Privacy Policy
How FlyTLV collects, uses, shares, stores and deletes personal data — and the rights you have over it.
1. Who We Are and What This Policy Covers
This Privacy Policy explains how FlyTLV ("FlyTLV", "we", "us" or "our") collects and processes personal data when you visit or use the FlyTLV website, dashboard, notifications, emails and related services (together, the "Service"). FlyTLV is a service operated by aerocraft.dev from Tel Aviv, Israel, which acts as the controller of the personal data described here; requests and questions can be sent through the contact form on this website, which is our official channel. This Policy applies to the Service only. It does not apply to airlines, booking platforms, search engines or other third-party websites you reach through our links, each of which processes your data under its own privacy policy. This Policy forms part of, and should be read together with, our Terms and Conditions.
2. Personal Data We Collect
We collect the minimum needed to run the Service. (a) Account data: when you sign in with Google we receive and store your Google account identifier, email address, display name and profile picture URL, together with the dates on which your account was created and last used. We never receive or store your Google password. (b) Preferences: your budget ceiling, email language, email report threshold, email subscription status and interface theme. (c) Activity you create: tracked scans (routes, dates, passenger and cabin selections, target prices), saved flights and packages, deal alerts, destination star ratings and in-app notifications. (d) Booking hand-offs: when you open a deal we record the route, price, currency, destination link, the page you came from, your browser's user-agent string and the time. (e) Messages you send us through the contact form, including your name, email address and the content of your message. (f) Technical data: server request logs and diagnostic information generated automatically when you use the Service.
3. Data We Do Not Collect
We do not ask for, and the Service has no facility to receive, payment card numbers, bank details, passport or identity document numbers, dates of birth, home addresses, telephone numbers, precise location data or any special category data such as health, biometric, religious or political information. No travel purchase is ever completed on the Service, so no passenger name, traveller document or payment instrument is ever transmitted to us; you provide those directly to the airline or booking platform under its own privacy policy. Your IP address is processed transiently in memory to apply rate limits and detect abusive traffic, and is not written to our database or linked to your account; we deliberately removed the IP address column that our booking hand-off records once contained, including for records stored before that change.
4. Why We Use Your Data and Our Legal Bases
We use personal data to: create and authenticate your account and keep your session secure; display the dashboard, deals, saved items, ratings and alerts you have asked for; run your tracked scans and generate the alerts and notifications you configure; send service and report emails you have not unsubscribed from; answer your messages; measure aggregate usage and improve the Service; and protect the Service against fraud, scraping, abuse and security incidents. Where the EU or UK General Data Protection Regulation applies, we rely on: performance of a contract with you (account, dashboard, scans, alerts and the emails inherent to them); your consent (analytics cookies, Google Sign-In loading, optional emails — withdrawable at any time); our legitimate interests in operating, securing, defending and improving the Service and in earning affiliate revenue that funds it; and compliance with a legal obligation where one applies. Where we rely on legitimate interests, we have balanced them against your rights and you may object as described below.
5. Cookies, Local Storage and Similar Technologies
We use a secure, first-party session cookie (`session_token`) that is strictly necessary to keep you signed in; it is HttpOnly, expires within 24 hours and is invalidated server-side when you sign out. A first-party cookie (`flytlv_cookie_consent`) records your cookie choices for 30 days so we do not have to ask again, and your interface theme is kept in your browser's local storage. Optional cookies are set only in line with the choices you make in Cookie Preferences, which you can change at any time; refusing them does not prevent you from using the Service, although Google Sign-In — and therefore the dashboard — requires the Google Sign-In consent to load. Cookies set by third parties in your browser are described in the following section and are governed by their own policies.
6. Analytics, Advertising and Affiliate Tags
Google Analytics (gtag.js) is loaded on every visit but starts in a denied state under Google's Consent Mode, setting no analytics cookies and collecting no analytics data until you grant Analytics consent; you may withdraw that consent at any time. Google Tag Manager is loaded as the container through which these tags are managed and inherits the same consent defaults. We also load a monetization tag from our advertising and affiliate partner, Travelpayouts ("Emerald"), which may set advertising cookies and identifiers, may call further advertising and exchange domains, and presents its own consent prompt where the law requires one. That tag is loaded only if you grant Advertising consent in Cookie Preferences: while that consent is off it is never requested, so it sets nothing and receives nothing, not even your IP address. The same choice governs Google's advertising signals (`ad_storage`, `ad_user_data`, `ad_personalization`), which start denied and are granted only by it. When the partner tag does load, the data it collects is governed by that partner's privacy policy rather than this one; we receive from it only aggregate performance and commission reporting, never your profile, your saved routes or your alerts. We do not operate social-media marketing pixels or retargeting cookies of our own.
7. Who We Share Data With
We do not sell, rent or trade personal data, and we do not disclose your profile, tracked scans, saved items, alerts or ratings to advertisers or data brokers. We share data only with service providers that process it on our behalf under contract and on our instructions: our cloud hosting and managed database provider; our transactional email provider, which delivers welcome, report, alert and contact-form messages; Google, which provides identity, analytics and tag-management services and whose publicly available flight-search results our scanners read; our advertising and affiliate partner as described above; and the content-delivery, map-tile and performance-monitoring providers whose resources your browser loads and which therefore receive your IP address and basic request data. We may also disclose data where required by law, court order or a lawful request from a competent authority, to establish, exercise or defend legal claims, to prevent fraud, abuse or a security threat, or to a successor in connection with a merger, acquisition or sale of assets, in which case this Policy continues to apply.
