Privacy policy
Last updated 17 July 2026
⚠️ Draft for review — not legal advice. Every statement below was written to match what this platform actually does in code, including where that is inconvenient. Text in [SQUARE BRACKETS] is a business or legal decision that must be completed before you publish, and this notice removed. Have a lawyer or your Data Protection Officer review the result.
[COMPANY LEGAL NAME] ("we", "us") is the personal information controller for the data described here. This notice explains what we collect, why, who we share it with, and the rights you have under the Philippine Data Privacy Act of 2012 (RA 10173).
1. What we collect
To book travel, from you and about your travellers:
- Full name, title, gender and date of birth
- Nationality
- Passport number, expiry date and country of issue — collected only when your itinerary requires it (generally international travel). We do not ask for it on domestic flights.
- Contact email address, mobile number, and billing address and city
- For hotels, the lead guest's name and contact details
If you create an account: your name, email address and a securely hashed password. If you choose to save travellers for faster booking, we store the same traveller details listed above under your account until you delete them.
Automatically: your IP address, and standard web-server request information.
We do not collect your card number — see section 4.
2. Why we use it, and our lawful basis
- To provide the booking you asked for — this is the necessary performance of our contract with you. Airlines and hotels require passenger identity details to issue a ticket or reservation; we cannot book without them.
- To contact you about your booking — confirmations, e-tickets, vouchers, and changes.
- To meet legal, tax and accounting obligations — this is why we keep transaction records.
- Saved travellers — only if you choose to save them, and you can delete them at any time.
3. Who we share it with, and where it goes
To book your travel we must send your details to:
- Our travel supplier, TBO, whose systems are operated outside the Philippines (in India); and through them
- The airline or hotel you booked, which may be anywhere in the world.
This is a cross-border transfer of your personal information. It is necessary to fulfil your booking — the carrier or property cannot issue your ticket or reservation without it. Under RA 10173 we remain accountable for information we transfer, and we require our supplier to protect it.
Third-party content on our pages: airline logos are loaded from a third-party image service
(images.kiwi.com), which means your browser contacts that service and it can see your IP address. We do not
send it any information about your booking.
We do not sell your personal information, and we do not share it for advertising.
4. Card payments
Card payments are processed by Maya, on their own secure hosted page. Your card details go directly to them and never reach our servers — we do not receive or store your card number, expiry, or CVV. We receive only the result of the payment and a masked reference (for example the last digits of the card), which we keep so we can match payments and process refunds.
5. Cookies
We use only what the site needs to function:
- A session cookie, so you stay signed in and your booking is preserved as you move between pages.
- A preference cookie recording whether you chose the 12-hour or 24-hour clock, kept for one year.
We do not use advertising or third-party tracking cookies.
6. How long we keep it
- Booking records — including passenger names, dates of birth and any passport details supplied — are kept as part of the transaction record. [STATE YOUR RETENTION PERIOD, e.g. "for N years after travel, to meet tax and accounting obligations". See the note below before completing this.]
- Technical API logs, which record the details sent to our supplier to make each booking, are kept for 30 days and then deleted automatically.
- Saved travellers are kept until you delete them or close your account.
[⚠️ NOTE FOR WHOEVER COMPLETES THIS — REMOVE BEFORE PUBLISHING. Do not state a retention period this platform does not yet implement. As of this draft there is no automated deletion of booking or passenger records, and passport numbers are retained in the stored supplier response. RA 10173 requires that personal information be kept only as long as necessary for the purpose. Either implement a retention schedule and then state it here, or state the retention you actually practise. Do not describe an intention as a fact.]
7. Deleting your account
If you delete your account, we remove your profile and your saved travellers.
Bookings you already made are not deleted. They are unlinked from your account and kept as part of our transaction records, because we are required to retain records of completed transactions. This means the passenger details on a past booking — including any passport details — remain in those records.
8. Your rights
Under RA 10173 you have the right to:
- Be informed about how your information is used — this notice
- Access the personal information we hold about you
- Correct anything inaccurate
- Object to processing, and to withdraw consent where we relied on it
- Erasure or blocking where the law allows it — note that we may need to retain transaction records to meet legal obligations, as described in section 7
- Data portability
- Lodge a complaint with the National Privacy Commission (privacy.gov.ph) if you believe your rights have been infringed
To exercise any of these, contact our Data Protection Officer below. We may need to verify your identity first.
9. Contact our Data Protection Officer
[DPO NAME] [DPO EMAIL] · [DPO CONTACT NUMBER] [REGISTERED ADDRESS]
Questions? Email [email protected].