ANYLK (PVT) LTD ("ANYLK", "we", "our", or "us") is a Sri Lanka-based travel and mobility platform connecting travellers with drivers, hotels and other accommodation providers, tour guides, photographers, and self-drive vehicle rental operators across Sri Lanka. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the ANYLK (traveller) and ANYLK Partner mobile applications and our website www.anylk.com (collectively, the "Services"). By registering for or using our Services, you agree to the practices described in this policy.
- Tracking & Analytics: Learn how we use tracking technologies on our website in our Cookie Policy.
- Financial Data: Understand how payments, wallets, and payouts are handled under our Payment Policy.
- Right to Erasure: Find step-by-step instructions for removing your account and personal data on our Account & Data Deletion page.
1.1 Traveller Accounts
- Full name, email address, and phone number
- Password (stored in hashed form — never in plain text)
- If you sign in with Google or Apple, we receive your name, email address, and (Google only) profile photo from that provider
- Language preference and profile details you choose to add
1.2 Driver Accounts (ANYLK Partner)
- Full name, email address, phone number
- National Identity Card (NIC) — front & back photos, and NIC number
- Driver's licence photo, vehicle insurance certificate, and vehicle registration document
- Vehicle details and photos (type, model, number plate)
- Bank account details for payouts (account number, holder name, bank, branch)
- Real-time GPS location while online and during trips
1.3 Tour Guide Accounts
- Full name, phone number, profile photo
- NIC or passport number and document photos
- Guide licence / SLTDA registration documents where applicable
- Experience, areas covered, languages spoken, and pricing
- Bank account details for payouts
1.4 Photographer Accounts
- Full name, phone number, city, and optional Instagram handle
- Experience, camera and equipment details, and pricing
- NIC document photos, profile photo, and portfolio photos
- Bank account details for payouts
1.5 Hotel & Accommodation Accounts
- Property name, type (hotel, villa, guest house, resort, bungalow, homestay, or hostel), contact number, city, and address
- Room / unit / bed types, prices (LKR & USD), and property photos
- Owner NIC document photos and business/SLTDA registration documents where applicable
- Bank account details for payouts
1.6 Self-Drive Rental Operator Accounts
- Business or owner name, contact number, city, and address
- Business registration number and NIC/passport document photos
- Vehicle details, condition, photos, and daily rental rates
- Bank account details for payouts
1.7 Automatically Collected Information
- Device type, operating system version, and app version
- IP address and device identifiers, including push-notification (FCM) tokens
- Crash reports and error logs
- Booking history, wallet transaction history, and in-app activity
- Ratings and reviews you submit
ANYLK includes an in-trip SOS emergency feature designed to protect travellers and drivers. When you (and only you) activate SOS during a trip, the following data is collected and processed:
- Live location: Your GPS position is streamed continuously to our safety team until the SOS is resolved.
- Voice recording: With your prior microphone permission, short audio clips are recorded — including while the app is in the background or the screen is off — and uploaded to secure storage. On Android a persistent notification is always visible while recording; recording stops automatically when the SOS ends, if the app is closed, or after a maximum session length.
- Emergency sharing: To get you help quickly, we may share a live-location link with police or emergency responders (for example via WhatsApp or Telegram). This public link shows only a map position — no name, phone number, or other personal details.
- Nearest police station lookup: Your location may be used to identify the closest police station.
Microphone access is optional for travellers — you can decline it and SOS will still work with location only. SOS voice clips are automatically deleted after 14 days, unless an incident is under active investigation and an administrator marks them for retention. SOS data is never used for advertising or any purpose other than safety.
3.1 Medical Assistance
If you use the in-app medical assistance feature, your GPS location is used once to find the nearest available doctor. Consultations (text, video, or in-person arrangement) take place over third-party messaging platforms such as WhatsApp or Telegram, which are governed by their own privacy policies. We store a record of the service request and any wallet payment; we do not store the content of your consultation or any medical records.
3.2 AI Travel Assistant
The in-app AI travel assistant sends your chat messages (and recent conversation history) through our servers to Google's Gemini AI service to generate answers. Usage is subject to a daily message limit. Please do not include sensitive personal information in AI chats. AI conversations are used solely to answer your questions — not for advertising or profiling.