8. International Transfers
FlyTLV is operated from Israel, and our hosting, database, email, analytics and advertising providers operate infrastructure in several countries. Your personal data may therefore be transferred to, stored in and processed in countries outside your own, including the United States and the European Economic Area. Israel benefits from a European Commission adequacy decision. Where a transfer is made to a country without an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses incorporated into our providers' data-processing terms. You may request further information about the safeguards applying to a specific transfer through our contact form.
9. How Long We Keep Data
We keep account data — profile, preferences, scans, saved items, alerts and ratings — for as long as your account exists, and delete it when you delete your account. Sessions expire within 24 hours and are revoked immediately on sign-out. Scan execution history is retained for approximately 30 days, price-trend data for approximately 90 days, cached fare listings for approximately 10 days, and server log files for approximately 3 days; in-app notifications are capped per user, with older ones removed automatically. Records of booking hand-offs are retained for commission reconciliation, fraud prevention and aggregate reporting; when you delete your account these records are de-identified by permanently detaching them from your user account rather than being deleted, so they can no longer be attributed to you. Cached fare, route and package data is not personal data and is retained and rebuilt on its own automated schedule. We may retain data for longer where a legal obligation, dispute or investigation requires it.
10. How We Protect Your Data
All traffic between your browser and our servers is encrypted in transit using industry-standard TLS. Data is stored in a managed PostgreSQL database with restricted network and credential access. We do not issue or store passwords: authentication is delegated to Google, session tokens are cryptographically signed, stored only as hashes on our servers and checked against a revocation list on every request, and signing out invalidates them server-side rather than only clearing your browser cookie. Administrative access is limited to the operator of the Service, and our application logs are written so that account identifiers and email addresses are not recorded in them. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; you are responsible for keeping your Google Account and your devices secure. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, affected users, without undue delay.
11. Your Privacy Rights
Subject to applicable law, you have the right to access the personal data we hold about you, to have inaccurate data corrected, to have your data erased, to restrict or object to certain processing (including processing based on our legitimate interests), to receive the data you provided in a portable machine-readable format, and to withdraw any consent you have given without affecting processing already carried out. Much of this is available immediately and without a request: your profile, preferences, scans, saved items, alerts and ratings are visible and editable in the dashboard, your cookie choices in Cookie Preferences, and your email settings in your profile. We do not sell or share personal information for cross-context behavioural advertising as those terms are defined under California law, and we do not discriminate against anyone who exercises a privacy right. We respond to rights requests without undue delay and in any event within one month, and we may need to verify that a request comes from you.
12. Deleting Your Account and Data
You can delete your account at any time from the profile page in the dashboard. Deletion is immediate, automated and irreversible: your profile, preferences, sessions, tracked scans and their private results, saved items, deal alerts, destination ratings and notifications are permanently removed, and your booking hand-off records are permanently detached from your identity as described above. Anonymous, aggregated or de-identified data that can no longer be linked to you, cached flight data that never identified you, and data we are required to retain by law are not affected. If you cannot access your account, you may request deletion through our contact form; we will verify the request against the email address on the account before acting on it.
13. Emails and Notifications
We send a small number of emails: a welcome message when you register, a recurring cheap-flight report, and messages responding to enquiries you send us. You can unsubscribe from non-essential email at any time from your profile page, and you can set the language and price threshold of your reports there. Essential service messages relating to security, your account or material changes to this Policy may still be sent while your account exists. In-app notifications and deal alerts are generated by automated processes on a best-effort basis and can be disabled or deleted from the alerts and notifications surfaces at any time.
14. Automated Processing and Profiling
The Service is automated by design: background scanners search publicly available flight-search results, group fares into packages, rank them and compare them against the thresholds and criteria you configure in order to decide which alerts and reports to send you. This processing uses the preferences and criteria you have set yourself and does not evaluate your personality, behaviour, creditworthiness or any similar characteristic. It produces no decision that has a legal effect on you or that similarly significantly affects you, and no automated decision-making within the meaning of Article 22 of the GDPR is carried out. Aggregate destination ratings are computed from the ratings submitted by all users; an individual rating is never published in a way that identifies who submitted it.
15. Children's Privacy
The Service is not directed at children. It is intended for individuals aged at least sixteen (16), or the minimum age of digital consent in their country if that age is higher, and we do not knowingly collect personal data from anyone below that age. If you believe that a child has provided us with personal data, please contact us through our contact form; on becoming aware of such an account, we will delete the account and the associated data without undue delay.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, to our providers or to applicable law. The current version is always published on this page together with the date on which it was last updated, and where a change is material we will make reasonable efforts to give notice within the Service before it takes effect. Your continued use of the Service after an updated Policy takes effect indicates that you have read it; where the law requires your consent to a change, we will ask for it separately. This Policy is published in English and Hebrew; in the event of any inconsistency between the versions, the English version prevails.
17. Contact and Complaints
Questions about this Policy, requests to exercise your rights and privacy complaints should be sent through the contact form on this website, which is our official channel for all enquiries and the fastest way to reach us. FlyTLV is operated by aerocraft.dev from Tel Aviv, Israel. We ask that you contact us first so that we can resolve the matter, but you also have the right to lodge a complaint with a supervisory authority — in Israel, the Privacy Protection Authority, and in the European Economic Area or the United Kingdom, the data protection authority of your country of residence, place of work or the place of the alleged infringement.
This Privacy Policy was last updated on 06-08-2026.