Back to home

Privacy Policy

Last updated: August 6, 2026

Faretriever watches flights you have already booked and tells you when the fare drops, the schedule moves, or the aircraft changes. To do that we have to hold some genuinely sensitive things about your travel — including your booking confirmation number. This page explains exactly what we hold, why, who else touches it, and how to get it back or get rid of it. It is written to be read, not skimmed past.

Faretriever is run by one person: Brian, trading as Cord Contracting, in the United States. If anything here is unclear, email brian@cordco.com and a human will answer.

The short version

  • We collect what you type in about your flights, plus your account details. Nothing is bought from data brokers and nothing is scraped from your inbox.
  • We do not sell or share your personal information, and there is no advertising or analytics tracking anywhere in the app or on this site.
  • We store your booking confirmation number, because our alerts hand it to you when you call the airline. That is a sensitive field — see the section on it below.
  • You can download everything we hold, correct it, or delete your account outright. Deletion is permanent.
  • Our servers and database are in the United States.

What we collect, and why

Every item below exists because a specific feature needs it. Nothing is collected “just in case.”

Your account

  • Email address — your login, and where alerts and password resets go.
  • Name — to address you in the app and in emails.
  • Password — stored only as a bcrypt hash. We never see, store, or can recover the password itself.
  • Username — a display name for the leaderboard. If you do not choose one at signup, we generate one from your first name plus four random digits.
  • Time zone — so a 2 a.m. fare drop does not email you at 2 a.m.
  • Quiet hours and your savings threshold — your settings for when we may email you and how big a drop has to be before we bother you.
  • Plan, billing status, and whether we have found you savings yet — this is how the “free until we save you money” model knows where you stand.

The flights you add

  • Airline and flight number, departure date and time, origin and destination airports, cabin class, and seat number.
  • What you paid — a cash price, or points plus the loyalty program you used — and how many passengers are on the booking.
  • Passenger names, if you choose to add them. They are optional and the app works without them.
  • Your confirmation number (record locator), if you enter it. Optional, but our price-drop emails print it so you can read it straight to the agent.
  • Which extra checks you want on a flight: nearby airports, alternative flights on the same airline, competing airlines.
  • If you paste a booking confirmation email into the importer, we read it on our own server with plain pattern matching to pull out those same fields. We do not send the pasted text to any outside service, and we do not keep the pasted text — only the flight fields it produced.

Your airline loyalty memberships

  • Airline, your elite status level, your frequent-flyer number, and any dedicated phone number or perks you record.
  • This exists for one reason: when we tell you to call, we can point you at your status-level priority line instead of the general queue. Your frequent-flyer number is never sent to anyone outside Faretriever — not to the airline, not to any data provider.

What the service produces about you

  • Fare checks over time for each flight you track, so we can show a price history and detect drops.
  • Alerts we have raised, whether you have read them, and whether you told us you acted on them.
  • Your savings history and totals, and any badges earned.
  • Family group membership and invitations you send or receive.

Technical data

  • Error logs. When something breaks we record the error message, the stack trace, and a small context blob that can include your user ID and the flight ID involved. This helps us fix bugs; it is deleted with your account.
  • Server request logs. Our host, Vercel, keeps ordinary web-server logs that include IP addresses and browser user-agent strings. We do not build profiles from them.
  • Device push tokens. The database has a place to store an iOS push token so we could send alerts to your phone. Push notifications are not switched on yet — today every alert is an email — and no push tokens are being collected. This policy will be updated before that changes.

We do not collect your location, your contacts, your calendar, photos, health data, or anything from other apps. We do not have your payment card details — see “Payments” below.

About your confirmation number

This deserves its own section, because we would rather you knew the risk than discovered it.

A record locator plus a last name is often enough.

On many airline websites, a six-character confirmation number together with a passenger surname is all it takes to view an itinerary — and sometimes to change or cancel it. If someone got hold of that pair, they could interfere with your booking.

