Privacy policy

Home / Privacy policy

Privacy Policy for Batumi Tourist Card

Effective Date: September 8, 2026
Last Updated: September 8, 2026

This Privacy Policy explains how NNLE Tourism Product Development Agency (the “Agency,” “we,” “us,” or “our”) processes information in connection with Batumi Tourist Card (the “App”), including its iOS, Android, and web versions.

The App provides public tourist information and Batumi Card discount information. It also includes restricted functions for authorized tourist information center operators and participating partner company employees, such as card activation, card verification, and visit registration.

1. Information We Process

1.1 Public use of the App

Public users can browse discounts, discount categories, place details, audio guides, and tourist information centers without creating an account or signing in.

When the App communicates with our servers, standard technical information may be processed to deliver content, maintain security, and diagnose service problems. This may include an IP address, device or browser type, operating system, request date and time, requested resource, and basic server logs. We do not use this information for advertising or cross-app tracking.

1.2 Information stored only on your device

The App may store the following information locally on your device or in your browser:

  • Language and appearance preferences;

  • Discounts you add to Favorites;

  • Itinerary dates, saved places, and their order;

  • Limited cached display information needed to show saved favorites and itinerary entries.

Favorites, itinerary information, and appearance or language preferences are not uploaded to our servers by the App and are not associated with an Agency account. You can remove individual favorites and itinerary entries in the App. You can remove all locally stored information by clearing the App’s data, clearing the website’s storage, or uninstalling the App.

1.3 Authorized staff accounts

Staff-only functions require an account issued or approved by the Agency or an authorized organization. For these functions, we process:

  • Login email address and password for authentication;

  • Staff profile, role, organization, and company or information-center association;

  • An authentication token or equivalent session information used to keep the staff member signed in.

The password is transmitted to our authentication service over an encrypted HTTPS connection and is not stored locally by the App. Limited staff profile and session information are stored locally on the device or browser so the authenticated session can be restored. This local session information is removed when the user signs out or clears the App’s data.

1.4 Cardholder information

When an authorized tourist information center operator activates or sells a Batumi Card, the operator may enter the cardholder’s:

  • First and last name;

  • Phone number;

  • Email address;

  • Country;

  • Associated Batumi Card identifier and card type.

This information is submitted to Agency systems to create and administer the cardholder record and provide the Batumi Card service.

1.5 Card sales and visit records

For card activation, sale administration, verification, and partner visit registration, we may process:

  • Card and QR identifiers;

  • Card type, validity dates, duration, and status;

  • Information center, operator, and participating partner company identifiers;

  • Sale date, selected payment method, and whether the card was sold online;

  • Visit location or participating company and visit date and time.

The App records only whether payment was made by cash or a card terminal. It does not collect or store payment-card numbers, security codes, or online banking credentials.

1.6 Camera and QR-code processing

The App requests camera access only when an authorized staff member opens the QR scanner and chooses to enable the camera. Camera access is used to recognize Batumi Card QR codes for card verification, activation, and visit registration.

The App does not take, record, store, or upload photographs or video. QR recognition occurs through the camera scanner, and only the decoded QR value is sent to our servers when needed to retrieve or update the corresponding card record. The App does not request microphone access for QR scanning.

You can deny or revoke camera access at any time through your device settings. Public browsing, favorites, itinerary planning, and tourist information-center listings remain available without camera access.

1.7 Communications and external services

The App may provide user-initiated links to websites, telephone, email, WhatsApp, or map services. When you choose one of these actions, the selected external service may receive information such as your IP address, device information, phone number, account information, or the destination you selected, according to that service’s own privacy policy.

The App does not automatically send your favorites or itinerary to those services.

2. How We Use Information

We process information as necessary to:

  • Provide public discount, place, audio-guide, and information-center content;

  • Save preferences, favorites, and itinerary information locally on the user’s device;

  • Authenticate authorized staff and apply role-based access;

  • Create and administer Batumi Card records;

  • Verify card validity and eligibility for participating discounts;

  • Register card sales and participating partner visits;

  • Provide support, investigate errors, prevent misuse, and protect the App and our systems;

  • Comply with applicable legal, accounting, regulatory, and public-authority requirements.

