
Online Travel Agency & Intermediary Platform
Privacy Policy
OTA Intermediary Platform
PRIVACY POLICY
This Privacy Policy forms an integral part of, and is incorporated by reference into, the GoFlyAdventure Terms of Use.
- Version
- 1.0
- Legal Entity
- GoFlyAdventure LLC
- Effective Date
- 01 September 2026
- Last Updated
- 01 September 2026
1. Introduction and Incorporation by Reference
This Privacy Policy (“Privacy Policy”) describes how GoFlyAdventure LLC and its affiliates (“GoFlyAdventure,” “Company,” “we,” “us,” or “our”) collect, use, disclose, store, transfer, and otherwise process personal data in connection with the GoFlyAdventure website, mobile applications, application programming interfaces (APIs), and all related digital services (collectively, the “Platform”).
This Privacy Policy forms an integral and legally binding part of the GoFlyAdventure Terms of Use (the “Terms of Use”), which are incorporated herein by reference in their entirety. This Privacy Policy shall be read together with, and interpreted consistently with, the Terms of Use.
Any capitalized term used but not defined in this Privacy Policy shall have the meaning ascribed to it in the Terms of Use. In the event of any express conflict between this Privacy Policy and the Terms of Use solely with respect to the processing of personal data, this Privacy Policy shall govern to the extent of such conflict; in all other respects, the Terms of Use shall govern.
By accessing, browsing, registering on, or otherwise using the Platform, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, disclosure, and processing of your personal data as described herein, to the extent permitted by applicable law.
As set out in the Terms of Use, GoFlyAdventure operates solely as an online travel agency (OTA), booking intermediary, payment collection intermediary, and online marketplace platform. GoFlyAdventure is not the provider of accommodation, transportation, tours, activities, insurance, or other travel services (“Travel Products”), and independent third-party Suppliers are solely responsible for the Travel Products they offer. This Privacy Policy should be read in light of that intermediary role, including with respect to the categories of personal data that GoFlyAdventure collects, uses, shares, and retains in order to operate the Platform and facilitate transactions between Users and Suppliers.
This Privacy Policy applies to personal data processed by GoFlyAdventure regardless of the means by which it is collected — including through the website, mobile applications, customer support channels, APIs, SDKs, and offline interactions — and regardless of the jurisdiction from which the Platform is accessed.
2. Scope and Application
This Privacy Policy applies to all Users of the Platform, including Travelers, Customers, registered account holders, business account holders, and Suppliers (collectively referred to in this Privacy Policy, unless the context requires otherwise, as “your or “Users”), and to all personal data processed by GoFlyAdventure in connection with the operation of the Platform.
This Privacy Policy applies globally to GoFlyAdventure’s processing of personal data in connection with the Platform, and is designed to comply with internationally recognized data protection principles and with applicable data protection, privacy, cybersecurity, and electronic communications laws in the jurisdictions in which GoFlyAdventure operates or provides its services, including, where applicable, the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”) and other U.S. state privacy laws, Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”), Australia’s Privacy Act 1988, Singapore’s Personal Data Protection Act (“PDPA”), Japan’s Act on the Protection of Personal Information (“APPI”), Brazil’s Lei Geral de Proteção de Dados (“LGPD”), the Swiss Federal Act on Data Protection (“FADP”), and the data protection legislation of the Republic of Albania (collectively, “Applicable Data Protection Laws”).
This Privacy Policy does not apply to the privacy practices of Suppliers, payment processors, or other third parties, who maintain their own independent privacy policies governing their processing of personal data. GoFlyAdventure encourages Users to review the privacy policies of any Supplier or third party with whom they interact through the Platform.
This Privacy Policy does not apply to information that has been aggregated, anonymized, or de-identified in a manner such that it can no longer reasonably be used to identify an individual, and which is therefore no longer considered personal data under Applicable Data Protection Laws.
3. Definitions
For purposes of this Privacy Policy, the following terms shall have the meanings set out below, in addition to any terms defined in the Terms of Use:
“Personal Data” means any information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Laws.
“Processing” means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, transmission, combination, restriction, erasure, or destruction.
“Controller” means the entity that determines the purposes and means of the Processing of Personal Data; “Processor” means an entity that Processes Personal Data on behalf of a Controller.
“Service Provider” or “Supplier” means any independent third-party provider of Travel Products listed or offered on the Platform, including hotels, airlines, tour operators, transport providers, activity operators, and ancillary service providers.
