Legal & Policies
Privacy Policy
Last updated: September 28, 2026 · Effective immediately
BookAeroFare.com is operated by People Information, LLC (“Company,” “we,” “us,” or “our”), an independent travel agency. We are not an airline. This policy explains how we collect, use, disclose, and protect personal information when you visit the website or contact us by phone. If you disagree, do not use the site. We do not sell travel to residents of California, Florida, Washington, Hawaii, or Iowa. See State licensing. EEA, UK, and Swiss readers should also read the GDPR Policy. California residents should read the CCPA Notice.
1. Information we collect
We collect information you provide and information collected automatically.
a) Information you provide
- Full name and date of birth (required to ticket)
- Email address and phone number
- Billing address and payment details (the processor stores a token; we do not store the full card number or CVV)
- Passport or government-issued ID details when the itinerary requires them
- Travel preferences, frequent-flyer numbers, and special-assistance requests you ask us to add
- Messages you send (calls, emails, contact form)
b) Information collected automatically
- IP address, browser, device, and operating system
- Pages viewed, time on page, and referring URLs
- Cookies and similar technologies (see the Cookie Policy)
- Call recordings, only when we give notice on the call
- Advertising interaction data if you accept optional cookies
2. How we use your information
Booking and fulfillment
Take a request, vault the card, ticket on our GDS, charge when the airline ticket is issued, and email the airline PNR.
Customer support
Answer questions and submit changes, cancellations, and upgrades you request.
Payment
Charge the stored token when ticketed and process refunds the airline approves.
Communications
Send the request email, ticket-issued email, and service notices.
Marketing
Optional promotional email only with consent. You may opt out at any time.
Legal compliance
Tax, accounting, aviation security, and Seller of Travel rules.
Fraud prevention
Detect, investigate, and prevent fraudulent or abusive use.
Analytics
Understand site use. Google Analytics loads only if you accept optional cookies.
3. Legal bases (GDPR / UK GDPR)
For people in the EEA, UK, and Switzerland we rely on: contract (booking and ticketing); legal obligation (tax and Seller of Travel); legitimate interests (security and fraud prevention); and consent (optional cookies and marketing). Details are in the GDPR Policy.
4. Who we share information with
We do not sell personal information for money. We share data as needed to run Book Aero Fare:
- Airlines and Amadeus GDS — a Book Aero Fare agent tickets your itinerary. The airline is a separate controller of the ticket and PNR.
- NMI / Network Merchants — stores the card token and charges it when we issue the ticket.
- Duffel — used only to display live fares. We do not create a Duffel order from this website.
- Resend — sends booking-received and ticket-issued emails.
- Vercel, Neon, and Cloudflare — host the site, database, DNS, and security.
- Google LLC — analytics and ads, only if you accept optional cookies. That can be “sharing” under California law. See the CCPA Notice.
- Professional advisers, insurers, or authorities when the law requires it, and a successor if the business is sold.
5. Cookies and tracking
Necessary cookies run so the site works. Analytics and advertising cookies (including Google Analytics 4, Google tags, and Google Ads) load only if you choose Accept on the cookie banner. Declining optional cookies does not stop you from searching fares or submitting a booking request. We honor the Global Privacy Control (GPC) signal as an opt-out of sale and sharing. Full details: Cookie Policy.
6. Retention
- Booking and payment records: up to 7 years after the trip
- Card vault: until the ticket is issued and charged, or the request is cancelled and the token is deleted
- Fare-search session data: hours, not months
- Support emails and call notes: up to 2 years unless a dispute requires longer
- Call recordings (if made): up to 90 days
- Optional cookies: until you withdraw consent or they expire
- Security logs: typically up to 12 months
7. Security
We use TLS, access controls, and hosted infrastructure to protect data. Payment cards are handled by a PCI-DSS processor. We do not store the full card number or CVV on our servers. No internet transmission is guaranteed secure. We are not liable for unauthorized access beyond our reasonable control.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing, and to opt out of sale or sharing. California rights are described in the CCPA Notice. EEA/UK/Swiss rights are described in the GDPR Policy. Other US state privacy laws (for example Virginia, Colorado, Connecticut, Texas, and Oregon) may give similar rights to know, delete, correct, and opt out of targeted advertising. Email privacy@bookaerofare.com or call +1 (800) 903-1468. We verify identity before fulfilling a request and respond within the time the applicable law requires (typically 30–45 days).
9. Children
The website is not directed at children under 13, and we do not knowingly collect personal information from children under 13 for marketing. An adult may include a child’s passenger details on a booking. That adult is responsible for accuracy and for any consent the law requires. We do not use children’s data for advertising. If you believe we have collected a child’s data in error, contact us and we will delete it where we are not required to keep a ticket record.
10. International transfers
People Information, LLC is in the United States. Information may be processed in the US and by vendors in other countries. For EEA, UK, and Swiss transfers we use Standard Contractual Clauses, the UK IDTA/Addendum, and Data Privacy Framework certification where a vendor provides it. Airline and GDS transfers also follow the contract of carriage. See the GDPR Policy.
11. Third-party links
Airline and other third-party sites have their own privacy practices. We are not responsible for those sites.
12. Changes
We will post updates on this page and change the last-updated date. For material changes we will provide a more prominent notice where appropriate. Continued use after an update means you accept the revised policy, except where the law requires consent.
13. Contact
People Information, LLC — Privacy
2101 W San Juan Ave Suite 2, Phoenix, AZ 85015, USA
Email: privacy@bookaerofare.com
Phone: +1 (800) 903-1468
General inquiries: support@bookaerofare.com
Related: Cookie Policy · GDPR Policy · CCPA Notice · Fulfillment Policy · Advertiser Disclosure · Terms.