Privacy Policy

Last updated: 26 June 2026

Who we are

FlexTrip Alerts ("we", "us") operates this website, which helps travellers track flight prices for flexible dates and notifies them by email when fares meet their chosen price limit. For privacy requests contact us at privacy@flextripalerts.com.

What data we collect

  • Account data: email address and a securely hashed password (if you sign up with email), or your Google account id and email when you use Google sign-in. Optional profile fields you enter (display name, country and city of residence).
  • Tracker data: routes, date windows, stay lengths, price limits, and optional filters you choose.
  • Technical data: session cookie, IP address (for rate limiting and security), and timestamps of scans and emails sent.
  • Usage data: outbound deal clicks logged via our redirect page, in aggregate to understand which routes perform well.

Why we process your data (legal bases)

  • Contract: to create your account, run your trackers, and send price-alert emails you asked for.
  • Legitimate interests: to secure the service, prevent abuse, and improve route coverage (balanced against your rights).
  • Consent:for non-essential cookies and advertising where required by law (see "Cookies and advertising" below).

Who we share data with

We do not sell personal data. We use processors where needed:

  • Hosting & database — to run the website and store your account.
  • Email provider (SMTP) — to deliver verification, reset, and alert messages.
  • Google— if you choose "Continue with Google", Google processes your sign-in under their privacy policy. We receive your email and a unique account id, not your Google password.
  • Flight price data providers — we look up fares by route to power alerts and deal pages; we do not send them your email.
  • Advertising partners — only if you consent to cookies; subject to their own policies.

International transfers

Processors may store or process data outside your country (including outside the EU). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses offered by our providers.

Cookies and advertising

We use essential cookies to keep you signed in and short-lived cookies during Google sign-in. Optional advertising cookies are loaded only if you consent through Google's Privacy & messaging dialog (EEA, UK, and Switzerland). We do not run a separate cookie banner on this site.

See our Cookie Policy for the full cookie list, Google AdSense details, and how to change your advertising choices.

Affiliate links

Booking links may earn us a commission. See our Affiliate Disclosure and the site footer for a short summary.

How long we keep data

We keep personal data only as long as needed for the purposes below. When you delete your account, we remove your user record, trackers, alert history, and sessions from the live database promptly (usually within seconds). Some copies may remain in encrypted database backups for a limited time — see "Backups" below.

  • Account and tracker data — while your account is active. Deleting a tracker removes that tracker and its alert history.
  • Alert history — while the related tracker exists, to prevent duplicate emails and support future in-app history features.
  • Sessions — up to 30 days, or until you log out; expired sessions are deleted when encountered.
  • Email verification and password-reset tokens — until used or until they expire (24 hours for email verification, one hour for password reset).
  • Rate-limit counters — only for the duration of each security window (for example 15 minutes for login attempts); expired rows are purged automatically.
  • Outbound deal clicksOutbound deal clicks are logged without your email or account identifier (route and price only). We keep these records for aggregate analytics until they are no longer needed for that purpose.
  • Shared fare cache — route/month price snapshots with no personal identifiers; refreshed each time we scan and not tied to your account.

Backups

We take encrypted database backups for disaster recovery. Deleted account data may remain in backups until those files rotate out — typically for up to approximately 365 days, and in rare cases longer if a copy is kept for recovery purposes.

Our email provider may retain delivery logs under its own retention policy for anti-abuse and deliverability purposes.

You may delete individual trackers from Trackers, or delete your whole account under Account → Security. To ask us to remove data from active systems or discuss backup erasure, email privacy@flextripalerts.com.

Your rights (GDPR / similar laws)

If you are in the EU/EEA, UK, or similar jurisdictions, you may:

  • Access the personal data we hold about you.
  • Receive a copy of your data in a portable format (on request).
  • Correct inaccurate data (e.g. update trackers in your account).
  • Delete your data ("right to erasure").
  • Object to or restrict certain processing.
  • Withdraw consent for optional cookies at any time (via Google's consent preferences or your browser settings).
  • Lodge a complaint with your local data-protection authority if you believe we handled your data unlawfully.

To exercise these rights, email privacy@flextripalerts.com. Unsubscribe from alert emails anytime via the signed link in each email, or turn alerts back on from Account → Profile.

Security

Passwords are securely hashed. Traffic is encrypted using industry-standard protocols (HTTPS). Alert unsubscribe links are cryptographically signed so they cannot be guessed. Links in alert emails pause that specific route only; older links may turn off all alert emails for your account.

Children

The service is not directed at children under 16. We do not knowingly collect data from children.

Changes

We may update this policy. Material changes will be reflected by the "Last updated" date above.