Privacy Policy
v2.6 · 6 Jul 2026
1. What We Collect
We collect: (a) Information you provide — name, email, phone, ID documents, selfie videos (for ID verification only), profile photo, bio. (b) Information you generate — trips, bookings, messages, ratings. (c) Device and usage data — IP address, browser type, pages visited. Airlo does not process payments, so we do not collect credit card or bank account details. CCPA categories collected: Identifiers (name, email, IP); Commercial Information (booking history); Internet Activity (page views, clicks); and Biometric Information (selfie videos used to confirm you match your ID, if you opt into verification). Sensitive Personal Information: When you opt into ID verification, we process government identification documents AND a selfie video of you holding that document. Both are treated as Sensitive Personal Information under GDPR Article 9 and California CPRA — see Sections 6 and 12 for your right to limit its use.
2. How We Use Your Data — and Our Legal Bases (GDPR Art. 6)
We process your data on the following bases: Contract — to provide and maintain the platform (account, bookings, messaging) and to send transactional and support emails. Explicit Consent (GDPR Art. 9) — to process biometric information (selfie video) and ID documents for identity verification; you choose whether to verify and consent specifically to biometric processing before recording. Legitimate Interest — to detect fraud, prevent abuse, and ban bad actors. Legal Obligation — to comply with legal or law-enforcement requests.
3. Data Sharing
We share data with: other users as needed to facilitate introductions (your name, rating, profile photo); and law enforcement when legally required. We do NOT sell your personal information for money. We do NOT share your personal information with advertisers or for cross-context behavioral advertising.
4. Cookies & Tracking
We use essential cookies for session management, authentication, and security — these are required for the platform to function. We do not use advertising or third-party tracking cookies. We also operate self-hosted analytics and diagnostics on our own servers in Canada: privacy-focused page analytics (cookieless), error monitoring, and session replay that records how the interface is used so we can find and fix bugs. Everything you type is masked before it leaves your browser, and sensitive areas such as ID verification and private messages are excluded from recording entirely. None of this data is sent to third-party analytics or advertising companies. You can manage cookie behavior via your browser settings, but disabling essential cookies will break sign-in and other core features.
5. Data Retention
We retain personal data only as long as needed for the purposes it was collected, your account remains active, and applicable legal/financial obligations require. Active accounts — retained while you use the platform. Account closure — when you close your account it is immediately deactivated: you can no longer sign in and your profile is no longer visible to other users. We then retain the underlying account data in deactivated form for up to 24 months so we can resolve outstanding disputes, prevent fraud and ban evasion, and meet legal obligations, after which it is deleted or irreversibly anonymized. You can request earlier deletion at any time by emailing [email protected] (see Section 6). ID verification documents and selfie videos — deleted from our servers when a submission is rejected; approved submissions are retained while your account is active so a reviewer can re-verify if needed, and are permanently deleted the moment you close your account. Legal-hold exception — if an active dispute or law-enforcement request exists, retention extends until resolution.
6. Your Rights
Depending on your jurisdiction you may have rights to: access a copy of your personal data; correct inaccurate data; delete your data ("right to be forgotten"); object to or restrict processing; request a copy of your personal data (we will compile and send it manually by email); withdraw consent at any time; limit use of Sensitive Personal Information (California CPRA — applies to ID documents and any data you've provided). To exercise any right, email [email protected] with your request. We will respond within 30 days, though this may be extended by an additional 60 days for complex requests, as permitted by law. EU/UK users also have the right to lodge a complaint with their national supervisory authority — find yours at edpb.europa.eu/about-edpb/about-edpb/members_en (EU) or ico.org.uk/global/contact-us (UK).
7. International Transfers & Data Location
Our database and authentication system are self-hosted in Canada and governed by PIPEDA, Canada's federal privacy law. The European Commission and the United Kingdom have both recognized Canadian commercial privacy law as providing adequate protection, so personal data may be transferred from the EU/UK to us on the basis of those adequacy decisions — no additional transfer mechanism is required. Some service providers (see Section 10) process limited data in the United States; for those transfers we rely on the safeguards in their data processing agreements, such as Standard Contractual Clauses. Our content delivery network may cache static assets in regions closer to you, but never personal account data.
8. Security
We use reasonable technical measures, including TLS encryption for data in transit, salted password hashing through our authentication provider, role-based access controls, and limited admin access to sensitive content. No system is impenetrable; we cannot guarantee absolute security but commit to industry-standard practices and prompt incident notification per Section 13.
9. Children
Airlo is not directed at children under 18. We do not knowingly collect data from minors. If you believe a child has provided us data, contact [email protected] immediately and we will delete it.
10. Sub-processors
We use a small number of service providers to operate the platform: Cloudflare, Inc. (USA) — content delivery, security, and bot protection; and Resend, Inc. (USA) — delivery of transactional emails such as sign-in codes and booking notifications. Our analytics, error monitoring, and session replay tools are self-hosted on our own infrastructure in Canada, so no usage data is shared with third-party analytics providers. This list may be updated from time to time; the latest version is always posted on this page. We do not sell your data to any of these providers.
11. Automated Decision-Making
Airlo does not use fully-automated decision-making that produces legal or similarly significant effects on you without human oversight. Account suspensions, ID verification rejections, and other consequential actions are reviewed by a human before being applied.
12. California Residents (CCPA / CPRA)
California residents have additional rights, including: Right to Know (categories and specific pieces of personal information collected); Right to Delete; Right to Correct; Right to Opt-Out of "Sale" or "Sharing" (we do not sell or share your personal information); Right to Limit Use of Sensitive Personal Information (covering ID documents); and Right to Non-Discrimination for exercising these rights. To exercise any of these, email [email protected] or contact us via the methods listed in Section 14. We will verify your identity before processing your request and respond within 45 days (extendable by an additional 45 days with notice).
13. Breach Notification
In the event of a data breach affecting your personal information, we will work to notify the relevant supervisory authority without undue delay, and within 72 hours where required by applicable law (e.g., GDPR Article 33). We will notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
14. Privacy Officer
As required by Canada's PIPEDA, we have designated a Privacy Officer who is accountable for our privacy practices. For privacy questions, complaints, or to exercise any rights described above, contact the Privacy Officer at [email protected]. We aim to respond within 30 days (45 days for CCPA requests).
Privacy questions? Email [email protected].