Privacy Policy

Last Updated: February 9, 2026

Introduction

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Manage My Booking portal. We are committed to protecting your privacy and ensuring the security of your personal data in compliance with GDPR, CCPA, and other applicable data protection laws.

Information We Collect

Personal Information

When you register or use our services, we may collect:

  • Identity Information: First name, last name, date of birth
  • Contact Information: Email address, phone number
  • Travel Information: Nationality, passenger category, travel preferences
  • Account Information: Password (encrypted), login preferences
  • Booking Information: PNR codes, flight details, passenger information

Automatically Collected Information

  • IP address and device information
  • Browser type and version
  • Usage data and analytics
  • Cookies and similar tracking technologies

How We Use Your Information

We use your information to:

  • Provide and manage your booking services
  • Process your transactions and authenticate your account
  • Send you booking confirmations and important updates
  • Verify special passenger categories (student, military, etc.)
  • Apply eligible discounts and benefits
  • Improve our services and user experience
  • Comply with legal obligations
  • Send marketing communications (only with your consent)

Legal Basis for Processing (GDPR)

We process your personal data based on:

  • Contract Performance: To fulfill our booking services
  • Consent: For marketing communications and optional data
  • Legitimate Interest: To improve our services and prevent fraud
  • Legal Obligation: To comply with applicable laws

Data Security

We implement industry-standard security measures including:

  • 256-bit SSL encryption for data transmission
  • Encrypted storage for sensitive personal information
  • Regular security audits and penetration testing
  • Access controls and authentication requirements
  • Secure data centers with physical security measures

Your Rights

Under GDPR and other data protection laws, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a structured format
  • Object: Object to processing for direct marketing
  • Withdraw Consent: Withdraw consent at any time

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, or as required by law. The retention periods vary by data category:

Data Category Retention Period Legal Basis
Booking & PNR Data 5–7 years from travel date EU PNR Directive 2016/681, aviation regulations
Payment & Financial Records 6–7 years from transaction Tax law, Anti-Money Laundering (AML) regulations
Security & Audit Logs 3 years from event Regulatory compliance, fraud prevention
Special Requests (e.g. accessibility) 5 years Anti-discrimination law
Marketing & Consent Records Until consent is withdrawn Consent (GDPR Art. 6(1)(a))
User Preferences Deleted upon account closure No legal retention obligation

How Erasure Requests Are Handled

When you request erasure of your data (GDPR Article 17), we follow a selective approach in compliance with Article 17(3)(b):

  • Immediately deleted: Preferences, session data, and marketing data (where consent is withdrawn)
  • Anonymized: Booking, payment, and passenger records are stripped of all personally identifiable information while retaining anonymized records required by law
  • Account closure: Your account is deactivated and all identifying information is replaced with irreversible anonymized data
  • Scheduled permanent deletion: Retained anonymized records are permanently deleted once their legal retention period expires

You will receive a detailed deletion report confirming which data was deleted, anonymized, or retained, along with the applicable retention periods and legal references.

Cookies Policy

We use cookies to:

  • Remember your login session
  • Store your preferences
  • Analyze site traffic and usage patterns
  • Personalize content and ads

You can control cookies through your browser settings. Note that disabling cookies may affect site functionality.

Third-Party Sharing

We do not sell your personal data. We may share information with:

  • Airlines and travel service providers (to fulfill bookings)
  • Payment processors (to process transactions)
  • Verification services (to verify special passenger categories)
  • Law enforcement (when legally required)

International Data Transfers

Your data may be transferred to and processed in countries outside your residence. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

Children's Privacy

Our services are not directed to individuals under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through a prominent notice on our website.

Contact Us

For questions about this Privacy Policy or to exercise your rights, please contact:

Data Protection Officer

Email: privacy@travelportal.com

Address: [Your Company Address]

You also have the right to lodge a complaint with your local data protection authority.