Storing it is optional. Every part of Faretriever works without it; the only difference is that our alert email will not be able to print it for you when you call. If you would rather not have it in our database, leave the field blank, or clear it later by editing the flight.

Being straight with you about how it is stored: your confirmation number sits in our database as ordinary text, protected by our database provider's own encryption of stored data and by the access controls on the account. We do not add a second, Faretriever-specific layer of encryption to that individual field today. It is never sent to any third-party service, never shown on the leaderboard, and never included in anything public. It does appear in your price-drop alert emails, which travel over standard email — so it is as private as your inbox is.

Your itinerary says when you are away from home

A tracked flight is, by definition, a statement that you plan to be somewhere else on a particular date. We treat it that way. Your flights are visible only to you, to anyone in a family group you have joined, and to the operator of the service for support and debugging. They are never published, never sold, and never used to build an advertising profile.

One exception you control: if you appear on the public leaderboard, a large saving of yours can be listed with your username, the airline, the flight number, the route and the date. See “The public leaderboard” below.

Why we are allowed to use it (legal bases)

  • To provide the service you asked for (performance of a contract) — your account, your flights, fare checks, alert emails, savings totals, family groups, billing status.
  • Our legitimate interests — keeping the service secure, debugging errors, preventing abuse, and comparing fare-data providers so the numbers we show you are as accurate as we can make them.
  • Your consent — optional extras you switch on yourself: appearing on the leaderboard, joining a family group, and push notifications if we enable them. You can withdraw consent at any time in the app.
  • Legal obligation — if we are ever legally required to keep or produce something, we will.

Who else touches your data

We use a small number of outside companies to run the service. Each one gets only what it needs, listed here honestly:

  • Neon — hosts our PostgreSQL database in the United States. Everything described above lives there, including confirmation numbers and frequent-flyer numbers.
  • Vercel — hosts the website and the scheduled job that checks fares. Vercel handles every request you make to Faretriever and keeps standard server logs.
  • SerpAPI — supplies current fares from Google Flights. We send it a route, a date, a cabin class, the number of passengers and the airline code. We do not send your name, email, confirmation number, frequent-flyer number, or any identifier that points back to you.
  • Duffel — a second fare source we currently query only to check SerpAPI's numbers against another provider. It receives the same limited search terms: route, date, cabin, passenger count, airline code. No personal identifiers.
  • Resend — delivers our email. It receives your email address, your name where the email uses it, and the full contents of the alert — which for a price-drop alert includes your route, dates, prices, and your confirmation number if you have stored one.
  • Expo — would deliver push notifications to the iOS app. Push is not enabled yet, so Expo is not receiving anything about you today. If we turn it on, Expo would receive a device push token and the text of the notification.
  • Apple — if you install the iOS app, Apple handles the download and, if we ever sell subscriptions through the App Store, the payment. Apple's own privacy policy governs what it collects.

These companies act as our processors: they may use the data to provide their service to us and not for their own purposes. We may also disclose data if we are legally required to, or if the service is ever sold or transferred — in which case we will tell you first.

Payments

Faretriever does not take card payments inside the app and stores no card numbers, expiry dates or CVCs. Our database keeps only a plan name, a flag for whether billing has started, and — reserved for future use — identifiers from a payment processor. If and when you are billed, that happens outside the app and the payment provider handles your card details under its own privacy policy.

What we never do

  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
  • We run no advertising, no ad pixels, and no analytics product of any kind. There is no Google Analytics, no Meta pixel, no session recorder.
  • We do not send your name, email, confirmation number or frequent-flyer number to the fare-data providers.
  • We do not read your email inbox. The import feature only sees text you paste in yourself.
  • We have no marketing mailing list. Every email we send is transactional: an alert about a flight you asked us to watch, a password reset, or a family invitation you triggered.

