Last updated 19 Feb 2022
At App in the Air (“AITA,” “we,” “us,” etc.), we believe that flying should be an adventure, not an ordeal. It should be pleasant, not painful. Fun, not bumpy. We can’t guarantee you won’t meet any turbulence in the air, but we want to make things as smooth as possible on the ground or in the cloud, wherever it is that you make and manage your flight arrangements. Think of it like this: altitude, not attitude.
Secure
We store data on your device and only distribute it as described in this Policy.
Control
You can change settings for storing and distributing your info at any time.
Transparency
This Policy explains how we collect and store your data. No hidden rules or small text!
About policy
Providing streamlined travel booking and management requires us to collect personal data from the more than 6 million worldwide users of our platform. Understanding their travel preferences, habits, and purposes leads to more efficient and enjoyable travel. We also understand that this information needs to be collected, protected, shared, and used judiciously – with an eye toward transparency.
Because your personal data is valuable and sensitive, we want you to be confident that we are handling it with care and respect. We also want to give you the necessary tools and options to manage and protect that information. This Privacy Policy is part of our effort to achieve these goals.
As you interact with us, you will share your personal data in various ways. Sometimes we collect it directly from you on a voluntary basis. Other times, we use technology to automatically collect personal data.
This Policy applies to our mobile App (App in the Air), Websites (https://www.appintheair.mobi/, https://b2b.appintheair.com/ and https://www.appintheair.com/), and any sites or products that display these terms (collectively, the Platform). It does not apply to any website, mobile app, service, or product that does not display or link to this Privacy Policy or that contains its own privacy Policy. If you do not agree with our policies and practices, please do not use our services. By accessing the Platform or using our services, you agree to this Policy.
We use certain Google services and are required to provide you with the following Privacy Policy Addendum which addresses non-standard PII data and includes the Google Limited.
How we collect personal data
We may collect personal data from you directly or indirectly. When you create an account with us, for example, you provide personal data directly to us. Other times, personal data is collected automatically as you use our Platform. And in some instances, third parties with whom we work provide personal data to us.
Whether you’re one of our Platform users, employees, or even a prospective employee, you may provide certain kinds of personal data directly by interacting with AITA online and offline (via the App, social media or Web forms, by phone, email, in person – or even through regular old postal mail).
When you register for an account with us, you will provide personal data that includes your name, email address, and your phone number. You will create a username and password or PIN, information that on subsequent visits helps us confirm your identity and makes it easier to use our services. We may also collect demographic information, such as a user’s gender, age, and photograph where a user elects to provide this information.
Job applicants also will provide personal data, such as their name and contact information and other applicant related information (prior employment, education, etc.), when they complete forms within the human resources software we use.
If you provide us with any personal data on behalf of another person (for example when booking tickets or hotels, auto check-in for flights or subscribing for notifications on flights on behalf of your employer or a parent, child or guardian), you: (i) represent that the individual requested these services and (ii) you have the legal authority to instruct us to process the individual’s personal data in accordance with this Privacy Policy and our Terms of Service.
We may collect personal data about you from third parties to process purchases and payments, streamline itineraries, offer travel and carbon offset options, and aggregate users’ ratings for accommodations and airlines. We may also receive personal data from our advertising partners to help us better understand what ads our customers interact with and when users download our App or visit our Websites. Click here to see a list of third parties with whom we work and the services they provide.
We also may collect personal data from online social networks if you use them to connect with AITA, or if you take part in a forum, for example, on Facebook. We may collect personal data when you click “Share This” or “Like” buttons or otherwise use social media buttons or plug-ins.
If you make a post on a third-party social media site, such as on Facebook, or by identifying us in your social media feed by tagging us using a hashtag (#) or “at” (@), your personal data may be publicly available and is subject to the privacy policies of those third-party social media sites. As a reminder, this Policy describes how we will treat your personal data once it is in our possession.
We recommend you review the privacy policies of any third-party sites you visit to understand the data collection and use practices of that third party.
