years from the date of the transaction to meet accounting, tax and financial record-keeping obligations. This period is a legal requirement and a deletion request does not shorten it.
- Cashback and wallet records — for as long as a balance or an unresolved entitlement exists, and then under the booking-record period above.
- Submitted evidence — receipts and claim images are kept while the claim is open and for 24 months after it is decided, so a reversed or disputed decision can be reviewed.
- Analytics and session replay — retained by Microsoft Clarity under its own retention schedule, currently up to 13 months.
- Server and security logs — up to 12 months.
- On-chain transactions — permanent, and outside anyone’s control. See the callout above.
When a retention period ends we delete the data or irreversibly anonymise it so it can no longer identify you.
Your rights, and how to use them
Depending on where you live, you have some or all of the following rights over your personal data:
- Access — a copy of the personal data we hold about you, and an explanation of what we do with it.
- Correction — to have inaccurate or incomplete data fixed. Much of this you can do yourself in your account settings.
- Deletion — to have your data erased, subject to the retention periods above. We cannot delete records we are legally required to keep, and we cannot delete anything written to a public blockchain.
- Portability — to receive the data you gave us in a structured, machine-readable format, or to have it sent to another provider where technically feasible.
- Objection — to object to processing we carry out on the basis of legitimate interest, including profiling for fraud detection, and to object to direct marketing at any time.
- Restriction — to have processing paused while an accuracy or objection question is being resolved.
- Withdraw consent — where processing rests on consent, you can withdraw it at any time. That does not affect processing already carried out.
How to exercise them
Email chhaya@derlengfree.com from the address on your account and say which right you are using. We may need to verify your identity before acting, so that nobody can obtain or delete your data by pretending to be you.
We respond within 30 days. There is no charge, unless a request is manifestly unfounded or repetitive. If you are unhappy with our response you have the right to complain to your local data protection authority, and we would ask that you tell us first so we can try to put it right.
How we protect it
Data is encrypted in transit. Access to production data is restricted to the people who need it, database access is governed by row-level security so an account can only reach its own records, and administrative consoles are separately gated and excluded from session recording.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant authority as the law requires. Keep your account credentials to yourself and tell us at chhaya@derlengfree.com if you suspect unauthorised access.
Children
DerLeng Free is not directed at children. You must be 18 or older to hold an account, and we do not knowingly collect personal data from anyone under 18.
Children’s names may appear in a booking as accompanying guests. That information is provided by the adult making the booking, is used only to hold the reservation, and is shared only with the accommodation provider.
If you believe a child has given us personal data, write to chhaya@derlengfree.com and we will delete it.
Changes to this policy
We update this policy when what we do with data changes — a new processor, a new feature, a change in the law. The current version and its effective date are always published at https://www.derlengfree.com/privacy.
Where a change materially affects how we use data you have already given us, we will make reasonable efforts to notify account holders directly rather than relying on this page alone.
Questions about this page
Write to chhaya@derlengfree.com and we will respond to the address on your account. Postal notices go to Derleng Free Travel LLC, Georgia, Tbilisi, Vake district, Vazha-Pshavela avenue, block II, building 1, entrance 1, floor 1.