What we collect
We collect only what we need: your email address (to verify your identity and manage your account), and anonymous usage data (which airlines are searched, trial usage counts). We do not collect your booking references, passenger names, or payment card details — card data is handled entirely by Stripe and never passes through our servers.
How we use it
Your email is used to send you a one-time verification code when you sign in, and to manage your subscription. We record which airline fare policies you look up to track your trial usage and subscription entitlement. We do not sell your data. We do not use it for advertising.
Session cookies
When you verify your email, we set a secure session cookie in your browser. This cookie is HttpOnly (cannot be read by JavaScript), Secure (HTTPS only), and SameSite=Strict (not sent on cross-site requests). It expires after 7 days or when you log out. We use this cookie solely to authenticate your requests — no third-party tracking cookies are used.
Subscription and billing data
We use Stripe for payment processing. Stripe assigns a secure customer identifier to your account which we store in our database — this is used solely to manage your subscription, process renewals, and provide access to your billing portal. If you cancel your subscription, we retain a record of the cancellation date for 90 days to determine whether a returning-subscriber discount applies. After 90 days, the discount eligibility flag is cleared.
Hold Call feature (coming soon)
When Hold Calls launch, your phone number will be stored as part of the call session record. This is necessary to connect the call when an agent answers, to send you SMS updates, and to handle retry and credit eligibility. Twilio (our telephony provider) will also process your number. Call session records will be retained for up to 90 days, after which they are deleted. You can request earlier deletion at any time.
Audit and operational logs
We maintain an audit log of security-relevant events: sign-in attempts, verification codes sent, subscription changes, portal access, and payment events. These logs are used solely for security monitoring, fraud prevention, and service reliability. They are not shared with third parties and are automatically deleted after 90 days.
Data storage
Your account data is stored in Supabase, a secure cloud database. Session records are deleted when they expire or when you log out. One-time verification codes are deleted immediately after use or after 15 minutes. All data is stored within secure, industry-standard infrastructure.
Your rights
You can request access to, correction of, or deletion of your account and all associated data at any time by emailing
hello@flexifarefixer.com. We will respond within 30 days. Account deletion removes your email, session records, and usage data. Stripe payment records are subject to Stripe's own retention policies.