Last updated: August 6, 2026
Faretriever watches flights you have already booked and tells you when the fare drops, the schedule moves, or the aircraft changes. To do that we have to hold some genuinely sensitive things about your travel — including your booking confirmation number. This page explains exactly what we hold, why, who else touches it, and how to get it back or get rid of it. It is written to be read, not skimmed past.
Faretriever is run by one person: Brian, trading as Cord Contracting, in the United States. If anything here is unclear, email brian@cordco.com and a human will answer.
Every item below exists because a specific feature needs it. Nothing is collected “just in case.”
Your account
The flights you add
Your airline loyalty memberships
What the service produces about you
Technical data
We do not collect your location, your contacts, your calendar, photos, health data, or anything from other apps. We do not have your payment card details — see “Payments” below.
This deserves its own section, because we would rather you knew the risk than discovered it.
A record locator plus a last name is often enough.
On many airline websites, a six-character confirmation number together with a passenger surname is all it takes to view an itinerary — and sometimes to change or cancel it. If someone got hold of that pair, they could interfere with your booking.
Storing it is optional. Every part of Faretriever works without it; the only difference is that our alert email will not be able to print it for you when you call. If you would rather not have it in our database, leave the field blank, or clear it later by editing the flight.
Being straight with you about how it is stored: your confirmation number sits in our database as ordinary text, protected by our database provider's own encryption of stored data and by the access controls on the account. We do not add a second, Faretriever-specific layer of encryption to that individual field today. It is never sent to any third-party service, never shown on the leaderboard, and never included in anything public. It does appear in your price-drop alert emails, which travel over standard email — so it is as private as your inbox is.
A tracked flight is, by definition, a statement that you plan to be somewhere else on a particular date. We treat it that way. Your flights are visible only to you, to anyone in a family group you have joined, and to the operator of the service for support and debugging. They are never published, never sold, and never used to build an advertising profile.
One exception you control: if you appear on the public leaderboard, a large saving of yours can be listed with your username, the airline, the flight number, the route and the date. See “The public leaderboard” below.
We use a small number of outside companies to run the service. Each one gets only what it needs, listed here honestly:
These companies act as our processors: they may use the data to provide their service to us and not for their own purposes. We may also disclose data if we are legally required to, or if the service is ever sold or transferred — in which case we will tell you first.
Faretriever does not take card payments inside the app and stores no card numbers, expiry dates or CVCs. Our database keeps only a plan name, a flag for whether billing has started, and — reserved for future use — identifiers from a payment processor. If and when you are billed, that happens outside the app and the payment provider handles your card details under its own privacy policy.
Faretriever has a leaderboard, open to anyone on the internet, showing who has saved the most. If you are included, it can show your username, your total savings, how many flights you have saved on, and — in the “biggest saves” list — the airline, flight number, route and date of the individual saving. It does not show your email, your real name (unless you set your username to it), your confirmation number, or your loyalty details.
You can turn this off. Go to your profile and switch off leaderboard visibility, and you disappear from every list. Your savings still count toward the anonymous community totals.
A family group is a deliberate act of sharing, and it shares more than you might assume. If you join or create one, every other member of that group can see the flights you are tracking in full detail through the family dashboard — including the price you paid, your seat, and your confirmation number.
Only join a group with people you would hand your booking to. You can leave a group at any time from the family page, which stops that sharing going forward. If the person who owns the group deletes their account, the group is dissolved and everyone else's accounts and data stay untouched. Invitations are sent by email and expire after seven days.
Alert emails are the core of the product, so they are transactional rather than marketing. You still control them:
Push notifications are not enabled today. If we turn them on in the iOS app, iOS will ask your permission first, and you will be able to revoke it at any time in Settings › Notifications › Faretriever, or by signing out.
We use no cookies for advertising, analytics, or tracking — none at all, from anyone.
The website keeps your login token and a copy of your basic account details in your browser's local storage so you stay signed in between visits. Clearing it simply signs you out. In the iOS app, the same login token is kept in the device keychain (via Expo SecureStore) rather than in ordinary app storage, so it is not exposed in a device backup.
Stated plainly, with no padding:
Equally plainly, what we do not have: we do not offer two-factor authentication yet; your itinerary details other than the confirmation number are stored unencrypted within the database; and we do not hold a formal security certification. No service can promise it will never be breached, and we are not going to pretend otherwise. If a breach ever affects your data, we will email you and describe what happened and what to do.
Wherever you live, you can do all of the following:
We do not charge for any of this and will not treat you differently for asking. We aim to respond within a few days and will not exceed the timeframes the law gives us (45 days under California law; one month under UK and EU law).
If you live in California, the CCPA as amended by the CPRA gives you the right to know what we collect and why, to get a copy of it, to correct it, to delete it, and to limit the use of sensitive information. The sections above tell you what we collect and the section above this one tells you how to exercise each right.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done either, and we have no plans to. There is therefore no “Do Not Sell or Share” process to complete — there is nothing to opt out of.
We collect some information California treats as sensitive — your account log-in credentials, and travel details that reveal your movements. We use it only to run the features you asked for, never to infer characteristics about you. You will never be denied service, charged a different price, or given a worse experience for exercising a privacy right. An authorised agent may make a request on your behalf; we will ask for proof of their authority and confirm it with you.
Faretriever is operated from the United States, and all of your data is stored and processed there, on servers run by Neon and Vercel. If you are in the UK or the European Economic Area, that is an international transfer, and by using the service you understand that your information is handled under US law, which does not offer the same protections as UK or EU law. We do not currently have Standard Contractual Clauses in place with you directly, and we do not have a representative in the UK or the EU.
For the purposes of UK and EU data protection law, we are the controller of your data. You have the rights of access, rectification, erasure, restriction, objection and portability described above, plus the right to complain to your local supervisory authority (in the UK, the Information Commissioner's Office). We would rather you came to us first — email brian@cordco.com and we will try to sort it out.
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
Faretriever is for adults managing their own travel. You must be at least 13 years old to create an account, and if you are under 18 you should only use it with a parent or guardian's involvement. The service is not directed at children, we do not knowingly collect information from anyone under 13, and we run no advertising or profiling of any user.
If you believe a child under 13 has an account, email us and we will delete it and its data promptly.
When this policy changes we will update the date at the top. For any change that meaningfully affects what we collect, who receives it, or what we do with it — such as turning on push notifications, adding a new provider, or introducing anything resembling advertising — we will email everyone with an account before it takes effect. Older versions are available on request.
Privacy questions, data requests, deletion requests, or anything that looks like a security problem: brian@cordco.com. A person reads that address, and we would much rather hear about a problem than not.
See also our Terms of Service.