When you make a booking, we collect:
Your data is used exclusively to:
Passport page images, boarding passes, and TDAC confirmations, together with encrypted passport numbers, are automatically deleted 30 days after your scheduled flight date. This is not immediate on the day of service — we retain documents through your travel date and a short post-travel window for operational support, then remove them without manual action.
The automated deletion process:
Booking records (name, contact, flight, payment references) are retained for up to 12 months for support and dispute resolution, then anonymised. You may request earlier deletion via Contact; we honour verified requests within 30 days where applicable law allows.
Blockchain transaction records are retained indefinitely as they are publicly available on-chain and serve as proof of payment.
Encryption at rest: passport numbers are encrypted using AES-256-GCM with a unique IV per entry before storage in our database. Document images are stored in private S3-compatible object storage with provider-side encryption at rest.
Access controls: decryption of passport numbers and viewing of passport images is limited to authenticated FastTrack admin users with site-scoped permissions. Airport partners receive only the minimum operational details needed to deliver the service — not standing access to our document store.
Access logging: every admin view of a decrypted passport number or passport image is recorded in an audit log (timestamp, admin identity, IP address).
Transfer security: document uploads and admin retrieval use short-lived presigned URLs. Images are not published on permanent public links.
Cloud infrastructure: our application, database, encrypted object storage, and transactional email run on established cloud providers under our control. See our Data & privacy page for categories of subprocessors.
If you choose to accept analytics on our site, we use our first-party FastTrack Analytics service to help us understand how pages are used (for example session replay and usage patterns). Analytics runs only after you grant consent via the in-app banner; without consent we do not collect usage data or session replay on your device. Data is processed under our control and is described in this policy. For architecture, retention defaults, and what we do not do with analytics, see our Data & privacy page.
We share the minimum necessary information with our airport partner operator to deliver the fast-track service. We do not sell, rent, or share your personal data with any other third party.
You may request access to, correction, or deletion of your personal data at any time by contacting us. Deletion requests will be honoured within 30 days, subject to legal retention requirements.