Privacy policy
Template — not yet reviewed by counsel
We collect what a charter booking actually needs: who you are on Telegram, the route you asked for, and the passport details operators require. Passport data is encrypted at rest and every access to it is logged.
1.Who is responsible
The controller of your personal data is [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Data protection contact: [DPO OR PRIVACY CONTACT EMAIL].
2.What we collect
Account. When you sign in with Telegram we receive your Telegram ID, username, first and last name and profile photo. We never receive your phone number, your contacts or your messages.
Requests. The routes, dates, times, passenger counts and preferences you enter, and the messages you send us in the order chat.
Passenger documents. For a confirmed booking: full name, date of birth, nationality, passport number and passport expiry, for each passenger.
Payment. The amount, the asset and network, the destination wallet address, and any transaction hash you give us. We do not hold your wallet keys and cannot move funds on your behalf.
3.Why we use it, and on what basis
| Purpose | Basis |
|---|---|
| Arranging and performing your charter | Performance of a contract |
| Giving operators and authorities the passenger manifest | Legal obligation of the carrier |
| Sanctions and lawfulness screening | Legal obligation |
| Keeping the service secure and diagnosing faults | Legitimate interests |
[CONFIRM THESE BASES AGAINST THE APPLICABLE REGIME — GDPR, UK GDPR OR LOCAL LAW — BEFORE PUBLISHING]
4.Who receives it
The operator flying you receives the passenger manifest, because the flight cannot be documented without it. Only the operator for your specific booking receives it.
Our processors: Supabase (database hosting, [REGION]), Vercel (application hosting), Telegram (authentication and messaging), Aviapages (fleet search and operator quotes), and our email provider [SMTP PROVIDER].
We do not sell personal data and do not use it for advertising.
5.How passport data is protected
Passenger records are encrypted with AES-256-GCM before they are written to the database, and the key is held outside it. Staff access is limited to administrators, and every read or export of passenger documents is written to an access log recording who did it and when.
6.How long we keep it
| Data | Retention |
|---|---|
| Passenger documents | [N] days after the flight |
| Booking and payment records | [N] years (accounting and tax) |
| Account and chat history | Until you ask us to delete the account |
7.Your rights
You can ask for a copy of your data, correction of it, deletion of it, restriction of its use, or a portable export, and you can object to processing based on legitimate interests. Write to [PRIVACY CONTACT EMAIL] and we will respond within [N] days.
You may also complain to the supervisory authority in your country; in [JURISDICTION] that is [AUTHORITY NAME].
8.Cookies and tracking
We set one cookie: a signed session cookie that keeps you logged in for 30 days. It is strictly necessary for the service and carries no tracking identifiers. We run no advertising or analytics trackers.
[UPDATE THIS SECTION IF ANALYTICS IS ADDED LATER]
9.International transfers
Operators are located worldwide, so a manifest may be sent outside your country when the aircraft flying you is based elsewhere. [DESCRIBE THE TRANSFER MECHANISM RELIED ON — SCCs, ADEQUACY OR ARTICLE 49 DEROGATION FOR CONTRACT PERFORMANCE]