- To create and manage your account and verify your identity and email address
- To match travellers with drivers, hotels, guides, photographers, and rental operators
- To process wallet top-ups, booking payments, refunds, commissions, and partner payouts
- To display real-time maps, routes, and fare estimates
- To verify the authenticity of submitted documents (NIC, licences, insurance, business registrations)
- To send booking confirmations, trip updates, payment receipts, and service notifications (push and email)
- To respond to SOS emergencies and protect user safety
- To handle customer support queries and resolve disputes
- To prevent fraud and enforce our Terms & Conditions
- To improve app features based on aggregated usage data
- To comply with applicable laws, regulations, and court orders
Location access is essential for core app functionality. We collect GPS location as follows:
- Travellers: Location is collected when you book a ride or service to determine pickup point, destination, and fare, and during active trips to show trip progress. It is also used once when you search for nearby services (e.g. medical assistance).
- Drivers: Real-time location is collected while you are online and available for bookings, and during active trips for navigation and passenger tracking. The Partner app may collect location in the background while you are marked "Online" — a visible notification is shown, and you can go offline or disable location in device settings at any time.
- Hotels, guides, photographers, rental operators: Only city/area-level location is collected at registration for search and discovery — precise GPS is not tracked for these partners.
- SOS: Live location streaming as described in Section 2.
We do not sell location data or share it with third parties for advertising. Disabling location access will prevent ride booking and other location-based features from working.
- The ANYLK Wallet is an in-app balance maintained by ANYLK. Wallet transaction history is stored to provide statements, receipts, and dispute resolution.
- Bank transfer top-ups: If you top up by bank transfer (including via Wise for international travellers), the payment receipt you upload is stored securely and used only for verification by our administrators.
- Card payments are processed by our payment gateway (PAYable) and PayPal for international payments. We never see or store your full card number or card security codes — these are handled entirely by PCI-DSS compliant payment processors.
- Partner bank details are stored in access-restricted records visible only to the partner themselves and authorised ANYLK administrators, and are used solely for processing payouts.
- Payment receipts and invoices are emailed to you automatically after successful top-ups.
See our Payment Policy for full details of payment flows, commissions, and payouts.
We do not sell your personal information. We share data only in these circumstances:
- Between users: Travellers see a partner's name, photo, vehicle/property details, and live trip location. Partners see the traveller's name and pickup/booking details needed to deliver the service.
- Google Firebase / Google Cloud: Our backend (database, authentication, storage, cloud functions, push notifications, analytics) runs on Google Cloud infrastructure.
- Google Maps: Location data is sent to Google Maps APIs to render maps, routes, and fare estimates.
- Google Gemini: AI assistant messages are processed by Google's AI services (Section 3.2).
- Payment processors: Transaction data is shared with PAYable and PayPal to process payments and handle disputes/chargebacks.
- Email delivery: Transactional emails (verification, receipts, booking confirmations) are delivered via Amazon SES.
- Emergency services: During an SOS, your live location (and where necessary trip details) may be shared with police or emergency responders (Section 2).
- Legal requirements: We may disclose information if required by Sri Lankan law, a valid court order, or to prevent imminent harm.
- Incident investigations: Where an incident between users leads to a police complaint, criminal investigation, or court proceeding, we may preserve and provide the relevant platform records — booking details, GPS/trip logs, SOS recordings, in-app communications, and payment records — to law enforcement authorities, courts, and other lawfully entitled parties, in accordance with applicable law.
- Business transfers: In a merger, acquisition, or sale of assets, user data may be transferred to the successor entity subject to the same protections.
- All data in transit is encrypted using HTTPS/TLS
- Passwords are managed by Firebase Authentication and stored as secure one-way hashes
- Database security rules restrict every record to the users authorised to access it
- Sensitive partner data (NIC numbers, identity documents, bank details) is kept in separately restricted records accessible only to the owner and authorised administrators
- Identity document images are stored in access-controlled cloud storage — they are never publicly accessible
- All money movements (payments, refunds, payouts, commissions) are executed server-side with transactional safeguards
- Administrator actions on user data are access-controlled and logged
- Card data is handled exclusively by PCI-DSS compliant payment processors
While we take strong precautions, no internet transmission is 100% secure. Please use a strong password and keep your credentials confidential.
