At a glance
This document forms part of the agreement between you and Zeptotravel LLC (“Zeptotravel”, “we”, “us”). It applies to every booking made through this website or through our telephone reservations desk.
Effective date: 28 August 2026 · Governing law: State of Delaware, USA · Questions: legal@zeptotravel.com
1. Who we are and what this policy covers
Zeptotravel LLC (“Zeptotravel”, “we”, “us”) is a travel agency and booking intermediary incorporated in the State of Delaware, United States, with its registered office at Zeptotravel LLC, 1201 Orange Street, Suite 600, Wilmington, DE 19801, USA. We arrange air travel and vehicle rental supplied by third parties. We are the business that decides how and why your information is handled when you search, ask for a quote, book, or contact our desk — in privacy law terms, we are the controller (or, in California terms, the business) for that activity.
This policy applies to www.zeptotravel.com, to our telephone reservations and support desk, and to email, SMS and messaging conversations you have with our advisors. It does not apply to the airlines and rental companies who actually deliver your travel. Once we pass a booking to a supplier, that supplier handles your information under its own privacy policy and for its own purposes, and we do not control what it does. If that matters to you for a particular booking, ask the advisor before you pay and we will tell you exactly which suppliers will receive your data.
We have written this in plain English on purpose. If any part of it is unclear, email privacy@zeptotravel.com or call +1-888-555-0119 and ask for the compliance desk.
2. Information we collect
We collect only what a booking actually requires, plus what we need to run and secure the site. The categories below use the same labels as the California Consumer Privacy Act so that the two halves of this document line up.
2.1 Identifiers and contact details
Name as it appears on your travel document, postal address, billing address, email address, telephone numbers, and any account or booking reference we issue you.
2.2 Traveller and travel-document data
Date of birth, gender marker as recorded on the travel document, nationality, passport or other travel document number with its issuing country and expiry date, redress number, known traveller number, visa and residence-permit details where a route requires them, and the Advance Passenger Information (APIS) fields that border authorities require for international itineraries. We also record travel preferences you give us: seat preference, meal preference, vehicle class, rental pick-up branch and time, and mobility, medical or dietary assistance requests you ask us to pass to a supplier.
A note on sensitive information
Some assistance requests — a wheelchair, an oxygen concentrator, a service animal, a medical clearance, a dietary requirement tied to a belief — reveal information about health or religion. We collect that data only because you have asked us to arrange the service, we use it only to arrange it, we pass it only to the supplier who must act on it, and we delete it from the working record once the trip is over. You can always call the supplier directly instead if you would prefer not to route it through us.
2.3 Payment information
Card data is handled by a payment processor and is never stored in readable form on our systems. Card numbers entered on this site are captured by the processor and tokenised; our systems receive a token, the card brand, the last four digits, the expiry month and year, the cardholder name and the billing address. We do not store the full primary account number or the card security code, and our advisors are not permitted to write those values down or repeat them back. This is a condition on which we will take payment at all: we will not accept a card payment through any route that does not meet it. Where a supplier requires a card to be presented at check-in or at a rental counter, the card details travel to that supplier through the reservation system, not through our own storage.
2.4 Loyalty and membership numbers
Frequent flyer numbers, rental company loyalty numbers, and corporate or association discount codes, where you give them to us so they can be added to a booking.
2.5 Call recordings and correspondence
Calls to and from our reservations desk are recorded for quality assurance, advisor training, fraud prevention and to evidence what was agreed on a booking — particularly the fare, the fare rules and the fee quoted before work began. You are told at the start of the call that it is recorded; if you do not wish to be recorded, tell the advisor and we will offer to complete the booking by email instead. We also retain emails, chat transcripts, SMS threads and support tickets.
2.6 Device, usage and network data
IP address, approximate location derived from IP at city level, browser and device type, operating system, screen size, referring URL, pages viewed, search parameters entered into our search forms, timestamps, and error and performance diagnostics.
2.7 Cookies and similar technologies
Cookies, local storage entries and pixels set by us and by a small number of analytics and advertising partners. What each category does and how to control it is set out in our Cookie Policy.
2.8 Inferences
Limited commercial inferences drawn from the above — for example that a visitor is researching a long-haul premium cabin, or that a returning customer books ground transport alongside air. We do not use these to set your price, and we do not carry out profiling that produces a legal or similarly significant effect on you.