The public leaderboard

Faretriever has a leaderboard, open to anyone on the internet, showing who has saved the most. If you are included, it can show your username, your total savings, how many flights you have saved on, and — in the “biggest saves” list — the airline, flight number, route and date of the individual saving. It does not show your email, your real name (unless you set your username to it), your confirmation number, or your loyalty details.

You can turn this off. Go to your profile and switch off leaderboard visibility, and you disappear from every list. Your savings still count toward the anonymous community totals.

Family plans

A family group is a deliberate act of sharing, and it shares more than you might assume. If you join or create one, every other member of that group can see the flights you are tracking in full detail through the family dashboard — including the price you paid, your seat, and your confirmation number.

Only join a group with people you would hand your booking to. You can leave a group at any time from the family page, which stops that sharing going forward. If the person who owns the group deletes their account, the group is dissolved and everyone else's accounts and data stay untouched. Invitations are sent by email and expire after seven days.

Emails, quiet hours, and push notifications

Alert emails are the core of the product, so they are transactional rather than marketing. You still control them:

  • Turn email alerts off entirely in your profile.
  • Set quiet hours (default 10 p.m. to 7 a.m. in your time zone). We do not send alert emails during them. Password resets and family invitations are sent whenever you ask for them, since you are waiting on those.
  • Raise your savings threshold so small drops do not generate an alert at all.
  • Stop a flight being watched by deleting it.

Push notifications are not enabled today. If we turn them on in the iOS app, iOS will ask your permission first, and you will be able to revoke it at any time in Settings › Notifications › Faretriever, or by signing out.

Cookies and local storage

We use no cookies for advertising, analytics, or tracking — none at all, from anyone.

The website keeps your login token and a copy of your basic account details in your browser's local storage so you stay signed in between visits. Clearing it simply signs you out. In the iOS app, the same login token is kept in the device keychain (via Expo SecureStore) rather than in ordinary app storage, so it is not exposed in a device backup.

How long we keep things

  • While your account exists — we keep your account, your flights, and your savings history for as long as you have an account. Your record of what you saved is the point of the product, so we never age it out.
  • Things we do age out — a weekly clean-up removes fare-check history after 24 months (and within 12 months of a flight departing), alerts you have already read and acted on after 24 months, our internal fare-comparison logs after 12 months, and technical error logs after 90 days. None of this touches your flights or your savings record.
  • When you delete a flight — that flight and everything attached to it (its fare checks, alerts, savings entries and fare comparisons) is deleted immediately and permanently.
  • When you delete your account — everything above goes at once, along with your loyalty memberships, badges, airport preferences, device tokens, password-reset tokens, family invitations and error logs tied to your user ID. It is a hard delete, not a hidden flag. We cannot get it back for you afterwards.
  • Backups and provider logs — deleted data can survive for a short period in our database provider's routine backups and in Vercel's server logs, according to their retention schedules, before ageing out.

How we protect it

Stated plainly, with no padding:

  • Passwords are hashed with bcrypt (cost factor 12). We store no reversible copy of your password.
  • Sessions use signed JSON Web Tokens that expire after two days. Signing keys are held in server environment variables, and the production server refuses to start a session if the key is missing. Changing your password, resetting it, or choosing “sign out everywhere” immediately invalidates every session on every device, including any an intruder may hold.
  • Your confirmation number and any frequent-flyer number are encrypted (AES-256-GCM) before being written to the database, with the key held separately from the database itself, so a copy of the database alone does not reveal them.
  • Repeated failed sign-in attempts are rate limited, per account and per network address, to blunt password-guessing.
  • Technical error logs are scrubbed of personal details such as email addresses and tokens before they are written.
  • All traffic to the site, the API, and the database runs over TLS.
  • Every flight, alert and settings endpoint checks that the signed-in user owns the record before returning or changing it.
  • On iOS, your session token is stored in the device keychain, not in plain app storage.
  • Password reset links are single-use, random 32-byte tokens that expire after one hour, and the “forgot password” screen gives the same answer whether or not an account exists, so it cannot be used to discover who has one.
  • The scheduled fare-checking job requires a secret and refuses to run in production without one.

