Policies & Legal

Privacy Policy

Booking a flight requires more personal data than most online purchases — carriers are legally obliged to collect it. This page sets out exactly what we take, why each item is necessary, and what you can ask us to do with it.

Last updated 1 September 2026privacy@travelbyluma.com

Who is responsible

travelbyluma is the data controller for the personal data described here. Where we pass data to an airline, that airline becomes an independent controller for its own processing, governed by its own privacy notice.

Data we collect

Booking and passenger data

Full name as printed on your travel document, date of birth, gender marker, nationality, passport or national ID number and expiry, frequent-flyer number, and any accessibility, meal or seating requirement you tell us about. Carriers and border authorities require these fields; a ticket cannot be issued without them.

Contact data

Email address, phone number and billing address.

Payment data

Card details are captured by our PCI-DSS certified payment processor and are never stored on travelbyluma systems. We retain only the card brand, the last four digits and an authorisation reference, which is what a refund needs.

Technical data

IP address, device and browser type, referring page, and the pages you viewed. Used for fraud screening, security and aggregate traffic measurement.

Accessibility and meal requirements can reveal health or religious information. We collect them only when you volunteer them, use them solely to pass the request to the carrier, and delete them once travel is complete.

Why we use it

PurposeLegal basis (GDPR Art. 6)
Issuing and servicing your ticketPerformance of a contract
Advance passenger information to border authoritiesLegal obligation
Fraud prevention and payment screeningLegitimate interests
Disruption and schedule-change alertsPerformance of a contract
Marketing emails and fare alertsConsent — withdrawable at any time
Accounting and tax recordsLegal obligation

Who we share it with

  • Operating and marketing carriers on your itinerary, to issue and service the ticket.
  • Global Distribution Systems (Amadeus, Sabre, Travelport) that hold the reservation record.
  • Border and customs authorities, where Advance Passenger Information or PNR transfer is legally mandated for your route.
  • Payment processors and acquiring banks, to take payment and issue refunds.
  • Hotel, rail, cruise and car suppliers, only for the components you actually book.

We do not sell personal data, and we do not share it with data brokers or advertising networks.

International transfers

Air travel is inherently cross-border: a flight to Dubai means your data reaches the UAE. Where data leaves the UK or EEA we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses, except where the transfer is necessary for the performance of your travel contract under GDPR Article 49(1)(b).

Cookies and analytics

This site sets no advertising or cross-site tracking cookies. Strictly necessary cookies maintain your session and search state. Where analytics are enabled they are aggregate and IP-truncated, and you can opt out without losing any functionality.

How long we keep it

  • Booking records: 7 years after travel, for tax and audit.
  • Passport and ID numbers: deleted 90 days after travel completes.
  • Special-category requests (accessibility, meals): deleted on completion of travel.
  • Marketing consent records: until you withdraw consent, plus 2 years as proof of withdrawal.
  • Technical logs: 12 months.

Your rights

Depending on where you live, you may ask us to:

  • confirm what we hold about you and give you a copy;
  • correct data that is wrong or incomplete;
  • delete data we no longer need — note that a ticketed reservation cannot be erased while the carrier is contractually obliged to retain it;
  • restrict or object to processing based on legitimate interests;
  • receive your data in a portable, machine-readable format;
  • withdraw marketing consent, which you can also do from any email footer.

California residents additionally have the right to know, to delete, to correct and to opt out of "sharing" under the CCPA/CPRA. We do not sell or share personal information as those terms are defined, so no opt-out link is required.

We respond within 30 days. If you are unhappy with the outcome you can complain to your national supervisory authority.

Security

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access to passenger records is role-based and logged. Payment card data never touches our infrastructure. We run annual third-party penetration testing and will notify affected travellers and the relevant authority within 72 hours of any breach likely to result in risk to their rights.

Contacting us

Privacy requests: privacy@travelbyluma.com. General support: support@travelbyluma.com or +1 (877) 413-3006. Please include your booking reference so we can verify your identity without asking for more data than necessary.