Privacy policy
How Mongova collects, uses, and protects your information.
Last updated: May 29, 2026
This Privacy Policy explains how Mongova ("we", "us", "the platform") collects, uses, and protects your personal information when you use our website, mobile applications, and related services.
1. Who we are
Mongova is a Mongolian travel and hospitality booking platform operated by Ikh Khunnu Mongol Media LLC (the "Operator"). Mongova connects travelers with hotels, resorts, tour operators, transport providers, and other tourism businesses across Mongolia.
If you have any questions about this policy or how your data is handled, you can reach us using the contact details in section 12.
2. What data we collect
We collect only the information needed to operate the service. The categories are:
Account information
- Name, email address, and phone number (collected through Firebase Authentication when you create an account or sign in)
- Profile preferences and language settings
Booking information
- Hotel and property preferences
- Guest details for each booking (number of guests, special requests)
- Check-in and check-out dates
- Booking and stay history
Payment information
- Payment is handled by third-party payment processors (QPay for domestic Mongolian payments and Bonum for international card payments when enabled)
- We do not receive or store your card number, bank account number, or CVV
- We only receive a transaction confirmation, payment status, and reference number from the payment processor
Device and usage data
- Standard analytics: app version, device type, operating system, crash diagnostics
- A Firebase Cloud Messaging (FCM) device token, used to deliver push notifications
- IP address and approximate region (used for security and fraud prevention)
Location data
- On Android we request coarse location only (
ACCESS_COARSE_LOCATION) - We use this to show hotels near you in search results
- You can decline the permission and continue to use the service — search will simply not be pre-filtered by your location
3. How we use your data
We use your information to:
- Process bookings and confirm reservations with the property
- Send transactional emails (booking confirmations, cancellations, refunds, receipts) through our email provider
- Send push notifications about your bookings and account activity
- Prevent fraud and protect the security of the platform
- Improve the service, fix bugs, and understand how the product is used
- Comply with applicable Mongolian tax and accounting laws
We do not sell your personal information to third parties.
4. Third-party processors
The platform uses the following third-party services. Each operates under its own privacy policy:
- Firebase (Google) — authentication, push notification delivery, image and file storage
- QPay — domestic Mongolian payment processing
- Bonum — international card payment processing (when enabled)
- Resend — transactional email delivery
- Vercel — web application hosting
- Railway — PostgreSQL database hosting
These processors only receive the data they need to perform their function (for example, QPay receives transaction amounts and reference numbers; Resend receives recipient email addresses and message content).
5. Data retention
- Booking records are retained for the period required by Mongolian tax and accounting law (typically up to 10 years for financial records)
- Account data is retained for as long as your account is active
- Marketing preferences are retained until you change them
- If you request account deletion, we remove your personal data within 30 days, except for booking and financial records that we are legally required to keep
6. Your rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate information
- Request deletion of your account and personal data (subject to legal retention requirements)
- Withdraw consent for marketing communications at any time
- Object to processing in certain circumstances
To exercise any of these rights, contact us using the details in section 12.
7. Cookies and local storage
We use cookies and browser local storage for essential platform functionality:
- Authentication tokens — to keep you signed in
- Locale preference — to remember your chosen language (Mongolian or English)
- Cart and booking state — to preserve your selections while you complete a booking
- Basic analytics — to understand which pages are used and to detect errors
We do not use third-party advertising cookies or cross-site tracking.
You can clear cookies and local storage from your browser settings at any time. Doing so will sign you out and reset your preferences.
8. Children
Mongova is not directed at children under 18 who are using the service without adult supervision. Users under 18 should only use the service with the consent and supervision of a parent or guardian, and any booking should be made by the adult. We do not knowingly collect personal information from unsupervised minors.
9. International data transfers
Some of our processors (Firebase, Vercel, Railway, Resend) store and process data on servers located outside Mongolia. By using the service, you understand and consent to your data being transferred to and processed in those jurisdictions. We choose processors with industry-standard security practices and contractual data protection terms.
10. Security
We protect your data with industry-standard measures, including:
- HTTPS / TLS encryption for all traffic
- Encrypted storage of authentication credentials by Firebase
- Role-based access control for staff and partners
- Audit logs for administrative actions
- Regular security updates of the platform's dependencies
No system is perfectly secure. If you believe your account has been compromised, contact us immediately.
11. Changes to this policy
We may update this policy from time to time. For material changes, we will notify you by email or by an in-app banner before the changes take effect. The "Last updated" date at the top of this page always reflects the current version.
12. Contact
For privacy questions, data access requests, or account deletion requests, contact us at:
- Mongova operator (Mongolia): munkhod.ch@gmail.com
- Platform support: ubwebdevelopers@gmail.com
Please include your registered email address so we can verify your identity before acting on the request.
Questions about these policies? Our team is happy to help.
Contact us