“Guest” means a Traveler or other individual on whose behalf a Booking is made, who may or may not be the Customer who created the Booking.
“KYC” means “Know Your Customer” identity verification procedures; “KYB” means “Know Your Business” verification procedures applicable to Suppliers and business account holders.
“Sensitive Personal Data” or “Special Category Data” means Personal Data that is subject to heightened protection under Applicable Data Protection Laws, such as data revealing racial or ethnic origin, religious beliefs, health information (including disability or dietary/medical requirements relevant to travel), biometric data, or, where applicable, government identification numbers.
“Cookies and Similar Technologies” means cookies, web beacons, pixels, tags, software development kits (SDKs), local storage, and similar tracking technologies described in Section 13 below.
“Transfer Safeguards” means legal mechanisms authorizing the cross-border transfer of Personal Data, including Standard Contractual Clauses (SCCs), adequacy decisions, binding corporate rules, and other mechanisms recognized under Applicable Data Protection Laws.
4. Categories of Personal Data We Collect
GoFlyAdventure collects the categories of Personal Data described below, depending on the nature of your interaction with the Platform. We collect only the Personal Data reasonably necessary to operate the Platform and provide our intermediary, booking, payment collection, and marketplace services.
4.1 Data Collected Directly from Users
Account and profile information, including full name, email address, telephone number, postal address, date of birth, gender (where relevant to travel bookings), username, and password.
Booking and Traveler information, including the names, contact details, dates of birth, and, where required by a Supplier or applicable law, passport or national identification details of Guests traveling under a Booking.
Payment and billing information as described in Section 4.6 below.
Identity verification information as described in Section 4.7 below.
Communications you send to us, including customer support inquiries, feedback, survey responses, and dispute or claims correspondence.
Content you submit to the Platform, including reviews, ratings, photographs, comments, and other User Content.
Preferences and special requirements you provide in connection with a Booking, including dietary requirements, accessibility needs, and other travel preferences, to the extent voluntarily provided by you.
4.2 Data Collected from Service Providers
Business and contact information of Suppliers, including company name, business registration details, tax identification numbers, business address, authorized representative details, and bank account or payment details for the purpose of remitting Booking proceeds.
KYB and licensing information, including business licenses, permits, certificates of insurance, and other documentation Suppliers are required to provide to be onboarded and remain active on the Platform.
Performance and compliance data relating to Suppliers, including Booking history, cancellation rates, complaint history, and ratings, which may include Personal Data of individual proprietors or authorized representatives of a Supplier.
4.3 Data Collected Automatically
Device and technical information, including IP address, device identifiers, browser type and version, operating system, language settings, mobile network information, and hardware identifiers.
Usage data, including pages or screens viewed, search queries, dates and duration of visits, clickstream data, referring and exit pages, and interactions with features of the Platform.
Location data, including approximate location derived from IP address and, where you have granted permission, precise geolocation data from your mobile device, used to provide location-relevant search results and services.
Data collected via cookies, SDKs, APIs, server logs, analytics tools, and other tracking technologies, as described further in Section 13 (Cookies and Similar Technologies) below.
Log data automatically generated by our servers, including access times, error logs, and referring URLs, used for security, diagnostics, and Platform performance purposes.
4.4 Information Received from Third Parties
Information from identity verification and fraud prevention providers engaged to verify the identity of Users and Suppliers and to assess fraud risk.
Information from payment processors and financial institutions relating to the processing, authorization, and settlement of payments.
Information from social media platforms or single sign-on providers where you choose to register for or log in to the Platform using a third-party account, subject to the permissions you grant to such third party.
Information from business partners, marketing partners, and publicly available sources, including sanctions and watchlist databases used for compliance screening.
Information from Suppliers relating to the fulfillment, modification, or cancellation of a Booking.
4.5 Booking Information
Details of the Travel Product booked, including dates, destination, Supplier, price, and Booking reference.
Guest and Traveler details submitted in connection with the Booking, including names as they appear on travel documents and, where applicable, passport, visa, or other identification details required by a Supplier, airline, or destination authority.
Special requests, ancillary services, and modifications associated with a Booking.
Cancellation, refund, and dispute records associated with a Booking.
4.6 Payment Information
Payment card details, bank account details, or other payment instrument information provided at the time of Booking, which is generally collected and processed directly by our third-party payment processors operating in compliance with the Payment Card Industry Data Security Standard (PCI DSS).