What we do not collect: we do not ask for Social Security numbers, we do not collect precise geolocation, we do not collect biometric identifiers, and we do not knowingly collect information from children under 13.
3. Where it comes from
Most of it comes directly from you, on the phone or through a form. The rest comes from: (a) the person who made the booking, if someone booked on your behalf — a colleague, a family member or a company travel arranger; (b) suppliers and global distribution systems, which return ticket numbers, record locators, schedule changes and cancellation notices into your booking file; (c) our payment processor, which returns authorisation, decline and chargeback results; (d) fraud-screening providers, which return a risk score on a transaction; and (e) your device, automatically, when you use the site.
4. Why we use it, and on what basis
We use personal information to search live inventory and quote you a price; to create, ticket, amend, reissue and cancel bookings; to take payment and issue refunds; to send confirmations, itineraries, schedule-change notices and disruption alerts; to answer questions and handle complaints; to screen transactions for fraud and card misuse; to keep records that tax, accounting and seller-of-travel rules require us to keep; to run, secure, debug and improve the website; to measure which pages and campaigns produce bookings; and, where you have not opted out, to send marketing about fares and destinations similar to what you have booked or searched.
Where the EU or UK General Data Protection Regulation applies to a traveller, our legal bases are: performance of a contract for everything required to make and service the booking; legal obligation for border, aviation-security, tax and accounting disclosures; legitimate interests for fraud prevention, security, service improvement, analytics and direct marketing to existing customers, balanced against your interests; and consent for non-essential cookies, for marketing to people who are not existing customers, and for the special-category data involved in assistance requests. Where we rely on consent you can withdraw it at any time without affecting what was done before you withdrew it.
5. Who we share it with
We share what a supplier needs to deliver your booking, and no more. In practice that means:
- Airlines and their ticketing systems — passenger name, contact details, travel document and APIS data on international itineraries, loyalty number, seat and service requests, and form-of-payment data where the ticket is issued on your card.
- Vehicle rental companies — driver name, date of birth, contact details, driving licence details where the supplier requires them at the time of reservation, flight number for counter timing, and payment guarantee.
- Global distribution systems, consolidators and ticketing partners — the reservation record itself, which by design lives in a shared system so that the airline, the agency and the ticketing partner all see the same file.
- Our payment processor, acquiring bank and card networks — the data needed to authorise, settle, refund or dispute a transaction.
- Service providers acting on our instructions — cloud hosting, email and SMS delivery, telephony and call recording, customer support tooling, analytics, error monitoring and professional advisers. They may use the data only to provide the service to us.
- Insurers and assistance providers, where you buy or claim on a travel protection product we arranged.
- Authorities, regulators, courts and law enforcement, where a valid legal requirement applies, and to establish, exercise or defend legal claims.
- A successor entity in a merger, acquisition or sale of assets, subject to the same commitments in this policy.
We do not sell your personal information for money. Some advertising cookies do involve “sharing” for cross-context behavioural advertising as California defines it, and you can switch that off — see section 11 and our Do Not Sell or Share page.
6. Government-mandated disclosures
Some transfers are not optional for either of us.
TSA Secure Flight. For flights to, from, within or over the United States, the Transportation Security Administration requires the operating carrier to collect and transmit your full name as it appears on the travel document you will present, date of birth, gender, and any redress or known traveller number, under 49 CFR Part 1560. We collect those fields so that the carrier can meet that obligation. If you decline to provide them, the airline cannot accept the reservation.
CBP and APIS. For international itineraries, carriers must transmit Advance Passenger Information — travel document number, issuing country, expiry, nationality, date of birth and itinerary details — to US Customs and Border Protection and to the equivalent border authority of the destination and any transit country. Where we hold those details in your booking file, they pass to the carrier for that transmission. Passenger Name Record data may also be provided to border and security agencies under the law of the countries you are flying to or from.
We tell you when a booking triggers one of these transfers, but we cannot suppress them, and we cannot delete data that a carrier or authority holds independently of us.
7. International transfers
We are based in the United States and our systems are hosted in the United States. Travel is international by nature: if you fly to Lisbon, your name and travel document details will reach a carrier and a border authority outside your home country. Where we transfer personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with technical and organisational measures appropriate to the transfer. Transfers of booking data that are strictly necessary to perform your travel contract, or to conclude a contract in your interest, may also be made on the basis of Article 49(1)(b) and (c) of the GDPR. You can request a copy of the safeguards we use by writing to privacy@zeptotravel.com.
