Privacy Policy
Last updated: October 1, 2026
1. Who We Are
Atlas Suite is currently operated by SÖR Turizm San. Tic. Ltd. Şti. ("we", "us", "our"). We operate the hospitality management platform at atlassuite.app. We provide hotel property management, revenue management, CRM, and distribution services to hotel operators ("Customers").
Contact: [email protected]
2. Data We Collect
Account Data
When you create an Atlas Suite account: name, email address, phone number, hotel property details, and billing information.
Operational Data
Data processed on behalf of our Customers includes guest reservations, room availability, pricing, housekeeping tasks and financial transactions. The hotel determines the purposes of processing its guest records; Atlas Suite processes those records on the hotel's instructions. Our operator is responsible for the processing it determines for Atlas account administration, billing and service security. A guest's request concerning hotel records may also require the hotel's involvement.
Analytics Data
Depending on consent and enabled features, website measurement can include page views, click events, session and browser-reported measurement identifiers, browser/device information, referrer and campaign parameters, consent decisions, advertising click identifiers and booking values. Advertising identifiers can include gclid, gbraid, wbraid, msclkid, fbclid, ttclid and fbp. Google Analytics and Atlas measurement have separate records; these identifiers are not anonymous merely because they are pseudonymous. Hosting services may also process network information such as IP addresses for service delivery and security.
Cookies
We use essential cookies for authentication. Optional analytics and advertising cookies or identifiers depend on the features enabled for the site and your applicable consent preferences. Advertising measurement and audience matching are separate from necessary cookies.
Optional Google Connections
A hotel operator can choose to connect a Google account through Google's authorization screen. Depending on the enabled integration and the permissions granted, Atlas Suite processes the connected account's email address, granted permissions, account and resource identifiers, and authorization credentials needed to access the selected Google services. These connections are optional; connecting an account does not by itself enable every integration.
3. How We Use Your Data
- Providing and maintaining the Atlas Suite platform
- Processing hotel reservations and guest communications
- Generating analytics and revenue management recommendations
- Sending transactional emails (booking confirmations, invoices)
- Improving the services selected by the Customer through permitted analytics; aggregation alone does not establish anonymity
- Complying with legal obligations
4. Data Sharing
We do not sell personal data. Recipients depend on the service and integrations enabled by the Customer, including:
- Sub-processors: Cloudflare (hosting, CDN), Supabase (database), Resend (transactional email), Google (analytics)
- Customer-selected integrations: Where enabled for the hotel, providers such as Meta (advertising measurement or audience matching), Channex (distribution), and EDM or BIEN (electronic fiscal documents) receive the information needed for that integration. The hotel's selected payment provider processes applicable payment information.
- Optional AI assistance: When an authorized operator requests RMS AI assistance, the hotel's configured provider, OpenAI or Anthropic, receives the current question and the minimized operational context needed for pricing and occupancy analysis. Calendar free-text titles, creator/organizer email addresses and previous conversation history are excluded from the automatic context. An operator should not enter guest or other personal information in a question. Provider processing terms depend on the selected account and configuration.
- Legal requirements: When required by law or valid legal process
5. Data Transfers
Hosting and selected integrations may involve processing outside your jurisdiction, including in Turkey, the European Union and the United States. The destination and applicable transfer arrangements depend on the provider, service configuration and hotel. This policy does not establish a transfer mechanism by itself. Contact us for the recipient and transfer information applicable to your service.
6. Your Rights
Under KVKK (Turkish Data Protection Law)
Where KVKK applies, data subjects can request information about processing and its purpose, recipients and transfers; correction of incomplete or inaccurate records; erasure or destruction under the legal conditions; and notification of these corrections or deletions to recipients. They can object to adverse results based solely on automated analysis and seek compensation for damage caused by unlawful processing. These rights are not limited to Turkish citizens. See Article 11 of Law No. 6698.
Where GDPR Applies
Subject to the law's conditions, rights include access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent.
To exercise these rights, contact us at [email protected].
7. Data Retention
We retain account and operational data for the purposes described in this policy, according to the Customer's instructions and applicable retention obligations. Closing an account or disconnecting an integration does not itself erase financial records, legally required records or imported operational data. Deletion requests are reviewed separately.
