Legal
Privacy Policy
What personal information Jetvala collects, why we collect it, who we share it with and the choices you have.
Last updated September 4, 2026
Draft for attorney review, not yet effective
This document is a working draft. It has not been reviewed by counsel and does not yet apply to any booking. It will be replaced by the final version before Jetvala starts selling tickets.
Draft for attorney review. Not yet in effect. Items marked ATTORNEY REVIEW need confirmation before launch.
1. Who is responsible for your data
This policy is issued by Jetvala Travel LLC, doing business as Jetvala, located at 963 Park Ave, Plainfield, NJ 07060, US. We decide how and why your personal information is processed when you use jetvala.com, our apps, our WhatsApp and SMS channels, and our phone support. For privacy questions or requests, contact our Privacy Lead at privacy@jetvala.com.
We wrote this policy to satisfy the California Online Privacy Protection Act (CalOPPA), the California Consumer Privacy Act as amended by the CPRA (to the extent its thresholds apply to us), the New Jersey Data Privacy Act (NJDPA), and other US state privacy laws. We do not currently market to people in the European Union or United Kingdom. If you reach us from there, the GDPR or UK GDPR may still give you rights, and we will honor requests from you in the same way we honor requests from US residents. ATTORNEY REVIEW: confirm CCPA applicability once revenue and record counts are known; confirm whether an EU representative is needed.
2. What we collect
Information you give us when you search or book:
- Traveler details: full name, date of birth, gender as shown on your ID, and, where the airline or destination requires it, passport or national ID number, issuing country, expiry date and nationality.
- Secure Flight data required by the US Transportation Security Administration for flights touching the United States: name, date of birth, gender, and any Known Traveler Number or Redress Number you choose to give us (49 CFR Part 1560).
- Contact details: email address, phone number, WhatsApp number, billing address.
- Payment details: your card is processed by Stripe, our payment provider. Jetvala never receives your full card number. We keep the last four digits, card brand, and a payment token so we can process refunds.
- Hotel, transfer, car rental and tour details when you book or request a quote for those products.
- Travel preferences and special requests: meal, seat, wheelchair or other assistance, frequent flyer numbers.
- Messages you send us on WhatsApp, SMS, email, chat or phone, and notes our team makes while helping you.
- Anything you add to your account, such as saved travelers.
Information we collect automatically: IP address, device and browser type, language, pages viewed, searches made, referring site, and approximate location derived from IP. We collect this through server logs and the strictly necessary cookies described in our Cookie Notice. We do not use a third-party analytics or advertising service.
Information from others: airlines, hotels and our travel technology provider send us booking status, ticket numbers, schedule changes and refund decisions. Our payment provider sends us fraud signals. If you sign in through a third party in future, we will receive the identifiers you authorize.
Minors. Jetvala's services are for adults. A traveler under 18 must be booked by a parent or legal guardian, who attests at booking that they are entitled to book for the child and to give us the child's details. We do not knowingly collect information from children under 13 except as traveler details entered by a parent or guardian for a booking.
3. Why we use it
| Purpose | Examples | Legal basis (where required) |
|---|---|---|
| Making and managing your booking | sending traveler data to the airline or hotel, issuing tickets, sending confirmations and schedule changes, processing refunds | Contract |
| Legal duties | Secure Flight, sanctions screening, tax and accounting records, responding to lawful requests | Legal obligation |
| Support | answering your messages, resolving problems with the airline or provider | Contract, legitimate interest |
| Fraud prevention and security | checking payments, detecting abuse, protecting accounts | Legitimate interest, legal obligation |
| Improving Jetvala | understanding which routes people search, fixing bugs, testing features, using our own server logs | Legitimate interest |
| Marketing, only if you opt in | fare alerts, route news, promotions by email, SMS or WhatsApp | Consent |
We do not use your data for automated decisions that have legal or similarly significant effects on you. We do not sell your personal information, and we do not use it for targeted advertising.
4. Who we share it with
We share personal information only with parties who need it to serve you or where the law requires it.
| Recipient | What and why | Where |
|---|---|---|
| Airlines and their systems | Traveler, contact and Secure Flight data to issue and manage your ticket. Each airline handles your data under its own privacy policy. | Airline's country |
| Hotels and other travel providers | Guest and booking details for a stay, transfer, rental or tour you chose. | Provider's country |
| Duffel (flight and hotel booking platform) | Passes booking data between Jetvala and airlines or hotels. | United States and United Kingdom |
| Stripe (payments) | Processes your card payment and refunds and performs fraud screening. Jetvala never receives your full card number. | United States |
| Neon (database) | Hosts our encrypted database. | United States (US East) |
| Vercel (hosting and edge network) | Hosts the site and runs our application code. | United States |
| Resend (email delivery) | Sends transactional and, if you opted in, marketing email. | United States |
| Twilio (SMS and WhatsApp), only when those channels are enabled | Delivers transactional and, if you opted in, marketing messages. SMS and WhatsApp sending is not yet switched on. | United States |
| Referral partners for cars and tours | Only if you follow a referral link or accept a concierge quote; the partner receives the details needed for that booking under its own privacy policy. | Partner's country |
| Government agencies | TSA (Secure Flight), Customs and Border Protection, and foreign authorities where a destination requires passenger data (APIS), and law enforcement under valid legal process. | Various |
| Professional advisers and successors | Accountants, lawyers, insurers, and any buyer of the business under confidentiality. | United States |
Vendors process data under written terms that limit their use of your data to the services they provide to us. We will update this list when a vendor changes.
