Skip to content

Passenger privacy

Flight passenger data notice

This notice applies when a verified traveler prepares passenger details for a saved flight or booking workflow. It supplements the Natifly Privacy Notice and explains what passenger information is collected, how it is protected, when it may be disclosed to a travel supplier, and how durable booking records are minimized.

Passenger-data version 2026-07-31

Information collected for passenger preparation

Passenger identity and contact details

The passenger draft can include title, given name, family name, date of birth, gender marker, email address, and international phone number.

Supplier passenger context

Natifly also keeps the passenger position and supplier passenger type needed to match the selected flight offer. For an infant without a seat, the responsible adult passenger position can also be recorded.

Information not collected in the current passenger draft

The current passenger-draft workflow does not collect passport or identity-document numbers, passport images, visa documents, loyalty-program numbers, payment-card data, bank information, or similar identity-document material. If a supplier requires additional identity documentation that the current Natifly workflow cannot safely support, the booking workflow should not proceed as though that requirement had been satisfied.

Encryption and access

Encrypted storage

Passenger fields are encrypted on the Natifly server before database storage using authenticated encryption. The encrypted payload is bound to the specific trip, passenger position, and passenger type so it cannot be safely moved between those contexts.

Limited visibility

The traveler can review or remove their own passenger draft. Staff-facing product surfaces are designed around readiness and status information rather than exposing passenger field values.

When passenger details may be sent to a travel supplier

Passenger information is not public profile content. It is used only for the travel workflow the traveler initiated.

Fare review, consent, and airline rules

Current fare and consent

A saved fare can change before a booking action. Natifly may refresh the supplier offer before recording or using checkout consent. If relevant trip or passenger details change, prior consent can be invalidated and the traveler may need to review the current information again.

Supplier and airline conditions

Fare, baggage, check-in, change, cancellation, and refund rules are controlled by the applicable supplier and airline conditions for the confirmed booking. A saved trip is not itself an airline ticket.

Retention and deletion

Travelers can remove passenger drafts where the product provides that control. Natifly also deletes passenger ciphertext and checkout consent under retention rules tied to events such as trip cancellation or supplier-offer expiry. Non-sensitive trip, transaction, supplier-reference, security, and count-only audit evidence can be kept where needed for operational, legal, accounting, fraud-prevention, or dispute reasons.

Durable Booking records are minimized

A durable Natifly Booking record is designed to retain the booking status, amount, currency, supplier references, and a minimal supplier snapshot without storing passenger names, birth dates, email addresses, phone numbers, passport data, or other passenger identity-document information in the Booking payload.

Related information and contact

Questions or passenger-data requests may be sent to [email protected]. Natifly may require account verification before acting on a request involving private traveler information.

Flight passenger data notice | Natifly