OneTapFly legal
Privacy policy
Last updated: 16 July 2026 · Operated by CIURENIS IT LTD (Company No. 16763272), 4 Wye Close, Aylesbury HP21 9NH, United Kingdom
OneTapFly sells flight tickets. To do that we must handle personal data that is far more sensitive than what a typical online shop touches: full legal names, dates of birth and, for some routes, passport details of every passenger. This policy explains — in plain language — what we collect, why, where it travels, how long we keep it, and which rights you can exercise against us.
The data controller is CIURENIS IT LTD, a company registered in England and Wales (Company No. 16763272), 4 Wye Close, Aylesbury HP21 9NH, United Kingdom ("OneTapFly", "we"). We are registered with the UK Information Commissioner's Office (registration reference: [●]). You can reach us about anything in this policy at support@onetapfly.com.
Our representative in the European Union (Article 27 EU GDPR) is: [name, address, email of appointed EU representative]. If you are in the EU, you may address any data protection matter to the representative instead of, or in addition to, us.
1. What we collect and why
Search data
When you search for flights we process your route, dates and passenger counts, your IP address and technical browser data. Legal basis: our legitimate interest in operating a flight search service, preventing abuse and keeping the service secure. Searches are not tied to your name — you can search without any account.
Booking and passenger data
When you book, we collect for each passenger: title, given and family names exactly as in the travel document, date of birth, gender as recorded in that document, and — where the airline or the destination country requires it — passport or national ID number, issuing country and expiry date. We also collect the contact email and phone number for the order. Legal basis: performance of a contract (we cannot issue a ticket without this data), and compliance with legal obligations of airlines and border authorities.
Payment data
Card payments are processed by a PCI-DSS certified payment service provider. The full card number never touches OneTapFly servers; we receive only a masked card reference, the authorisation result and the amount. Legal basis: performance of a contract and legitimate interest in fraud prevention.
Support and email data
If you write to support we keep the correspondence. Transactional emails (payment confirmation, e-ticket, schedule changes, refund notices) are a mandatory part of the service and are sent to the contact email of the order.
2. Where your data travels — the booking chain
A flight booking is a chain, and your passenger data must travel along it. The chain is: OneTapFly → Duffel Technology Ltd (our ticketing supplier, UK) → the operating airline → border and security authorities of the countries on your route. Each link receives the data because international carriage rules and national law require it: airlines must know who is on board, and many states (for example Spain, the USA, Colombia and other Latin American destinations) require Advance Passenger Information before departure. Once your data reaches an airline or a state authority, that organisation processes it under its own rules — airlines and border authorities act as independent controllers of passenger data, not as our processors.
Some links of the carriage chain are outside the UK and the European Economic Area. Where a transfer to an airline or a border authority is not covered by an adequacy decision, it happens under the derogation for the performance of a contract concluded in your interest (UK GDPR / EU GDPR Article 49(1)(b) and (c)) — you cannot fly to a country without your booking data reaching that country's carrier and border control. This derogation is used only for the carriage chain; transfers to service providers that we choose ourselves rely on the safeguards described in section 3.
3. Recipients of your data — and their roles
- Duffel Technology Ltd (UK) — ticketing infrastructure; receives full passenger data for every order in order to create the booking and issue the ticket. Duffel is established in the UK, so no international transfer is involved at this link.
- Resend Inc. (USA) — our processor for transactional email delivery; receives your email address and email content (booking references, itinerary). Resend is certified under the EU-U.S. Data Privacy Framework and the UK Extension to it; our transfers to Resend rely on that certification, with the standard contractual clauses in our data processing agreement as a fallback safeguard.
- Our payment service provider — a PCI-DSS certified provider; processes card data under its own certification and acts as an independent controller for payment processing and fraud prevention. Named in checkout before you pay.
- Hosting provider (EU) — our processor; runs our servers and encrypted database.
4. How we protect it
Passenger documents and dates of birth are encrypted at rest (AES-256-GCM) in our database; the encryption key is stored separately from the data. Personal data is masked in our technical logs (you appear as ant\\*\*@gmail.com*, never in full). Access to production data is limited to the people who operate the service. All traffic uses TLS.
5. How long we keep it
- Passport and national ID details (document number, issuing country, expiry date): deleted from our systems no later than 12 months after the last flight of your order. We keep them that long only to handle payment disputes and airline claims; they are not needed for tax records and are removed first.
- Other booking and passenger data (names, dates of birth, itinerary, contact details): 6 years after the flight — UK tax and accounting law and the limitation period for contract claims.
- Payment records: 6 years, same reasons.
- Search logs and technical logs: up to 13 months, then deleted or anonymised.
- Consent records (cookie choices): 3 years from the choice.
- Support correspondence: 3 years after the ticket closes.
6. Your rights
Under the UK GDPR (and the EU GDPR where it applies to you) you can: request access to your data; ask us to correct it; ask for deletion where we no longer have a legal duty to keep it; object to processing based on legitimate interest; ask for a portable copy; and withdraw consent (for cookies) at any time without affecting past processing. Write to support@onetapfly.com — we answer within one month. One honest caveat: we cannot delete booking data that the law obliges us to keep, and we cannot recall data already lawfully transmitted to an airline or a border authority — deletion requests for that part must go to those organisations directly.
7. Children
We sell tickets for child and infant passengers, so we process their names and dates of birth — always entered by an adult making the booking. We do not knowingly let minors create bookings themselves, and we show no advertising to children.
8. Complaints
If you believe we mishandled your data, please contact us first — most issues are resolved in days. You also have the right to complain to the UK Information Commissioner's Office (ICO) or to your local EU supervisory authority (in Spain, the AEPD).
9. Changes
We update this policy when the service changes (for example when new payment methods or locales launch). The date at the top always reflects the current version; substantive changes are announced on this page at least 14 days in advance.