1.Introduction
WiseTravel Technology Limited ("WiseTravel", "we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our website at wise-travel.com and related services (the "Service").
WiseTravel Technology Limited is incorporated in Hong Kong SAR (Company No. 79125922). For users in the European Economic Area (EEA) and the United Kingdom, our UK entity WiseTravel Technology Limited (Company No. 17053275) acts as the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR).
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2.Data controller
The data controller responsible for your personal data is:
- Entity: WiseTravel Technology Limited
- Address: Room A, 7/F, 721 Star House, 3 Salisbury Road, Tsim Sha Tsui, Hong Kong
- UK address: Unit A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom
- Email: [email protected]
3.Personal data we collect
We collect the following categories of personal data:
Information you provide
- Account information: name, email address, password (hashed), phone number.
- Booking information: passenger names, dates of birth, gender, nationality, passport/identity document numbers, passport expiry dates.
- Partner-submitted booking information: where you start a booking inside an approved travel partner’s product, that partner may send us the booking details listed above on your instruction (see Section 14).
- Contact information: email address and phone number provided at checkout for order communications.
- Payment information: payment is processed by our third-party payment provider. We do not store your full credit card number or CVV.
- Communications: messages you send via our contact form or customer support.
Information collected automatically
- Usage data: pages visited, search queries, browser type, operating system, device type, IP address, referring URL.
- Cookies and similar technologies: see Section 9 below.
4.Lawful basis for processing (GDPR)
For users in the EEA and UK, we process your personal data on the following lawful bases under the GDPR:
| Purpose | Lawful basis |
|---|---|
| Processing and fulfilling bookings | Performance of a contract (Art. 6(1)(b) GDPR) |
| Sending booking confirmations and order updates | Performance of a contract (Art. 6(1)(b) GDPR) |
| Processing payments | Performance of a contract (Art. 6(1)(b) GDPR) |
| Responding to customer support inquiries | Legitimate interest (Art. 6(1)(f) GDPR) |
| Preventing fraud and ensuring security | Legitimate interest (Art. 6(1)(f) GDPR) |
| Complying with legal obligations (tax records, etc.) | Legal obligation (Art. 6(1)(c) GDPR) |
| Sending marketing communications (if opted in) | Consent (Art. 6(1)(a) GDPR) |
| Improving our Service and analytics | Legitimate interest (Art. 6(1)(f) GDPR) |
5.How we use your data
We use your personal data for the following purposes:
- To search, book, and manage flight reservations and ancillary services on your behalf.
- To communicate with you regarding your bookings (confirmations, updates, cancellations, ticketing notifications).
- To process payments and issue refunds.
- To provide customer support and respond to your inquiries.
- To detect, prevent, and investigate fraud or security incidents.
- To comply with applicable laws, regulations, and legal processes.
- To improve and personalise the Service.
6.Data sharing and disclosure
We share your personal data only when necessary and with appropriate safeguards:
Travel suppliers
We share passenger details (names, dates of birth, passport information) with airlines and other travel suppliers to fulfil your booking. Suppliers process this data according to their own privacy policies.
Payment processors
We share necessary transaction data with our payment processor to process your payment securely. Our payment provider is PCI DSS compliant.
Service providers
We use third-party service providers for hosting, email delivery, and analytics. These providers process data on our behalf under data processing agreements and are required to protect your data.
Advertising and conversion measurement
We use Google services (including Google Ads and Google Analytics) to measure the effectiveness of our advertising. To measure completed bookings more accurately, we may share a limited set of identifiers — such as your email address and phone number — with Google in a hashed (irreversible) form, a feature Google refers to as "enhanced conversions". Hashing is applied in your browser before the data is sent, so Google does not receive these details in plain text. This data is used solely to match a booking to an advertising interaction for measurement purposes; it is not used by us to build advertising profiles and we do not sell it. You can control ad personalisation through your Google Ads settings and manage analytics cookies as described in Section 9.
Legal requirements
We may disclose your data if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of WiseTravel, our users, or others.
Business transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred as part of the transaction. We will notify you of any such change.
We do not sell your personal data to third parties.
7.International data transfers
Your personal data may be transferred to and processed in countries outside your country of residence, including Hong Kong, the United Kingdom, and China, where our offices and technology infrastructure are located.
