Privacy Policy
Effective 18 August 2026 · Onward Ticket is a service of Onward Ticket Inc.
To place a flight reservation we have to handle the same details an airline needs, including passport information. This policy explains exactly what we collect, why, who receives it, how long we keep it, and how to have it corrected or deleted. Onward Ticket Inc. is the data controller for onwardticket.travel. Questions: privacy@onwardticket.travel.
1. What we collect
| Data | Why we need it |
|---|---|
| Traveller details: title, given and family names, date of birth, gender, nationality, passport number and expiry date | Required by airlines to hold a reservation and print it on the itinerary. Names must match the passport for verification. |
| Contact details: email address, phone number | To deliver the PDF, send order updates, and reach you if something needs fixing. |
| Trip details: route, dates, trip type, chosen issue time | To search availability and place the reservation. |
| Payment records: payment and refund identifiers, amount, currency, status | To confirm payment, issue refunds and keep accounts. Card numbers are handled only by our payment provider; we never see or store them. |
| Order history: order number, status changes, documents issued, emails sent, support notes | To operate the service, support you, and prove delivery. |
| Technical data: IP address, browser type, pages viewed, referring site or campaign, approximate location from IP | Security, fraud prevention, and understanding how the site is used (analytics). |
| Support correspondence: emails you send us | To answer you and improve the service. |
We do not collect card numbers, government IDs other than passport details needed for the booking, or any special-category data beyond what appears on a passport.
2. Why we may process it (legal bases)
- Contract: everything needed to take your order, place the reservation, deliver it, and support you.
- Legal obligation: keeping payment and tax records; responding to lawful requests.
- Legitimate interests: securing the site, preventing fraud and chargeback abuse, and measuring and improving the product, balanced against your rights.
- Consent: where local law requires it for analytics cookies; you can withdraw it any time (see section 7).
4. How passport details are protected
- Passport numbers are stored encrypted at rest and transmitted only over TLS.
- In our internal tools, passport numbers are masked (only the last two characters show). Revealing a full number requires a named staff account with the right permission, and every reveal is logged with who, when, and which order.
- Staff access is per person, with roles; support staff cannot move money, and finance staff cannot reveal passports.
- The passport number appears on the itinerary PDF because airline itineraries carry it and consulates expect it; we never put passport numbers in email text, URLs or analytics.
5. How long we keep it
- Order and payment records (order number, route, amounts, status history, refund references) are kept for as long as accounting and tax law requires, typically seven years, because they are financial records.
- Traveller details, including passport data, are kept while the reservation could still be needed (through the travel date or the reservation’s validity plus a margin for disputes) and are then deleted or irreversibly masked. You can ask us to delete them sooner once the reservation has expired; we do this within 30 days.
- Support emails are kept for two years after the last exchange.
- Technical logs are kept for up to 90 days unless needed for a security investigation.
- Analytics data is retained per Google Analytics settings (14 months) and is pseudonymous.
6. Your rights
Depending on where you live (including under the GDPR, UK GDPR, and India’s DPDP Act) you can:
- ask what personal data we hold about you and receive a copy;
- have inaccurate data corrected (before a reservation is created, corrections are also free through support);
- ask us to delete data we no longer need for the service or the law;
- object to, or ask us to restrict, processing based on legitimate interests;
- withdraw consent to analytics at any time;
- complain to your data protection authority.
Email privacy@onwardticket.travel from the address used at checkout, with your order number. We answer within 30 days and will verify identity before releasing data. Note that we cannot delete records we are legally required to keep, or traveller details while a reservation is still live in an airline’s system.
8. Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to named staff accounts with role-based permissions, sessions expire, and internal actions are audit-logged. Payments are handled by a PCI-DSS compliant provider. No system is perfectly secure; if we learn of a breach affecting your data we will notify you and the relevant authority as the law requires.
9. Children
The site is for adults. Reservations for children are placed by an adult traveller or guardian who provides the child’s details; we process those details only to place the reservation.
10. Changes and contact
We will post changes here and update the effective date. Material changes affecting existing orders will be emailed. Contact: privacy@onwardticket.travel for privacy matters, support@onwardticket.travel for everything else. Controller: Onward Ticket Inc., operating Onward Ticket at onwardticket.travel.