Status: Pre-launch draft
Last updated: August 20, 2026
Effective: [EFFECTIVE_DATE]
Our current practices
Based on the integrations currently implemented, we do not sell personal information and do not share personal information for cross-context behavioral advertising.
The configured analytics implementation is limited to aggregate Plausible pageviews and allowlisted service events; it is not used for behavioral advertising. These statements must be revalidated against production configuration and network requests before launch and whenever tracking technology changes.
Available requests
Depending on the law that applies to you, you may be able to request access, correction, deletion, portability, restriction, objection, or withdrawal of consent.
How to submit a request
Email privacy@[DOMAIN] with the subject “Privacy Request.” Include the email address used with the service and the type of request. Do not include booking credentials, passport information, or payment-card details.
Verification
We may need to verify your identity and authority before responding. Verification will be limited to information reasonably needed to match the request to our records. We will not request airline passwords, loyalty passwords, passport information, or full payment-card details.
Request form
You may also use the secure contact form and select “Privacy request.” Do not include booking credentials, passport information, or payment-card details.
What happens next
We will record the request, search the systems reasonably related to it, and respond as required by applicable law. Some information may be retained where an exception, legal hold, fraud-prevention need, or accounting obligation applies. Response timing and any appeal process depend on the law that applies.
Scope
We do not claim that any specific state privacy law, including the CPRA, applies unless legally confirmed. Final rights, response timing, appeals, nondiscrimination, and authorized-agent language are LEGAL_REVIEW_REQUIRED.