Legal & Policies

Privacy Policy

Last updated: September 28, 2026 ·  Effective immediately

BookAeroFare.com is operated by People Information, LLC (“Company,” “we,” “us,” or “our”), an independent travel agency. We are not an airline. This policy explains how we collect, use, disclose, and protect personal information when you visit the website or contact us by phone. If you disagree, do not use the site. We do not sell travel to residents of California, Florida, Washington, Hawaii, or Iowa. See State licensing. EEA, UK, and Swiss readers should also read the GDPR Policy. California residents should read the CCPA Notice.

1. Information we collect

We collect information you provide and information collected automatically.

a) Information you provide

  • Full name and date of birth (required to ticket)
  • Email address and phone number
  • Billing address and payment details (the processor stores a token; we do not store the full card number or CVV)
  • Passport or government-issued ID details when the itinerary requires them
  • Travel preferences, frequent-flyer numbers, and special-assistance requests you ask us to add
  • Messages you send (calls, emails, contact form)

b) Information collected automatically

  • IP address, browser, device, and operating system
  • Pages viewed, time on page, and referring URLs
  • Cookies and similar technologies (see the Cookie Policy)
  • Call recordings, only when we give notice on the call
  • Advertising interaction data if you accept optional cookies

2. How we use your information

Booking and fulfillment

Take a request, vault the card, ticket on our GDS, charge when the airline ticket is issued, and email the airline PNR.

Customer support

Answer questions and submit changes, cancellations, and upgrades you request.

Payment

Charge the stored token when ticketed and process refunds the airline approves.

Communications

Send the request email, ticket-issued email, and service notices.

Marketing

Optional promotional email only with consent. You may opt out at any time.

Legal compliance

Tax, accounting, aviation security, and Seller of Travel rules.

Fraud prevention

Detect, investigate, and prevent fraudulent or abusive use.

Analytics

Understand site use. Google Analytics loads only if you accept optional cookies.

3. Legal bases (GDPR / UK GDPR)

For people in the EEA, UK, and Switzerland we rely on: contract (booking and ticketing); legal obligation (tax and Seller of Travel); legitimate interests (security and fraud prevention); and consent (optional cookies and marketing). Details are in the GDPR Policy.

4. Who we share information with

We do not sell personal information for money. We share data as needed to run Book Aero Fare:

  • Airlines and Amadeus GDS — a Book Aero Fare agent tickets your itinerary. The airline is a separate controller of the ticket and PNR.
  • NMI / Network Merchants — stores the card token and charges it when we issue the ticket.
  • Duffel — used only to display live fares. We do not create a Duffel order from this website.
  • Resend — sends booking-received and ticket-issued emails.
  • Vercel, Neon, and Cloudflare — host the site, database, DNS, and security.
  • Google LLC — analytics and ads, only if you accept optional cookies. That can be “sharing” under California law. See the CCPA Notice.
  • Professional advisers, insurers, or authorities when the law requires it, and a successor if the business is sold.

5. Cookies and tracking

Necessary cookies run so the site works. Analytics and advertising cookies (including Google Analytics 4, Google tags, and Google Ads) load only if you choose Accept on the cookie banner. Declining optional cookies does not stop you from searching fares or submitting a booking request. We honor the Global Privacy Control (GPC) signal as an opt-out of sale and sharing. Full details: Cookie Policy.

6. Retention

  • Booking and payment records: up to 7 years after the trip
  • Card vault: until the ticket is issued and charged, or the request is cancelled and the token is deleted
  • Fare-search session data: hours, not months
  • Support emails and call notes: up to 2 years unless a dispute requires longer
  • Call recordings (if made): up to 90 days
  • Optional cookies: until you withdraw consent or they expire
  • Security logs: typically up to 12 months

7. Security

We use TLS, access controls, and hosted infrastructure to protect data. Payment cards are handled by a PCI-DSS processor. We do not store the full card number or CVV on our servers. No internet transmission is guaranteed secure. We are not liable for unauthorized access beyond our reasonable control.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing, and to opt out of sale or sharing. California rights are described in the CCPA Notice. EEA/UK/Swiss rights are described in the GDPR Policy. Other US state privacy laws (for example Virginia, Colorado, Connecticut, Texas, and Oregon) may give similar rights to know, delete, correct, and opt out of targeted advertising. Email privacy@bookaerofare.com or call +1 (800) 903-1468. We verify identity before fulfilling a request and respond within the time the applicable law requires (typically 30–45 days).

9. Children

The website is not directed at children under 13, and we do not knowingly collect personal information from children under 13 for marketing. An adult may include a child’s passenger details on a booking. That adult is responsible for accuracy and for any consent the law requires. We do not use children’s data for advertising. If you believe we have collected a child’s data in error, contact us and we will delete it where we are not required to keep a ticket record.

10. International transfers

People Information, LLC is in the United States. Information may be processed in the US and by vendors in other countries. For EEA, UK, and Swiss transfers we use Standard Contractual Clauses, the UK IDTA/Addendum, and Data Privacy Framework certification where a vendor provides it. Airline and GDS transfers also follow the contract of carriage. See the GDPR Policy.

11. Third-party links

Airline and other third-party sites have their own privacy practices. We are not responsible for those sites.

12. Changes

We will post updates on this page and change the last-updated date. For material changes we will provide a more prominent notice where appropriate. Continued use after an update means you accept the revised policy, except where the law requires consent.

13. Contact

People Information, LLC — Privacy

2101 W San Juan Ave Suite 2, Phoenix, AZ 85015, USA

Email: privacy@bookaerofare.com

Phone: +1 (800) 903-1468

General inquiries: support@bookaerofare.com

Related: Cookie Policy · GDPR Policy · CCPA Notice · Fulfillment Policy · Advertiser Disclosure · Terms.