Billing address and cardholder or accountholder name associated with a payment instrument.
Transaction records, including amounts charged, refunded, or disputed, currency, and payment method used.
GoFlyAdventure does not store full, unencrypted payment card numbers on its own systems except to the extent permitted under applicable PCI DSS requirements and necessary for fraud prevention, chargeback management, or as otherwise required by law.
4.7 Identity Verification (KYC/KYB) Information
Government-issued identification documents, such as passports, national identity cards, or driver’s licenses, submitted for identity verification purposes.
Selfie images or biometric verification data used to match an individual to their submitted identification document, where such verification methods are used.
For Suppliers and business account holders, business registration certificates, beneficial ownership information, tax identification numbers, and authorized signatory details collected for KYB purposes.
Identity verification information is processed for the purposes described in Sections 7 and 8 below, including fraud prevention, AML compliance, and sanctions screening, and is retained in accordance with Section 15 (Data Retention Periods).
5. Legal Bases for Processing
Where required by Applicable Data Protection Laws (including the GDPR and UK GDPR), GoFlyAdventure relies on one or more of the following legal bases to Process Personal Data:
Performance of a contract, where Processing is necessary to create your account, process a Booking, collect payment, or otherwise perform our obligations to you under the Terms of Use.
Compliance with a legal obligation, where Processing is necessary for GoFlyAdventure to comply with applicable tax, accounting, AML, sanctions, consumer protection, or other legal or regulatory requirements.
Legitimate interests, where Processing is necessary for GoFlyAdventure’s or a third party’s legitimate interests, including operating and improving the Platform, preventing fraud, ensuring platform security, enforcing the Terms of Use, and conducting business analytics, provided such interests are not overridden by your data protection interests or fundamental rights.
Consent, where you have provided consent for a specific Processing activity, such as receiving marketing communications or the use of certain non-essential cookies, which consent you may withdraw at any time as described in Section 17 below.
Vital interests, in the limited circumstance that Processing is necessary to protect your vital interests or those of another person, such as in a travel emergency.
Where Applicable Data Protection Laws in a given jurisdiction do not require identification of a specific legal basis, GoFlyAdventure Processes Personal Data on the bases and for the purposes described in this Privacy Policy, consistent with such laws.
6. Purposes of Processing
GoFlyAdventure Processes Personal Data solely for purposes necessary to operate the Platform and provide its intermediary, booking, payment collection, and marketplace services, including the following purposes:
To create, maintain, and administer User and Supplier accounts.
To process, confirm, modify, and cancel Bookings, and to facilitate communication between Users and Suppliers necessary to fulfill a Booking.
To collect, process, and remit payments, including through third-party payment processors, and to manage refunds, chargebacks, and payment disputes.
To verify the identity of Users and Suppliers (KYC/KYB) and to perform fraud prevention, risk assessment, AML, and sanctions screening as described in Sections 7 and 8.
To provide customer support and respond to inquiries, complaints, and dispute resolution requests.
To send transactional communications, including Booking confirmations, itinerary changes, and service notifications.
To send marketing communications where you have provided consent or as otherwise permitted by Applicable Data Protection Laws, and to manage your marketing preferences.
To personalize your experience on the Platform, including displaying relevant search results, recommendations, and offers.
To maintain the security and integrity of the Platform, including detecting and preventing fraud, unauthorized access, and abuse.
To comply with legal obligations, respond to lawful requests from courts, regulators, and law enforcement authorities, and enforce the Terms of Use and this Privacy Policy.
To conduct analytics, research, and business intelligence, including through the use of aggregated, anonymized, or de-identified data, to improve the Platform and develop new features and services.
To train, test, and improve artificial intelligence and automated technologies used in connection with the Platform, as described in Section 12 below, where permitted by applicable law.
To facilitate a merger, acquisition, reorganization, financing, or sale of assets, as described in Section 21.5 below.
7. Fraud Prevention and Risk Management
GoFlyAdventure Processes Personal Data, including device, transaction, behavioral, and identity verification data, to detect, investigate, and prevent fraudulent transactions, fraudulent listings, fake accounts, payment fraud, chargeback abuse, and other abusive or illegal activity on the Platform.
GoFlyAdventure employs automated risk-scoring tools and manual review processes to assess the risk associated with a given User, Supplier, transaction, or Booking, which may result in additional verification requirements, transaction holds, or account restrictions.
