Privacy Center

Privacy Policy

This notice explains how FlyMeOut collects, uses, and protects the personal data that powers flight price watches, alerts, and hotel experiments across our web application and supporting services.

Effective December 10, 2025

Data controller

FlyMeOut, Inc. (San Francisco, CA, USA)

Effective date

December 10, 2025

1. Information we collect

We capture only the data needed to authenticate you, configure price watches, and keep our platform reliable. The categories align with how travel meta-search leaders such as Skyscanner, Hopper, and Kayak structure their notices, with added specificity for fare-tracking workflows.

Depending on how you use FlyMeOut we process:

  • Account & identity data - name, email, authentication identifiers from Clerk, and role metadata (admin, beta tester, waitlist).
  • Travel preference data - route names, airport codes, cabin class, travel dates, price thresholds, flexible date ranges, loyalty numbers, and notes you add to a watch.
  • Transactional & support records - waitlist submissions, feedback, support tickets, and responses to surveys or promotions.
  • Usage and device data - log files, IP address, locale, browser version, device identifiers, and product analytics events that help us understand feature adoption.
  • Derived insights - price deltas, alert history, and aggregated metrics we calculate from Amadeus and other fare sources to surface trends back to you.
  • Partner-sourced data - enriched airport metadata, airline names, and downstream reference data delivered via our backend integrations.

2. How we use information

We process personal data to operate the service, improve accuracy, and communicate with you. The purposes mirror common industry practices but are scoped to fare intelligence:

  • Authenticating and securing accounts via Clerk, enforcing admin/waitlist rules, and preventing fraud or abuse.
  • Configuring, running, and troubleshooting watches, snapshots, alerts, hotel experiments, and waitlist workflows.
  • Personalizing dashboards, recommended routes, and notification pacing based on your historical usage.
  • Conducting analytics, forecasting, and benchmarking to keep alerts trustworthy without exposing individual itineraries.
  • Sending transactional emails or push notifications about watch status, product changes, or required legal updates.
  • Marketing FlyMeOut features (only with the preferences you set) and measuring the performance of campaigns.
  • Complying with applicable law, responding to lawful requests, and enforcing agreements or policies.

3. Legal bases (EEA/UK/Swiss users)

Where GDPR or similar regimes apply, we rely on the following lawful bases:

  • Contractual necessity - delivering the flight price monitoring capabilities you ask us to run.
  • Legitimate interests - securing the platform, preventing abuse, and improving accuracy in ways that do not override your rights.
  • Consent - sending optional marketing messages, enabling non-essential cookies, or honoring beta research programs.
  • Legal obligation - record keeping, responding to regulators, tax authorities, or law enforcement when required.

4. Sharing & disclosure

We do not sell personal information. We only share it with trusted processors under written agreements or as required by law:

  • Infrastructure & security partners - Vercel (hosting), Supabase/PostgreSQL (data storage via backend), Clerk (identity), logging and monitoring vendors.
  • Travel & data suppliers - Amadeus, airline reference providers, or hotel partners strictly to fetch fares or enrich your watches.
  • Analytics & communications - product analytics, survey, and email delivery tools that help us understand engagement and send updates.
  • Professional advisors - auditors, legal counsel, or insurers when needed to protect FlyMeOut and our users.
  • Regulators & law enforcement - when we must respond to lawful requests, enforce our agreements, or protect users from harm.

5. Retention, security, and international transfers

We retain personal data only while an account is active or as long as necessary to meet legal/reporting obligations. Travel history tied to cancelled watches is anonymized or deleted after 24 months unless an alert dispute requires longer retention.

We host production workloads primarily in the United States using hardened cloud infrastructure and apply encryption in transit and at rest, role-based access, continuous monitoring, and least-privilege controls.

When we transfer information from the EEA, UK, or Switzerland to the United States, we rely on the EU Standard Contractual Clauses (and the UK Addendum where required) supplemented by additional technical controls.

6. Your choices and rights

You can manage most preferences directly inside FlyMeOut, including watch settings, alert channels, and marketing opt-ins. Additional controls include:

  • Profile controls - update or delete account data through your settings or by contacting us.
  • Marketing opt-out - every promotional email includes an unsubscribe link; you can also opt out inside settings.
  • Access, correction, deletion, portability, or restriction requests - available to all users, with additional statutory rights for EEA/UK/Swiss (GDPR) and U.S. state privacy laws (including CCPA/CPRA, CPA, VCDPA). Submit requests via privacy@flymeout.com.
  • Authorized agent requests (California) - agents must present verifiable proof of authority before we respond.
  • Appeals - if we deny a privacy request, U.S. residents covered by state laws may appeal by replying to our decision email.

7. Cookies & tracking technologies

We use only the categories needed for a data-rich application:

  • Essential cookies - keep you signed in through Clerk, route requests through Vercel, and secure the waitlist and dashboard.
  • Functional analytics - product analytics that aggregate engagement signals so we can benchmark alert performance without storing raw itinerary details for longer than necessary.
  • Optional marketing cookies - only activated if you opt in to beta promos; you can change this anytime inside the app or via your browser controls.

8. Children's privacy

FlyMeOut is designed for business and frequent travelers. We do not knowingly collect data from anyone under 16. If we learn we have information about a child, we delete it and disable associated access.

9. Changes to this policy

We will update this page when we materially change how data is processed. For significant updates we will provide in-product notice or email at least 14 days before the new policy becomes effective unless immediate changes are required by law.

10. Contact us

Reach the privacy team at privacy@flymeout.com or by mail at FlyMeOut, Inc., 548 Market St PMB 32010, San Francisco, CA 94104 USA. EU/UK residents can also request to connect with our data protection representative through the same email address.

Need something specific or want to report a vulnerability? Email security@flymeout.com for urgent security questions, or privacy@flymeout.com for everything else.