Flights API: requests open. How it works

Legal

Privacy policy

Last updated · Applies to iata.co

This policy explains what personal data we collect, why we collect it, who we share it with and the choices you have. We keep it short and specific.

1. Who is responsible

IATA.co is the controller of the personal data described here. You can reach us at info@iata.co with "Privacy" in the subject for any question or request about your data. IATA.co is an independent company and is not the International Air Transport Association.

2. What we collect

Account data. When you create an account we collect your first and last name, email address, country, city, phone number, agency name, agency registration number (optional) and agency address, plus your password (stored only as a salted hash). We record the network address and browser used to sign up and to log in.

Passenger data. To issue a ticket we collect the details the airline requires for each passenger: full name as on the travel document, date of birth, gender where required, nationality and travel document number and expiry where required, and contact details for the booking. This data may relate to people other than you; you must have the right to give it to us.

Balance and payment data. Top-up amounts, dates, payment references and the result of each payment. We do not store card numbers; payment providers handle them under their own policies.

Usage and activity data. A log of actions on your account (sign-up, logins including failed ones, password changes, searches, bookings, changes made by our staff to your account) with the time, network address, approximate location derived from the address, and browser or client used. For API keys, the calls made with the key, their timing, result and the calling address.

Website traffic. Page views on the public site with the page, the time, the referring site, campaign parameters in the address, the country and city derived from the network address, the device and browser type, and a visitor identifier that is a one-way hash of the address and browser which changes every day. We do not set analytics cookies and we do not load third-party analytics scripts.

Correspondence. Emails and messages you send us, and our replies.

3. Why we use it and on what basis

  • To provide the Services (performance of our contract with you): creating and securing your account, searching and booking flights, issuing tickets, managing your balance, providing API access, and answering your requests.
  • To issue tickets and service bookings (performance of the contract, and the airline's legal obligations): passenger data is sent to the airline or supplier that operates the flight and to the systems that issue the ticket.
  • To keep the Platform secure and prevent fraud (our legitimate interest): activity logs, login protection, rate limits, address whitelisting, the bot check at sign-up.
  • To understand and improve the site (our legitimate interest): traffic statistics, which do not identify you.
  • To meet legal obligations: accounting, tax, sanctions and anti-money-laundering rules, and lawful requests from authorities.
  • To send service messages (contract and legitimate interest): activation and password emails, booking confirmations, schedule changes, security notices, changes to our terms. These are not marketing and cannot be opted out of while you hold an account.
  • Marketing only with your consent, which you can withdraw at any time using the link in the message or by writing to us.

4. Who we share it with

  • Airlines, consolidators and ticketing systems that operate or issue the flights you book. They receive passenger and booking data because a ticket cannot be issued without it. Each of them handles that data under its own privacy policy and the conditions of carriage.
  • Payment providers and banks for top-ups and refunds.
  • Cloudflare, which hosts the Platform, delivers the site, stores our database and runs the sign-up bot check (Turnstile). Cloudflare processes data on our instructions.
  • Email delivery providers that deliver our service messages.
  • Professional advisers and authorities where the law requires it or to establish, exercise or defend legal claims.
  • A successor if our business is sold or merged, under the same protections.

We do not sell personal data and we do not share it with advertisers.

5. International transfers

Airlines and suppliers are located wherever the flights are operated, so booking data necessarily travels to the countries involved in the journey. Our hosting provider stores and processes data in its global network. Where a transfer goes to a country without an adequate level of protection, we rely on the contractual safeguards our providers offer or on the fact that the transfer is necessary to perform the contract you asked for (the booking).

6. How long we keep it

  • Account data: for as long as the account exists, then for up to 7 years for accounting, tax and dispute purposes.
  • Booking and passenger data: for as long as the booking may need servicing (changes, refunds, claims) and then for the period required by accounting and tax law, normally 7 years from the end of the year of travel.
  • Balance ledger: for the accounting retention period; the ledger is never edited.
  • Activity logs: up to 24 months.
  • Website traffic: up to 400 days, and the daily visitor hash can never be linked back to a person after the day it was made.
  • Login attempt records: one hour.
  • Correspondence: for as long as needed to handle the matter and then for the accounting retention period if it concerns a booking or payment.

7. How we protect it

All traffic is encrypted in transit. Passwords are hashed, session and API tokens are stored only as hashes, access to customer data inside IATA.co is limited to staff who need it to help you, and every administrative change to an account is logged. Our security page has more detail. No system is perfectly secure; if we learn of a breach affecting your data we will tell you and the relevant authority as the law requires.

8. Cookies

The site uses a small number of strictly necessary cookies: a session cookie when you log in, short-lived cookies during sign-up and password reset, and the cookie set by the bot check. Your theme choice and your last flight search are stored in your browser's local storage, not in cookies. We do not use advertising or third-party analytics cookies. Details are in the cookie policy.

9. Your rights

Depending on where you live you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to its processing, to receive a copy in a portable format, and to withdraw consent where processing is based on consent. You can change your account details and see your logged-in devices from your account page. For anything else, write to info@iata.co. We may need to verify your identity before acting. We answer within one month. Some data cannot be deleted while a booking is live or while a legal retention period runs; we will tell you if that applies. You also have the right to complain to the data protection authority in your country.

10. Passengers who are not our customers

If your details were entered by a travel agency that booked your flight through IATA.co, the agency is responsible for telling you how it uses your data and we process your data on the agency's instruction to issue and service the ticket. You may still contact us directly about the data we hold, and we will work with the agency to answer you.

11. Children

Accounts are for adults and businesses. Passenger data may include children's details when a child travels; we process it only to issue and service the booking.

12. Changes to this policy

We may update this policy; the date at the top shows the current version. For material changes we notify account holders by email or in the dashboard before they take effect.

Questions about this page? Write to info@iata.co. IATA.co is an independent platform. It is not affiliated with, endorsed by or operated by the International Air Transport Association.