---
title: 隐私政策
description: FastTrack BKK 隐私说明：为何收集预订与护照照片、HTTPS 加密传输与存储、保留期限与自动删除、是否与第三方共享，以及如何通过页脚邮箱联系我们行使查阅、更正或删除等隐私权利。
---

# 隐私政策

## 1. Data We Collect

When you make a booking, we collect:

- **Personal information:** full name, date of birth, nationality, email address, phone number
- **Passport data:** passport number (encrypted at rest with AES-256-GCM), passport photo page image, selfie
- **Flight details:** flight number, date, terminal
- **Payment data:** blockchain transaction hash, wallet address (sender), payment amount, chain and token

## 2. How We Use Your Data

Your data is used exclusively to:

- Process and fulfil your booking
- Forward necessary details to the partner operator at the airport
- Send your electronic voucher
- Handle support inquiries and refund requests

## 3. Data Retention

**Passport data** (encrypted passport numbers, passport photos, selfies) is automatically purged **30 days** after the flight date to minimise data exposure risk.

**Blockchain transaction records** are retained indefinitely as they are publicly available on-chain and serve as proof of payment.

**Booking records** (name, contact, flight) are retained for up to 12 months for support and dispute resolution, then anonymised.

## 4. Data Security

Passport numbers are encrypted using AES-256-GCM with a unique IV per entry. Decryption is only performed on-demand by authorised admin personnel, and every decryption event is logged in an immutable audit trail including timestamp, admin identity, and IP address.

Images are stored in encrypted-at-rest blob storage and served via time-limited signed URLs.

## 5. Website analytics (FastTrack Analytics)

If you choose to accept analytics on our site, we use our first-party FastTrack Analytics service to help us understand how pages are used (for example session replay and usage patterns). Analytics runs only after you grant consent via the in-app banner; without consent we do not collect usage data or session replay on your device. Data is processed under our control and is described in this policy. For architecture, retention defaults, and what we do not do with analytics, see our Data & privacy page.

## 6. Third Parties

We share the minimum necessary information with our airport partner operator to deliver the fast-track service. We do not sell, rent, or share your personal data with any other third party.

## 7. Your Rights

You may request access to, correction, or deletion of your personal data at any time by contacting us. Deletion requests will be honoured within 30 days, subject to legal retention requirements.