Sometimes personal data is collected by automated technologies and shared with us when Platform visitors navigate through our products and services online. We may track your browsing actions and log your IP address. We may collect data that identifies the device (phone, tablet, etc.) you are using to connect online with us. We also track keystrokes , browsing histories, product preferences, and purchase histories to make future visits to our Platform more relevant and efficient.
Other automated collection technologies – such as cookies, beacons, tags, and scripts – are used by us to analyze trends, administer the Platform, and track users’ movements around the Platform. We, and our third-party partners, also use these technologies to gather demographic information about our user base as individuals and in the aggregate. Read more about our use of cookies here.
Some businesses we work with serve ads through the Internet. These third parties may use cookies to collect information about your visits to our Websites, as described in the automated technologies section of this Privacy Policy. They also may use information about your visits to serve targeted advertisements that are relevant to you. Those may appear on other sites that you visit.
We will never knowingly collect personal data directly from anyone younger than 16 years. However, personal data about children and teens is sometimes provided by parents and other adult caretakers who arrange for their travel. If we become aware that personal data of anyone younger than 16 has been provided to us by someone without legal authority to do so, we will delete the information from our files.
Some browsers offer a “Do Not Track” privacy preference. Generally, when a user turns on the Do Not Track Signal, their browser sends a message to websites requesting that the user not be tracked. Our Websites currently do not respond to “Do Not Track” signals.
How we use personal data
We know your personal data is important to you, so we want to be as transparent as possible while explaining how we use that information.
As mentioned above, those logging into the App will register by providing their name and email address to create profiles that include user IDs and passwords. Collecting this information allows easier, quicker access to our Platform on subsequent visits. As users navigate through the Platform, their movements will be tracked and analyzed. Doing so allows us to make our products better and their experiences easier.
We also use personal data:
We sometimes take personal data and strip away identifying details, then combine it into a dataset that allow us to predict users’ behavior and interests. In this way, we can fine-tune our marketing campaigns and improve our travel recommendations and services. Because we remove the personal data, the subjects of the data remain anonymous.
How we secure personal data
We have implemented industry-accepted administrative, physical, and technology-based security measures to protect against loss, misuse, unauthorized access, and alteration of personal data in our systems. We ensure that any employee, contractor, corporation, organization, or vendor who has access to personal data in our systems is subject to legal or professional obligations to safeguard that personal data.
While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or form of electronic storage is 100 percent secure. Therefore, we cannot guarantee its absolute security.
If you have received unwanted or unsolicited e-mail from us or purporting to be sent by us, please forward a copy of that e-mail with your comments to [email protected] for our review. If you feel that any of our privacy practices or security standards detailed in this Privacy Policy have been violated, you may contact us (see Contact Us at the end of this Policy for additional details).
Your Rights
We understand that you want to protect and control your personal data. If you do not see your specific question addressed below, contact us at [email protected] with “Personal Data Request” in the subject line. Please provide full details relating to your request, including your contact information and any other details you believe are relevant. We are committed to responding to requests to exercise data protection rights in accordance with applicable data protection laws.
This section details how you may review, update, correct, or delete your information.
You may update your name, contact information, email preferences, and physical address by accessing your account on the Platform. You may also submit a request to access your personal data by emailing us at [email protected] with “Access to Personal Data” in the subject line.
You may delete your account any time after you create it. To delete your account, please send an email to [email protected] with “Delete Account” in the subject line. Upon receiving your request, we will deactivate your account and delete personal data when allowed or required by applicable law.
Users of our Platform may download all of their account data by visiting their profile and clicking “Export Data”. If you choose to “Export” your account data, the information will be emailed to the email addresses attached to your account.
If you do not wish to receive promotional e-mails from us, you may follow the unsubscribe process at the bottom of the promotional e-mail you received or by emailing us at [email protected]. Please keep in mind that you still may receive transactional e-mails from us (such as e-mails related to the completion of your account registration, purchases, correction of user data, password reset requests, reminder e-mails you have requested, and other similar communications) that may be necessary for us to make the Platform available to you or respond to your inquiries and support requests.
Laws in certain jurisdictions may require that we store your personal information within that jurisdiction; where that is the case, we will store your personal information in that local region. In addition, certain laws require that we provide you notice of additional rights and disclosures as set out below.
