Private account identity
Natifly processes account identifiers such as email address, password hash, verification state, account role and status, session/security information, and the records needed to operate authentication and account recovery.
Cookie preferences
Natifly uses necessary browser storage for core features such as sign-in, security, private account workflows, and remembering this choice. Optional Google Analytics cookies are used only if you allow analytics.
Supports essential site, security, account, booking, and consent-preference functions. These are not switched on or off by the analytics choice.
Measures sanitized page categories and a small allowlist of product interactions. The Google Analytics tag stays blocked until you allow analytics.
Google advertising consent signals remain denied by this control. Analytics does not determine qualified creator views or creator earnings. Read the Cookie Notice and Privacy Notice.
Privacy
Natifly is operated by Tuffice LLC. This notice explains the main categories of information Natifly processes, why they are used, which information can become public, and how private account, travel, support, and transaction information is kept separate from public discovery.
Privacy version 2026-07-29
Natifly processes account identifiers such as email address, password hash, verification state, account role and status, session/security information, and the records needed to operate authentication and account recovery.
Depending on your profile visibility and creator status, public profile fields can include a username, display name, profile image, headline, biography, city, country, home airport, and website. Private-profile identity is not treated as public creator content.
Natifly processes articles, photo posts, captions, media, itinerary content, moderation state, publishing state, and creator ownership information so content can be drafted, reviewed, published, displayed, and managed.
Follows, bookmarks, reactions, comments, reports, blocks, and notifications are processed to provide social features, keep each user's private library and network state accurate, and enforce visibility and safety boundaries.
Natifly uses server-side timing, derived security fingerprints, rate limits, and other anti-abuse controls to distinguish meaningful audience activity from duplicates, automation, self-views, or concentrated manipulation.
If Google Analytics is enabled for the public Natifly site, it remains off until you choose to allow analytics. You can change that choice later from Analytics choices in the public footer.
Natifly sends sanitized page categories, generic page labels, and a small allowlist of fixed product-interaction events to understand visits, navigation, and feature use. The current interaction allowlist covers follow changes, bookmark changes, reaction changes, flight-search submissions, attraction and experience discovery, successful Add to Trip actions, flight-planning CTA clicks, outbound booking clicks, and successful public sharing actions. Share measurement records only the fixed content category and whether the browser completed its native sharing flow or Natifly copied the public link. Event parameters are fixed categorical labels only. Dynamic creator usernames, story IDs, attraction IDs or names, Experience product codes, private trip IDs, destination or city names, shared URLs, page titles, recipients, selected share destinations, support-ticket IDs, query strings, search text, airport codes, travel dates, passenger counts, passenger details, payment references, fare or money values, and provider references are not sent as Analytics page locations, titles, or product-event parameters.
Google Analytics is separate from Natifly's server-qualified audience measurement and product state. GA pageviews and product events do not count as qualified creator views, do not create creator earnings, and do not determine follow/bookmark/reaction state, Add to Trip state, payout, membership, Booking, payment, flight search, or supplier state.
Natifly may use Google advertising on public web discovery surfaces and native sponsored cards in the Android Home Feed to help fund the service. Ads are labeled and are not creator content.
On the web, third-party vendors including Google may use cookies or similar technologies for ad delivery and measurement. In the Android app, the Google Mobile Ads SDK may process IP address (which can be used to estimate general location), app/ad interactions, diagnostic or performance information, and device or advertising identifiers for advertising, analytics, and fraud prevention. Google and participating advertising technology providers may process applicable device, network, interaction, and consent signals to select, deliver, limit, measure, protect, and report advertisements, subject to the choices and regional requirements that apply to the user.
Natifly's Analytics preference does not grant advertising consent. Where a publisher consent flow is required, Natifly uses Google consent tooling for the applicable web or mobile advertising surface. The first Android native-ad release requests non-personalized ads and exposes Google's advertising privacy options from the in-app Privacy choices screen where those options are available. Advertising choices are handled separately from Natifly's optional Analytics control. You can also manage Google personalized-ad settings through Google Ads Settings.
Private trip plans can contain route, dates, cabin, fare, supplier references, offer expiry, and sanitized itinerary information. These records are scoped to the signed-in traveler and are not public creator content.
Passenger details used in a checkout workflow are handled under the separate Flight Passenger Data Notice, which explains the fields, encryption, access, supplier disclosure, and deletion rules.
Natifly Booking records are designed to retain transaction and supplier information without storing passenger names, birth dates, email addresses, phone numbers, passport data, or identity-document data in the Booking payload.
Natifly processes membership plan, subscription, billing-period, entitlement, payment-reference, amount, currency, and reconciliation information. Full card numbers, card security codes, and similar payment credentials are collected by secure payment components rather than stored as Natifly card fields.
Natifly may process qualified audience records, creator earning entries, payout requests, Community Support payments, writer/platform split amounts, refunds, disputes, payout-account status, and related transaction records to operate creator financial features and respond to payment questions.
See the Creator Earnings & Community Support Policy for the current program rules.
Private support tickets can contain the category, subject, customer-visible messages, status, priority, service timing, and audit information needed to investigate and respond. Internal staff notes are not shown in the customer thread. Security and abuse investigations can also use account, session, rate-limit, block, report, and audit information where necessary to protect Natifly and its users.
Natifly may use specialized providers for services such as analytics, advertising, email delivery, payment processing, flight shopping and fulfillment, hosting, security, and other platform operations. Information is disclosed only as needed for the relevant service or as required by law. Passenger details are disclosed to a travel supplier only when a traveler initiates a workflow that requires those details and the applicable consent and validation requirements are satisfied.
Different records have different retention needs. Account, security, audit, transaction, supplier, support, advertising-consent, and fraud-prevention records may be retained as needed for operational, legal, dispute, accounting, and safety purposes. Passenger drafts use more specific deletion rules described in the Passenger Data Notice.
Available controls can include profile visibility, profile updates, avatar removal, session management, passenger-draft removal, trip cancellation, social blocking, analytics choices, advertising-consent choices where presented, and support requests. You can also request permanent account deletion from the dedicated Natifly account deletion page, including after uninstalling the app. Natifly removes or de-identifies associated personal data that is no longer needed. Limited transaction, booking, payment, creator-financial, fraud-prevention, legal-consent, security, dispute, and audit records may be retained only where necessary for legal, accounting, safety, fraud-prevention, or dispute purposes.
Email [email protected]. Natifly may require account verification before fulfilling a request involving private account or travel information.