GoFlyAdventure may share Personal Data with fraud prevention service providers, payment processors, and, where necessary, other OTA or marketplace platforms and industry fraud-prevention consortia, for the purpose of preventing fraud across the travel industry, subject to Applicable Data Protection Laws.
Personal Data Processed for fraud prevention purposes is retained in accordance with Section 15 (Data Retention Periods) and may be retained for longer periods than other categories of Personal Data where necessary to detect and prevent recurring or emerging fraud patterns.
8. Anti-Money Laundering (AML) and Sanctions Screening
Where applicable to GoFlyAdventure’s role as a payment collection intermediary, GoFlyAdventure and its payment processing partners may Process Personal Data to comply with applicable anti-money laundering, counter-terrorist financing, and economic sanctions laws and regulations.
GoFlyAdventure and its service providers may screen Users and Suppliers, and the beneficial owners of Supplier businesses, against sanctions lists, politically exposed person (PEP) databases, and other watchlists maintained by competent governmental and international authorities.
Where screening identifies a potential match or compliance concern, GoFlyAdventure may request additional information, suspend or decline a transaction or Booking, restrict or terminate an account, and/or report the matter to competent authorities where required by applicable law.
Records relating to AML and sanctions screening are retained in accordance with applicable legal and regulatory recordkeeping requirements, which may exceed the general retention periods described in Section 15.
9. Communications and Customer Support
GoFlyAdventure Processes Personal Data contained in communications you send to us, including through the Platform’s help center, live chat, email, or telephone customer support channels, in order to respond to your inquiries and resolve complaints and disputes.
Communications with customer support, including call recordings and chat transcripts where applicable, may be retained for quality assurance, training, dispute resolution, and legal compliance purposes, consistent with Section 15 below.
GoFlyAdventure may engage third-party customer support service providers to assist in responding to inquiries, subject to contractual confidentiality and data protection obligations as described in Section 24.5.
GoFlyAdventure sends transactional and service-related communications (such as Booking confirmations, itinerary changes, and security alerts) that are necessary to the performance of the Platform’s services and are not considered marketing communications subject to opt-out under Section 10.
10. Marketing Preferences and Consent Management
Where required by Applicable Data Protection Laws, GoFlyAdventure will only send you marketing communications, including promotional offers, newsletters, and personalized recommendations, with your prior consent or where otherwise permitted (such as an existing customer relationship, subject to opt-out rights).
You may manage your marketing preferences, including opting in or out of specific marketing channels (email, SMS, push notification), at any time through your account settings, the unsubscribe link included in marketing emails, or by contacting us using the details in Section 32.
Where consent is the legal basis for a marketing communication, you may withdraw such consent at any time, without affecting the lawfulness of Processing carried out prior to withdrawal, in accordance with Section 17.7.
Opting out of marketing communications does not affect GoFlyAdventure’s ability to send you transactional or service-related communications necessary to administer your account or fulfill a Booking.
11. Automated Decision-Making and Profiling
GoFlyAdventure may use automated means, including algorithms and, where applicable, machine learning models, to conduct profiling for purposes such as fraud risk scoring, personalized search ranking and recommendations, dynamic pricing display, and marketing personalization.
Where GoFlyAdventure’s automated Processing produces legal or similarly significant effects concerning a User (such as declining a transaction on suspicion of fraud), and to the extent required by Applicable Data Protection Laws, GoFlyAdventure will provide appropriate safeguards, which may include the right to request human review, to express a point of view, and to contest the decision, as further described in Section 17.
Search result rankings on the Platform are determined by algorithms considering factors such as relevance, price, availability, ratings, Booking history, and Supplier quality signals. Sponsored or promoted results are clearly labeled, consistent with the Terms of Use.
You may contact us using the details in Section 32 to request further information regarding the logic, significance, and consequences of automated decision-making that concerns you, to the extent required by applicable law.
12. Artificial Intelligence and Automated Technologies
GoFlyAdventure may use artificial intelligence (AI) and machine learning technologies to support functions such as customer support chatbots, fraud detection, search and recommendation personalization, content moderation, translation, and operational analytics.
Where permitted by applicable law, GoFlyAdventure may use aggregated, anonymized, or de-identified data to train, test, validate, and improve AI and automated technologies used in connection with the Platform. GoFlyAdventure does not knowingly use Sensitive Personal Data to train AI models except where necessary and permitted by applicable law and subject to appropriate safeguards.