Individuals from the European Union, including the United Kingdom and Switzerland, have certain rights associated with their personal data based on applicable law.
International Transfers. AITA is headquartered in the United States. Your personal data will be transferred to, processed, and maintained on computer systems located in the United States.
The United States currently is not a country the European Union has deemed “adequate” under applicable data protection laws. AITA collects, transfers, and processes personal data under terms required by applicable law, including: when you provide your consent, to perform a contract with you (such as to deliver services through our Platform, or to fulfill a compelling legitimate interest of AITA in a manner that does not outweigh your rights and freedoms. AITA may enter into data protection agreements or other legally approved mechanisms with its vendors to support compliance with applicable law.
We have taken appropriate safeguards to require that the personal data we process will remain protected in accordance with this Policy when transferred internationally, including when processed internationally by third-party service providers and partners. The safeguards we have taken include implementing the European Commission's Standard Contractual Clauses, relying on a third-party service provider’s Binding Corporate Rules, Certification, or other legally approved mechanism for any transfer of personal data to non-EEA third-party service providers or business partners.
Your data protection rights. In addition to any of the general rights granted to you under this Privacy Policy, European users have the following data protection rights:
To make a request associated with any of the above-described rights, please contact us at [email protected] with “Personal Data Request” in the subject line. Provide full details relating to your request, including your contact information and any other details you believe are relevant. We are committed to responding to requests to exercise data protection rights in accordance with applicable data protection laws.
Our Data Protection Officer. We have appointed a Data Protection Officer to address any questions you may have. You may reach Bayram Annakov at [email protected].
Individuals from Brazil have certain rights associated with their personal data based on applicable law. For clarity, personal data processed by us via our Platform is processed by us as a controller (as that term is defined under applicable law).
International Transfers. AITA is headquartered in the United States. Your personal data will be transferred to, processed, and maintained on computer systems located in the United States.
Your data protection rights. In addition to any of the general rights granted to you under this Policy, Brazilian users have the following data protection rights:
To make a request associated with any of the above rights, please contact us at [email protected] with “Personal Data Request” in the subject line. Provide full details relating to your request, including your contact information and any other details you believe are relevant. We are committed to responding to requests to exercise data protection rights in accordance with applicable data protection laws.
The California Consumer Privacy Act provides specific rights to those who live in the state of California. If you are a California-based consumer, as that term is defined under California law, this section will apply in addition to all other applicable rights and information contained in this Policy:
If you are a California consumer and have additional questions based on this section of our Privacy Policy, email us at [email protected] with “California Personal Data Request” in the subject line and include full details relating to your request, including your contact information and any other details you believe are relevant, or call us toll-free at (800) 940-7635.
Be sure to check this Policy for updates, as we will review it at least every 12 months and make necessary changes.
The law requires us to verify that any personal data request submitted was made by someone with the legal right to access the information. Therefore, before accessing or divulging any information pursuant to a data subject access request, we may request that you provide us with additional information so we can verify your identity and legal authority.
To make a request, please contact us at [email protected] with “Personal Data Request” in the subject line and provide full details about your request, including your contact information and anything you believe is relevant. We will provide a response to an access request within the timeframes required by law. If we cannot substantively respond in a timely manner, we will notify you and provide the reason for the delay.
Under certain circumstances, we may not fulfill your request, such as when doing so would interfere with our regulatory or legal obligations, when we cannot verify your identity, if your request involves disproportionate cost or effort, or where the law allows us to retain that information. But we will respond to your request within a reasonable time, as required by law, and provide an explanation.
Updates
This Privacy Policy will be updated to reflect our personal data handling practices. We reserve the right to amend this Policy at any time, for any reason, without additional notice to you, other than through posting the updated Privacy Policy on our Platform. We invite you to return to this page to ensure you are informed of any updates we make about how we collect, use, and protect customer information. You can see when this Privacy Policy was last updated by checking the “last updated” date displayed at the beginning of this Policy.
Contact us
If you have questions about the way we handle personal data, please contact us:
App in the Air
1201 3rd Ave., Floor 22
Seattle, WA 98101
[email protected]
(800) 940-7635