Last updated 17 August 2026
Privacy Policy
Fare-Watch is the data controller for the personal data described here. We collect the minimum needed to monitor a fare and contact you about it, and we never ask for airline account credentials.
Who we are
Fare-Watch, PO Box 123, Dublin, Ireland. For any privacy question, or to exercise the rights in section 7, email [email protected].
On the agency plan, where an agency submits bookings for its own clients, the agency is the data controller for that passenger data and we act as its processor.
What we collect
- Account data: your name, email address, and which account you belong to.
- Booking data: airline, flight numbers, dates, route, cabin, booking class, fare paid, currency, ticket date, booking reference, and passenger count.
- Hotel booking data (if you use hotel monitoring): hotel name, city, stay dates, rooms and guests, rate paid, currency, booking reference, where it was booked, and the free-cancellation deadline.
- Payment data: handled by Stripe. We receive a customer reference and subscription status; we never see or store your card number.
- Technical data: the IP address a sign-in link was requested from, and a session cookie. See the Cookie Notice.
We never collect airline account passwords, frequent-flyer PINs or any other airline login credential. There is no field for one anywhere in the product and no way to store one.
Why we use it, and our legal basis
- To provide the service — monitoring your fare, filing claims, showing results. Legal basis: performance of our contract with you.
- To take payment — billing and subscription management. Legal basis: performance of our contract.
- To sign you in — emailed sign-in links and session cookies. Legal basis: performance of our contract.
- To keep records of what was done — an audit log of actions taken on a booking. Legal basis: our legitimate interest in being able to evidence what we did, and the agency's equivalent interest.
- To email you about the service — fare alerts and account notices. Legal basis: performance of our contract. Marketing email, if we ever send it, would be consent-based and separately opt-in.
Who we share it with
We use a small number of processors, each bound to act only on our instructions:
- Stripe — payment processing and subscription billing.
- Resend — transactional email delivery (sign-in links, alerts).
- Railway — application and database hosting.
- Sabre — fare pricing queries. We send itinerary details (route, dates, flight numbers, cabin) to price a fare. We do not send passenger names to price a fare.
- SerpApi — published-price lookups on Google Flights and Google Hotels. We send the itinerary (route, dates, flight numbers, cabin) or the stay (hotel name, city, dates, guests) to look up the current price. We never send your name, email, or booking reference.
We do not sell personal data and we do not share it for advertising. Where a processor is outside the EEA, transfers are covered by Standard Contractual Clauses or an adequacy decision.
How long we keep it
- Booking and passenger data: purged after the retention period set on the account, measured from the departure date. The default is 90 days after departure.
- Account data: for as long as the account is open, then up to 12 months after closure.
- Billing records: 6 years, as required for tax and accounting.
- Audit log entries: retained for the life of the account, since their purpose is to evidence what was done.
How we protect it
- Passenger names and ticket numbers are encrypted at field level, with keys held by the application and never by the database.
- Each account’s data is isolated at the database level by row-level security, so one account cannot read another’s rows.
- Sign-in links are single-use, expire after 15 minutes, and are stored only as a hash.
- We never log credential values, tokens or passenger names.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Have inaccurate data corrected.
- Have your data erased, where we have no overriding obligation to keep it.
- Restrict or object to processing based on legitimate interests.
- Receive your data in a portable format.
- Withdraw consent, where processing is based on consent.
Email [email protected] to exercise any of these. We respond within one month.
If you are not satisfied with how we handle your request, you may complain to the Irish Data Protection Commission (dataprotection.ie), or to the supervisory authority in your own EU country.
Cookies
We use a strictly necessary session cookie and nothing else. Details are in the Cookie Notice.
Changes
We will update this page if our processing changes, and will email you if the change is material. The date at the top shows the current version.