Your Privacy Matters

Privacy Policy

AeroJet is a travel agency platform — not an airline. We facilitate flight search and booking, but all flight operations, passenger carriage, and associated legal responsibilities belong to the operating airline. Here's how we handle your data.

Effective: September 8, 2026Updated: September 8, 2026

Important Disclaimer

AeroJet is a travel agency and technology platform — not an airline carrier. We do not operate any aircraft, set flight schedules, or determine baggage policies. All contractual obligations related to flight operations, on-board services, passenger carriage, delays, cancellations, and refunds are the sole responsibility of the operating airline. By using AeroJet, you acknowledge this distinction.

1. Who We Are

AeroJet ("we," "us," or "our") operates the website https://aerojet.vercel.app (the "Platform"). AeroJet is a travel technology and booking agency that enables users to search, compare, and book airline tickets from multiple carriers.

We are NOT an airline. We do not operate flights, set fares, determine baggage allowances, or control in-flight services. When you book a flight through AeroJet, your contract of carriage is directly between you and the operating airline. We act solely as an intermediary agent facilitating the booking transaction.

This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Platform. By using AeroJet, you consent to the practices described herein.

2. Information We Collect

2.1 Personal Information You Provide

When you search for or book flights through AeroJet, we may collect:

  • Identity Data: Full legal name, date of birth, gender, nationality, and passport or government ID details (as required by airlines and immigration authorities).
  • Contact Data: Email address, phone number, and billing/mailing address.
  • Passenger Data: Frequent flyer numbers, meal preferences, seat preferences, special assistance requirements, and Known Traveler Numbers (TSA PreCheck/Global Entry).
  • Payment Data: Credit/debit card numbers, expiry dates, and billing information. Payment details are processed by PCI-DSS-compliant payment processors and are never stored on AeroJet servers.
  • Communication Data: Messages, emails, and feedback you send to our customer support team.

2.2 Information Collected Automatically

When you use our Platform, we automatically collect:

  • Device Data: IP address, browser type and version, operating system, device identifiers, and screen resolution.
  • Usage Data: Pages visited, search queries (origin/destination cities, travel dates, cabin class preferences), click patterns, session duration, and referral URLs.
  • Location Data: Approximate geographic location derived from your IP address to provide region-relevant results and currency formatting.

2.3 Information from Third Parties

  • Airlines & GDS Providers: Booking confirmation details, e-ticket numbers (PNR), itinerary updates, and fare rules received from airlines and Global Distribution Systems (e.g., Amadeus, Sabre, Travelport).
  • Payment Providers: Transaction verification and fraud detection signals.

3. How We Use Your Information

We use the information we collect for the following purposes:

Flight Booking & Ticketing

Processing your flight search requests, executing bookings with airlines, issuing e-tickets and PNR confirmations.

Passenger Communication

Sending booking confirmations, itinerary changes, check-in reminders, and flight status notifications.

Customer Support

Responding to your queries, processing refund or change requests, and coordinating with airlines on your behalf.

Regulatory Compliance

Sharing mandatory Advance Passenger Information (API/APIS) with airlines, immigration, and customs authorities as legally required.

Fraud Prevention

Detecting and preventing fraudulent transactions, unauthorized access, and abuse of our Platform.

Platform Improvement

Analyzing aggregated usage patterns to improve search results, user experience, and system performance.

4. Airline Responsibility & Limitation of Liability

Key Principle: AeroJet acts exclusively as a booking intermediary. The operating airline is the contracting carrier and bears all legal responsibility for flight operations, passenger carriage, delays, cancellations, lost/damaged baggage, and in-flight services under applicable aviation law (EU Regulation 261/2004, US DOT Title 14 CFR, Montreal Convention 1999, etc.).

4.1 What the Airline Is Responsible For

  • Contract of Carriage: Your ticket constitutes a contract directly between you and the airline. The airline's conditions of carriage, not AeroJet's terms, govern the flight.
  • Flight Operations: All scheduling, routing, aircraft selection, crew operations, on-time performance, and safety decisions.
  • Delays & Cancellations: Compensation, rebooking, duty of care (meals, hotel accommodation), and refunds for flight disruptions.
  • Baggage: Checked/carry-on baggage allowances, fees, loss, damage, and delay claims under the Montreal Convention.
  • Refunds: Processing fare refunds directly to passengers as required by applicable law and the airline's fare rules.
  • Passenger Data during Carriage: The airline independently collects, processes, and manages your data under its own privacy policy once your booking is transferred to the carrier.

4.2 What AeroJet Is Responsible For

  • Accurately transmitting your booking details and passenger information to the airline.
  • Providing you with confirmed booking references (PNR), e-ticket numbers, and itinerary receipts.
  • Assisting with communication between you and the airline for booking modifications (subject to airline policies and fare rules).
  • Safeguarding your personal data while it is in our custody, as described in this Privacy Policy.
  • Providing customer support for booking-related queries processed through our Platform.

5. Third-Party Data Sharing

We share your personal data only when necessary to fulfill your booking or as required by law. We never sell your personal information to marketers or data brokers.

Airlines & Carriers

Your name, passport details, date of birth, contact information, frequent flyer numbers, and special requests are transmitted to the operating airline to fulfill your booking and comply with Advance Passenger Information System (APIS) requirements.

Global Distribution Systems (GDS)

Booking data is transmitted through GDS/API platforms (such as Amadeus, Duffel, Sabre, Travelport) that serve as intermediaries between AeroJet and airlines.

Payment Processors

Payment card information is processed by PCI-DSS Level 1 certified processors (e.g., Stripe, Adyen). AeroJet does not store full card numbers on its servers.

