Privacy Policy

Last updated: 2025-04-03

This policy sets out what we collect when you use AirBooking, why, who sees it, how long we keep it, and what you can ask us to do with it. It is written to meet India's Digital Personal Data Protection Act, 2023 and the UAE's Personal Data Protection Law, Federal Decree-Law No. 45 of 2021.

Who is responsible for your data

Two companies operate AirBooking. Which one is responsible for your data depends on where you are billed.

Billed in India, in rupees: AIRBOOKING TRAVEL AND TOURS PRIVATE LIMITED, CIN U79110KL2020PTC062822, Door No. 25/14, Ohm Nivas, K T Gopalan Road, Kottooli, Kuthiravattom, Kozhikode 673016, Kerala, India. It is the Data Fiduciary under the DPDP Act.

Billed anywhere else: AirBooking Technology LLC, Office No. 716, Business Village, B Block, Deira, Dubai, PO Box 117402, United Arab Emirates. It is the Controller under the UAE PDPL.

The two companies share one platform and one support team, so either may handle your record when a booking or a request needs it. "AirBooking", "we" and "us" means whichever company is responsible for you.

Who this covers

Anyone who visits AirBooking, starts a conversation, searches or books, or creates an account, on the website or in the iOS and Android apps. It also covers the travellers you add to a booking; by adding them you confirm you may give us their details. People who use AirBooking through their employer, travel agency or travel management company are covered too, with the differences set out under "Booking through your organisation".

What we collect

What you give us, and what a search or a booking needs.

  • Name, email address and phone number, for you and each traveller you add. Date of birth and gender when an airline requires them.
  • Passport or national ID details (number, nationality, issue and expiry dates) when the airline or the destination requires them for the ticket.
  • Trip details: dates, cities, cabin or room preferences, seat, meal or accessibility requests, and what you type or say to the assistant so we can search.
  • Voice, if you speak to the assistant instead of typing: the audio is processed as it streams, turned into text, and not recorded. See "Talking to the assistant".
  • Booking records: confirmations, tickets, invoices, changes, refunds.
  • Payment results. We never see or store your full card number. Card details go into a payment page run by Razorpay (rupee payments) or Stripe (everything else). They return a confirmation, the card type and the last four digits, which is what we need for a receipt and a refund. A card you choose to save is stored as a network token issued under the card scheme's rules and, in India, the Reserve Bank of India's tokenisation rules. The card number is never held by us.
  • Account details: login, saved travellers, communication preferences.
  • Technical data: device type, operating system, app version, IP address, browser, an approximate location derived from your IP address or billing country, and the logs that keep the service running and secure.

If you add preferences later, we keep them so we do not ask twice.

Some of this reveals more than it seems to. A meal preference can indicate a religion, an assistance request can indicate a health condition, a passport shows nationality. We collect these only when you ask for the service that needs them, pass them only to the supplier that has to act on them, and use them for nothing else.

The app asks for a device permission only when a feature needs it: the microphone when you speak to the assistant, notifications so we can tell you about a gate change. Refuse or revoke any permission in your device settings; the feature that depends on it stops, nothing else does.

Why we use it

Most of what we do is carry out the booking you asked for: search, hold, book, ticket, change, refund, show you your trips, invoice you, and send the messages a booking requires. In India this is processing you consent to when you book. In the UAE it is processing needed to perform our contract with you.

Some of it is required by law: tax and accounting records, lawful requests from courts, regulators, immigration and aviation authorities, and the fraud and sanctions checks that payment providers and airlines require.

Some of it is running the service properly: monitoring for security problems and fraud, fixing errors, and looking at how the product is used so we can improve it, in ways that do not override your interests.

Anything else, such as marketing or optional cookies, we ask for separately. You can withdraw that consent at any time, as easily as you gave it. Withdrawing does not undo processing that already happened.

We do not sell your information. We do not use the conversation to advertise other companies' products to you.

Two things are automated. The order in which travel options appear is set by rules weighing price, timing, your preferences and, for organisation bookings, the travel policy. And payment providers and airlines run fraud and sanctions screening that can decline a payment. If a decline affects you and you think it is wrong, contact us and a person will look at it. We make no other automated decisions with a legal or similarly serious effect on you.

Talking to the assistant

You can type to the assistant or speak to it. Speaking is optional; everything the assistant does can be done by typing.

We do not use your data to train artificial intelligence or large language models. Nothing you say, type, search for or book is used to train, fine-tune or improve any AI or language model, whether ours or anyone else's. Your conversations are used to answer you and to complete the booking you asked for, and for nothing else.

The microphone is used only while you have started a voice conversation. It is not open in the background, before you start or after you end one, and the app asks for microphone permission the first time you use the feature. End the conversation, turn the microphone off in the app, or revoke the permission in your device settings, and the capture stops.

