Status: Pre-launch draft
Last updated: August 20, 2026
Effective: [EFFECTIVE_DATE]
1. Scope and data controller
This policy describes how FlightChangeCheck handles personal information when you use the website, submit a Quick Check, purchase or receive a report, or contact us.
Data controller: [LEGAL_NAME], organized in [BUSINESS_COUNTRY]. Privacy contact: privacy@[DOMAIN].
Business address: [BUSINESS_ADDRESS]. Registration number: [BUSINESS_REGISTRATION_NUMBER].
2. Information we collect and its sources
Depending on how you use the service, we may collect:
- Email address
- Airline, flight number, route, and travel date
- Original and revised itinerary details
- Type of schedule change and booking source
- Optional fare type and optional redacted airline-message text
- Consent records and campaign attribution
- Security logs and privacy-friendly analytics
- Payment status and an external transaction reference
- Support or privacy-request messages you choose to send
Most service information comes directly from you. Security and analytics information comes from your browser, device, and network interaction with the site. Payment status and transaction references come from the configured hosted-payment provider.
3. Information we do not need
Please do not provide a booking reference, confirmation code, full passenger name, ticket number, passport information, date of birth, airline password, loyalty password, loyalty credentials, or payment-card information. FlightChangeCheck does not provide any payment-card fields; card details are handled only on an external hosted-checkout page.
4. Purposes of processing
- Provide and deliver the review service
- Process and verify payment through an external provider
- Respond to billing, technical, privacy, and factual-correction requests
- Prevent abuse and protect the service
- Measure anonymous website usage
- Maintain legally required business and accounting records
- Send marketing messages only when separate consent was given
Where a law requires a legal basis for processing, the applicable basis may include performance of a requested service, legitimate interests in operating and securing the service, consent for optional marketing, and compliance with legal obligations. The correct basis for each market is LEGAL_REVIEW_REQUIRED.
5. Analytics details
Analytics is disabled unless Plausible and a valid public site URL are configured.
Like browser analytics requests, the first-delivery event necessarily transmits network metadata such as IP address and user agent to Plausible. Final provider, lawful-basis, consent, retention, and international-transfer language is LEGAL_REVIEW_REQUIRED.
6. Security and fraud prevention
Cloudflare Turnstile is used to distinguish legitimate form submissions from automated abuse. It may process browser, device, and network signals needed for that security check; FlightChangeCheck does not intentionally send the contents of your form to Turnstile. We also use rate limits, server-side validation, restricted database access, and security logs.
7. Service providers and international transfers
Vercel may provide hosting, Supabase may provide database infrastructure, Resend may deliver service email, Cloudflare may provide bot protection, and Plausible may provide analytics when enabled. A configured hosted-payment provider processes checkout and returns a transaction reference and status. The final provider list must be reconciled with production contracts and configuration before launch.
These providers may process information outside your country, including in the United States, Israel, or other locations used by their infrastructure. The applicable transfer mechanism, provider processing location, data-processing terms, and Israeli, EEA, and UK transfer language are LEGAL_REVIEW_REQUIRED.
8. Retention
Recommended defaults are flight-submission data until 90 days after travel, reports for 12 months, and support messages for 12 months. Payment and accounting records may be retained as legally required. Marketing-consent records may be retained until withdrawal plus reasonable compliance retention. Final periods are LEGAL_REVIEW_REQUIRED.
Deletion may be delayed where records are needed for an unresolved transaction, a legal hold, fraud prevention, or a legal or accounting obligation. The cleanup process is designed to remove service submissions separately from retained payment records.
9. Your choices and rights
Where applicable law provides these rights, you may request access, correction, deletion, portability, objection, restriction, or withdrawal of consent. Identity verification may be required before completing a request.
Our service is designed primarily for travelers in the United States. Where privacy laws outside the United States apply to a user, we will handle privacy requests in accordance with applicable law.
Optional marketing consent may be withdrawn at any time by using the unsubscribe method in a marketing message or contacting the privacy email below. Withdrawing marketing consent does not affect required service messages.
10. Automated decisions and airline outcomes
FlightChangeCheck provides informational analysis and recommendations. It does not make decisions about airline tickets, refunds, or rebooking, and it does not make automated decisions that determine legal rights. Final approval rests with the airline or ticketing agency.
11. Security and children
We use technical and organizational measures intended to limit access and reduce the information collected. No online system is completely secure. The service is not designed for children, but the final minimum age and children’s-privacy wording are LEGAL_REVIEW_REQUIRED.
12. Changes to this policy
We may update this policy as the service or applicable requirements change. The page will display a revised last-updated date, and material notices will be provided where required by law.
13. Contact
Send privacy questions or requests to privacy@[DOMAIN]. Do not include booking credentials, passport details, or payment-card information.