Sub-processors
This list is generated from the integrations this deployment actually has configured — not kept by hand. A third-party credential cannot reach production without an entry in the register behind this page: the build fails first. That is the only reason a list like this can be trusted to still be true.
In use (14)
Configured in this deployment and receiving what the purpose describes.
Application database, authentication and storage.
Application hosting and edge routing. All requests to the product pass through it.
Transactional email: sign-in codes, nomination and guardian invitations.
Flight search and, when booking is live, order creation.
Flight search, including self-transfer itineraries.
Live flight status and delay observations, by flight number.
Transit schedules and routing between airport and city.
Award availability lookups.
Bookable experience inventory and affiliate handoff.
Rate limiting and short-lived caches. Keys are hashed identifiers, not names.
Bot protection on public forms.
Wallet pass signing. Passes are signed by us; Apple receives nothing at issue.
Wallet pass issuance. The pass object carries a pass id, never a name.
Affiliate handoff for experiences. The traveller leaves for their site.
Integrated, not in use (2)
Supported by the codebase and not configured here, so nothing is being sent to them. Listed because that can change with a credential.
Place details and ratings. Search terms only; no traveller identity is sent.
Developer tooling only: an MCP server that lets a developer's Claude session ask ChatGPT. Outside the request path; no traveller, partner or operator data is sent.
Regions are as each vendor states them. Where a purpose says no personal data reaches a vendor, that is a statement about what we send them — not about what they could collect from you if you visit their own site after leaving ours.
What we collect and why is on the privacy page. To ask what we hold about you, or to have it deleted, write to us.
Ask what we hold about youDraft. Not reviewed by counsel. The vendor rows are generated and current; the wording around them is not a reviewed disclosure yet, and saying so here is the same discipline as marking an assumed term in a buffer estimate.