Policies
Privacy Policy
Last updated 25 August 2026
This policy sets out what we collect when you use AirBooking, why, who sees it, how long we keep it, and what you can ask us to do with it. It is written to meet India's Digital Personal Data Protection Act, 2023 and the UAE's Personal Data Protection Law, Federal Decree-Law No. 45 of 2021.
Who is responsible for your data
Two companies operate AirBooking. Which one is responsible for your data depends on where you are billed.
Billed in India, in rupees: AIRBOOKING TRAVEL AND TOURS PRIVATE LIMITED, CIN U79110KL2020PTC062822, Door No. 25/14, Ohm Nivas, K T Gopalan Road, Kottooli, Kuthiravattom, Kozhikode 673016, Kerala, India. It is the Data Fiduciary under the DPDP Act.
Billed anywhere else: AirBooking Technology LLC, Office No. 716, Business Village, B Block, Deira, Dubai, PO Box 117402, United Arab Emirates. It is the Controller under the UAE PDPL.
The two companies share one platform and one support team, so either may handle your record when a booking or a request needs it. "AirBooking", "we" and "us" means whichever company is responsible for you.
Who this covers
Anyone who visits AirBooking, starts a conversation, searches or books, or creates an account, on the website or in the iOS and Android apps. It also covers the travellers you add to a booking; by adding them you confirm you may give us their details. People who use AirBooking through their employer, travel agency or travel management company are covered too, with the differences set out under "Booking through your organisation".
What we collect
What you give us, and what a search or a booking needs.
- Name, email address and phone number, for you and each traveller you add. Date of birth and gender when an airline requires them.
- Passport or national ID details (number, nationality, issue and expiry dates) when the airline or the destination requires them for the ticket.
- Trip details: dates, cities, cabin or room preferences, seat, meal or accessibility requests, and what you type into the conversation so we can search.
- Booking records: confirmations, tickets, invoices, changes, refunds.
- Payment results. We never see or store your full card number. Card details go into a payment page run by Razorpay (rupee payments) or Stripe (everything else). They return a confirmation, the card type and the last four digits, which is what we need for a receipt and a refund. A card you choose to save is stored as a network token issued under the card scheme's rules and, in India, the Reserve Bank of India's tokenisation rules. The card number is never held by us.
- Account details: login, saved travellers, communication preferences.
- Technical data: device type, operating system, app version, IP address, browser, an approximate location derived from your IP address or billing country, and the logs that keep the service running and secure.
If you add preferences later, we keep them so we do not ask twice.
Some of this reveals more than it seems to. A meal preference can indicate a religion, an assistance request can indicate a health condition, a passport shows nationality. We collect these only when you ask for the service that needs them, pass them only to the supplier that has to act on them, and use them for nothing else.
The app asks for a device permission only when a feature needs it, for example notifications so we can tell you about a gate change. Refuse or revoke any permission in your device settings; the feature that depends on it stops, nothing else does.
Why we use it
Most of what we do is carry out the booking you asked for: search, hold, book, ticket, change, refund, show you your trips, invoice you, and send the messages a booking requires. In India this is processing you consent to when you book. In the UAE it is processing needed to perform our contract with you.
Some of it is required by law: tax and accounting records, lawful requests from courts, regulators, immigration and aviation authorities, and the fraud and sanctions checks that payment providers and airlines require.
Some of it is running the service properly: monitoring for security problems and fraud, fixing errors, and looking at how the product is used so we can improve it, in ways that do not override your interests.
Anything else, such as marketing or optional cookies, we ask for separately. You can withdraw that consent at any time, as easily as you gave it. Withdrawing does not undo processing that already happened.
We do not sell your information. We do not use the conversation to advertise other companies' products to you.
Two things are automated. The order in which travel options appear is set by rules weighing price, timing, your preferences and, for organisation bookings, the travel policy. And payment providers and airlines run fraud and sanctions screening that can decline a payment. If a decline affects you and you think it is wrong, contact us and a person will look at it. We make no other automated decisions with a legal or similarly serious effect on you.
Who we share it with
A booking has to reach the airline, hotel or activity operator and, when you pay, the payment provider. Each gets only what it needs for its step.
Airlines, hotels, activity operators, and the distribution systems and consolidators we book through, receive traveller names, contact details, travel documents where required, and the booking. From there they process it under their own privacy terms, which we show you before you pay.
Razorpay and Stripe receive payment details directly and return the result. Each is a separate controller for the payment data it holds.
Companies that host or secure the product for us (cloud infrastructure, email and messaging delivery, customer support tools, analytics) act on our instructions under contract.
Our group companies, meaning the two companies named above and AirBooking Travel and Tours LLC (UAE), see your record where a booking or a support request needs it.
Authorities receive data when the law requires it, when an airport, border, immigration or aviation authority asks for passenger data, or when we need to protect our rights or someone's safety.
If AirBooking is sold or merges, your data goes with it under the same protections.
We do not give your data to data brokers. Advertising and measurement tools, such as those from Meta or Google, run only if you accept advertising cookies on the website or allow tracking in the app, and receive only what is needed to measure our own campaigns. They never receive travel documents or booking details.
Booking through your organisation
When your employer, travel agency or travel management company gives you access to AirBooking, that organisation decides why and how your travel data is processed. It is the Data Fiduciary (India) or Controller (UAE) for the data it gives us and for bookings made under its account; we process that data on its instructions, under our agreement with it. Its own privacy notice tells you what it does with your travel data.
