Privacy Policy
Version: 2026.07.1 · Last updated: July 2026
This Privacy Policy explains how Pet Jet Travel (“we”, “us”) processes personal data when you use the Pet Jet Travel website and booking services (passenger + pet flight eligibility and lead capture). We comply with the EU General Data Protection Regulation (GDPR) and applicable national law.
1. Data controller
- Controller: Pet Jet Travel
- Contact: privacy@petjettravel.com
- Address: Madrid, Spain (EU)
2. Personal data we collect
For passenger + pet bookings we may process:
- Passenger identity & travel: name, title, gender, date of birth, nationality, passport/ID number and expiry, contact email and phone
- Pet data: name, species, breed, weight, age, microchip, EU pet passport number, vaccination records, compliance documents (including uploaded scans)
- Booking & payment: flight selections, fare, payment method, amount, transaction reference, card brand/last four digits (we do not store full card numbers in this MVP demo)
- Technical: browser session/local storage for checkout recovery and cookie consent preference
- GDPR records: consent timestamp and policy version, data retention date, erasure log reference (without PII after erasure)
3. Purposes and legal bases (Art. 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Flight search & pet eligibility | Steps prior to contract (Art. 6(1)(b)) |
| Booking, payment, ticketing (demo) | Contract performance (Art. 6(1)(b)) |
| Pet compliance (vaccines, documents) | Contract + legal obligations for pet travel (Art. 6(1)(b)/(c)) |
| Privacy consent record | Consent (Art. 6(1)(a)) — withdraw via erasure request |
| B2B sub-agency orders | Contract with agency; agency responsible to their clients |
4. Recipients & processors
We may share data only as needed with:
- Hosting & database (e.g. Supabase, EU region where configured)
- Email notifications (e.g. Resend) — operational alerts to our team
- Payment service provider (Stripe, including Apple Pay and Google Pay) — card details go directly to Stripe; we never store your full card number
- Airlines & partners — when your booking is completed with the airline
We do not sell personal data. International transfers outside the EEA, if any, will use appropriate safeguards (SCCs or adequacy decisions).
5. Retention
We retain booking data for up to 730 days after your scheduled departure date, unless you request earlier erasure and we have no overriding legal obligation to keep it (e.g. tax or dispute records). Uploaded documents are deleted with the booking on erasure or purge.
6. Your rights
You have the right to access, rectify, erase, restrict, object, and data portability.
Use our GDPR rights page to download or delete your booking data. We respond within one month (Art. 12(3) GDPR).
You may complain to the Spanish Data Protection Agency (AEPD) or your local EU supervisory authority.
7. Security
We use encryption in transit (HTTPS), access controls, private storage for documents, Row Level Security on databases, and server-only API keys. See our internal security checklist in deployment documentation.
8. Children
Our service is not directed at children under 16. Pet bookings must be submitted by an adult passenger or authorised guardian.
9. Changes
We will update this policy when processing changes. Material changes require renewed consent where legally required. The active version is always published here with version 2026.07.1.
