Zum Hauptinhalt springen
Legal

Privacy Policy

Effective date: September 26, 2026

1. Controller

The controller responsible for the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR) is:

OnlineBuilders LLC
131 Continental Dr, Suite 305
Newark, DE 19713, USA
E-mail: [email protected]

Full corporate identification: /imprint.

2. Data-Protection Officer

A statutory obligation to appoint a Data-Protection Officer under Art. 37 GDPR / § 38 BDSG does not apply to PrivJet. Privacy inquiries should be addressed to [email protected].

3. Definitions

This Policy uses the GDPR definitions (Art. 4 GDPR). “Personal data” means any information relating to an identified or identifiable natural person.

  • Art. 6(1)(a) GDPR — consent (e. g. newsletter, optional cookies, marketing emails)
  • Art. 6(1)(b) GDPR — performance of a contract or pre-contractual measures (booking, pre-contract, Operator confirmation, payment processing)
  • Art. 6(1)(c) GDPR — compliance with a legal obligation (commercial and tax retention requirements)
  • Art. 6(1)(f) GDPR — legitimate interest (fraud prevention, IT security, reach analysis, server logs)
  • § 25(1) TTDSG — consent for storing/reading cookies and similar technologies that are not strictly necessary
  • § 25(2) No. 2 TTDSG — strictly necessary cookies (auth session, hCaptcha protection, basket)

5. What Data We Process

5.1 Server Logs

Each request automatically processes IP address (anonymized after 7 days), date/time, user agent, referrer and HTTP status. Requests are first routed through Cloudflare’s edge network for DNS, TLS termination and DDoS mitigation; Cloudflare keeps its own edge-logs (IP, request metadata, fingerprint) for up to 30 days for security purposes. Legal basis: Art. 6(1)(f) GDPR (IT security). Retention on our application servers: 7 days raw, 90 days aggregated / anonymized.

5.2 Account Registration and Login

E-mail address, optional name and phone, login provider (Apple / Google for OAuth), account metadata. Legal basis: Art. 6(1)(b) GDPR. Retention: until account deletion plus 6 years after the last booking event for commercial-tax retention (§ 257 HGB, § 147 AO).

5.3 Booking Inquiry and Pre-Contract

First and last name, address, phone, e-mail, date of birth, optionally passport number, passenger manifest, flight details, special requests, handwritten signature (canvas image), IP address at signing. Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (aviation passenger manifest obligations).

Pax-manifest security measures: passenger PII is encrypted with AES-256-GCM before storage and automatically purged 90 days after the flight is marked “completed”. Pre-contracts (master document) are retained for 6 years for commercial-tax purposes.

Passport / ID-card scan (optional): to fill in the passenger manifest faster, you can scan the machine-readable zone (MRZ) of a passport or ID card with the camera or upload a photo of it. In our mobile apps the text is first recognised on your device (Google ML Kit, on-device — the image does not leave your phone). Only if that fails, and on our website, the photo is sent once over an encrypted connection to our server and from there to the Google Gemini API (see § 6.8), which transcribes the MRZ lines. We validate the check digits and fill in first and last name, date of birth, nationality, document type and number. The photo itself is processed in memory only and is neither stored nor logged by us; the extracted fields are treated like the rest of the passenger manifest (encryption and 90-day purge, see above). Using the scan is voluntary — you can always type the details instead. Legal basis: Art. 6(1)(b) GDPR.

5.4 Payment Processing

We use Stripe as our payment processor (Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA, and for customers in the EEA Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland). Stripe processes card and wallet data for the PrivJet service fee and for API subscriptions directly; PrivJet does not store card or bank data, only payment IDs, status codes and receipts. Where an operator accepts card payment through Stripe Connect, Stripe processes the payment of the flight price on the operator’s behalf. Stripe also uses the data for fraud prevention under its own responsibility. Legal basis: Art. 6(1)(b) GDPR. Retention of invoice / payment records: 10 years after the end of the calendar year (§ 14b UStG, § 147 AO). Stripe’s privacy policy: stripe.com/privacy.

5.5 Newsletter

E-mail address, double-opt-in confirmation. Legal basis: Art. 6(1)(a) GDPR. Withdrawal at any time via the unsubscribe link in any e-mail or by writing to [email protected].

