Privacy Policy
Last updated 20 September 2026 · BOOSTER.LLC
1. Who is responsible for your data
BOOSTER.LLC, company number Pending — registration number to be published, of Los Angeles, California, United States — full registered address to be published, is the controller of the personal data described here.
For any question about this policy or about your data, write to [email protected]. We are established in United States.
2. What we collect, and why
| Data | Why we need it | Lawful basis |
|---|---|---|
| Passenger full name, exactly as in the passport | An airline reservation cannot exist without a passenger name, and the name must match the travel document for the reservation to be of any use to you | Performance of our contract with you |
| Date of birth | Required by the airline distribution system to create a booking. We do not use it for anything else and we do not profile on it | Performance of our contract |
| Title and gender marker | Airlines record one alongside the passenger name and reject a booking without it | Performance of our contract |
| Email address | To send your booking reference and itinerary, to sign you in, and to warn you before a hold expires | Performance of our contract |
| Route, dates, cabin, passenger count | To search fares and place the reservation | Performance of our contract |
| Payment records — amount, currency, status, Stripe identifiers, the last four digits and card brand as Stripe reports them | To take payment, issue refunds, answer disputes and keep accounting records | Performance of our contract; legal obligation for the accounting records |
| Telephone number, if you give one | Optional. Passed to the airline as a booking contact where required | Performance of our contract |
| IP address, browser and device information, timestamps | To keep accounts secure, apply rate limits, and prevent abuse of paid airline systems | Our legitimate interest in running the service securely |
| Support correspondence | To answer you and to keep a record of what was agreed | Performance of our contract; our legitimate interest in defending claims |
We do not ask for passport numbers, document scans, photographs or nationality. If you send them to us anyway, we delete them and ask you not to send them again.
We do not handle special category data. The gender marker an airline requires is recorded for that purpose alone.
We never see your card number. Card details are collected by Stripe on Stripe's own pages and never reach our servers.
3. Children
The Service is for adults. We do not knowingly collect data about anyone under 18, and adult passengers only are accepted. If you believe a child's data has reached us, write to us and we will delete it.
4. Who we share it with
We share only what each recipient needs, and only to deliver the Service. We do not sell personal data and we do not share it for anyone else's marketing.
| Recipient | What they receive | Role |
|---|---|---|
| Duffel (airline distribution) and, through them, the operating airline | Passenger name, date of birth, title, email, route and dates | Processor for Duffel; the airline acts as its own controller once the booking exists |
| Stripe | Email, name, amount, and the card details you enter on Stripe's pages | Independent controller for payments and fraud prevention |
| Our email provider | Email address and the contents of the messages we send you | Processor |
| Our hosting and network providers | Data held on the server; IP addresses at the network edge | Processor |
| Professional advisers, authorities | Only what is required, only when we are legally obliged or must defend a legal claim | Controller in their own right |
Once the airline holds a reservation, that booking sits in the airline's system under its own privacy terms. We cannot delete it there; it expires on its own at the hold deadline.
5. International transfers
Airlines and our providers operate globally, so your data may be processed outside the country you live in, including outside the UK and the EEA. Where that happens we rely on the safeguards those providers have in place, such as the European Commission's standard contractual clauses or an adequacy decision. A reservation on an international route necessarily involves the carrier's own systems, wherever they are.
6. How long we keep it
| Record | Kept for | Why |
|---|---|---|
| Order and itinerary records | 24 months from the order | To answer questions and disputes, and to prove what was delivered |
| Payment and accounting records | As long as tax law requires, typically 6 to 7 years | Legal obligation |
| Account and sign-in records | While the account exists, then 12 months | Security and dispute handling |
| Sign-in codes | 15 minutes, then deleted | They are single-use |
| Security and rate-limit logs | 90 days | Abuse prevention |
| Support correspondence | 24 months from the last message | Continuity of support |
When a period ends the record is deleted or irreversibly anonymised.
7. Your rights
Depending on where you live, you have some or all of the following rights. In the UK and the EEA you have all of them.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything inaccurate.
- Erasure — deletion, where we no longer need the data and no legal obligation requires us to keep it.
- Restriction and objection — including objecting to processing we carry out on the basis of legitimate interest.
- Portability — your data in a machine-readable form.
- Withdraw consent, where we relied on consent, without affecting what came before.
Write to [email protected]. We respond within 30 days and we do not charge for it. We may ask you to confirm the email address on the account, because that is how we know who you are.
If you are unhappy with our answer you can complain to your data protection authority. In the UK that is the Information Commissioner's Office; in the EEA it is the supervisory authority where you live.
8. Cookies and similar technology
We keep this deliberately small.
| What | Purpose | Lasts |
|---|---|---|
oa_session cookie | Keeps you signed in. Strictly necessary; set only after you sign in | 30 days |
| Browser local storage | Remembers your last search and your draft booking so a refresh does not lose it. Never leaves your device | Until you clear it |
| Network-edge cookies | Set by our CDN to filter malicious traffic. Strictly necessary | Up to 30 days |
We use no advertising cookies, no analytics that identify you, and no cross-site tracking. Because everything we set is strictly necessary for a service you asked for, no consent banner is required. Stripe sets its own cookies on its own checkout pages, governed by Stripe's privacy policy.
9. Email we send you
We send transactional email only: your itinerary, expiry warnings, payment receipts and answers to your questions. These are part of the service and are not marketing.
If we ever introduce a newsletter it will be opt-in, separate from this, and unsubscribing will never affect the transactional messages you need.
10. How we protect it
- Everything travels over HTTPS; the site refuses plain HTTP.
- Sign-in uses one-time codes, not passwords, so there is no password to steal from us.
- Session tokens are stored hashed, never in plain text.
- Links to an itinerary carry a signed token tied to that single booking.
- The database sits on a server with no public access, behind a firewall, and is backed up daily.
- Card data never touches our systems.
No system is perfect. If a breach occurs that is likely to put your rights at risk, we notify the relevant authority within 72 hours and tell you directly where the law requires it.
11. Automated decisions
We do not make decisions about you by automated means that produce legal effects. Rate limiting and abuse checks may temporarily refuse a request; if that happens to you in error, email us and a person will look at it.
12. Changes
We update this policy when what we do changes. The date at the top is the date of the last change. If a change materially affects you, we will tell you by email before it takes effect.
13. Contact
BOOSTER.LLC
Los Angeles, California, United States — full registered address to be published
[email protected]