Retention differs by record type and service. Atlas website-event records and data held in Google Analytics have separate retention settings and deletion processes. There is no single automatic deletion period that applies to all analytics records. Contact us to request information about the retention and deletion applicable to your account or hotel's records.
8. Children's Data
Atlas Suite accounts and administration tools are intended for hotel operators, not children. Hotels may process records concerning children who are guests, where necessary for reservations and legal obligations. These operational records follow the hotel's instructions and applicable protections; they are separate from registering a child for an Atlas account.
9. Security
We use access controls and tenant-scoped permissions to restrict access to hotel records. Google connections are operated on the server; the public website does not display authorization credentials. Specific security controls depend on the integration and service provider.
10. Changes
We may update this policy as our services and data processing change. The published policy will identify its effective revision date. Where applicable law requires notice or renewed consent, the update must include that process.
11. Google API User Data
What We Access and Why
- Google account email: We identify and display the account connected by the hotel operator. We do not request access to the account's email messages.
- Google Calendar: With read permissions, we list available calendars so the operator can choose which to synchronize. We read events from the selected calendars and import event details, such as titles, dates, event and source identifiers, and links, for the hotel's calendar and demand planning. These permissions do not allow Atlas Suite to create, edit or delete events in Google Calendar.
- Google Ads: We access the connected account's advertising accounts and conversion-action information to let an authorized operator choose the hotel's destination. Where the hotel enables conversion delivery, Atlas Suite submits relevant booking or lead identifiers, attribution identifiers, values, currency and occurrence times, and applicable conversion-value adjustments. This helps the hotel measure advertising outcomes. Granting the Google Ads permission does not itself start a campaign or authorize a new advertising budget.
- Google Data Manager: Where the hotel enables eligible audience synchronization, Atlas Suite submits the hotel's first-party audience identifiers and required consent and destination information to the selected Google marketing destination. Supported contact identifiers are hashed for matching; hashing does not make them anonymous. Guest consent and audience eligibility are separate from the operator's authorization of the Google connection.
- Google Analytics: Where GA4 reporting is available and separately authorized, read permission allows Atlas Suite to read the selected property's booking reports, including purchase and refund event counts, values, tax and transaction identifiers, to compare website booking outcomes with the hotel's records. We also read property and web-stream metadata, including currency, time zone, stream ID and measurement ID, to check that reports match the hotel's selected website and currency. This permission does not allow Atlas Suite to change the property's configuration or send measurement events. Any event-delivery feature requires a separate configuration.
Use, Sharing and Limited Use
We use Google API information to provide the integrations selected by the hotel operator. Google Calendar content and the connected account's profile information are not a source of guest advertising audiences. Audience synchronization uses the hotel's separately authorized first-party records. Calendar titles and person/account metadata are excluded from automatic RMS AI context; the AI feature uses minimized operational context and the operator's current question, not a replay of previous conversations.
We do not sell Google user data or use it to train general-purpose AI models. We limit its transfer to what is necessary to provide the requested integration with the user's consent, security or applicable legal obligations. Any human access must be limited to specific data the user explicitly permits us to view for support, necessary security investigations, legal requirements or permitted aggregated internal operations. Our hosting and database service providers process information needed to run the service; Google receives the information submitted to the Google integration chosen by the operator.
Atlas Suite's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Access Controls and Retention
Google authorization credentials are used by server-side integrations and are not displayed in public website content. Access to a hotel's imported records is limited to its authorized users and permitted service processing. Imported records follow the applicable retention described above; stopping a connection does not automatically erase previously imported operational or financial records.
Disconnecting and Requesting Deletion
An authorized operator can disconnect Google Marketing in Atlas Core's integration settings, or disconnect Google Calendar in its connection settings. This disables that Atlas connection and removes its active local credentials. Google Marketing also attempts to revoke its Google authorization; if remote revocation cannot be confirmed, the operator can remove access directly in the Google Account connections page. Google Calendar's local disconnect is separate from removing access in Google Account.
Revoking Google access stops future access under that authorization. It does not itself delete existing records in Atlas or previously submitted data in Google advertising destinations. To request deletion of retained Google-derived records, contact [email protected] and identify the connected account and hotel. We will assess the request, the hotel's instructions and applicable retention obligations. Do not include passwords or access tokens in your request.