1. Who we are
Trasst Global (“Trasst”, “we”, “us”) provides technology that hotels and hospitality partners use to operate captive-portal Wi-Fi login, guest messaging, and related travel experience features (including product discovery on the portal).
Website: www.trasst.com
Privacy contact: [email protected]
2. Scope of this Policy
This Policy covers personal data processed in connection with:
- Hotel Wi-Fi / hotspot captive-portal login pages operated with Trasst technology;
- Transactional service messages confirming Wi-Fi access or first registration;
- Optional marketing emails, only where you give explicit opt-in consent;
- Optional WhatsApp / phone-based login flows configured by the hotel;
- Limited product-interaction analytics on the portal (for example, product card views or booking clicks), used to improve the service;
- The public Trasst website pages that link to this Policy (including
/privacy).
It does not replace hotel-specific terms, PMS/reservation policies, or third-party product providers’ own privacy notices (for example eSIM or ticket vendors) that you may encounter after leaving the portal.
3. Controllers, processors and joint roles
3.1 Hotel (network operator)
The hotel (or hospitality group) that provides the Wi-Fi SSID generally determines the purposes of granting network access and may act as a data controller (or equivalent under KVKK) for guest connectivity records necessary to operate the network and comply with local rules.
3.2 Trasst (platform provider)
Trasst processes data to operate the identification / portal platform, deliver service messages, and—only with your opt-in—send marketing communications. Depending on the hotel contract and the processing activity, Trasst may act as a processor (on the hotel’s documented instructions) and/or as an independent controller for platform security, abuse prevention, service improvement analytics, and Trasst-originated marketing where consent is collected for Trasst.
3.3 Processors and tools
We use carefully selected service providers (for example email delivery platforms such as Mailjet, hosting, and network authentication components such as RADIUS-related systems) under contracts that require appropriate confidentiality and security measures.
4. Personal data we may process
Depending on the login method enabled for your hotel, we may process:
| Category | Examples |
|---|---|
| Identity / contact | Email address; phone number (including country code); optionally room number if requested by the hotel flow |
| Authentication & network | Portal session identifiers; interface / hotel identifiers; device-related technical identifiers used for Wi-Fi session management (as configured by the network) |
| Communications | Transactional email / WhatsApp delivery status; marketing preference (opt-in / opt-out) |
| Usage / product analytics | Aggregated or event-level portal interactions (for example product modal opens, booking clicks) tied to hotel/context identifiers |
| Technical logs | Timestamps, error/diagnostic logs, approximate request metadata needed to secure and operate the service |
We do not require government ID numbers or payment card data on the Wi-Fi login form described in this Policy.
5. Purposes and legal bases
| Purpose | Typical legal basis |
|---|---|
| Authenticate you and grant hotel Wi-Fi access | Performance of a service request / contract-like steps at your request; legitimate interests in operating secure guest Wi-Fi; KVKK Art. 5 equivalents where applicable |
| Send transactional service messages (access / registration confirmation) | Necessary for the requested service; legitimate interests in informing you about access status |
| Optional marketing emails (hotel offers, Istanbul experiences, Trasst updates) | Consent — only if you actively tick the opt-in checkbox (never pre-ticked) |
| Security, fraud/abuse prevention, troubleshooting | Legitimate interests; legal obligations where applicable |
| Service improvement and portal product analytics | Legitimate interests in understanding feature usage in an operational hospitality context |
| Compliance with enforceable legal requests | Legal obligation |
6. Marketing communications (opt-in only)
- Marketing/promotional emails are sent only if you actively opt in on the login form.
- The marketing checkbox is never pre-selected.
- You may withdraw consent at any time via the unsubscribe link in marketing messages or by emailing [email protected].
- Withdrawal does not affect the lawfulness of processing before withdrawal, and does not by itself disconnect your Wi-Fi session.
- We do not buy or rent email lists for this captive-portal service, and we do not treat Wi-Fi login alone as marketing consent.
7. Sharing of personal data
We may share personal data only as needed for the purposes above:
- With the hotel / hospitality partner operating the network you joined;
- With processors such as email delivery providers (e.g. Mailjet), infrastructure/hosting providers, and authentication-related systems;
- With professional advisers or authorities where required by law or to protect rights, safety, and security;
- In a business transfer (merger, acquisition, restructuring), subject to appropriate safeguards.
We do not sell personal data.
8. International transfers
Some processors may process data in countries outside Türkiye and/or the EEA/UK. Where required, we rely on appropriate transfer mechanisms (such as contractual safeguards / standard contractual clauses or equivalent protections) and require recipients to protect the data appropriately.
9. Retention
We keep personal data only as long as needed for the purposes described, including:
- Wi-Fi authentication / session-related records: for the operational period required by the hotel network and platform security, then deleted or anonymised according to retention schedules;
- Transactional communication logs: for a limited period needed for delivery confirmation, support, and abuse prevention;
- Marketing contact details & consent records: until you unsubscribe / withdraw consent, or the list is otherwise closed, plus a short period thereafter to evidence compliance;
- Analytics events: retained in identifiable or hotel-linked form only as long as useful for reporting, then aggregated or deleted.
Where a longer retention is required by law (for example to respond to legal claims), we limit access and use accordingly.
10. Security measures
We apply technical and organisational measures appropriate to the risk, including access controls, encrypted transport (HTTPS) where configured, least-privilege administration, logging, and vendor due diligence. No method of transmission or storage is completely secure; we work continuously to reduce residual risk.
11. Your rights
Subject to applicable law (including KVKK and, where relevant, GDPR), you may have the right to:
- Request access to your personal data;
- Request rectification of inaccurate data;
- Request deletion (“right to be forgotten”) in certain circumstances;
- Request restriction of processing;
- Object to processing based on legitimate interests;
- Withdraw consent (for marketing) at any time;
- Data portability, where technically applicable;
- Lodge a complaint with a supervisory authority.
In Türkiye, the supervisory authority is the Personal Data Protection Authority (KVKK) (www.kvkk.gov.tr. EU/EEA guests may contact their local data protection authority; UK guests may contact the ICO.
To exercise rights relating to this portal, email [email protected] with enough detail for us to identify the hotel stay / login context. We may need to verify your identity before responding.
12. Cookies and similar technologies
The captive portal and website may use strictly necessary technical storage (for example language preference, session continuity, or security tokens). We do not use the Wi-Fi login page as an advertising tracking surface. If non-essential analytics cookies are introduced on marketing pages in the future, we will update this Policy and, where required, present a consent mechanism.
13. Children
The Wi-Fi login service is intended for hotel guests and is not directed at children. If you believe a child’s data was submitted inappropriately, contact us and we will take reasonable steps to delete it where required.
14. Changes to this Policy
We may update this Policy to reflect legal, technical, or operational changes. The “last updated” date at the top will change when we do. Material changes affecting marketing consent practices will be reflected on the login form and this page.
15. Contact
Privacy requests & questions:
[email protected]
Web: www.trasst.com