1. Scope
This policy applies to every use of IATA.co: the website, the booking portal, the prepaid balance and the flights API, whether by you, your staff or software acting on your behalf. It forms part of the Terms of Service.
2. Bookings
You must not:
- make speculative, duplicate, fictitious or test bookings on live inventory, or hold seats without a genuine passenger and intention to travel;
- book and cancel repeatedly to probe fares or availability;
- enter false passenger details or details of people who have not agreed to travel;
- use the Services to circumvent airline rules, including hidden-city, back-to-back or throwaway ticketing where the airline prohibits it;
- resell tickets in a way that misrepresents the fare conditions to the end customer.
Airlines monitor these practices and raise debit memos and penalties against the issuing channel. Any such cost caused by your bookings is charged to your balance.
3. Payments and balance
You must not fund your balance with payment instruments you are not authorised to use, launder money through top-ups and refunds, or open chargebacks for amounts spent on issued tickets. We verify unusual patterns and we report what the law requires us to report.
4. API and data
You must not:
- scrape, crawl or bulk-download the website or search results by any means other than the API under a valid key;
- exceed or evade rate limits, share one key across unrelated products, or use several accounts to multiply free allowances;
- cache or republish fares beyond what the API Terms of Use allow, or present cached data as live;
- resell, sublicense or redistribute API data to third parties without our written agreement;
- use the data to train models, build competing fare databases or feed price-comparison services without our written agreement.
5. Security and integrity
You must not probe, scan or test the Platform for vulnerabilities except under our responsible disclosure rules, attempt to access other customers' accounts or data, interfere with the operation of the Services, introduce malicious code, or impersonate IATA.co, its staff, an airline or another customer.
6. Lawful use
You must comply with the laws that apply to you and your customers, including travel licensing, consumer protection, sanctions, export control and data protection rules. You may not use the Services for any unlawful purpose or in any country or for any person where doing so is prohibited.
7. What happens on a breach
Depending on the seriousness we may warn you, limit features, suspend API keys, suspend or close your account, cancel bookings made in breach, charge losses and penalties to your balance, and refer the matter to the authorities. We tell you what we have done and why unless the law or an investigation prevents it. You may appeal by writing to info@iata.co.
8. Reporting abuse
If you see the Services being misused, email info@iata.co with "Abuse" in the subject and what you observed. Reports are handled in confidence.
Questions about this page? Write to info@iata.co. IATA.co is an independent platform. It is not affiliated with, endorsed by or operated by the International Air Transport Association.