For transfers of personal data from the EEA or UK to countries that do not have an adequacy decision from the European Commission or the UK Government, we implement appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, as applicable.
You may request a copy of the safeguards we use by contacting us at [email protected].
8.Data retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
| Data category | Retention period |
|---|---|
| Account information | Duration of your account plus 2 years after deletion |
| Booking and transaction records | 7 years (for legal and tax compliance) |
| Passenger identity documents | Duration of the trip plus 1 year |
| Contact form submissions | 2 years |
| Usage and analytics data | 26 months |
When data is no longer needed, it is securely deleted or anonymised.
9.Cookies and tracking technologies
We use cookies and similar technologies to operate the Service and enhance your experience. The types of cookies we use include:
- Essential cookies: required for the Service to function (e.g., session management, authentication). These cannot be disabled.
- Functional cookies: remember your preferences such as language and currency selection.
- Analytics cookies: help us understand how visitors use the Service so we can improve it.
You can accept or decline non-essential cookies at any time using the Cookie preferences panel, which is also linked in the footer of every page. Declining does not affect essential cookies required for the Service to function.
You can additionally manage cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service.
10.Your rights (GDPR and UK GDPR)
If you are located in the EEA or UK, you have the following rights under the GDPR:
- Right of access (Art. 15): request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
- Right to restrict processing (Art. 18): request that we limit how we use your data in certain circumstances.
- Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): object to processing based on legitimate interests, including profiling.
- Right to withdraw consent (Art. 7(3)): where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: you have the right to file a complaint with your local data protection authority. In the UK, this is the Information Commissioner’s Office (ICO) at ico.org.uk.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
11.Your U.S. privacy rights (California/CCPA)
This section provides additional privacy disclosures for residents of the United States, and in particular for residents of California under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (together, the "CCPA"). Where this section conflicts with the rest of this Privacy Policy, this section controls for California residents.
Categories of personal information we collect
In the preceding 12 months, we have collected the following categories of personal information, as defined by the CCPA:
- Identifiers: name, email address, phone number, IP address, and account credentials.
- Customer records (Cal. Civ. Code § 1798.80(e)): passenger names, dates of birth, and payment information processed by our provider.
- Protected classification characteristics: gender and nationality, where required to book travel.
- Commercial information: bookings made, ancillary services purchased, and transaction history.
- Internet or network activity: pages visited, search queries, and browser and device information.
- Geolocation data: approximate location inferred from your IP address.
- Sensitive personal information: passport and government identity document numbers, collected solely to fulfil your booking.
Sources, purposes, and disclosures
We collect this information from you directly, automatically through your use of the Service, and from travel suppliers. We use it for the business purposes described in Sections 5 and 6. We disclose personal information to travel suppliers, payment processors, and service providers as described in Section 6 — each of which is contractually bound to use it only for the purposes we specify.
We do not sell or share your personal information
We do not sell your personal information for money or other valuable consideration, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA. We have not sold or shared the personal information of California residents, including minors under 16 years of age, in the preceding 12 months. We also do not use or disclose your sensitive personal information for purposes beyond those permitted by the CCPA.
Your California privacy rights
If you are a California resident, you have the right to:
- Know / access: request the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of third parties to whom we disclose it.
- Delete: request deletion of the personal information we have collected, subject to legal exceptions (e.g., completing a transaction or complying with tax and record-keeping laws).
- Correct: request correction of inaccurate personal information.
- Opt out of sale or sharing: because we do not sell or share personal information, no action is required — but you retain this right.
- Limit the use of sensitive personal information: we use sensitive personal information only as permitted by the CCPA, so no separate opt-out is required.
- Non-discrimination: we will not discriminate against you for exercising any of these rights.
How to exercise your rights
To submit a request, email us at [email protected] with “California Privacy Request” in the subject line. We will verify your identity by matching the information in your request against our records before fulfilling it. You may use an authorised agent to submit a request on your behalf, provided the agent supplies proof of authorisation. We will respond within 45 days and may extend this by a further 45 days where reasonably necessary, with notice to you. You may make a request to know or access twice within a 12-month period.