Understanding speech takes specialist services we do not run ourselves. While you are speaking, the audio is streamed over an encrypted connection to a speech recognition provider, which turns it into text and, for the assistant's reply, turns text back into speech. Only that text, never the audio, then goes to an artificial intelligence provider that works out what you are asking for; if it is unavailable, the same text goes to a second such provider so the conversation does not break mid-booking.

We use these services on enterprise terms. Each provider acts strictly as our processor, on our instructions: it may use what it receives only to return the result we asked for, it is contractually prohibited from using your data to train or improve its models, and it may not use, keep or disclose your data for any purpose of its own. Your data is not part of any consumer or free service tier and is not pooled with other companies' data. We can tell you who these providers are on request.

We do not record your voice. The audio is processed as it streams and is not saved by us or written to our servers. What is kept is the text of the conversation, which the assistant needs to follow what you have already told it, and which is held under "How long we keep it" below: with the booking if you make one, and for 12 months from your last activity if you do not.

Your voice is not used to identify you, is not matched against any voiceprint, and is never used for advertising or shared with advertising or analytics companies.

Your data is not used to train any LLM models.

Using our apps

The app asks for a device permission only when a feature needs it, and each one is optional. The microphone is used when you speak to the assistant. Notifications, if you allow them, tell you about your bookings. Face ID, Touch ID or fingerprint unlock is used only if you turn it on.

If you turn on biometric unlock, the check happens entirely on your device, through the operating system. We never receive, see or store your fingerprint or face data; all we get is the device's confirmation that the check passed.

To keep you signed in and the app working, we store your session, your email address and your preferences in the protected storage your operating system provides, the iOS Keychain or the Android Keystore. It stays on your device. Signing out or deleting the app removes it.

When you save or share a ticket, invoice or itinerary, the app creates the document on your device and hands it to whichever app you choose. It contains traveller names and booking details, so anyone you send it to can see them. We are not part of that transfer and cannot recall a document once you have shared it.

We send notifications about bookings you have made. Marketing notifications are sent only if you opt in, and you can turn them off in the app or in your device settings. Notifications a booking requires, such as a cancellation or a schedule change, are sent regardless, because you need them to travel.

Who we share it with

A booking has to reach the airline, hotel or activity operator and, when you pay, the payment provider. Each gets only what it needs for its step.

Airlines, hotels, activity operators, and the distribution systems and consolidators we book through, receive traveller names, contact details, travel documents where required, and the booking. From there they process it under their own privacy terms, which we show you before you pay.

Razorpay and Stripe receive payment details directly and return the result. Each is a separate controller for the payment data it holds.

Companies that host or secure the product for us (cloud infrastructure, email and messaging delivery, customer support tools, analytics) act on our instructions under contract. So do the speech recognition and artificial intelligence providers behind the assistant, described under "Talking to the assistant", and the provider that delivers push notifications to your device. Each is engaged on enterprise terms as our processor: it may use your data only to perform the service we asked for, not for any purpose of its own, and never to train or improve its models.

Our group companies, meaning the two companies named above and AirBooking Travel and Tours LLC (UAE), see your record where a booking or a support request needs it.

Authorities receive data when the law requires it, when an airport, border, immigration or aviation authority asks for passenger data, or when we need to protect our rights or someone's safety.

If AirBooking is sold or merges, your data goes with it under the same protections.

We do not give your data to data brokers. Advertising and measurement tools, such as those from Meta or Google, run only if you accept advertising cookies on the website or allow tracking in the app, and receive only what is needed to measure our own campaigns. They never receive travel documents, booking details, or anything you say to the assistant.

Booking through your organisation

When your employer, travel agency or travel management company gives you access to AirBooking, that organisation decides why and how your travel data is processed. It is the Data Fiduciary (India) or Controller (UAE) for the data it gives us and for bookings made under its account; we process that data on its instructions, under our agreement with it. Its own privacy notice tells you what it does with your travel data.

The organisation can see the bookings made under its account, including itineraries, traveller names, spend, and whether a booking was inside its travel policy. It sets how long that data is kept and can ask us to return or delete it when it stops using AirBooking. Requests to see, correct or delete data held under an organisation's account go to the organisation; if you send one to us, we pass it on and help the organisation answer.

Two things stay with us. We remain responsible for the security of the platform. And the business contact details of the people who run the organisation's account with us (names, work emails, roles) are processed by us in our own right, for account management, billing and support.

If you also have a personal AirBooking account, the two are kept apart. Your organisation cannot see your personal bookings.

Where your data is stored

The platform runs on cloud infrastructure that may be outside the country you are in, and booking data has to reach the airline, hotel or operator wherever they are.

If you are in India, your data may be transferred to and stored in the UAE and other countries where our infrastructure and suppliers operate. Section 16 of the DPDP Act permits this except to countries the Central Government restricts.

