Security and data
How we protect your data
A secure connection, encrypted document numbers, no stored card data and the data minimisation rule.
What this is for
You leave important things with us: your e-mail address, phone number, sometimes a passport number.
This article says in plain words what we do with them and how we look after them.
Who it is for
For everyone. You do not need to be logged in to read this.
What you see
The "Privacy and data protection" page has these sections:
- Data controller — who is responsible for your data.
- Scope and data minimisation — how much data we collect.
- Traveller documents — how we protect passport numbers.
- Marketing consents — how consent to advertising works.
- Your rights — what you can do with your data.
- Data retention — how long we keep data.
At the bottom there is the date of the last update.
Step by step
You do not have to do anything — the protection works by itself. But you can check a few things yourself:
- Look at the address in your browser. It should start with
https://, with a closed padlock symbol next to it. That means the connection is encrypted. - Go to "Settings" → "Privacy and data". You will see what data we hold about you.
- Click "Download JSON export" to read all of it.
- Turn on two-step verification in "Settings". That is the single most effective thing you can do for the safety of your account.
- Check "Active sessions" and log out devices you no longer use.
What happens next
An encrypted connection (HTTPS)
Everything you send us and everything we send you travels through an encrypted channel. The https and the padlock in your browser say so. Nobody along the way can read your password or traveller details.
Traveller document numbers
This is the most sensitive data you leave with us. We treat it specially:
- We save it only when the fare or the carrier requires it, and only with your explicit consent.
- We encrypt it as soon as the form is sent, with the AES-256-GCM cipher.
- The number never comes back to the browser and never lands in our event logs. The panel only shows the type, expiry date and country of issue: "The document number is encrypted — we only show the type, validity and country of issue.".
- The only place you see it decrypted is your GDPR export, downloaded after entering your password; its link lives 10 minutes and works once.
Payment card data
We do not store your card data. We do not even hold it for a moment.
You give the card number, expiry date and CVC code on the payment operator's page (Stripe). We only get the information "it worked" or "it did not work". The same goes for the BLIK code — the payment page says clearly: "You will type the BLIK code on the secure payment page — we do not collect it here.".
Data minimisation
We collect only what is genuinely needed to deliver the service: contact details, traveller details and billing details. Nothing more.
That is why, for example, the travel document and the frequent flyer number are optional. We only ask for them when the carrier requires them.
When data goes to a partner
We pass traveller details to the service provider only after the booking is paid. We say so under the form: "We pass traveller details to the service provider only after the booking is paid.".
Retention, or how long we keep data
- Saved travellers — up to 540 days from saving. After that the data anonymises itself and disappears. You see the date on each traveller card as "Retention until".
- Booking documents — available only to the owner, once logged in.
- Billing data — we keep it as long as tax law requires. After you delete your account it stays, but with no link to you.
Breached password checking
When you set or change a password, we check whether it has appeared in a known data breach from other websites. We do it safely: we send only the first five characters of the password hash to an outside service, and do the matching ourselves. Your password never leaves our server.
Account protection
- A password must be at least 12 characters.
- After 10 failed logins the account locks for 15 minutes.
- You can turn on two-step verification with a code from an app.
- You can see the list of active sessions and log them out.
- Every sensitive operation (data export, account deletion, 2FA changes) needs your password again.
Frequent questions
Can somebody at Airsockfly read my passport number? The number is encrypted in the database. It is decrypted at only two moments: when we pass the details to the carrier after the booking is paid, and when you download your own GDPR export after entering your password.
Do you sell my data? No. Data goes only to partners who must know it to deliver your service, such as the carrier issuing your ticket.
What if I suspect somebody got into my account? Change your password, click "Log out other devices", turn on two-step verification and write to us through "Support".
Is my profile photo public? No. Only you see it on your account.
Where can I read the full rules? On the "Privacy and data protection" page (footer link). Your rights plus the export and deletion buttons are in "Settings" → "Privacy and data".