“Shine the Light” (California Civil Code § 1798.83)
California residents may request information about our disclosure of personal information to third parties for those third parties’ own direct-marketing purposes. We do not disclose personal information to third parties for their direct marketing.
Other U.S. state privacy laws
Residents of other U.S. states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, and Texas) may have similar rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising or the sale of personal information. We honour these rights on the same basis described above. To exercise them, contact us at [email protected].
12.Data security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL).
- Secure password hashing (PBKDF2).
- Access controls limiting data access to authorised personnel only.
- Regular security assessments and monitoring.
While we take reasonable steps to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
13.Children’s privacy
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16 without parental consent. Booking a flight for a child passenger requires an adult to provide the child’s information. If we learn that we have collected data from a child under 16 without appropriate consent, we will delete it promptly.
14.Data received from travel partners
Some bookings begin inside the product of an approved WiseTravel travel partner (for example, a travel-planning application or a travel advisory service). In that case, the partner may transmit booking information to us on your instruction — passenger names, dates of birth, gender, contact details and, where required for the itinerary, passport or identity document details — so that your booking form arrives pre-filled.
- How it is transmitted: server-to-server over encrypted connections (TLS). These details are never placed in URLs.
- How long we keep it: partner-submitted details are held in short-lived storage bounded by the validity of the booking link (currently up to 24 hours) and are then automatically deleted. They are retained beyond that window only if you complete a booking, at which point they become booking information and are handled as described in the rest of this policy.
- What we do not do: we do not write these details to application logs, do not use them for marketing, and do not sell them. They are shared only as described in Section 6 — for example, with the airline to fulfil a booking you complete.
- The partner’s role: the partner transmits your details on your instruction and is responsible for the accuracy of the information it sends and for its own privacy practices, which are governed by that partner’s privacy policy.
15.Data received through AI assistants
WiseTravel publishes a connector that an AI assistant — such as Claude — can be connected to, so that you can search flights and start a booking from inside a conversation with that assistant. The connector is open: it requires no WiseTravel account and no credentials. This section explains what reaches us when you use it, and what does not.
What the assistant sends us
- When you search: only the criteria needed to quote a fare — airport or city codes, dates, cabin class and the number and ages of travellers. No personal details are involved in a search.
- When you ask it to prepare a booking: the traveller details you have given the assistant — names, dates of birth, gender, nationality and, where the itinerary requires them, passport number, issuing country and expiry date — together with a contact email address and, optionally, a phone number. These are sent to us server-to-server over an encrypted connection and are never placed in a URL.
- Technical data: the network address the request arrives from, which we record to apply fair-use limits and to prevent abuse of an open connector.
What never reaches us this way
Payment card details are never part of the connector. They are entered only on our own checkout, in the payment provider’s secure fields, exactly as described in Section 6. We also do not receive your conversation with the assistant: only the specific fields listed above are transmitted, when the assistant calls the connector.
How long we keep it
Traveller details supplied this way are held in short-lived storage bounded by the validity of the booking link the connector returns — currently up to 24 hours — and are then automatically deleted. They are retained beyond that window only if you complete a booking, at which point they become booking information and are handled as described in the rest of this policy. We do not write these details to our application logs; our records of connector activity contain counts, routes and reference identifiers only.
The assistant provider is a separate controller
The assistant you are talking to is operated by another company under its own privacy policy and its own retention practices. Anything you type into that conversation — including traveller names or passport details — is held by that provider as part of your conversation, and that copy is outside WiseTravel’s control. We are the controller only for the data the connector transmits to us, as described above.
If you would prefer not to enter personal details into a conversation, ask the assistant for a plain booking link instead. That link opens the search on wise-travel.com, where you enter passenger details directly on our own booking form and nothing personal passes through the assistant.
Children
As elsewhere on the Service, details for a child or infant traveller must be provided by the responsible adult making the booking. Section 13 applies equally to details supplied through the connector.
16.Changes to this policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. For material changes, we will make reasonable efforts to notify you (e.g., by email or a notice on the Service). Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
17.Contact us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
- Data protection inquiries: [email protected]
- General support: [email protected]
- Company: WiseTravel Technology Limited
- Hong Kong office: Room A, 7/F, 721 Star House, 3 Salisbury Road, Tsim Sha Tsui, Hong Kong
- UK office: Unit A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom