OnwardAir

Privacy Policy

Last updated 20 September 2026 · BOOSTER.LLC

In plain terms. To place an airline reservation we need the passenger's name and date of birth as they appear in the passport, plus an email address to send the itinerary to. That information goes to the airline, because that is the whole point of it. We never sell anything about you, and we never see your card number.

1. Who is responsible for your data

BOOSTER.LLC, company number Pending — registration number to be published, of Los Angeles, California, United States — full registered address to be published, is the controller of the personal data described here.

For any question about this policy or about your data, write to [email protected]. We are established in United States.

2. What we collect, and why

DataWhy we need itLawful basis
Passenger full name, exactly as in the passport An airline reservation cannot exist without a passenger name, and the name must match the travel document for the reservation to be of any use to you Performance of our contract with you
Date of birth Required by the airline distribution system to create a booking. We do not use it for anything else and we do not profile on it Performance of our contract
Title and gender marker Airlines record one alongside the passenger name and reject a booking without it Performance of our contract
Email address To send your booking reference and itinerary, to sign you in, and to warn you before a hold expires Performance of our contract
Route, dates, cabin, passenger count To search fares and place the reservation Performance of our contract
Payment records — amount, currency, status, Stripe identifiers, the last four digits and card brand as Stripe reports them To take payment, issue refunds, answer disputes and keep accounting records Performance of our contract; legal obligation for the accounting records
Telephone number, if you give one Optional. Passed to the airline as a booking contact where required Performance of our contract
IP address, browser and device information, timestamps To keep accounts secure, apply rate limits, and prevent abuse of paid airline systems Our legitimate interest in running the service securely
Support correspondence To answer you and to keep a record of what was agreed Performance of our contract; our legitimate interest in defending claims

We do not ask for passport numbers, document scans, photographs or nationality. If you send them to us anyway, we delete them and ask you not to send them again.

We do not handle special category data. The gender marker an airline requires is recorded for that purpose alone.

We never see your card number. Card details are collected by Stripe on Stripe's own pages and never reach our servers.

3. Children

The Service is for adults. We do not knowingly collect data about anyone under 18, and adult passengers only are accepted. If you believe a child's data has reached us, write to us and we will delete it.

4. Who we share it with

We share only what each recipient needs, and only to deliver the Service. We do not sell personal data and we do not share it for anyone else's marketing.

RecipientWhat they receiveRole
Duffel (airline distribution) and, through them, the operating airline Passenger name, date of birth, title, email, route and dates Processor for Duffel; the airline acts as its own controller once the booking exists
Stripe Email, name, amount, and the card details you enter on Stripe's pages Independent controller for payments and fraud prevention
Our email provider Email address and the contents of the messages we send you Processor
Our hosting and network providers Data held on the server; IP addresses at the network edge Processor
Professional advisers, authorities Only what is required, only when we are legally obliged or must defend a legal claim Controller in their own right

Once the airline holds a reservation, that booking sits in the airline's system under its own privacy terms. We cannot delete it there; it expires on its own at the hold deadline.

5. International transfers

Airlines and our providers operate globally, so your data may be processed outside the country you live in, including outside the UK and the EEA. Where that happens we rely on the safeguards those providers have in place, such as the European Commission's standard contractual clauses or an adequacy decision. A reservation on an international route necessarily involves the carrier's own systems, wherever they are.

6. How long we keep it

RecordKept forWhy
Order and itinerary records24 months from the order To answer questions and disputes, and to prove what was delivered
Payment and accounting recordsAs long as tax law requires, typically 6 to 7 years Legal obligation
Account and sign-in recordsWhile the account exists, then 12 months Security and dispute handling
Sign-in codes15 minutes, then deletedThey are single-use
Security and rate-limit logs90 daysAbuse prevention
Support correspondence24 months from the last messageContinuity of support

When a period ends the record is deleted or irreversibly anonymised.

7. Your rights

Depending on where you live, you have some or all of the following rights. In the UK and the EEA you have all of them.

Write to [email protected]. We respond within 30 days and we do not charge for it. We may ask you to confirm the email address on the account, because that is how we know who you are.

If you are unhappy with our answer you can complain to your data protection authority. In the UK that is the Information Commissioner's Office; in the EEA it is the supervisory authority where you live.

8. Cookies and similar technology

We keep this deliberately small.

WhatPurposeLasts
oa_session cookieKeeps you signed in. Strictly necessary; set only after you sign in30 days
Browser local storageRemembers your last search and your draft booking so a refresh does not lose it. Never leaves your deviceUntil you clear it
Network-edge cookiesSet by our CDN to filter malicious traffic. Strictly necessary Up to 30 days

We use no advertising cookies, no analytics that identify you, and no cross-site tracking. Because everything we set is strictly necessary for a service you asked for, no consent banner is required. Stripe sets its own cookies on its own checkout pages, governed by Stripe's privacy policy.

9. Email we send you

We send transactional email only: your itinerary, expiry warnings, payment receipts and answers to your questions. These are part of the service and are not marketing.

If we ever introduce a newsletter it will be opt-in, separate from this, and unsubscribing will never affect the transactional messages you need.

10. How we protect it

No system is perfect. If a breach occurs that is likely to put your rights at risk, we notify the relevant authority within 72 hours and tell you directly where the law requires it.

11. Automated decisions

We do not make decisions about you by automated means that produce legal effects. Rate limiting and abuse checks may temporarily refuse a request; if that happens to you in error, email us and a person will look at it.

12. Changes

We update this policy when what we do changes. The date at the top is the date of the last change. If a change materially affects you, we will tell you by email before it takes effect.

13. Contact

BOOSTER.LLC
Los Angeles, California, United States — full registered address to be published
[email protected]