GoFlyAdventure may engage third-party AI service providers, subject to contractual confidentiality, security, and data protection obligations consistent with Section 24.
Content generated with the assistance of AI tools on the Platform (such as automated translations or generated summaries) may not always be error-free, and Users should exercise independent judgment when relying on such content.
14. Cross-Border Data Transfers and International Transfer Safeguards
GoFlyAdventure operates internationally, and Personal Data may be transferred to, stored in, and Processed in countries other than the country in which you reside, including countries that may not have data protection laws equivalent to those in your home jurisdiction.
Where GoFlyAdventure transfers Personal Data originating from the European Economic Area, the United Kingdom, Switzerland, or other jurisdictions with cross-border transfer restrictions to a country not deemed to provide an adequate level of protection, GoFlyAdventure implements appropriate Transfer Safeguards, including Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Addendum, or other legally recognized transfer mechanisms.
GoFlyAdventure takes supplementary measures, where necessary, to ensure that transferred Personal Data continues to receive a level of protection consistent with Applicable Data Protection Laws, including contractual, technical, and organizational safeguards.
By using the Platform, you acknowledge that your Personal Data may be transferred internationally as described in this Section, subject to the safeguards described herein and to the extent permitted by Applicable Data Protection Laws.
You may request further information regarding the specific transfer safeguards applicable to your Personal Data by contacting us using the details in Section 32.
15. Data Retention Periods
GoFlyAdventure retains Personal Data only for as long as reasonably necessary to fulfill the purposes for which it was collected, as described in this Privacy Policy, including to provide the Platform’s services, comply with legal, tax, and accounting obligations, resolve disputes, prevent fraud, and enforce our agreements.
As a general matter, and subject to variation based on applicable legal requirements: (a) account information is retained for as long as your account remains active and for a reasonable period thereafter; (b) Booking and transaction records are generally retained for the period required by applicable tax, accounting, and consumer protection laws, which is commonly between five (5) and ten (10) years; (c) identity verification, AML, and sanctions screening records are retained for the period required by applicable financial services and AML regulations; (d) customer support communications are generally retained for a reasonable period to resolve disputes and for quality assurance purposes; and (e) marketing consent and preference records are retained until consent is withdrawn and for a reasonable period thereafter to evidence compliance.
Where Personal Data is no longer necessary for the purposes described in this Privacy Policy, GoFlyAdventure will securely delete, anonymize, or otherwise dispose of such Personal Data in accordance with Section 16, unless a longer retention period is required or permitted by applicable law, including for the establishment, exercise, or defense of legal claims.
Specific retention periods may vary depending on the jurisdiction and the applicable legal, regulatory, or contractual requirements in effect from time to time.
16. Data Deletion Procedures
Upon expiry of the applicable retention period described in Section 15, or upon a valid deletion request submitted in accordance with Section 17, GoFlyAdventure will delete or anonymize the relevant Personal Data using commercially reasonable technical and organizational measures, unless retention is required or permitted by applicable law.
Where full deletion is not immediately possible due to technical constraints (such as the presence of Personal Data in encrypted backups), GoFlyAdventure will restrict further Processing of such Personal Data until it can be permanently deleted in accordance with GoFlyAdventure’s data retention and deletion schedules.
GoFlyAdventure may retain certain Personal Data notwithstanding a deletion request where necessary to comply with a legal obligation, to complete a transaction for which the Personal Data was collected, to resolve a dispute, to detect and protect against fraudulent or illegal activity, to exercise or defend legal claims, or for other purposes permitted by applicable law.
Requests to delete Personal Data associated with an active Booking may be processed after the completion of the Booking and any applicable dispute or cancellation window, consistent with Section 28 (User Account Deletion).
17. User Rights and Privacy Requests
Subject to Applicable Data Protection Laws and applicable exceptions, you may have the following rights with respect to your Personal Data. Where these rights apply, GoFlyAdventure will respond to verified requests within the time period required by applicable law.
Right of access: the right to request confirmation of whether we Process your Personal Data, and to obtain a copy of such Personal Data and related information.
Right to rectification: the right to request correction or updating of inaccurate or incomplete Personal Data.
Right to erasure (“right to be forgotten”): the right to request deletion of your Personal Data, subject to the exceptions described in Section 16.
Right to restriction of processing: the right to request that we limit the way we use your Personal Data in certain circumstances.
