Skip to main content

Policy

Privacy Policy

Last updated: March 9, 2026

1. Introduction

Prime360 Holding Ltd. ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect personal information when you use the FlyorBook platform, including our website, mobile web app, and API ("the Service"). This policy applies to all users worldwide, including those protected by the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

2. Information We Collect

We collect the following categories of information:

Account Information

Name, email address, phone number (optional), and securely hashed password. If you sign in via social login (Google, GitHub), we receive your name and email from the provider.

Travel Information

Flight search queries, booking details, passenger profiles (names, dates of birth), cabin class preferences, bid history, and saved travel preferences.

Payment Information

Payment processing is handled by Stripe. We never store full credit card numbers, CVVs, or complete card details on our servers. We store only a Stripe payment method ID and the last four digits for display purposes.

Location Data

Airport Mode uses your device's geolocation with your explicit consent to identify nearby airports. Location data is used in real-time only and is not stored persistently on our servers.

Device and Usage Data

IP address, browser type, device type, operating system, pages visited, features used, session duration, and referring URLs. Collected automatically through server logs and first-party analytics.

Communications

Content of support tickets, emails sent to our team, and in-app feedback submissions.

3. How We Use Your Information

We use the information we collect to:

  • Process and complete flight bookings and travel-document delivery
  • Monitor your target-price bids and send real-time notifications when conditions are met
  • Generate ML-powered price predictions using aggregated, anonymized search data
  • Power Airport Mode with real-time location-based flight discovery
  • Calculate flight risk scores using historical delay data and airline performance metrics
  • Provide customer support and respond to your inquiries
  • Improve our Service through analytics, A/B testing, and performance monitoring
  • Send transactional emails (booking confirmations, bid triggers, price alerts)
  • Send marketing communications (with opt-out available in every email)
  • Detect and prevent fraud, abuse, and security threats
  • Comply with legal obligations, tax reporting, and regulatory requirements

4. Legal Bases for Processing (GDPR)

If you are in the European Economic Area (EEA) or UK, our legal bases for processing are:

  • Contract performance — processing bookings, bids, payments, and account management
  • Legitimate interest — analytics, security monitoring, fraud prevention, and service improvement
  • Consent — marketing communications, location data (Airport Mode), and non-essential cookies
  • Legal obligation — tax record retention, law enforcement cooperation, and regulatory compliance

5. Information Sharing

We share your information only with:

  • Airlines — passenger names, dates of birth, and contact information to complete bookings
  • Stripe — payment processing (Stripe acts as an independent data controller for payment data)
  • Cloud infrastructure providers — for hosting and data storage (encrypted at rest)
  • Analytics services — aggregated, anonymized usage data only
  • Law enforcement — when required by valid legal process (subpoena, court order, or statutory obligation)

We never sell your personal information to third parties. We never share your data with advertisers or data brokers.

6. International Data Transfers

Prime360 Holding Ltd. is based in Malta, a member state of the European Union. Your data is primarily processed within the EU/EEA. Where data is transferred outside the EEA (e.g., to cloud infrastructure providers), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate data protection.

7. Data Security

We implement industry-leading security measures to protect your data:

  • HTTPS encryption for data in transit
  • Field-level encryption for configured personal data in production
  • Payment card details are collected by Stripe-hosted payment components
  • Least-privilege access controls with role-based permissions
  • Multi-factor authentication (MFA) support with TOTP
  • Automated security monitoring and anomaly detection
  • Password hashing using the application security configuration

8. Data Retention

Data Type
Retention Period
Account data
Duration of account + 30 days after deletion
Booking records
7 years (tax and legal requirements)
Payment records
As required by Stripe and tax law
Search history
90 days
Location data
Session only (not stored persistently)
Support tickets
3 years
Analytics data
2 years (aggregated)
Bid history
1 year after bid completion

9. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

GDPR Rights (EEA/UK)

  • Right of access — request a copy of your personal data
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure — request deletion of your data ("right to be forgotten")
  • Right to restriction — limit how we process your data
  • Right to data portability — receive your data in a machine-readable format
  • Right to object — opt out of processing based on legitimate interests
  • Right to withdraw consent — revoke consent at any time for consent-based processing

CCPA Rights (California)

  • Right to know — what personal information we collect and why
  • Right to delete — request deletion of your personal information
  • Right to opt-out of sale — we do not sell personal information, but you may still exercise this right
  • Right to non-discrimination — we will not treat you differently for exercising your rights

To exercise any of these rights, email privacy@flyorbook.com or visit your Account Settings page. We will respond within 30 days (GDPR) or 45 days (CCPA).

10. Cookies and Tracking

We use cookies and similar technologies (localStorage, service workers) to maintain sessions, remember preferences, and improve the Service. For full details on what cookies we use, their purposes, and how to manage them, please see our Cookie Policy.

11. Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a person under 18, we will promptly delete it. If you believe a minor has provided us with personal information, please contact us at privacy@flyorbook.com.

12. Automated Decision-Making

FlyorBook uses automated algorithms for price predictions, flight risk scoring, and price-trend analysis. These automated systems provide recommendations and informational outputs only. No solely automated decision with legal or similarly significant effects is made about you without human review. Auto-book decisions are initiated by your explicit configuration and can be cancelled at any time.

13. Third-Party Links

The Service may contain links to third-party websites (airline sites, payment processors, social media). We are not responsible for the privacy practices of external sites. We encourage you to review the privacy policies of any third-party site you visit.

14. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice via email to the address associated with your account. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance.

15. Contact and Data Protection Officer

For privacy-related inquiries:

Privacy inquiries: privacy@flyorbook.com

Data Protection Officer: dpo@flyorbook.com

Address: Prime360 Holding Ltd., Triq Il-Kurat Schembri, Mosta, Malta

General Support: Contact Page

If you are in the EEA and believe your data protection rights have not been addressed, you have the right to lodge a complaint with your local Data Protection Authority (DPA).

Partner destination

Curated places worth considering on your next trip.

Green hills and lake landscape in Rwanda

East Africa

Visit Rwanda

Lake shores, tea country and a thousand green hills.

Discover Rwanda (opens in a new tab)

Review the fare. Check the risk. Book with context.

Get started