Equally plainly, what we do not have: we do not offer two-factor authentication yet; your itinerary details other than the confirmation number are stored unencrypted within the database; and we do not hold a formal security certification. No service can promise it will never be breached, and we are not going to pretend otherwise. If a breach ever affects your data, we will email you and describe what happened and what to do.

Your rights, and how to use them

Wherever you live, you can do all of the following:

  • See and export everything. Faretriever can produce a single JSON file containing every record we hold about you — your account, flights, fare checks, alerts, savings, badges, loyalty memberships, airport preferences and devices. Your password hash is left out, since it is a credential rather than information about you. If you do not see a data-download control in your version of the app, email us and we will send you the file.
  • Correct anything. Your name, username, quiet hours, time zone, threshold and leaderboard setting are all editable on your profile page. Every field of a flight, including the confirmation number, is editable on that flight's edit screen — and you can clear a field by emptying it.
  • Delete your account. Deletion is permanent and immediate, and it takes your flights and history with it. To protect you from doing it by accident, we ask you to type your own email address to confirm. If you cannot find the delete control in your version of the app, email us and we will delete the account for you — we will confirm your identity by replying to the address on the account.
  • Object, restrict, or withdraw consent. Turn off email alerts, leave a family group, hide yourself from the leaderboard, or ask us to stop a particular use — email us and we will deal with it.

We do not charge for any of this and will not treat you differently for asking. We aim to respond within a few days and will not exceed the timeframes the law gives us (45 days under California law; one month under UK and EU law).

California residents

If you live in California, the CCPA as amended by the CPRA gives you the right to know what we collect and why, to get a copy of it, to correct it, to delete it, and to limit the use of sensitive information. The sections above tell you what we collect and the section above this one tells you how to exercise each right.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done either, and we have no plans to. There is therefore no “Do Not Sell or Share” process to complete — there is nothing to opt out of.

We collect some information California treats as sensitive — your account log-in credentials, and travel details that reveal your movements. We use it only to run the features you asked for, never to infer characteristics about you. You will never be denied service, charged a different price, or given a worse experience for exercising a privacy right. An authorised agent may make a request on your behalf; we will ask for proof of their authority and confirm it with you.

If you are in the UK, the EU, or elsewhere outside the US

Faretriever is operated from the United States, and all of your data is stored and processed there, on servers run by Neon and Vercel. If you are in the UK or the European Economic Area, that is an international transfer, and by using the service you understand that your information is handled under US law, which does not offer the same protections as UK or EU law. We do not currently have Standard Contractual Clauses in place with you directly, and we do not have a representative in the UK or the EU.

For the purposes of UK and EU data protection law, we are the controller of your data. You have the rights of access, rectification, erasure, restriction, objection and portability described above, plus the right to complain to your local supervisory authority (in the UK, the Information Commissioner's Office). We would rather you came to us first — email brian@cordco.com and we will try to sort it out.

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

Children

Faretriever is for adults managing their own travel. You must be at least 13 years old to create an account, and if you are under 18 you should only use it with a parent or guardian's involvement. The service is not directed at children, we do not knowingly collect information from anyone under 13, and we run no advertising or profiling of any user.

If you believe a child under 13 has an account, email us and we will delete it and its data promptly.

Changes to this policy

When this policy changes we will update the date at the top. For any change that meaningfully affects what we collect, who receives it, or what we do with it — such as turning on push notifications, adding a new provider, or introducing anything resembling advertising — we will email everyone with an account before it takes effect. Older versions are available on request.

Contact

Privacy questions, data requests, deletion requests, or anything that looks like a security problem: brian@cordco.com. A person reads that address, and we would much rather hear about a problem than not.

See also our Terms of Service.