Government & Immigration Authorities

Advance Passenger Information (API/APIS) data is shared with customs and border control agencies as mandated by law for international travel.

Analytics Providers

Anonymized, aggregated usage data may be shared with analytics services (e.g., Google Analytics) to improve Platform performance. No personally identifiable information is shared.

Legal & Regulatory Bodies

We may disclose information if required by law, court order, subpoena, or to protect the rights, safety, and security of AeroJet and its users.

6. Cookies & Tracking Technologies

AeroJet uses cookies and similar technologies to enhance your experience:

Cookie TypePurposeDuration
EssentialSession management, CSRF protection, authentication, and shopping cart persistence.Session / 24 hrs
FunctionalRemembering language, currency, search preferences, and recent searches.30 days
AnalyticsAggregated visitor statistics, page performance metrics, and error monitoring.13 months
MarketingRetargeting ads and conversion measurement (only with your explicit consent).90 days

You can manage cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of our Platform, including the ability to complete bookings.

7. Payment Security

All payment transactions on AeroJet are processed through PCI-DSS Level 1 certified payment processors. We implement the following safeguards:

  • Encryption: All payment pages use TLS 1.3 encryption. Card data is transmitted directly to the payment processor and is never stored on or passes through AeroJet servers.
  • Tokenization: For returning users, payment instruments are represented as secure tokens — AeroJet never has access to raw card numbers.
  • 3-D Secure: We support 3-D Secure (Verified by Visa / Mastercard SecureCode) for additional authentication on applicable transactions.
  • Fraud Detection: Automated risk scoring is applied to every transaction to flag and prevent unauthorized purchases.

8. Data Retention

We retain your personal data only for as long as necessary:

Data CategoryRetention Period
Booking & Itinerary Records7 years (regulatory/tax compliance)
Payment Transaction Logs7 years (financial audit requirements)
Customer Support Records3 years from last interaction
Account Profile DataUntil account deletion request
Analytics & Usage Logs26 months (anonymized after 13 months)
Marketing Consent RecordsDuration of consent + 3 years

Upon expiration of the applicable retention period, personal data is securely deleted or irreversibly anonymized.

9. Data Security

We employ industry-standard technical and organizational measures to protect your data:

  • Encryption in Transit: All communications between your browser and our servers use TLS 1.2/1.3 encryption.
  • Encryption at Rest: Sensitive personal data stored in our databases is encrypted using AES-256 encryption.
  • Access Control: Strict role-based access control (RBAC) limits employee access to personal data on a need-to-know basis.
  • Infrastructure: Our Platform is hosted on enterprise-grade cloud infrastructure with DDoS protection, WAF (Web Application Firewall), and continuous monitoring.
  • Incident Response: We maintain a documented data breach response plan and will notify affected users and regulatory authorities within 72 hours as required by applicable law (GDPR Article 33).

While we implement robust security measures, no system is entirely impervious. We encourage you to use strong, unique passwords and enable two-factor authentication where available.

10. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

10.1 GDPR Rights (EU/EEA/UK Residents)

  • Right of Access: Request a copy of all personal data we hold about you.
  • Right to Rectification: Correct inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your data ("right to be forgotten"), subject to legal retention obligations.
  • Right to Restrict Processing: Limit how we use your data in certain circumstances.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or for direct marketing.
  • Right to Withdraw Consent: Withdraw consent at any time for consent-based processing.

10.2 CCPA/CPRA Rights (California Residents)

  • Right to Know: What personal information we collect, use, disclose, and sell.
  • Right to Delete: Request deletion of your personal information.
  • Right to Opt-Out: Opt out of the sale or sharing of personal information. Note: AeroJet does not sell personal information.
  • Right to Non-Discrimination: We will not deny services, charge different prices, or provide a different quality of service for exercising your rights.

10.3 How to Exercise Your Rights

To exercise any of your rights, contact us at privacy@aerojet.com. We will respond to verified requests within 30 days (GDPR) or 45 days (CCPA/CPRA). We may request identity verification before processing your request.

Important: Your rights under this section apply to data held by AeroJet. For data held by airlines (after your booking has been transferred to the carrier), you must contact the airline directly under their own privacy policy.

11. International Data Transfers

As a global flight booking platform, your personal data may be transferred to and processed in countries outside your country of residence, including:

  • Airline headquarters and operational systems worldwide.
  • GDS providers with data centers across multiple regions.
  • Cloud hosting providers in the United States and European Union.
  • Government immigration systems in destination and transit countries.

For transfers from the EU/EEA/UK, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission and/or adequacy decisions. Airlines receiving your data operate under their own legal transfer mechanisms.

12. Children's Privacy

AeroJet does not knowingly collect personal information from children under the age of 16 without verifiable parental or guardian consent. Flight bookings for minors must be made by a parent or legal guardian.

If we discover that we have inadvertently collected data from a child under 16 without proper consent, we will promptly delete such information. If you believe a child's data has been submitted without authorization, please contact us at privacy@aerojet.com.

13. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or regulatory obligations. When we make material changes:

  • We will update the "Last Updated" date at the top of this page.
  • For significant changes, we will provide a prominent notice on our Platform and/or notify you via email if you have an account with us.
  • Your continued use of AeroJet after the effective date constitutes acceptance of the updated Privacy Policy.

We encourage you to review this page regularly for the latest information on our privacy practices.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Data Privacy Team

Email: privacy@aerojet.com

Website: https://aerojet.vercel.app

Platform: AeroJet

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority (e.g., the ICO in the UK, CNIL in France, or the relevant state attorney general in the US).

Frequently Asked Questions

Have Questions?

Our privacy team is here to help. If you have any concerns about how your data is handled, don't hesitate to reach out.