Cross-border transfers. Airlines, hotels and destination governments are often outside the United States. Your booking data travels to them because the trip requires it. Our own systems are hosted in the United States.
5. How long we keep it
| Data | Retention |
|---|---|
| Tax and accounting records | As required by applicable law, generally 3 years after the tax year, and longer where a specific law requires it |
| Booking records, receipts, disclosures shown at checkout, and refund evidence | 5 years after travel |
| Passport numbers and Secure Flight fields | Encrypted at rest with AES-256-GCM. Deleted 90 days after the last flight on the booking |
| Support messages and notes | 2 years after the last message |
| Marketing consent evidence (date, time, number, how you opted in) | As long as we rely on the consent, plus 4 years |
| Permanent suppression list (numbers and addresses that opted out) | Indefinitely, so we never contact you again by mistake |
| Login codes | 1 day |
| Search history | 400 days |
| Account data | Until you delete your account, then 30 days |
| Backups | Rolling backups, kept up to 35 days, then overwritten |
| Legal holds | Any data subject to a litigation hold, regulator request or open dispute is kept until the matter closes, then handled per the rows above |
ATTORNEY REVIEW: confirm the retention periods against IRS record-keeping rules, DOT complaint windows, the TCPA four-year statute of limitations, and state seller-of-travel record requirements once registrations are issued.
6. How we protect it
Data in transit is encrypted with TLS. Sensitive fields such as passport numbers are encrypted at rest with AES-256-GCM using keys held separately from the database. Access to passport data is restricted to staff who need it to help you and is recorded. Payment card data never touches our servers. We sign in with one-time email codes rather than passwords so there is no password for anyone to steal. No system is perfectly secure; if a breach affects your data, we will notify you and regulators as the law requires.
7. Your choices and rights
Depending on where you live, you may have the right to:
- Know what personal information we hold about you and receive a copy.
- Correct inaccurate information.
- Delete your information, subject to records we must keep by law.
- Opt out of the sale or sharing of personal information and of targeted advertising. Jetvala does not sell personal information and does not use it for targeted advertising, so there is nothing to opt out of today. We honor the Global Privacy Control browser signal and will treat it as an opt-out if that ever changes.
- Limit the use of sensitive personal information to what is needed to provide the service.
- Withdraw consent to marketing at any time. Reply STOP to any SMS or WhatsApp message, click unsubscribe in any marketing email, or contact us.
- Appeal a decision we make on your request.
- Not be discriminated against for exercising your rights.
To make a request, email our Privacy Lead at privacy@jetvala.com from the address on your booking, or write to us at 963 Park Ave, Plainfield, NJ 07060, US. We will verify your identity by sending a code to the email or phone on file and, for sensitive data, may ask for the booking reference. You can use an authorized agent; we will ask for proof of authorization. We respond within 45 days and will tell you if we need more time. New Jersey and California residents who disagree with our response can appeal by replying to our decision; we will answer the appeal within 45 days and tell you how to contact your state attorney general.
California residents. In the last 12 months we collected the categories listed in Section 2 for the purposes in Section 3 and disclosed them to the recipients in Section 4. We do not sell or share personal information as those terms are defined in the CCPA, and we have no actual knowledge of selling or sharing the data of anyone under 16. Under California's Shine the Light law you may ask once a year for a list of third parties to whom we disclosed personal information for their own direct marketing; we do not do this.
Nevada residents. We do not sell covered information as defined in NRS 603A. You may still submit an opt-out request to privacy@jetvala.com.
8. Do Not Track and Global Privacy Control
We honor the Global Privacy Control signal. Browsers' older "Do Not Track" setting has no agreed meaning, so we do not respond to it. We do not run analytics or advertising trackers on the site.
9. Marketing messages
We send marketing email only if you opt in, and every message has an unsubscribe link. We send marketing SMS or WhatsApp messages only with your prior express written consent, given separately for each channel, which is never required to book. Message and data rates may apply. Reply STOP to stop, HELP for help. Details are on our SMS and WhatsApp Consent page.
10. Links to other sites
Airline, hotel, partner and government sites have their own privacy policies. We are not responsible for them.
11. Changes to this policy
When we change this policy, we will update the date at the top and, for material changes, notify you by email or a notice on the site before the change applies. Past versions are available on request.
12. Contact
- Privacy requests: Privacy Lead, privacy@jetvala.com
- General support: support@jetvala.com
- Mail: Jetvala Travel LLC, 963 Park Ave, Plainfield, NJ 07060, US
ATTORNEY REVIEW: confirm NJDPA applicability thresholds (100,000 consumers, or 25,000 consumers plus revenue from data sales). The NJDPA universal opt-out mechanism obligation applies only to controllers that sell personal data or process it for targeted advertising; Jetvala does neither today, so no universal opt-out mechanism is implemented beyond honoring Global Privacy Control. Revisit if either activity begins.