5.6 Customer Contact

For inquiries via contact form, e-mail, WhatsApp or Telegram, we process submitted data to handle the request. Legal basis: Art. 6(1)(b) or (f) GDPR.

6. Recipients / Sub-Processors

We use carefully selected sub-processors and have entered into Art. 28 GDPR data-processing agreements with them. Third-country transfers (in particular to the USA) are based on EU Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework (DPF) following the EU Commission’s adequacy decision of 10 July 2023.

6.1 Hosting, Backend Infrastructure and Edge / CDN

  • Google Cloud / Google Ireland Ltd. (Firebase Authentication, Cloud Firestore, Cloud Storage, App Hosting, Cloud Messaging / FCM, Cloud Functions, App Check) — Gordon House, Barrow Street, Dublin 4, Ireland. Primary EU data centers (europe-west). Purpose: authentication, real-time database, file storage, web hosting, push notifications, serverless functions, anti-abuse signals. Third-country fallback transfers to Google LLC (USA) on the basis of EU-US-DPF / SCCs. firebase.google.com/support/privacy · cloud.google.com/terms/data-processing-addendum
  • Cloudflare, Inc. — 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare provides our global edge network (DNS, CDN, TLS termination, DDoS mitigation, Web Application Firewall) as well as bot-management (Turnstile, see § 6.5) and the asset host cdn.privjet.net. Cloudflare processes IP address, request metadata, TLS fingerprint and (anonymized) abuse signals for the duration of the connection plus log retention up to 30 days. EU traffic is normally terminated at EU edge nodes; cross-border processing to U.S. systems on the basis of EU-US-DPF / SCCs. cloudflare.com/privacypolicy
  • Google Ireland Limited (Gemini API) — Gordon House, Barrow Street, Dublin 4, Ireland. Google hosts our LLM inference workloads (Gemini API, see § 6.8). Under the paid Gemini API terms, prompts and completions are not used to train Google's models. Transfers to the U.S. are covered by the EU-U.S. Data Privacy Framework and SCCs. ai.google.dev/gemini-api/terms

6.2 Payments

  • Stripe, Inc. / Stripe Payments Europe, Ltd.— card payments of the service fee and API subscriptions, card payments to operators via Stripe Connect. Third-country transfers to the USA on the basis of SCCs / EU-US-DPF. stripe.com/privacy

6.3 E-Mail

  • Mailgun Technologies Inc. (EU region: api.eu.mailgun.net). Third-country transfer to the USA on the basis of SCCs. mailgun.com/privacy-policy

6.4 Maps and Location

  • Mapbox Inc. — 50 Beale Street, San Francisco, CA 94105, USA. SCCs. mapbox.com/privacy
  • Google LLC (Google Maps Platform) — 1600 Amphitheatre Parkway, Mountain View, CA, USA. policies.google.com/privacy. On capable devices (desktop and TV, in daylight) the cockpit view of the private-jet tracker and its TV mode load Photorealistic 3D Tiles directly from Google's Map Tiles API (tile.googleapis.com, 3D decoder from www.gstatic.com). Google receives your IP address, browser information and the map area being displayed. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in showing the requested 3D view). Where Google is not reachable or not used, the view shows Mapbox imagery instead. EU-US-DPF / SCCs.

6.5 Anti-Spam & Bot Protection

  • Cloudflare, Inc. (Cloudflare Turnstile)— privacy-friendly captcha alternative. Processes IP address, browser fingerprint signals and a short-lived challenge token to distinguish humans from bots. No advertising tracking, no cross-site profiling. SCCs / EU-US-DPF. cloudflare.com/privacypolicy
  • Google reCAPTCHA Enterprise (Firebase App Check) — Google Ireland Ltd. Used by Firebase App Check to attest that API requests originate from genuine app installations.

6.6 Analytics

  • Google Ireland Ltd. (Google Analytics 4) — active only after explicit consent in the cookie banner („Accept all“). IP is anonymized; transfer to the USA on the basis of SCCs / EU-US-DPF.
  • Matomo — page views and clicks, operated on our own servers without cookies. No data is passed to third parties.

