Privacy Policy

Effective 18 August 2026 · Onward Ticket is a service of Onward Ticket Inc.

To place a flight reservation we have to handle the same details an airline needs, including passport information. This policy explains exactly what we collect, why, who receives it, how long we keep it, and how to have it corrected or deleted. Onward Ticket Inc. is the data controller for onwardticket.travel. Questions: privacy@onwardticket.travel.

1. What we collect

DataWhy we need it
Traveller details: title, given and family names, date of birth, gender, nationality, passport number and expiry dateRequired by airlines to hold a reservation and print it on the itinerary. Names must match the passport for verification.
Contact details: email address, phone numberTo deliver the PDF, send order updates, and reach you if something needs fixing.
Trip details: route, dates, trip type, chosen issue timeTo search availability and place the reservation.
Payment records: payment and refund identifiers, amount, currency, statusTo confirm payment, issue refunds and keep accounts. Card numbers are handled only by our payment provider; we never see or store them.
Order history: order number, status changes, documents issued, emails sent, support notesTo operate the service, support you, and prove delivery.
Technical data: IP address, browser type, pages viewed, referring site or campaign, approximate location from IPSecurity, fraud prevention, and understanding how the site is used (analytics).
Support correspondence: emails you send usTo answer you and improve the service.

We do not collect card numbers, government IDs other than passport details needed for the booking, or any special-category data beyond what appears on a passport.

2. Why we may process it (legal bases)

  • Contract: everything needed to take your order, place the reservation, deliver it, and support you.
  • Legal obligation: keeping payment and tax records; responding to lawful requests.
  • Legitimate interests: securing the site, preventing fraud and chargeback abuse, and measuring and improving the product, balanced against your rights.
  • Consent: where local law requires it for analytics cookies; you can withdraw it any time (see section 7).

3. Who receives your data

We share data only with the parties needed to provide the service. We do not sell personal data.

RecipientWhatPurpose
Airlines and airline distribution systems (via our reservation platform, Duffel)Traveller details, trip details, contact emailCreating and holding the reservation. The airline processes this data under its own privacy policy.
Payment provider (Razorpay) and its hosted checkoutAmount, order reference, your email and phone; your card details go directly to themTaking payment and issuing refunds.
Email delivery provider (Resend)Email address, itinerary PDF, order emailsDelivering documents and updates.
Hosting and database providers (Vercel, Supabase)All order data, encrypted at rest and in transitRunning the site and storing orders.
Analytics (Google Analytics 4)Pseudonymous usage data, pages, events such as “search performed” and “purchase”; never names or passport dataUnderstanding how the site is used.
Professional advisers, authoritiesWhat is legally requiredLegal compliance, fraud investigations, defending claims.

Some of these providers are outside your country, including in the United States, the European Union and India. Where required, transfers rely on the providers’ standard contractual safeguards.

4. How passport details are protected

  • Passport numbers are stored encrypted at rest and transmitted only over TLS.
  • In our internal tools, passport numbers are masked (only the last two characters show). Revealing a full number requires a named staff account with the right permission, and every reveal is logged with who, when, and which order.
  • Staff access is per person, with roles; support staff cannot move money, and finance staff cannot reveal passports.
  • The passport number appears on the itinerary PDF because airline itineraries carry it and consulates expect it; we never put passport numbers in email text, URLs or analytics.

5. How long we keep it

  • Order and payment records (order number, route, amounts, status history, refund references) are kept for as long as accounting and tax law requires, typically seven years, because they are financial records.
  • Traveller details, including passport data, are kept while the reservation could still be needed (through the travel date or the reservation’s validity plus a margin for disputes) and are then deleted or irreversibly masked. You can ask us to delete them sooner once the reservation has expired; we do this within 30 days.
  • Support emails are kept for two years after the last exchange.
  • Technical logs are kept for up to 90 days unless needed for a security investigation.
  • Analytics data is retained per Google Analytics settings (14 months) and is pseudonymous.

6. Your rights

Depending on where you live (including under the GDPR, UK GDPR, and India’s DPDP Act) you can:

  • ask what personal data we hold about you and receive a copy;
  • have inaccurate data corrected (before a reservation is created, corrections are also free through support);
  • ask us to delete data we no longer need for the service or the law;
  • object to, or ask us to restrict, processing based on legitimate interests;
  • withdraw consent to analytics at any time;
  • complain to your data protection authority.

Email privacy@onwardticket.travel from the address used at checkout, with your order number. We answer within 30 days and will verify identity before releasing data. Note that we cannot delete records we are legally required to keep, or traveller details while a reservation is still live in an airline’s system.

7. Cookies and similar storage

Name / typeSet byPurposeLifetime
Google Analytics cookies (_ga, _ga_*)GoogleAnalytics: page views and funnel events, pseudonymousUp to 2 years
Session storage: first-touch source (utm, referrer)UsAttributing an order to the campaign or site you arrived fromUntil the tab is closed
Local storage: one-time flagsUsPreventing duplicate analytics events; remembering staff display preferences on internal pagesPersistent
Staff session cookieUsSigning our own staff into internal tools; never set for customers12 hours
Payment provider cookiesRazorpayOperating the hosted checkout and fraud preventionPer Razorpay’s policy

To refuse analytics, use your browser’s cookie controls, a content blocker, or Google’s opt-out add-on. The site works fully without analytics cookies.

8. Security

Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to named staff accounts with role-based permissions, sessions expire, and internal actions are audit-logged. Payments are handled by a PCI-DSS compliant provider. No system is perfectly secure; if we learn of a breach affecting your data we will notify you and the relevant authority as the law requires.

9. Children

The site is for adults. Reservations for children are placed by an adult traveller or guardian who provides the child’s details; we process those details only to place the reservation.

10. Changes and contact

We will post changes here and update the effective date. Material changes affecting existing orders will be emailed. Contact: privacy@onwardticket.travel for privacy matters, support@onwardticket.travel for everything else. Controller: Onward Ticket Inc., operating Onward Ticket at onwardticket.travel.