Right to object: the right to object to Processing of your Personal Data carried out on the basis of legitimate interests, including for direct marketing purposes.
Right to data portability: the right to receive certain Personal Data you have provided to us in a structured, commonly used, machine-readable format, and to request its transmission to another Controller, where technically feasible.
Right to withdraw consent: where Processing is based on consent, the right to withdraw such consent at any time, without affecting the lawfulness of Processing carried out prior to withdrawal.
Right to opt out of marketing communications, as described in Section 10, and, where applicable, the right to opt out of the sale or sharing of Personal Data or of targeted advertising, to the extent such rights are recognized under Applicable Data Protection Laws (such as the CCPA/CPRA).
Right to lodge a complaint with a competent supervisory or data protection authority in your jurisdiction of residence, work, or the location of the alleged infringement.
GoFlyAdventure honors recognized universal opt-out mechanisms, including the Global Privacy Control (GPC) signal, where required by applicable law, as a valid method of exercising applicable opt-out rights. GoFlyAdventure does not currently respond to browser Do Not Track (DNT) signals that are not legally binding, except where required by applicable law.
To exercise any of the rights described in this Section, you may submit a request through your account settings, the Platform’s privacy request form (where available), or by contacting us using the details in Section 32. We may need to verify your identity before fulfilling a request, and we may decline or limit a request to the extent permitted or required by applicable law.
18. Children’s Privacy
The Platform is not directed to, and is not intended for use by, individuals under the age of eighteen (18) (or the age of majority in the applicable jurisdiction, if higher). GoFlyAdventure does not knowingly collect Personal Data directly from children for the purpose of creating an account or booking travel services independently.
Guest information for minors may be submitted by a parent, legal guardian, or the responsible adult Customer in connection with a Booking that includes minor travelers. By submitting such information, the submitting adult represents that they are authorized to provide such Personal Data on behalf of the minor.
If GoFlyAdventure becomes aware that it has collected Personal Data directly from a child in violation of applicable law without appropriate parental or guardian consent, it will take reasonable steps to delete such Personal Data promptly.
Parents or guardians who believe their child has provided Personal Data to GoFlyAdventure in violation of this Section may contact us using the details in Section 32.
19. Security Measures, Encryption, and Cybersecurity Practices
GoFlyAdventure implements appropriate technical and organizational security measures designed to protect Personal Data against unauthorized access, alteration, disclosure, loss, or destruction, consistent with the Cybersecurity Provisions of the Terms of Use.
Such measures include, as applicable, encryption of Personal Data in transit and, where appropriate, at rest; access controls and role-based access restrictions; network security controls, including firewalls and intrusion detection systems; regular security assessments, vulnerability scanning, and penetration testing; and employee training on data protection and information security.
Payment card information is processed in a manner designed to comply with the Payment Card Industry Data Security Standard (PCI DSS), primarily through the use of PCI DSS-compliant third-party payment processors.
While GoFlyAdventure takes reasonable steps to protect Personal Data, no method of transmission over the internet or method of electronic storage is completely secure, and GoFlyAdventure cannot guarantee absolute security. Users are responsible for maintaining the confidentiality of their account credentials, consistent with the Terms of Use.
GoFlyAdventure maintains internal incident response procedures designed to detect, contain, investigate, and remediate security incidents affecting Personal Data.
20. Data Breach Notification Procedures
In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data (a “Data Breach”), GoFlyAdventure will assess the nature and severity of the Data Breach and take reasonable steps to contain and remediate it.
Where a Data Breach is likely to result in a risk to the rights and freedoms of affected individuals, GoFlyAdventure will notify the competent supervisory authority without undue delay and, where feasible, within any timeframe required by Applicable Data Protection Laws (such as seventy-two (72) hours under the GDPR, where applicable).
Where a Data Breach is likely to result in a high risk to the rights and freedoms of affected individuals, and to the extent required by Applicable Data Protection Laws, GoFlyAdventure will notify affected Users without undue delay, describing the nature of the Data Breach, the likely consequences, and the measures taken or proposed to address it.
GoFlyAdventure maintains an internal record of Data Breaches, including their effects and the remedial action taken, consistent with applicable recordkeeping obligations.
22. International Compliance
GoFlyAdventure is committed to complying with Applicable Data Protection Laws in each jurisdiction in which it operates or provides services, consistent with the Data Protection and Regulatory Disclosures provisions of the Terms of Use.
