Sub-processors
Who else touches the data you give this site, and what reaches them
Generated, not written down
This list comes from the integrations this deployment actually has configured — not from a list somebody maintains. A third-party credential cannot reach production without an entry in the register behind this page: the build fails first. A hand-written vendor list is correct on the day it is written and quietly wrong from the next integration onward, with nothing to signal the change.
What a region and a purpose mean here
Regions are as each vendor states them. Where a purpose says no personal data reaches a vendor, that is a statement about what we send them — not about what they could collect from you if you visit their own site after leaving ours.
What we collect, and getting it back
What this product collects and why is on the privacy page. To ask what we hold about you, or to have it deleted, write to us and we will treat it as a request under the law rather than as a comment.
Write to us about thisDraft. Not reviewed by counsel. The vendor rows are generated and current; the wording around them is not a reviewed disclosure yet, and saying so here is the same discipline as marking an assumed term in a buffer estimate.
In use (14)
Configured in this deployment and receiving what the purpose describes.
Application database, authentication and storage.
Application hosting and edge routing. All requests to the product pass through it.
Transactional email: sign-in codes, nomination and guardian invitations.
Flight search and, when booking is live, order creation.
Flight search, including self-transfer itineraries.
Live flight status and delay observations, by flight number.
Transit schedules and routing between airport and city.
Award availability lookups.
Bookable experience inventory and affiliate handoff.
Rate limiting and short-lived caches. Keys are hashed identifiers, not names.
Bot protection on public forms.
Wallet pass signing. Passes are signed by us; Apple receives nothing at issue.
Wallet pass issuance. The pass object carries a pass id, never a name.
Affiliate handoff for experiences. The traveller leaves for their site.
Integrated, not in use (2)
Supported by the codebase and not configured here, so nothing is being sent to them. Listed because that can change with a credential.
Place details and ratings. Search terms only; no traveller identity is sent.
Developer tooling only: an MCP server that lets a developer's Claude session ask ChatGPT. Outside the request path; no traveller, partner or operator data is sent.