Payment and Security Policy
This Policy explains the card and bank-transfer payment methods available through Sativa Tour & Travel, together with payment confirmation, security and refund procedures.
1. Accepted payment methods
Card payment through iyzico
Credit and debit card payments are processed online through the secure payment infrastructure provided by iyzico.
Bank transfer
Payment must be sent only to the Company bank account identified below.
2. Card payments through iyzico
Card payments are processed through the iyzico infrastructure provided by İyzi Ödeme ve Elektronik Para Hizmetleri A.Ş.
- Card information is transmitted to the payment infrastructure over a secure connection.
- The transaction may be redirected to 3D Secure verification depending on the bank or security assessment.
- The payment result is returned to the Company’s reservation system.
- Raw card numbers, card passwords and CVV/CVC codes are not stored in the Sativa reservation database.
Where 3D Secure is used, the single-use verification credential is delivered by the cardholder’s bank through its registered communication channel.
3. Bank-transfer details
- Verify that the recipient name matches the Company’s full legal name.
- Enter the reservation number and booking holder’s name in the payment description.
- A payment notification does not by itself confirm receipt of funds.
- The reservation is confirmed after the payment reaches the Company account and is verified.
4. Bank-transfer verification
A receipt or payment notification is not final proof that payment has been received. The Company verifies:
- That the funds have reached the Company account;
- That the sender and reservation details correspond;
- That the amount matches the reservation balance.
Altered or fraudulent receipts do not result in booking confirmation and may be reported to competent authorities.
5. Prices and additional charges
- The total price, including taxes and approved extras, is displayed before payment.
- Website prices are stated in Turkish lira unless expressly indicated otherwise.
- No undisclosed or unapproved additional charge is collected.
- Available instalments, if any, are displayed on the payment screen and depend on the card, bank, iyzico and transaction conditions.
- Customers must check the total amount and payment plan before confirmation.
Interest, cash-advance, late-payment, currency-conversion or similar retail banking charges imposed by a customer’s own bank are not determined by the Company.
6. Security approach
Encrypted connection
Website traffic is transmitted through an HTTPS/TLS connection.
Access controls
Access to payment and booking records is restricted according to role and operational need.
Transaction records
Payment outcomes, times, reservation references and status changes may be recorded.
Server-side verification
Payment amounts are checked against server-side booking records.
Limited card data
Raw card numbers, card passwords and CVV/CVC codes are not stored by Sativa.
Fraud controls
Additional verification may be requested for inconsistent or potentially unauthorised transactions.
7. Customer security responsibilities
- Use only the https://sativa.com.tr domain and a secure connection;
- Verify the IBAN and legal account-holder name before transfer;
- Do not save payment details on shared or untrusted devices;
- Never share 3D Secure codes or banking passwords;
- Check the reservation number and amount before payment;
- Report suspicious links, accounts or alternative IBAN requests;
- Review bank and reservation records after payment.
8. Failed, interrupted or duplicate transactions
If an error occurs or the connection is interrupted, customers should check their bank activity, payment notifications, reservation status and confirmation email before trying again.
If funds have been debited but payment is not shown on the reservation, contact the Company before submitting a second payment.
Where duplicate collection for the same reservation is verified, the excess amount will be refunded through the appropriate payment channel.
A detailed card-decline reason may not always be disclosed to the Company because of banking and security rules. The customer may need to contact the card-issuing bank.
9. Refunds
Refund eligibility is determined under the Pre-Contract Information Form, Distance Sales Agreement, Booking Conditions and Cancellation and Refund Conditions.
- Card-payment refunds are processed through iyzico to the payment instrument used for purchase.
- Bank-transfer refunds are made after the required identity and account checks.
- Refunds are generally returned to the original payer and source of payment.
- Requests to refund an unrelated person or account may be rejected for security reasons.
After the Company completes a refund, the time required for the amount to appear on a card or bank account depends on the processing periods of the relevant bank and payment provider.
10. Unauthorised or suspicious transactions
If you suspect unauthorised use of your card or bank account:
- Contact the issuing bank or payment provider immediately;
- Block the affected card or banking channel where necessary;
- Notify the Company with the transaction date, amount and reservation number;
- Change affected passwords and access credentials;
- Contact competent authorities where appropriate.
The Company may temporarily review, request additional verification for or reject a transaction to prevent fraud, protect payment security or comply with legal obligations.
11. Payment data and privacy
Payment processing may involve the reservation number, amount, transaction time, result, limited masked card information, bank-transfer sender details and transaction-security records.
Such data is processed for payment execution, booking confirmation, accounting, billing, refunds, fraud prevention, dispute management and compliance with legal obligations.
Necessary information may be shared, to the extent required, with iyzico, banks, card schemes, accounting providers and legally authorised public bodies.
Payment support
Contact us regarding payments, transfer receipts, duplicate charges, refunds or suspicious transactions.
Include the reservation number, transaction date, amount and payment method. Never send a full card number, CVV/CVC, card password, online banking password or 3D Secure code by email. This English version is provided for information; Turkish law and the Turkish text prevail.