Where Applicable Data Protection Laws impose jurisdiction-specific requirements or grant jurisdiction-specific rights (such as the CCPA/CPRA in California, the LGPD in Brazil, or the PDPA in Singapore), GoFlyAdventure will comply with such requirements and honor such rights to the extent they apply to you.
GoFlyAdventure maintains records of Processing activities and cooperates with data protection authorities and other competent regulators in accordance with applicable law.
Where required by applicable law, GoFlyAdventure will designate a local representative or data protection point of contact for a given jurisdiction; details, where applicable, are available upon request using the contact information in Section 32.
24. Third-Party Websites and Integrations
The Platform may contain links to, or integrate with, third-party websites, applications, and services that are not owned or controlled by GoFlyAdventure. This Privacy Policy does not apply to such third parties, and GoFlyAdventure encourages you to review their respective privacy policies.
24.1 Payment Gateway Providers
GoFlyAdventure uses third-party payment gateway providers, including Stripe or its successor providers, to process payments on the Platform. These providers Process Personal Data in accordance with their own privacy policies and applicable PCI DSS requirements.
24.2 Cloud Hosting Providers
GoFlyAdventure uses reputable third-party cloud infrastructure and hosting providers to store and Process Personal Data securely, subject to contractual data processing and security obligations consistent with Applicable Data Protection Laws.
24.3 Analytics Providers
GoFlyAdventure uses third-party analytics providers to understand how Users interact with the Platform and to improve its performance and usability, as described in Section 13.
24.4 Advertising Partners
GoFlyAdventure may work with third-party advertising partners to deliver and measure the effectiveness of advertising, subject to applicable consent requirements and your cookie preferences described in Section 23.
24.5 Customer Support Providers
GoFlyAdventure may engage third-party customer support platforms and outsourced support providers to assist in responding to User and Supplier inquiries, subject to contractual confidentiality and data protection obligations.
25. Record Keeping
GoFlyAdventure maintains records of its Processing activities, including the categories of Personal Data Processed, the purposes of Processing, categories of recipients, and applicable retention periods, as required by Applicable Data Protection Laws.
GoFlyAdventure maintains transaction, Booking, identity verification, and compliance records for the periods described in Section 15, in order to satisfy applicable tax, accounting, AML, consumer protection, and regulatory recordkeeping obligations.
Records maintained under this Section may be made available to competent regulatory authorities upon lawful request, consistent with Section 26.
26. Compliance with Court Orders, Law Enforcement, and Regulatory Requests
GoFlyAdventure may access, preserve, and disclose Personal Data where it has a good-faith belief that such action is necessary to: (a) comply with a valid legal process, court order, subpoena, or other lawful request from a competent authority; (b) enforce the Terms of Use and investigate potential violations; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of GoFlyAdventure, its Users, Suppliers, or the public, as required or permitted by applicable law.
GoFlyAdventure cooperates with regulatory investigations and law enforcement inquiries to the extent required or permitted by applicable law, and will, where legally permitted, seek to notify affected Users of a request for their Personal Data prior to disclosure, unless prohibited from doing so by law or legal process.
GoFlyAdventure reviews requests from law enforcement and regulatory authorities to confirm their legal validity before disclosing Personal Data.
27. Intellectual Property Relating to User-Generated Content
Reviews, ratings, photographs, comments, and other User Content that you submit to the Platform may include your name, profile information, or other Personal Data that will be displayed publicly or to other Users, as described in the Intellectual Property provisions of the Terms of Use.
By submitting User Content, you acknowledge that any Personal Data contained within such content may be visible to other Users and the public, consistent with the license granted to GoFlyAdventure under the Terms of Use.
You may request the removal of Personal Data contained in User Content you have submitted, subject to GoFlyAdventure’s content moderation policies and applicable legal requirements, by contacting us using the details in Section 32.
28. User Account Deletion
You may request deletion of your account at any time by using the account deletion feature within the Platform or by contacting customer support, consistent with the Termination provisions of the Terms of Use.
Account deletion does not automatically delete Personal Data associated with completed or active Bookings, transaction records, or other information that GoFlyAdventure is required or permitted to retain in accordance with Section 15 and Section 16.
Following a verified account deletion request, GoFlyAdventure will deactivate your account and, subject to the retention exceptions described in this Privacy Policy, delete or anonymize Personal Data that is no longer necessary to retain.
