1. Our approach
FastTrack BKK ("we", "us") treats data sovereignty as a product choice: we decide what we collect, where it is stored, how long we keep it, and who can access it. We do not outsource website usage analytics to third-party session-replay vendors. Booking data and optional website analytics are handled as separate systems with different purposes and retention rules.
2. Two kinds of data
| Kind | Purpose | When collected |
|---|
| Booking data | Fulfil your fast-track service, issue vouchers, support, refunds | When you book or contact us |
| Website analytics | Understand how pages are used (optional session replay and usage events) | Only after you accept the analytics consent banner |
These streams are not stored in the same database. A booking record is not merged with analytics replay by default; where we link a completed booking to a browsing session, we use opaque identifiers supplied at checkout, not passport numbers in analytics storage.
3. Booking data
When you make a booking, we process personal data needed to deliver the service, including:
- Contact details, flight information, and passenger names
- Passport data (encrypted passport numbers, passport photos) for operator handoff
- Payment references only — PayPal/Stripe order and capture IDs, payer email, amounts, bank transfer references, or blockchain transaction hashes. We never store full card numbers or CVV codes.
We share the minimum necessary details with our vetted airport partner operator to deliver the service. We do not sell or rent booking data.
Passport and document retention
Passport-related data is not kept indefinitely. Deletion is automatic and documented:
- Passport page images, boarding passes, and TDAC confirmations are automatically deleted 30 days after your scheduled flight date (not immediately after the service — we need documents through travel day and a short post-travel window for operational support).
- Encrypted passport numbers in our database are cleared at the same time.
- An automated daily job removes storage objects, wipes related database fields, and marks the booking as purged.
- Booking contact details, flight information, and payment references may be kept for up to 12 months for support and dispute resolution, then anonymised. You can request earlier deletion via Contact.
Storage and access controls
- Encryption at rest: passport numbers are encrypted with AES-256-GCM (unique IV per record) before storage. Document images are held in private S3-compatible object storage with provider-side encryption at rest.
- Access limited to authorised staff: full passport images and decrypted passport numbers are available only to authenticated FastTrack admin users with site-scoped permissions — not to the public or anonymous API callers.
- Access logging: every admin view of a passport image or decrypted passport number is recorded (timestamp, admin identity, IP address) in an audit log.
- Time-limited URLs: document uploads and admin retrieval use short-lived presigned URLs; images are not served from permanent public links.
- Third-party infrastructure: we use established cloud providers for application hosting, PostgreSQL databases, encrypted object storage, and transactional email (see section 6). Airport partners receive only the minimum operational details needed to perform the service.
- Payments: card data is entered on PayPal-hosted fields or Stripe-hosted checkout; our servers never receive card numbers or CVV codes. We store only provider order IDs, capture/settlement metadata, and reconciliation references.
- Staff MFA: ops admin accounts that can decrypt passport data can enable TOTP-based multi-factor authentication.
- Document OCR: passport, boarding-pass, and TDAC images are sent to Mistral AI (paid API) only to extract booking fields. We do not use this data to train AI models; Mistral’s paid API does not use API inputs or outputs for model training.
Full legal detail: Privacy Policy.
4. Website analytics (FastTrack Analytics)
If you accept analytics in our consent banner, we use first-party FastTrack Analytics — software we operate ourselves — to collect usage events and optional session replay on this website. If you decline, we do not enable analytics collection or session replay for your browser session.
- No third-party session replay (for example Microsoft Clarity or similar marketing analytics replay tools)
- Consent-first: analytics runs only after your explicit choice on the banner
- Separate storage: analytics events and replay chunks live in a dedicated analytics database and object storage, not in our booking database
- Retention limits: usage events are retained for up to 90 days; session replay for up to 30 days, then automatically purged
- Erasure: we can delete analytics data tied to a visitor identifier on request (subject to verifying the request)
Analytics may record page paths, clicks, and a masked replay of page structure. We configure replay masking for sensitive fields where applicable. Do not enter passport or payment details into free-text fields on marketing pages.
5. What we do not do
- Sell or rent your personal data to data brokers or advertisers
- Use third-party ad-tech pixels for on-site session replay on this booking site
- Require analytics consent to complete a booking — analytics is optional
- Store passport numbers inside our analytics product database
- Use your travel documents or extracted fields to train AI models
6. Infrastructure
Our systems run on established cloud providers under our control (including hosting, databases, and encrypted object storage). Payment processing is provided by PayPal and Stripe. Data may be processed in regions where those providers operate data centres. We choose subprocessors for reliability and security; a current list of categories is: web hosting and CDN, application and database hosting, encrypted blob storage, transactional email, payment processors (PayPal, Stripe), and document OCR (Mistral AI).
Document OCR (Mistral AI): uploaded passport, boarding-pass, and TDAC images are sent to Mistral’s paid API solely to extract booking fields. We do not use this data to train AI models, and Mistral’s paid API does not use API inputs or outputs for model training.
This page describes architectural choices and defaults. It does not replace the Privacy Policy for lawful bases, international transfers, or formal data-subject requests.
7. Your choices
- Decline analytics on the consent banner — no usage replay or analytics events are collected for that choice
- Change your mind by clearing site data for this domain; the banner will appear again on your next visit
- Request access, correction, or deletion of booking personal data via Contact; we respond within 30 days where applicable law requires
- Analytics erasure: contact us with details from your request; we will action deletion of analytics visitor data where we can verify the request