6.6a How You Found Us (Source of Enquiries)

We want to know which channels lead to enquiries and bookings. When you open our website we note where you came from: the domain of the referring website (never the full address), campaign parameters in the link (such as utm_source), whether you arrived via an ad click (only the type of click ID, never its value), the first page you visited and your country as derived by Cloudflare from your IP address.

When you contact us from the website via WhatsApp, Telegram or email, the pre-filled message or subject contains a short reference code (for example „Ref K7QM“; on Telegram it is part of the start link). It lets us connect your enquiry to that information. You can delete the code before sending. Contact forms, website chat, registration, charter requests and contracts carry the same information directly.

Without consent this information is kept only in your browser’s memory for the current visit. If you choose „Accept all“, we also keep it in your browser’s localStorage (pj.attr.v1, 90 days) so that a later visit can be linked to your first one. Records of clicks on contact links are deleted after 90 days; the source stored with an enquiry, ticket, account or contract is kept as long as that record. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in understanding which channels bring enquiries); storage in your browser beyond the visit: consent, § 25(1) TTDSG.

6.6b Partner Programme

If you arrive via a partner link (a link with ?ref=CODE or privjet.net/p/CODE), we note the partner code in the same way as described in § 6.6a and count the visit for that partner per day, without your IP address or any other identifier. If you then create an account, send a request or book, we record which partner referred you so that we can pay the partner’s commission: the link or code counts for 365 days, and after your first paid booking your further bookings count for the same partner for 12 months. The partner never sees your name, email address or phone number — only the route, the month, the amount of the commission and its status. If you entered the partner’s code, you may receive the discount on the service fee the partner offers. Legal basis: Art. 6(1)(b) GDPR where the code gives you a discount, otherwise Art. 6(1)(f) GDPR (our legitimate interest in paying our partners correctly); storage in your browser beyond the visit: consent, § 25(1) TTDSG.

If you are a partner, we process the data from your application (name, company, email address, phone number, website and channels, country), your partner code, statistics on clicks, sign-ups, requests and bookings, your commissions and payouts, and the bank and tax details you provide for payouts. Bank details and tax identification numbers are stored encrypted and are only decrypted to make a transfer. Legal basis: Art. 6(1)(b) GDPR (partner agreement) and Art. 6(1)(c) GDPR (retention obligations under tax and commercial law). We keep this data for as long as you take part in the programme and afterwards for as long as statutory retention periods require (generally up to 10 years for payout records).

6.7 Messaging and Voice

  • Telegram FZ-LLC (UAE) — admin notifications and concierge bot upon explicit contact by you.
  • WhatsApp Ireland Ltd. (Meta) — WhatsApp concierge upon explicit contact by you. The gateway is self-hosted on our own servers in Germany; no third-party messaging provider processes the content of your chats.
  • Twilio Ireland Ltd. — voice confirmation calls to Operators on last-minute bookings. SCCs.

6.8 AI Concierge (LLM Inference)

The AI concierge runs on managed model providers. By default we route prompts to the Google Gemini API and use Anthropic only as a fall-back. For the concierge, only conversation content (prompts and tool-calling JSON) is transmitted — no plain-text passenger data or payment data. The optional passport / ID-card scan (§ 5.3) is the only feature that sends an image of a government-issued ID to the Gemini API, and only when you actively use it. All providers operate under zero-retention or short-retention APIs for non-training use.

  • Google Ireland Limited (Gemini API) — default provider, model family Gemini Flash. Under the paid Gemini API terms, Google does not use prompts or completions to train its models. Transfers to the U.S. are covered by the EU-U.S. Data Privacy Framework and SCCs. ai.google.dev/gemini-api/terms
  • Anthropic, PBC (USA) — optional fallback provider for Claude LLM via Anthropic’s direct API. Anthropic does not use API data for model training (zero-retention API). SCCs. anthropic.com/legal/privacy
  • Google Cloud / Vertex AI (Google Ireland Ltd.) — reserved for future model A/B-tests; not active in production at the date of this Policy unless noted otherwise on the cookie / consent banner.

6.9 Image Services and Backgrounds

  • Immich (self-hosted) — own EU servers for background imagery.
  • serper.dev / Serper LLC — Google-image API for aircraft-image enrichment. Only public aircraft model labels are queried; no PII of platform users.