8. How long we keep it
We keep each category only as long as it has a job to do, then delete it or reduce it to a form that no longer identifies you. Periods run from the later of the end of travel or the closing of the related support matter.
| Category | Primary purpose | Typical retention |
|---|---|---|
| Identifiers and contact details | Making and servicing the booking; disruption contact | 7 years from end of travel, aligned to our tax and accounting record obligations |
| Booking and itinerary records (ticket numbers, record locators, fare rules applied) | Proof of what was sold and on what conditions; refund and chargeback defence | 7 years from end of travel |
| Passport, visa and APIS details | Carrier and border-authority transmission required by law | Removed from the active booking file within 90 days of the last flown segment, unless a live dispute requires it |
| Assistance, mobility, medical and dietary requests | Arranging the specific service you asked for | Deleted within 90 days of end of travel |
| Payment tokens, card brand, last four digits, authorisation results | Settlement, refunds, chargeback response | Up to 24 months after the transaction, or until the dispute window closes if later; full card numbers are never retained by us |
| Loyalty and membership numbers | Crediting your account on a booking | Until you remove them, or 36 months after your last booking |
| Call recordings | Quality, training, fraud prevention, evidence of quoted price and fees | 13 months, extended only for a specific complaint, claim or investigation |
| Email, chat and support correspondence | Answering and evidencing the matter raised | 36 months from closure of the ticket |
| Device, log and security data | Security monitoring, debugging, abuse prevention | 13 months |
| Analytics and measurement data | Understanding how pages perform | 14 months, then aggregated |
| Marketing contact record and consent state | Sending, and proving your choices about, marketing | Until you unsubscribe, plus a permanent suppression entry so we do not contact you again |
| Rights requests and our responses | Demonstrating compliance with privacy law | 24 months |
9. How we protect it
The measures we apply, and commit to applying: TLS in transit across the site and our internal systems; encryption at rest for booking and support databases; tokenised card handling by a payment processor so that card numbers do not enter our environment in readable form; access limited to the records a person is actually working on; multi-factor authentication on the systems that hold booking data; logging and alerting on unusual access; least-privilege contracts with service providers; and a documented incident response process under which we notify affected individuals and regulators where the law requires it. Where a measure depends on a supplier we have not yet contracted, we will not process the data it protects until that is in place. No system is perfectly secure, we hold no security certification of our own, and we do not claim otherwise. If you believe your booking or account has been compromised, call +1-888-555-0119 immediately and email privacy@zeptotravel.com.
10. Children
Our services are directed to adults. We do not knowingly collect personal information from children under 13, and the site is not intended for their use. We do process children’s data when an adult books travel for a family — a child’s name and date of birth are needed for a ticket — and in that case the adult is providing it, and we treat it as part of the booking record with the retention periods above. If you believe a child under 13 has given us information directly, write to privacy@zeptotravel.com and we will delete it. We do not sell or share the personal information of consumers under 16.
11. California rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the following rights, and we will not discriminate against you for using any of them — you will not be charged a different price, given a lower level of service, or denied a booking.
- Right to know. Ask what categories and specific pieces of personal information we collected about you in the preceding 12 months, where we got them, why we collected them, and the categories of third parties we disclosed them to.
- Right to delete. Ask us to delete personal information we collected from you, subject to the exceptions the statute allows — we may keep what is needed to complete a transaction, detect security incidents, defend legal claims, or comply with a legal obligation such as our tax records.
- Right to correct. Ask us to fix inaccurate personal information. Note that a name on an issued ticket can usually only be corrected through the airline’s own name-correction process, which may carry a supplier charge; see our service fee schedule.
- Right to opt out of sale or sharing. We do not sell personal information for money. We do use advertising cookies that may constitute “sharing” for cross-context behavioural advertising. Opt out at Do Not Sell or Share My Personal Information, or by enabling Global Privacy Control in your browser.
- Right to limit use of sensitive personal information. The only sensitive personal information we handle is what a booking requires — travel document numbers, and health-related assistance requests you ask us to pass on. We use it solely to provide the service you asked for and for the ancillary purposes the regulations permit, so no further limitation is available; we do not use it to infer characteristics about you.