The organisation can see the bookings made under its account, including itineraries, traveller names, spend, and whether a booking was inside its travel policy. It sets how long that data is kept and can ask us to return or delete it when it stops using AirBooking. Requests to see, correct or delete data held under an organisation's account go to the organisation; if you send one to us, we pass it on and help the organisation answer.
Two things stay with us. We remain responsible for the security of the platform. And the business contact details of the people who run the organisation's account with us (names, work emails, roles) are processed by us in our own right, for account management, billing and support.
If you also have a personal AirBooking account, the two are kept apart. Your organisation cannot see your personal bookings.
Where your data is stored
The platform runs on cloud infrastructure that may be outside the country you are in, and booking data has to reach the airline, hotel or operator wherever they are.
If you are in India, your data may be transferred to and stored in the UAE and other countries where our infrastructure and suppliers operate. Section 16 of the DPDP Act permits this except to countries the Central Government restricts.
If you are in the UAE, we transfer data abroad where the destination has adequate protection or, where it does not, on the basis of your consent, the transfer being necessary for your booking, or contractual safeguards, under Articles 22 and 23 of the PDPL.
The same protections apply wherever the data sits.
How long we keep it
Booking records, meaning tickets, invoices and the conversation that produced them, for as long as you may need them and as long as tax, accounting and dispute rules require: in India generally eight years from the end of the financial year of the booking, in the UAE between five and seven years depending on the record. Account data for as long as the account is open.
Travel document details only for the booking that needed them; they are removed once the trip has ended and any refund or dispute window has closed. Conversations that did not lead to a booking, 12 months from the last activity. Technical logs, normally 90 days, longer only for a security investigation.
Data held under an organisation's account, for the period set in the organisation's agreement with us; returned or deleted when the agreement ends.
When a retention period ends we delete the data or make it anonymous. If you have not used your account for three years we write to you; if you do not respond we close the account and delete everything the law does not require us to keep.
Your rights
You can ask to see the information we hold about you, to correct or complete it, to delete it where the law allows, and to be told who we have shared it with. You can withdraw any consent you gave. You can object to processing that is not needed to complete a booking you already made. In India you can nominate someone to exercise these rights for you if you die or lose capacity.
Ask in the conversation, use your account settings, or write to the address at the end of this page. We need enough detail to find the right record and confirm it is you. We answer within 30 days. India's DPDP Rules allow up to 90 days; if we ever need longer than 30 we tell you why.
Some booking records must stay after a deletion request because tax law or an open dispute requires it. We tell you what we are keeping and why.
Deleting your account
You can delete your account and its data yourself, without contacting support: in the app under Account, then Delete account, or on the website at [/account/delete]. Deletion removes your login, saved travellers, saved payment tokens, preferences and conversation history. Booking and invoice records we are legally required to keep are separated from your account, held for that purpose only, then deleted.
Marketing
You receive marketing from us only if you tick the marketing box at checkout or in your account. The box is unticked by default and is separate from accepting the Terms. Every marketing email, SMS or WhatsApp message has an unsubscribe route, and you can change the setting in your account. Messages a booking requires, meaning the confirmation, e-ticket, schedule change, cancellation or receipt, are not marketing and are sent regardless, including to Indian numbers on the DND register, because you need them to travel.
If your organisation gave you access, we send you no marketing unless you opt in on a personal account.
Cookies
Cookies that keep you signed in, remember a guest session and keep the product working are necessary and always on. Analytics and advertising cookies are set only if you accept them in the notice on your first visit; change your choice from the cookie settings link in the footer. We do not use cookies to follow you around other websites.
Security
Data is encrypted in transit and at rest. Access is limited to staff who need it and is logged. Payment pages are run by payment providers certified under PCI DSS; card details belong there and never in a message to the concierge. No method of transmission is perfect. If a breach affects your personal data we tell you, and we notify the Data Protection Board of India or the UAE Data Office as the law requires.
Children
You must be 18 or over to create an account or book. Children can travel on a booking made by an adult, and a child's name and date of birth on a ticket are used only for that booking. We do not knowingly create accounts for children and do not use children's data for tracking, profiling or advertising. If you believe a child has created an account, tell us and we delete it.
Grievance and data protection contacts
Come to us first with any question or complaint about your data and we respond within the timelines above.
India, under the DPDP Act and the Consumer Protection (E-Commerce) Rules, 2020: Grievance Officer Kavitha Jaganathan, AIRBOOKING TRAVEL AND TOURS PRIVATE LIMITED, Door No. 25/14, Ohm Nivas, K T Gopalan Road, Kottooli, Kuthiravattom, Kozhikode 673016, Kerala, India, support@airbooking.com, +91 89430 86351. We acknowledge grievances within 48 hours and resolve them within one month. If you are not satisfied, you can complain to the Data Protection Board of India.
UAE, under the PDPL: data protection contact Kavitha Jaganathan, AirBooking Technology LLC, Office No. 716, Business Village, B Block, Deira, Dubai, PO Box 117402, support@airbooking.com. If you are not satisfied, you can complain to the UAE Data Office.
Changes to this policy
We may update this page. The date at the top is the version in force. If a change is material, we tell you in the product or by email before it takes effect.
Related
Bookings are governed by our Terms of booking, which include the cancellation and refund policy.
Contact
Privacy questions go through the same door as everything else: ask in the conversation, or write to support@airbooking.com. Postal addresses and support hours are on the Contact page.
