← Back to paxID

Privacy Policy

Last updated: 28 September 2026

In short. paxID saves the travel details you give us so you do not have to type them again for every trip, form and booking. We protect them with encryption and strict access controls, and we use them only for the travel tasks you ask for. We do not sell your data and we do not use it for advertising. You enter card details in our payment provider's secure fields.

1. Who we are

paxID is operated by paxID OÜ, a private limited company registered in Estonia (registry code 17608154), Juhkentali 8, Tallinn, 10132, Estonia. For privacy questions or rights requests, contact [email protected]. For bookings, refunds and other help, use support in the app or email [email protected]. For users in the EU, EEA and UK, read this policy with our GDPR & Data Protection notice.

2. Your traveller profile

Your traveller profile holds the details you may need for travel, bookings, forms and checkout. This can include passport names and surnames, document numbers, issue and expiry dates, fields taken from a document you scan, nationalities, country of birth, date of birth, addresses, phone numbers, additional email addresses and emergency-contact details. You can add profiles for other travellers you are authorised to manage.

These details are stored on paxID's systems. They are encrypted in transit and at rest, and access is limited to the parts of the service that need them. Because paxID checks requirements, completes bookings and helps fill official forms for you, our systems use these details on your behalf when you ask for one of those tasks. We restrict, log and review that access, and we keep sensitive fields out of ordinary application logs, error reports and analytics.

You do not need a second password to unlock your saved details. Your account sign-in protects your profile, and recovering your account does not wipe the travel details you have saved. On supported devices you can also require a fingerprint or face check before sensitive actions.

3. Other data we hold

We also store data needed for account access, trip planning, requirement checks, reminders, fraud prevention and support:

4. Optional document scanning

You may choose to scan a passport, driving licence or ID card instead of typing the details. Scanning is optional and you can always enter details by hand or add them later. When you scan, the image is sent to a document-parsing provider to extract the fields, and you review and confirm them before they are saved.

We keep the details you confirm. We delete the source image after extraction unless you separately choose to save a copy of the document. We configure parsing providers, such as Azure document intelligence services, so that images and intermediate processing data are not used for training and are not retained beyond processing where the provider supports that mode.

5. Payments

You enter card details in our payment provider's secure fields, not in paxID's own forms. Where your device supports it, you can pay with Apple Pay or Google Pay. If you save a card for reuse, the payment provider keeps it and gives paxID a token for it. paxID keeps that token with the card brand, last four digits and expiry date so you can recognise the card. Payment providers may process, tokenise, authorise, settle, refund and retain payment data under their own security and legal obligations.

6. How we use data

7. When we share data

We share data only where needed for the service, where you direct us, or where the law requires it:

We do not sell your personal data. We do not use your travel or document details for advertising.

8. Cookies, analytics and marketing

We may use essential cookies, local storage or similar technologies to operate the website and apps. If we use optional analytics, advertising or marketing technologies that require consent in your region, we will ask for that consent before using them. You can unsubscribe from marketing emails at any time; service, security, booking, refund and account messages may still be sent where needed.

9. International transfers

paxID OÜ is registered in Estonia and may use providers in the United States, United Kingdom, European Economic Area and other countries. Where personal data is transferred internationally, we use appropriate safeguards such as adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, data-processing agreements, transfer risk assessments, and technical safeguards such as encryption in transit and at rest.

10. Retention

We keep personal data only as long as needed for the purposes described above. Account records are kept while your account is active and for any legally required period after closure. Traveller profiles, trip records, searches, uploads and forwarded confirmations are kept until you delete them, delete your account, or they are no longer needed for the service, support, legal, tax, dispute or security purposes. Payment, refund, tax and fraud records may be kept longer where required by law or payment-network rules. We may keep de-identified or aggregated data that no longer identifies you.

11. Your choices and rights

You can view, correct and delete your traveller profiles, documents, trips and account directly in paxID, on the website or in the apps. Depending on where you live, you may also have rights to access, correct, delete, port, restrict or object to processing of your personal data, and to withdraw consent where processing is based on consent. To make a request, email [email protected].

12. Security

We protect personal data with encryption in transit and at rest, access controls that limit each part of the service to the data it needs, restricted and logged access to sensitive fields, redaction of sensitive values from application logs and error reports, retention limits, and contractual security obligations on our providers. On supported devices you can require a fingerprint or face check before sensitive actions. No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal data, we will assess it and notify you and the relevant authorities where the law requires.

13. Children and family travel

paxID is not directed to children under 16, and children may not create their own accounts unless local law allows it and a parent or guardian provides any required consent. Adults may store details for children or other travellers they are authorised to manage. If you add another person's data, you are responsible for having the right to do so.

14. Changes and contact

We may update this policy as the product, providers and law evolve. We will revise the date above and notify you of material changes where required. Questions: [email protected].