Where required by applicable law, our processing is based on performance of the requested service, our legitimate interests in operating and securing the Batumi Card program, compliance with legal obligations, and consent for access to protected device features such as the camera.

3. How We Disclose Information

We do not sell or rent personal information, and we do not share personal information for behavioral advertising or cross-app tracking.

Information may be disclosed only as necessary to:

  • Authorized Agency personnel and tourist information center operators who administer Batumi Cards;

  • Authorized employees of participating partner companies, where necessary to verify a card or register and review visits connected with that partner;

  • Service providers that host, maintain, secure, or support the App and our systems, subject to appropriate confidentiality, security, and data-protection obligations;

  • Government authorities, courts, regulators, or other parties when required by law or necessary to protect legal rights, safety, and system security.

External services that you open voluntarily, such as Google Maps, WhatsApp, your phone application, your email application, or a third-party business website, process information under their own terms and privacy policies.

4. Data Retention and Deletion

We retain information only for as long as reasonably necessary for the purposes described in this Policy:

  • Local preferences, favorites, and itinerary entries remain on the device or browser until the user removes them, clears local data, or uninstalls the App;

  • Locally stored staff session information remains until logout, session removal, clearing of App data, or uninstalling the App;

  • Staff account records are retained while the account remains authorized and afterward only as necessary for security, audit, dispute-resolution, and legal obligations;

  • Cardholder, card-sale, and visit records are retained as necessary to administer the Batumi Card program, verify transactions and visits, resolve disputes, and comply with applicable accounting, archival, and legal requirements;

  • Operational and security logs are retained only for the period reasonably necessary to maintain and protect the service.

When information is no longer required, we delete or anonymize it unless continued retention is required by law. A deletion request may not apply to records that we are legally required to retain. In that case, we will restrict the information to the required purpose and delete or anonymize it when the retention obligation ends.

To request access, correction, account deactivation, or deletion of server-side personal information, contact us using the details in Section 10. We may need to verify the requester’s identity and authority before acting on a request.

5. Your Choices and Rights

Depending on applicable law, you may have the right to request access to, correction of, deletion of, or restriction of your personal information; object to certain processing; receive a copy of information you provided; or withdraw consent where processing relies on consent.

Withdrawing consent does not affect processing already performed lawfully. Camera permission can be changed in device settings. Staff members may request account deactivation through their organization or by contacting the Agency. Public users do not need an Agency account to use the public features.

6. Data Security

We use reasonable administrative, technical, and organizational measures designed to protect personal information. These include encrypted HTTPS communications, authenticated access, and role-based restrictions for staff functions. Authentication credentials and tokens should not be shared with another person.

No electronic transmission or storage method is completely secure. If you believe an account, card, or personal record has been accessed improperly, please contact us promptly.

7. International Processing

The App may be used by visitors from different countries. Information may be processed in Georgia and in other locations where our contracted technology service providers operate. Where applicable, we use safeguards required by data-protection law for transfers of personal information.

8. Children’s Privacy

The public tourist-information features may be viewed by users of different ages, but the App is not designed to collect personal information directly from children. Staff-only functions are intended for authorized adult personnel.

If cardholder information relating to a minor is provided, it should be provided by, or with the authorization of, a parent or legal guardian where required by law. If you believe personal information relating to a child was provided without appropriate authorization, contact us so that we can review and, where appropriate, delete it.

9. Changes to This Privacy Policy

We may update this Privacy Policy when the App, our practices, or legal requirements change. We will publish the updated Policy, revise the “Last Updated” date, and provide any additional notice required by applicable law.

10. Contact Us

Questions, privacy requests, and complaints can be submitted to:

NNLE Tourism Product Development Agency
Website: https://infoajara.com
Email: agency@infoajara.com

Please include enough information for us to understand and respond to your request, but do not send passwords or complete payment-card details by email.

Tourism Product Development Agency

Tourism Product Development Agency is actively working on the development of tourism potential beyond the coastline, in the mountainous Adjara, which implies activities such as creating and improving rural tourist routes.


© 2015-2026 Tourism Product Development Agency