Legal

Privacy notice

Effective
[Effective date]
Draft last edited
Status
Not in force

We collect what is needed to run searches you asked for, take payment, and keep the service working. We do not sell personal data, we do not profile you for advertising, and we deliberately never ask for a loyalty-program login or a card number.

The section that people find most surprising is the second one, so it comes first: what we do not collect.

Section 1

Who is responsible for your data

[Company legal name], of [Registered address], is the controller of the personal data described in this notice. Our privacy contact is [Data protection representative], reachable at privacy@[domain].

This notice takes effect on [Effective date] and applies to the website and the award-search service.

Section 2

What we deliberately never collect

Starting here because it is the part most people actually want to know. We do not ask for, and the product has no field for:

  • loyalty-program logins, passwords, member numbers or security answers;
  • card numbers or bank details — payment details are entered on Stripe’s hosted checkout and never reach our servers;
  • passport, government identity or date-of-birth data;
  • location data. Searches use the airports you type, not where you are.

Saved point balances are numbers you enter yourself. They are not connected to any loyalty account and we cannot verify or update them.

Section 3

What we do collect

Account data
Email address, display name and authentication identifiers from our identity provider, plus your locale and notification preferences.
Search data
The queries you run: airports, dates, cabins, passenger counts, programs and filters, along with saved searches and alert configurations. Alerts store the query, never the results.
Points balances
Program, amount, as-of date and any note you add. Entered manually and deletable at any time.
Billing data
Subscription status, plan, entitlement version, renewal dates and invoice references. The card itself is held by Stripe, not by us.
Usage and technical data
Request logs, IP address, browser and device information, error reports and the usage ledger that records how much of your daily search budget you have spent. Logs are used for security, abuse prevention, billing accuracy and debugging.
Correspondence
Anything you send to a support or privacy mailbox, and our replies.

Section 4

Why we use it, and on what basis

  • To provide the service you asked for — running searches, storing saved searches, sending alerts, applying plan limits. Basis: performance of our contract with you.
  • To take payment — managing subscriptions, invoices and entitlement. Basis: performance of our contract, and our legal obligations for tax and accounting records.
  • To keep the service working and safe — diagnosing faults, enforcing rate and fair-use limits, preventing abuse of upstream sources. Basis: our legitimate interest in a functioning, non-abusive service, balanced against your interests.
  • To understand aggregate usage — which features are used and where searches fail. Basis: consent where a non-essential analytics cookie is involved, otherwise legitimate interest using aggregated data.
  • To answer you — handling support and privacy correspondence. Basis: performance of our contract or our legitimate interest in responding.

We do not sell personal data, we do not share it with data brokers, and we do not use your searches to build advertising profiles.

Section 5

Who processes data on our behalf

We use a small number of sub-processors, each under a contract limiting them to acting on our instructions:

  • Identity — Clerk, for sign-in and session management.
  • Payments — Stripe, for checkout, subscription management and invoices. Stripe is a controller in its own right for payment data.
  • Email delivery [Email delivery provider], for alert emails, receipts and account mail.
  • Hosting and infrastructure — production data is stored and processed in [Hosting region].
  • Analytics [Analytics provider], if deployed, configured without cross-site identifiers. See the cookie notice.

The current list, with each provider’s role and location, is maintained at [Sub-processor list URL].

Section 6

International transfers

Some sub-processors operate outside [Hosting region]. Where personal data is transferred out of a region whose law restricts transfers, we rely on an approved transfer mechanism — typically standard contractual clauses — together with an assessment of the destination and additional safeguards where the assessment requires them.

Section 7

How long we keep it

We keep each category only as long as it is needed for the purpose it was collected for:

  • account, saved searches, alerts and balances: while your account is open, then deleted within [Retention period] of closure;
  • billing and tax records: for the period the applicable tax law requires, which is longer than the account retention above;
  • security and request logs: a short rolling window, then deleted or aggregated;
  • support correspondence: kept while it may still be relevant to a dispute, then deleted.

Aggregated statistics that can no longer identify you may be kept indefinitely.

Section 8

Your rights

Depending on where you live, you may have the right to:

  • get a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • have data deleted, subject to records we must keep by law;
  • receive your data in a portable format;
  • object to, or ask us to restrict, processing based on legitimate interest;
  • withdraw consent at any time where processing relies on it.

The product includes an account export and a deletion request flow, so you do not have to email us to exercise the main ones. If you prefer to write, use privacy@[domain]; we will respond within the period the applicable law requires and will not charge you for a first request.

You can also complain to a data protection authority, including [Supervisory authority]. We would appreciate the chance to fix the problem first.

Section 9

Security

Access to production data is restricted to the people who need it, authenticated individually and logged. Data is encrypted in transit and at rest. Administrative actions that touch customer records are recorded in an audit trail.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to you, we will notify you and the relevant authority within the timeframes the law sets.

Section 10

Children

The service is not directed at children and is not intended for anyone below the age at which they can form a binding contract where they live. We do not knowingly collect their data; if we learn that we have, we delete it.

Section 11

Changes to this notice

When this notice changes we update the effective date and, for changes that materially affect you, tell you by email or in the product before they take effect. Previous versions are available on request from privacy@[domain].

Facts the operator must supply before this document takes effect

11 bracketed values appear in this document. Each one is a fact, not a missing clause — the wording around it is complete.

[Company legal name]
The registered entity that contracts with customers, exactly as it appears on the certificate of incorporation.
[Registered address]
Registered office address for service of notices. A PO box is usually not sufficient.
[Effective date]
The date this version of the document takes effect. Set it when counsel signs off, not before.
privacy@[domain]
Mailbox for data-subject requests: access, correction, deletion, portability and objection.
[Data protection representative]
Named privacy contact, and an EU or UK representative if one is required for the customer base.
[Supervisory authority]
The data protection authority customers may complain to, with its contact details.
[Hosting region]
Where production data is physically stored and processed, at country or region level.
[Sub-processor list URL]
A maintained, publicly reachable list of sub-processors, with a change-notification mechanism.
[Retention period]
How long each category of personal data is kept after an account closes. One period per category, not a single blanket figure.
[Analytics provider]
The analytics product used, if any, and whether it is configured without cross-site identifiers.
[Email delivery provider]
The transactional email provider that sends alerts, receipts and account mail.