Legal · Data protection

Privacy policy

Booking a premium cabin means handing over a passport number and a card. This is exactly what we do with both — what we collect, who receives it, how long we keep it, and how to get it back or have it deleted.

Last updated
12 June 2026
Effective
1 July 2026
Applies to
All buybusinessclass bookings
01

Who we are

Buybusinessclass Travel, Inc. ("buybusinessclass", "we") is a travel agency incorporated in Delaware with its principal office at 180 North Stetson Avenue, Chicago, IL, 60601, United States. When you search, book or manage a trip with us, we decide why and how your personal data is processed — we are the data controller for that activity.

Our Data Protection Officer can be reached at info@buybusinessclass.com. For travellers in the European Union and the United Kingdom, our representative under Article 27 GDPR is named in the same mailbox's auto-reply.

02

What we collect

Air travel is unusually data-hungry: a carrier cannot issue a ticket without a full legal name, and a border agency will not accept a passenger without document details. We collect what is needed to book you and no more.

CategoryExamplesWhy we hold itKept for
Search dataOrigin, destination, dates, cabin, traveller countReturning fares and improving results13 months, then aggregated
Traveller identityLegal name, date of birth, gender marker, nationalityMandatory for ticket issuance7 years (tax and audit)
Travel documentsPassport number, issuing country, expiryAdvance passenger information required by border agenciesDuration of travel + 90 days
Contact detailsEmail, telephone, emergency contactConfirmations, disruption alerts, carrier contact7 years
Payment dataCard token, last four digits, billing addressTaking payment and preventing fraudToken only — see below
Special category dataMeal preference, wheelchair or medical assistanceFulfilling the service request you madeDuration of travel + 90 days
Technical dataIP address, device and browser, pages viewedSecurity, fraud prevention, service reliability12 months
We never see your full card number
Card details are captured by our PCI DSS Level 1 payment processor and returned to us as a token. Full card numbers and security codes never reach buybusinessclass systems and are not stored in our booking database.
03

Health and other special category data

Some service requests reveal information that data-protection law treats as sensitive. A wheelchair request implies a mobility condition; a kosher or halal meal may imply a religious belief. We only ask for these when you choose to request the service.

Where the request concerns health or accessibility we rely on your explicit consent, which you can withdraw at any time by contacting the concierge — though withdrawing it means the carrier can no longer guarantee the assistance. Meal preferences are passed to the airline as a service code only.

04

Why we use it, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Searching fares and holding an itinerary you selectedSteps prior to a contract, Art. 6(1)(b)
Issuing tickets and passing data to the operating carrierPerformance of a contract, Art. 6(1)(b)
Advance passenger information and border formalitiesLegal obligation, Art. 6(1)(c)
Fraud screening and payment securityLegitimate interests, Art. 6(1)(f)
Disruption alerts and schedule-change monitoringPerformance of a contract, Art. 6(1)(b)
Retaining booking records for tax and auditLegal obligation, Art. 6(1)(c)
Marketing emails about fares and destinationsConsent, Art. 6(1)(a) — withdrawable at any time
Analytics and product improvementLegitimate interests, Art. 6(1)(f)

We do not use automated decision-making that produces legal effects for you. Fraud screening may flag a transaction for manual review, but a person makes the final call on any booking we decline.

05

Who we share it with

Booking a flight necessarily means sending your details to other organisations. We share the minimum each one needs, and we do not sell personal data to anyone.

  • Operating and marketing carriers — the airlines flying you, who receive names, contact details and document data as required to issue and honour the ticket.
  • Global distribution systems — principally Sabre, which holds the passenger name record through which the booking is created and amended.
  • Payment processors and card schemes, for authorisation, settlement, refunds and chargebacks.
  • Border and security agencies, where advance passenger information or a passenger name record transfer is required by the law of the countries you fly between.
  • The insurer, if you buy trip protection at checkout, and only the data needed to issue the certificate.
  • Professional advisers, auditors and regulators, where we are legally required to disclose.
  • An acquirer of our business, if buybusinessclass is ever sold — under the same protections described here.
Carriers become controllers too
Once your details reach an airline, that airline processes them as its own controller under its own privacy policy. We cannot delete data from a carrier's reservation system on your behalf, though we will always pass a request on.
06

International transfers

International travel means international data flows. If you fly from London to Doha, your details will be processed in the United Kingdom, Qatar and the United States, and possibly in any country you transit.

Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on an adequacy decision where one exists, and otherwise on the European Commission's Standard Contractual Clauses together with a transfer risk assessment. Transfers required to perform your travel contract are additionally covered by Article 49(1)(b) GDPR. Copies of the safeguards we use are available on request.

07

Cookies and similar technologies

We use a deliberately small number of cookies. Strictly necessary cookies keep your session and your search state alive and cannot be switched off. Everything else is optional and off until you opt in.

TypeWhat it doesConsent needed
Strictly necessarySession, security, fraud prevention, search stateNo
PreferenceRemembers cabin, currency and recent searchesYes
AnalyticsAggregated page and funnel measurementYes
AdvertisingNot used — we run no third-party ad pixels—
08

How we protect it

  • Transport encryption (TLS 1.3) on every connection, and encryption at rest for the booking database.
  • Card data handled exclusively by a PCI DSS Level 1 processor; buybusinessclass systems hold tokens only.
  • Least-privilege access — concierge staff see the bookings they are working on, and access is logged.
  • Mandatory multi-factor authentication for all staff, with hardware keys for administrative roles.
  • Independent penetration testing at least annually, and continuous dependency monitoring.

No system is perfect. If a breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and tell you directly without undue delay.

09

Your rights

Depending on where you live, you can exercise some or all of the following. We do not charge for these requests and we do not treat you differently for making one.

  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of anything inaccurate. Note that a name on an issued ticket can only be corrected within carrier limits.
  • Erasure — deletion, except where we must retain records for tax, audit or legal-claim purposes.
  • Restriction and objection — including an absolute right to object to direct marketing.
  • Portability — your data in a structured, machine-readable format.
  • Withdrawal of consent — at any time, without affecting processing already carried out.
  • Complaint — to your supervisory authority, such as the Irish DPC, the UK ICO, or your state Attorney General.

California residents may additionally request disclosure of the categories of personal information collected and shared, and may opt out of "sharing" as that term is defined by the CCPA. We do not sell personal information and have not done so in the preceding twelve months.

How to make a request
Email info@buybusinessclass.com from the address on your booking. We respond within one month, extendable by two further months for complex requests — we will tell you if that happens and why.
10

Children

Our service is not directed at children, and we do not knowingly create accounts for anyone under 16. We do process the details of children travelling as passengers, supplied by the adult making the booking, who must be entitled to provide them. If you believe a child's data has reached us in any other way, contact us and we will delete it.

11

Changes to this policy

We will post any revision here and update the effective date. Where a change materially affects how we use data you have already given us, we will tell you by email before it takes effect and, where the law requires it, ask for your consent again.

Questions about this document

Write to info@buybusinessclass.com or Buybusinessclass Travel, Inc., 180 North Stetson Avenue, Chicago, IL, 60601, United States. We reply to written enquiries within five business days.