Last updated: October 1, 2026
Effective: October 1, 2026
1. Who is responsible
This policy covers the FlightChangeCheck website, Quick Check submissions, digital reports, and support communications. FlightChangeCheck operates from Israel and is responsible for the personal information it processes to provide these services.
Contact privacy@flightchangecheck.com for privacy questions or requests.
2. Information we collect
- Your email address and the flight details you submit: airline, flight number, airports, travel date, original and revised times, change types, and booking channel.
- Optional fare type and redacted airline-message text.
- Your contact name, email, request category, and any support information you send by email.
- Consent records, limited campaign attribution, and security records used to prevent abuse.
- Your report, payment status, selected plan, amount, and payment-provider transaction reference.
- Browser, device, and interaction information collected through optional analytics when you permit it.
Information comes from you, your interaction with our website, and service providers confirming transactions or message delivery. Research uses published airline policies and flight information; we do not access your airline account.
For explicit-access reports, we keep the checkout policy version and acceptance time, the report version fingerprint, your access confirmation text and time, and a separate browser acknowledgment of display. These minimal service records help deliver the report and assess billing requests; they are not optional analytics, contain no inbox access, and do not prove you read the report or contacted an airline. Access records are retained with the report for up to 12 months after delivery, subject to unresolved disputes or legal holds.
3. Information not needed for a review
Do not send booking references, confirmation codes, full passenger names, ticket numbers, passport details, dates of birth, loyalty-account details, airline passwords, or payment-card information. Remove them from pasted messages. Automated checks may flag likely sensitive information, but cannot detect every case. Contact us if you accidentally submit it.
The hosted payment provider may separately collect billing or card information needed for payment. Our itinerary forms do not collect card details.
4. Why we use information
We use information to assess your flight change, prepare and deliver a report, verify payment, handle refunds and factual corrections, respond to support or privacy requests, secure the service, and keep required business records.
Where a legal basis is required, we rely on performing the service you request, legitimate interests in security and service administration, applicable legal obligations, and consent for optional analytics and marketing. We consider your rights when relying on legitimate interests. Marketing consent is separate from service consent and is optional.
5. Analytics and marketing choices
Our single optional-cookie choice covers site analytics, advertising measurement, and advertising audiences. If you accept, Google Analytics measures public pageviews, service steps, and verified purchases. Google Ads measurement may use advertising cookies and valid ad-click identifiers on public landing pages to measure our Google campaigns. When Google Ads account linking is configured, consented measurement may also be shared with that account. Google ad personalization, Google Signals, and remarketing remain disabled. If you reject, these optional browser tags stay off. You can change or withdraw your choice using “Cookie settings” in the footer.
When optional cookies are accepted and Global Privacy Control is not active, Meta Pixel measures Facebook and Instagram advertising and helps build relevant advertising audiences. Meta may receive browser and network information, public page URLs, cookie or click identifiers, and purchase events. This may constitute sharing for targeted or cross-context behavioral advertising under applicable law. Global Privacy Control keeps Google Ads measurement and Meta Pixel off even if optional cookies are accepted. We do not sell customer lists or flight details.
Tracking scripts are excluded from private checkout, report, and operations pages. On a separate confirmation page, a server-verified purchase can send the plan, currency, value after discounts excluding tax, and a pseudonymous transaction identifier to permitted providers. Google also receives the tax separately. We do not include email, itinerary details, pasted messages, card information, raw payment references, or private access tokens in these events, and do not enable Meta automatic advanced matching.
When configured, a separate server event counts first report delivery using a new random identifier for that event. It contains no customer, report, flight, payment, or submission identifier and is not linked to a browser analytics identity.
Short, non-personal campaign codes may be kept for the browser-tab session and associated with a submission to understand referral sources. With optional cookies accepted, those codes may also be sent to Google Analytics.
Email marketing permission remains separate from the optional-cookie choice. Use the unsubscribe option or email us to stop marketing emails. Essential service and billing messages may still be sent.
6. Service providers and disclosures
- Vercel hosts the website; Supabase provides database infrastructure.
- Resend delivers service email. Cloudflare provides DNS, email routing, and security services including Turnstile. Business messages may be handled in Google-hosted email.
- With optional-cookie acceptance, Google provides Analytics and Google Ads measurement, and Meta provides advertising measurement and audiences under its Privacy Policy. Global Privacy Control keeps the advertising technologies off.
- Flight-data providers, including FlightAPI when used, receive route and travel-date search parameters to research alternatives, not your email, booking credentials, or passenger identity.
- The payment provider identified at checkout handles payment information. If Paddle is the seller on your receipt, it acts as merchant of record and processes transaction data under its own Privacy Policy.
We disclose information to providers only as needed for their functions. We may also disclose information where legally required, to address fraud or security incidents, to protect legal rights, or as part of a business transfer with appropriate notice and safeguards. We do not send your report or itinerary to an airline on your behalf.
7. International processing
Our business is in Israel and providers may process data in the United States and other countries. Privacy protections may differ from those in your country. Where transfer restrictions apply, an appropriate lawful mechanism is required, such as an applicable adequacy decision or contractual safeguards. Contact us for information about the safeguards relevant to your request; this policy does not itself create or certify a transfer mechanism.
8. Retention
Our retention schedule is:
- Closed flight submissions without an active report: eligible for deletion 90 days after the travel date.
- Delivered reports and supporting submission details: retained for up to 12 months after delivery so the report remains available and factual or billing issues can be addressed.
- Support messages: normally retained for up to 12 months after the matter is closed.
- Payment and accounting records: retained for the periods required by applicable law and to address disputes.
- Marketing preferences: retained while subscribed; a limited suppression or consent record may remain after withdrawal to respect your choice and demonstrate compliance.
Deletion is performed through periodic review and cleanup, not necessarily at the exact cutoff time. Active cases, unresolved payments, legal obligations, security needs, or legal holds can require longer retention. Backups may retain copies until their normal rotation. You can request earlier deletion, subject to applicable exceptions.
9. Your rights
Depending on the law that applies, you may have rights of access, correction, deletion, portability, restriction, objection, withdrawal of consent, or complaint to a supervisory authority. Withdrawing consent does not affect processing already lawfully carried out.
Our service is designed primarily for travelers in the United States. Where privacy laws outside the United States apply, we handle requests in accordance with applicable law. See Your Privacy Choices for request instructions. We may verify your request using information reasonably necessary to locate your records.
10. Security and automated processing
We use restricted access, server-side validation, bot protection, rate limits, and other safeguards. No online system is completely secure. Turnstile may process browser, device, and network signals for abuse prevention; we do not intentionally send it the contents of your flight submission.
Analysis may be assisted by software, but our service does not make airline booking decisions or determine legal rights. The airline or ticketing agency makes any rebooking or refund decision. Recommendations are information for you to consider, not actions taken on your booking.
11. Children
The service is for adults aged 18 or over and is not directed to children. We do not knowingly collect children’s personal information. If you believe a child has supplied information, contact us so we can investigate and delete it where appropriate.
12. Changes and contact
Updates will appear with a revised effective date. We will provide further notice of material changes where required. Send privacy requests to privacy@flightchangecheck.com; do not include sensitive booking or payment information.