lettuce.flights Privacy Notice
1. Who is the controller of your data
Lettuce, Inc. (“Lettuce”) is the data controller for the personal information you submit to lettuce.flights. For UK and EEA residents you may contact us at privacy@lettuce.flights.
2. What we collect
| Category | Examples | Purpose |
|---|---|---|
| Account data | Email, display name, password hash, Firebase UID | Authentication, account access |
| Search data | Origin, destination, dates, cabin class | Fulfilling your search; recent-searches feature |
| Passenger data | Each traveler's first name, last name, date of birth, gender, title, email, phone number | Issuing the airline ticket; required by the operating airline and IATA |
| Payment data | Card brand, last four digits, billing ZIP (held by Stripe) | Payment processing; chargeback evidence |
| Booking data | PNR, order ID, total, refund status | Reservation management, refund issuance |
| Device & log data | IP, user agent, request IDs | Security, abuse prevention, audit |
3. Where your data goes
- Duffel Ltd. (UK) — receives passenger data and itinerary to issue tickets via the operating airline, and acts as merchant of record and card processor for your payment. Duffel's processors are PCI-DSS Level 1 certified.
- The operating airline shown on your itinerary — receives passenger and booking data and may be subject to its own privacy notice.
- Payment processors — card capture and refunds are handled by PCI-DSS Level 1 certified processors engaged by our travel supplier; we never receive or store your full card number.
- Google Firebase — stores account credentials, encrypted at rest, in US-region multi-region buckets.
- Vercel, Inc. — hosts the website and edge functions.
- Government agencies — passenger information may be shared with US APIS, EU PNR, and equivalent regimes as required by law.
4. Legal basis (GDPR/UK GDPR)
- Contract — to provide the booking you requested (Art. 6(1)(b)).
- Legal obligation — for sanctions screening and required passenger data transmission (Art. 6(1)(c)).
- Legitimate interests — for fraud prevention, security, and analytics (Art. 6(1)(f)).
- Consent — for any marketing emails you opt into (Art. 6(1)(a)). You may withdraw consent at any time.
5. Retention
Booking records (including PNR, passenger data, and payment ledger) are retained for 7 years after the trip date to meet tax and consumer-protection record-keeping rules. Account data is retained until you delete your account. You can request deletion at any time; certain records must be retained for legal compliance.
6. International transfers
Personal data may be transferred outside your country. For UK/EEA transfers we rely on Standard Contractual Clauses and, where relevant, the UK International Data Transfer Addendum. A copy of our SCCs is available on request.
7. Your rights
- Access, correction, deletion — request via privacy@lettuce.flights.
- CCPA / CPRA (California) — right to know, delete, correct, and to limit use of sensitive personal information. We do not sell personal information.
- Portability — we can export your booking history as JSON.
- Complaint — to your supervisory authority (ICO in the UK, your DPA in the EEA).
8. Security
We enforce HTTPS via HSTS, a strict Content Security Policy on every lettuce.flights page, role-segregated Firebase Admin credentials on the server, and read-only Firestore rules on confirmed bookings so the browser cannot mint or modify them. Card data is handled entirely within PCI-DSS certified processor-controlled iframes; lettuce.flights is therefore PCI-DSS SAQ-A scope.
9. Cookies
We use a small number of strictly-necessary cookies for Firebase authentication and session management. We do not set advertising or cross-site tracking cookies on lettuce.flights.
10. Children
Bookings for travelers under 18 must be made by an adult. The lettuce.flights account itself is restricted to users 18+.
11. Contact
Privacy questions: privacy@lettuce.flights. Support: support@lettuce.flights.