Who is responsible
travelbyluma is the data controller for the personal data described here. Where we pass data to an airline, that airline becomes an independent controller for its own processing, governed by its own privacy notice.
Data we collect
Booking and passenger data
Full name as printed on your travel document, date of birth, gender marker, nationality, passport or national ID number and expiry, frequent-flyer number, and any accessibility, meal or seating requirement you tell us about. Carriers and border authorities require these fields; a ticket cannot be issued without them.
Contact data
Email address, phone number and billing address.
Payment data
Card details are captured by our PCI-DSS certified payment processor and are never stored on travelbyluma systems. We retain only the card brand, the last four digits and an authorisation reference, which is what a refund needs.
Technical data
IP address, device and browser type, referring page, and the pages you viewed. Used for fraud screening, security and aggregate traffic measurement.
Accessibility and meal requirements can reveal health or religious information. We collect them only when you volunteer them, use them solely to pass the request to the carrier, and delete them once travel is complete.
Why we use it
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Issuing and servicing your ticket | Performance of a contract |
| Advance passenger information to border authorities | Legal obligation |
| Fraud prevention and payment screening | Legitimate interests |
| Disruption and schedule-change alerts | Performance of a contract |
| Marketing emails and fare alerts | Consent — withdrawable at any time |
| Accounting and tax records | Legal obligation |
Who we share it with
- Operating and marketing carriers on your itinerary, to issue and service the ticket.
- Global Distribution Systems (Amadeus, Sabre, Travelport) that hold the reservation record.
- Border and customs authorities, where Advance Passenger Information or PNR transfer is legally mandated for your route.
- Payment processors and acquiring banks, to take payment and issue refunds.
- Hotel, rail, cruise and car suppliers, only for the components you actually book.
We do not sell personal data, and we do not share it with data brokers or advertising networks.
International transfers
Air travel is inherently cross-border: a flight to Dubai means your data reaches the UAE. Where data leaves the UK or EEA we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses, except where the transfer is necessary for the performance of your travel contract under GDPR Article 49(1)(b).
Cookies and analytics
This site sets no advertising or cross-site tracking cookies. Strictly necessary cookies maintain your session and search state. Where analytics are enabled they are aggregate and IP-truncated, and you can opt out without losing any functionality.
How long we keep it
- Booking records: 7 years after travel, for tax and audit.
- Passport and ID numbers: deleted 90 days after travel completes.
- Special-category requests (accessibility, meals): deleted on completion of travel.
- Marketing consent records: until you withdraw consent, plus 2 years as proof of withdrawal.
- Technical logs: 12 months.
Your rights
Depending on where you live, you may ask us to:
- confirm what we hold about you and give you a copy;
- correct data that is wrong or incomplete;
- delete data we no longer need — note that a ticketed reservation cannot be erased while the carrier is contractually obliged to retain it;
- restrict or object to processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw marketing consent, which you can also do from any email footer.
California residents additionally have the right to know, to delete, to correct and to opt out of "sharing" under the CCPA/CPRA. We do not sell or share personal information as those terms are defined, so no opt-out link is required.
We respond within 30 days. If you are unhappy with the outcome you can complain to your national supervisory authority.
Security
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access to passenger records is role-based and logged. Payment card data never touches our infrastructure. We run annual third-party penetration testing and will notify affected travellers and the relevant authority within 72 hours of any breach likely to result in risk to their rights.
Contacting us
Privacy requests: privacy@travelbyluma.com. General support: support@travelbyluma.com or +1 (877) 413-3006. Please include your booking reference so we can verify your identity without asking for more data than necessary.