29. Business Account Privacy
Users who register a business or corporate account on the Platform (“Business Account Holders”) may be required to provide additional information, including company registration details, authorized representative information, and billing details for corporate Bookings.
Personal Data of individuals associated with a Business Account (such as authorized representatives, travelers, or billing contacts) is Processed in accordance with this Privacy Policy, and the Business Account Holder is responsible for ensuring it has the necessary authority and, where required, consent to provide such Personal Data to GoFlyAdventure.
Business Account Holders are responsible for maintaining the confidentiality of their account credentials and for managing the access permissions of individual users authorized to act on behalf of the business account.
30. Provider Privacy Obligations
Suppliers who receive Personal Data of Guests through the Platform in order to fulfill a Booking act as independent Controllers of such Personal Data and are responsible for complying with Applicable Data Protection Laws in their own right, consistent with the Supplier obligations set out in the Terms of Use.
Suppliers must: (a) Process Guest Personal Data solely for the purpose of fulfilling the relevant Booking and any legally required related purposes; (b) implement appropriate technical and organizational security measures to protect such Personal Data; (c) not use Guest Personal Data received through the Platform for independent marketing purposes without an appropriate legal basis; and (d) promptly notify GoFlyAdventure of any Data Breach affecting Personal Data received through the Platform, to the extent it may affect GoFlyAdventure’s Users.
GoFlyAdventure is not responsible for a Supplier’s independent Processing of Personal Data outside the scope of the Platform, consistent with GoFlyAdventure’s intermediary status under the Terms of Use.
31. Changes to This Privacy Policy
GoFlyAdventure reserves the right to modify, amend, or update this Privacy Policy at any time, consistent with Section 5 (Updates to Terms) of the Terms of Use.
Material changes to this Privacy Policy will be communicated through the Platform or via email, and, where required by Applicable Data Protection Laws, GoFlyAdventure will obtain your renewed consent prior to any material change in the purposes for which your Personal Data is Processed.
The “Effective Date” at the top of this Privacy Policy indicates when the most recent version took effect. Your continued use of the Platform after the effective date of any update constitutes acceptance of the revised Privacy Policy, to the extent permitted by applicable law.
32. Contact Information and Data Protection Officer
If you have questions, concerns, or requests regarding this Privacy Policy or GoFlyAdventure’s Processing of your Personal Data, you may contact us at privacy@goflyadventure.com.
GoFlyAdventure’s Data Protection Officer, designated where required by Applicable Data Protection Laws, can be contacted at dpo@goflyadventure.com, consistent with the Terms of Use.
General correspondence and legal notices may also be directed to GoFlyAdventure LLC through the contact channels made available on the Platform’s help center.
Where you are located in the European Economic Area, the United Kingdom, or Switzerland and have concerns regarding GoFlyAdventure’s Processing of your Personal Data that cannot be resolved directly with us, you have the right to lodge a complaint with your local supervisory authority.
33. Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of Albania, without regard to its conflict of law provisions, consistent with the governing law provisions of the Terms of Use.
Any dispute arising out of or relating to this Privacy Policy shall be subject to the Dispute Resolution and Class Action Waiver provisions of the Terms of Use, including the internal complaint procedure, mediation, and binding arbitration seated in Tirana, Republic of Albania.
The foregoing governing law and dispute resolution provisions apply to the extent permitted by applicable law and do not deprive you of any mandatory statutory protections available to you as a consumer under the law of your country of habitual residence.
34. Severability
If any provision of this Privacy Policy is held to be invalid, illegal, or unenforceable by a court or authority of competent jurisdiction, the remaining provisions shall continue in full force and effect. The invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving its original intent, consistent with the Severability provisions of the Terms of Use.
35. Entire Agreement
This Privacy Policy, together with the Terms of Use, Cookie Policy, and any other policies incorporated by reference, constitutes the entire agreement between you and GoFlyAdventure LLC regarding the Processing of your Personal Data in connection with the Platform, and supersedes all prior and contemporaneous agreements, representations, and understandings, whether written, oral, or implied, regarding such subject matter.
36. Electronic Acceptance
By accessing, browsing, registering on, or using the Platform in any manner, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy, consistent with the Electronic Consent provisions of the Terms of Use.
You agree that your electronic acceptance of this Privacy Policy, and all notices and disclosures provided to you electronically, satisfy any legal requirement that such acceptance, notices, or disclosures be in writing.
If you do not agree to this Privacy Policy, you must not access or use the Platform.