- Right to data portability. Receive the information you gave us in a portable, readily usable format.
Categories of personal information we have collected, disclosed for a business purpose, and shared for cross-context behavioural advertising in the preceding 12 months are the categories listed in section 2. The categories we disclose for a business purpose are identifiers, traveller and travel document data, commercial information, payment tokens, audio (call recordings), internet activity and inferences, to the recipient categories listed in section 5. The categories that may be shared for cross-context behavioural advertising are internet or other electronic network activity and inferences, and identifiers in hashed form, to advertising partners only.
12. Other US state rights
Residents of Virginia, Colorado, Connecticut, Utah and other states with comprehensive privacy statutes in force have broadly similar rights: to confirm whether we process their data and access it, to correct inaccuracies (Utah excepted), to delete, to obtain a portable copy, and to opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We do not carry out that kind of profiling. Colorado, Connecticut and Virginia residents also have a right to appeal a refusal — see section 16. We honour a universal opt-out signal such as Global Privacy Control as an opt-out of targeted advertising in every state that recognises one. Use the same request routes in section 14; tell us which state you live in so we apply the right rules.
Nevada residents may submit a verified request that we not sell covered information as Nevada defines it. We do not engage in such sales, but we will record your request.
13. EEA and UK travellers
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on our legitimate interests — including an unconditional right to object to direct marketing. You may withdraw consent at any time where we rely on it, and you may lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office). We ask that you raise it with us first so we can try to fix it. We do not make decisions about you by automated means that produce legal or similarly significant effects. Where we rely on legitimate interests, you can ask us for a summary of the balancing assessment.
14. Exercising your rights
Submit a request in any of these ways:
- Email privacy@zeptotravel.com with the subject line “Privacy request”.
- Call +1-888-555-0119 and ask for the compliance desk. Desk hours to be confirmed before launch.
- Write to Zeptotravel LLC, 1201 Orange Street, Suite 600, Wilmington, DE 19801, USA, marked for the attention of the Privacy Officer.
Tell us what you want us to do, which state or country you live in, and enough information to find your records — typically the email address or telephone number used to book, plus a booking reference. Verification: because a booking file contains travel document data, we verify before we act. For access and deletion we match at least two data points you provide against our records (for example booking reference plus billing postal code, or the last four digits of the card used). For a request covering specific pieces of sensitive information we ask for a signed declaration under penalty of perjury that you are the person the data relates to. We use verification data only for verification and then delete it.
We acknowledge requests within 10 business days and respond within 45 calendar days, extendable once by a further 45 days where the request is complex — we will tell you if we need the extension and why. Requests under the GDPR are answered within one month, extendable by two further months on the same basis. There is no charge for the first two requests in a 12-month period; we may charge a reasonable fee for manifestly unfounded or excessive repeat requests, and we will tell you the amount before doing any work.
15. Authorised agents
You may use an authorised agent to submit a request. We will ask the agent for written permission signed by you, and we will separately verify your identity and confirm directly with you that you gave the permission, unless the agent provides a valid power of attorney under California Probate Code sections 4000 to 4465. An agent registered with the California Secretary of State must still meet these requirements.
16. Appeals
If we refuse a request, our response will say why and how to appeal. To appeal, reply to that response or email privacy@zeptotravel.com with “Appeal” in the subject line within 60 days. A reviewer who was not involved in the original decision will re-examine it and write to you with a decision and reasons within 45 days (60 days in Colorado). If we still refuse, we will give you the contact details for your state attorney general or supervisory authority so you can complain.
17. Changes to this policy
We update this policy when our practices, our suppliers or the law change. The effective date at the top of this page always reflects the current version. If a change materially reduces your rights or materially expands how we use information you have already given us, we will give notice at least 30 days in advance by email to customers with a booking in the last 24 months and by a banner on this site, and where the law requires it we will ask for your consent. We keep prior versions and will send you the version that applied to a particular booking on request.
18. Contact us
Privacy questions, requests and complaints: privacy@zeptotravel.com. Other legal matters: legal@zeptotravel.com. General support: support@zeptotravel.com or +1-888-555-0119.
Zeptotravel LLC
1201 Orange Street, Suite 600
Wilmington, DE 19801
United States
Related documents: Cookie Policy, Do Not Sell or Share My Personal Information, Terms & Conditions.