Preview environment — flight bookings and payments use test systems. Do not enter real payment details.
Home

ZaraTrip

Privacy notice

Last updated September 2026

Preview notice: this draft describes the current test application and the intended live service. It must be reviewed against the final operating company, suppliers and applicable laws before launch.

This policy explains what personal data ZaraTrip collects, why, and your rights over it. We aim to collect the minimum needed to book and service your travel.

Data we collect

  • Account: email, name, password (stored only as a secure hash).
  • Passenger details needed for a booking: names, date of birth, contact details, and travel document details where the airline requires them.
  • Booking and payment records (we never store full card numbers or CVV).
  • Technical data: IP address, device/browser info, used for security and fraud checks.

How we use it

To create and service your bookings, process payments and refunds, provide customer support, prevent fraud, comply with legal obligations, and — only with your consent — send marketing.

Sharing

We share the data necessary to fulfil a flight booking with the relevant airlines and with Duffel, our flight-content and sandbox-booking provider. A live payment provider has not yet been selected for this preview. We do not sell your personal data.

Card data

Live card collection is not enabled in this preview. Do not enter real payment details. Before launch, card data will be collected only through a verified payment provider’s hosted or embedded secure components, and this notice will name that provider and explain the data flow.

Your rights

Where the GDPR applies, you have rights to access, correct, delete, restrict, or port your data, and to withdraw consent. We honour right-to-erasure requests by anonymising bookings while retaining the minimal financial records the law requires. Email privacy@zaratrip.com.

Retention & security

We keep personal data only as long as needed for the purposes above or as required by law. Data is encrypted in transit (TLS) and at rest, with document details held under column-level encryption.

This notice is not marked final. It requires qualified privacy review before public launch.