- Account and profile data is retained while your account is active
- Booking and trip history is retained for dispute resolution while your account is active
- SOS voice clips are automatically deleted after 14 days unless retained for an active investigation
- When you delete your account, it is deactivated immediately and your personal data — including profile, documents, photos, wallet records, and booking history — is permanently erased within 180 days (see our Account & Data Deletion page)
- Financial transaction records required for legal, tax, or regulatory compliance may be retained for up to 6 years as required by Sri Lankan law
- Anonymised, aggregated analytics data may be retained indefinitely
ANYLK is not intended for persons under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a user is under 18, we will promptly delete their account and associated data. If you believe a minor has registered on our platform, please contact us at support@anylk.com.
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Update inaccurate data via your profile settings or by contacting us
- Deletion: Delete your account and associated data directly in the app
- Portability: Request a machine-readable export of your data where technically feasible
- Withdrawal of consent: Withdraw consent for optional data uses (e.g. marketing emails) at any time
- Objection: Object to certain processing of your data
How to Delete Your Account
- Open the ANYLK or ANYLK Partner app → Profile → Delete Account, OR
- Email support@anylk.com with the subject "Account Deletion Request"
Full details — including what is deleted, what is retained, and timelines — are on our dedicated Account & Data Deletion page. To exercise any other right, contact us using the details in Section 15; we respond within 30 days.
Our Services integrate the following third-party services, each governed by its own privacy policy:
- Google Firebase / Google Cloud — database, authentication, storage, cloud functions, push notifications, analytics
- Google Maps — maps, navigation, routing, and fare estimation
- Google Sign-In & Apple Sign-In — optional authentication methods
- Google Gemini — AI travel assistant responses
- PAYable — card payment processing (Sri Lanka)
- PayPal — international payment processing
- Amazon SES — transactional email delivery
- WhatsApp / Telegram — optional communication channels for support, medical assistance, and emergency coordination
- Google Play / Apple App Store — app distribution
If you access ANYLK from the European Economic Area, the following applies in addition to the rest of this policy:
- Legal basis: We process personal data based on contract performance (providing the Services), legitimate interests (fraud prevention, safety), legal obligations, or your explicit consent.
- Data transfers: Your data may be transferred to and processed in Sri Lanka and on Google Cloud infrastructure. We apply appropriate safeguards consistent with GDPR requirements.
- Rights: You have the right to access, rectify, erase, restrict, and port your data, and to object to certain processing.
- Complaints: You may lodge a complaint with your local Data Protection Authority.
- Right to Know: Request disclosure of the categories and specific pieces of personal information we collect and the purposes for collection.
- Right to Delete: Request deletion of personal information (subject to legal exceptions).
- Right to Opt-Out: ANYLK does not sell personal information, so no sale opt-out is required.
- Non-Discrimination: We will not discriminate against you for exercising your rights.
To submit a request, contact us via the details in Section 15. We respond within 45 days.
We may update this Privacy Policy from time to time. For material changes we will notify you via in-app notification or email before the changes take effect, and post the updated policy here with a new date. Continued use after the effective date constitutes acceptance.
Questions, concerns, or requests regarding this policy or your personal data:
- Data Controller: ANYLK (PVT) LTD (Business Registration No. PV00365236)
- Address: No 96, Pahalagama, Mahabulankulama, Anuradhapura 50000, Sri Lanka
- Customer Support: support@anylk.com | +94 78 749 2227 (Call / WhatsApp / SMS)
- General Inquiries: info@anylk.com
- Response time: We aim to respond within 5 business days
This Privacy Policy is governed by the laws of the Democratic Socialist Republic of Sri Lanka. Any dispute arising from this policy is subject to the exclusive jurisdiction of the courts of Sri Lanka.