6.10 Social-Media Auto-Posts

  • Crosspostify — distributes platform-owned marketing posts to Instagram, TikTok and Threads. No customer PII is transmitted.

7. Cookies and Similar Technologies

We use cookies and localStorage. On first visit we ask for your consent through a cookie banner.

7.1 Strictly Necessary (no consent required, § 25(2) No. 2 TTDSG)

  • __session / firebase-auth — login session (lifetime: session up to 14 days)
  • cf_clearance, __cf_bm — Cloudflare bot-management and DDoS protection (lifetime: 30 min / 24 h)
  • cf_chl_* — Cloudflare Turnstile challenge tokens (lifetime: short-lived, per session)
  • cookie-consent (localStorage) — your choice in the cookie banner (kept until you change it)
  • currency — display currency (lifetime: 90 days)
  • privjet_ab_* — A/B variant assignment (lifetime: 30 days, no PII without login)

7.2 Optional (consent required, § 25(1) TTDSG)

  • Analytics: _ga, _ga_* — Google Analytics 4 (lifetime: up to 14 months)
  • Source of enquiries: pj.attr.v1 (localStorage) — how you first found us and, if you came via a partner link, the partner code, see §§ 6.6a and 6.6b (lifetime: 90 days; a partner code up to 365 days)

You may withdraw or change your consent at any time. Withdrawing deletes the Google Analytics cookies and the stored source.

8. Push Notifications

With your consent we send push notifications via Firebase Cloud Messaging (web/iOS/Android), e. g. about matching empty legs. Legal basis: Art. 6(1)(a) GDPR. You can disable push at any time in your browser/device settings or via your profile.

9. International Data Transfers

  • EU-US Data Privacy Framework (Commission adequacy decision of 10 July 2023) for certified U.S. recipients;
  • EU Standard Contractual Clauses (SCCs) under Implementing Decision (EU) 2021/914 for other third countries;
  • additional safeguards (transfer impact assessment, encryption-at-rest and in-transit, pseudonymized transmission, access controls).

10. Retention Periods

  • Booking / contract data: 6 years (§ 257 HGB)
  • Invoices and payment records: 10 years (§ 14b UStG, § 147 AO)
  • Server logs: 7 days raw, 90 days aggregated
  • Pax-PII: 90 days after flight completion
  • Newsletter data: until withdrawal

11. Your Rights

11.1 GDPR (Art. 15–22)

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure / right to be forgotten (Art. 17)
  • Restriction (Art. 18)
  • Data portability (Art. 20) — JSON export on request
  • Objection (Art. 21), in particular against direct marketing
  • Withdrawal of consent with effect for the future (Art. 7(3))
  • Lodging a complaint with a supervisory authority (Art. 77).

11.2 California Residents — CCPA / CPRA

California residents have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including:

  • Right to know what personal information we collect and how we use it;
  • Right to delete personal information we hold about you;
  • Right to correct inaccurate personal information;
  • Right to opt-out of sale or sharing of personal information — we do not sell or share personal information for cross-context behavioral advertising;
  • Right to non-discrimination for exercising these rights.

California requests can be sent to [email protected] with the subject line “California Privacy Request”.

Inquiries are processed within 30 days where required by GDPR and within 45 days for CCPA requests.

12. Automated Decision-Making / Profiling

We do not engage in solely automated decision-making with legal effects (Art. 22 GDPR). Our score-based Operator-matching is a decision-support tool only; final booking decisions are made manually by you and the selected Operator.

13. Security

We implement technical and organizational measures pursuant to Art. 32 GDPR, including:

  • TLS 1.2+ for all data transmissions
  • AES-256-GCM encryption for sensitive Pax-PII at rest in the database
  • Firebase App Check and Bearer-token authentication for APIs
  • Rate limiting, IP throttling, Cloudflare Turnstile bot-challenge and Firebase App Check on public endpoints
  • HMAC-signed webhooks and magic-link tokens
  • Strict role-based access control (Admin / Operator / Customer)
  • Regular security audits and penetration tests

14. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in legal requirements or in our services. Subsequent visits will be governed by the new version.