If you are in the UAE, we transfer data abroad where the destination has adequate protection or, where it does not, on the basis of your consent, the transfer being necessary for your booking, or contractual safeguards, under Articles 22 and 23 of the PDPL.

The same protections apply wherever the data sits.

How long we keep it

Booking records, meaning tickets, invoices and the conversation that produced them, for as long as you may need them and as long as tax, accounting and dispute rules require: in India generally eight years from the end of the financial year of the booking, in the UAE between five and seven years depending on the record. Account data for as long as the account is open.

Travel document details only for the booking that needed them; they are removed once the trip has ended and any refund or dispute window has closed. Conversations that did not lead to a booking, including the text of anything you spoke to the assistant, 12 months from the last activity. Technical logs, normally 90 days, longer only for a security investigation. Voice audio is not retained at all. Our speech and AI providers do not keep your data beyond what is needed to return the result we asked for, and no copy of it survives in any model, because your data is never used to train one.

Data held under an organisation's account, for the period set in the organisation's agreement with us; returned or deleted when the agreement ends.

When a retention period ends we delete the data or make it anonymous. If you have not used your account for three years we write to you; if you do not respond we close the account and delete everything the law does not require us to keep.

Your rights

You can ask to see the information we hold about you, to correct or complete it, to delete it where the law allows, and to be told who we have shared it with. You can withdraw any consent you gave. You can object to processing that is not needed to complete a booking you already made. In India you can nominate someone to exercise these rights for you if you die or lose capacity.

Ask in the conversation, use your account settings, or write to the address at the end of this page. We need enough detail to find the right record and confirm it is you. We answer within 30 days. India's DPDP Rules allow up to 90 days; if we ever need longer than 30 we tell you why.

Some booking records must stay after a deletion request because tax law or an open dispute requires it. We tell you what we are keeping and why.

Deleting your account

You can ask us to delete your account and its data at any time. Write to support@airbooking.com from the email address on your account. We may check it is you before we act, so nobody else can close your account. We acknowledge within 48 hours and complete the deletion within 30 days.

Deletion removes your login, saved travellers, saved preferences and conversation history. Booking and invoice records we are legally required to keep are separated from your account, held for that purpose only, then deleted. If you have an untravelled trip or an open refund or dispute, we tell you what has to stay until it closes.

Marketing

You receive marketing from us only if you tick the marketing box at checkout or in your account. The box is unticked by default and is separate from accepting the Terms. Every marketing email, SMS or WhatsApp message has an unsubscribe route, and you can change the setting in your account. Messages a booking requires, meaning the confirmation, e-ticket, schedule change, cancellation or receipt, are not marketing and are sent regardless, including to Indian numbers on the DND register, because you need them to travel.

If your organisation gave you access, we send you no marketing unless you opt in on a personal account.

Cookies

Cookies that keep you signed in, remember a guest session and keep the product working are necessary and always on. Analytics and advertising cookies are set only if you accept them in the notice on your first visit; change your choice from the cookie settings link in the footer. We do not use cookies to follow you around other websites.

Security

Data is encrypted in transit and at rest. Access is limited to staff who need it and is logged. Payment pages are run by payment providers certified under PCI DSS; card details belong there and never in a message to the concierge. No method of transmission is perfect. If a breach affects your personal data we tell you, and we notify the Data Protection Board of India or the UAE Data Office as the law requires.

Children

You must be 18 or over to create an account or book. Children can travel on a booking made by an adult, and a child's name and date of birth on a ticket are used only for that booking. We do not knowingly create accounts for children and do not use children's data for tracking, profiling, advertising, or to train artificial intelligence models. If you believe a child has created an account, tell us and we delete it.

Grievance and data protection contacts

Come to us first with any question or complaint about your data and we respond within the timelines above.

India, under the DPDP Act and the Consumer Protection (E-Commerce) Rules, 2020: Grievance Officer Kavitha Jaganathan, AIRBOOKING TRAVEL AND TOURS PRIVATE LIMITED, Door No. 25/14, Ohm Nivas, K T Gopalan Road, Kottooli, Kuthiravattom, Kozhikode 673016, Kerala, India, support@airbooking.com, +91 89430 86351. We acknowledge grievances within 48 hours and resolve them within one month. If you are not satisfied, you can complain to the Data Protection Board of India.

UAE, under the PDPL: data protection contact Kavitha Jaganathan, AirBooking Technology LLC, Office No. 716, Business Village, B Block, Deira, Dubai, PO Box 117402, support@airbooking.com. If you are not satisfied, you can complain to the UAE Data Office.

Changes to this policy

We may update this page. The date at the top is the version in force. If a change is material, we tell you in the product or by email before it takes effect.

Related

Bookings are governed by our Terms of booking, which include the cancellation and refund policy.

Contact

Privacy questions go through the same door as everything else: ask in the conversation, or write to support@airbooking.com. Postal addresses and support hours are on the Contact page.