Privacy Policy
Last updated: 28 September 2026
In short. paxID saves the travel details you give us so you do not have to type them again for every trip, form and booking. We protect them with encryption and strict access controls, and we use them only for the travel tasks you ask for. We do not sell your data and we do not use it for advertising. You enter card details in our payment provider's secure fields.
1. Who we are
paxID is operated by paxID OÜ, a private limited company registered in Estonia (registry code 17608154), Juhkentali 8, Tallinn, 10132, Estonia. For privacy questions or rights requests, contact [email protected]. For bookings, refunds and other help, use support in the app or email [email protected]. For users in the EU, EEA and UK, read this policy with our GDPR & Data Protection notice.
2. Your traveller profile
Your traveller profile holds the details you may need for travel, bookings, forms and checkout. This can include passport names and surnames, document numbers, issue and expiry dates, fields taken from a document you scan, nationalities, country of birth, date of birth, addresses, phone numbers, additional email addresses and emergency-contact details. You can add profiles for other travellers you are authorised to manage.
These details are stored on paxID's systems. They are encrypted in transit and at rest, and access is limited to the parts of the service that need them. Because paxID checks requirements, completes bookings and helps fill official forms for you, our systems use these details on your behalf when you ask for one of those tasks. We restrict, log and review that access, and we keep sensitive fields out of ordinary application logs, error reports and analytics.
You do not need a second password to unlock your saved details. Your account sign-in protects your profile, and recovering your account does not wipe the travel details you have saved. On supported devices you can also require a fingerprint or face check before sensitive actions.
3. Other data we hold
We also store data needed for account access, trip planning, requirement checks, reminders, fraud prevention and support:
- Account data: your registered email address, account identifiers, authentication records, session and device records, and the name of the main account holder.
- Trip data: origins, destinations, transit points, travel dates and time windows, airports, flight numbers, hotels, booking references, and other details you add, upload, forward or confirm.
- Search data: the searches you run, including the travel windows and travellers you selected, so we can show recent searches and compare results.
- Uploaded or forwarded travel documents: screenshots, PDFs, emails, proof of accommodation, arrival-card confirmations and related parsed fields. These may include personal data and are used to prepare trip records and readiness checks.
- Mobile data (eSIM) records: not collected yet, because paxID does not offer mobile data yet. When it launches: your mobile-data balance, top-ups, eSIM installation and usage records, the destinations where you use data, support events and mobile-network partner records.
- Payments: purchase records, receipts, refund records, charge status, fraud-prevention signals, and payment-provider references such as saved-card tokens, card brand, last four digits and expiry date.
- Support, logs and device data: messages you send us, diagnostic logs, IP address, approximate location from network data, device and app version, crash or error information, and security logs.
- Waitlist and communications: email addresses and communication preferences you submit before or after launch.
4. Optional document scanning
You may choose to scan a passport, driving licence or ID card instead of typing the details. Scanning is optional and you can always enter details by hand or add them later. When you scan, the image is sent to a document-parsing provider to extract the fields, and you review and confirm them before they are saved.
We keep the details you confirm. We delete the source image after extraction unless you separately choose to save a copy of the document. We configure parsing providers, such as Azure document intelligence services, so that images and intermediate processing data are not used for training and are not retained beyond processing where the provider supports that mode.
5. Payments
You enter card details in our payment provider's secure fields, not in paxID's own forms. Where your device supports it, you can pay with Apple Pay or Google Pay. If you save a card for reuse, the payment provider keeps it and gives paxID a token for it. paxID keeps that token with the card brand, last four digits and expiry date so you can recognise the card. Payment providers may process, tokenise, authorise, settle, refund and retain payment data under their own security and legal obligations.
6. How we use data
- To create and secure your account, authenticate you, and keep your details available across your devices and the website.
- To search for flights that fit the travellers, documents and travel windows you choose.
- To check entry requirements, travel documents, forms, health or transit rules, and trip readiness for journeys you create or explore.
- To parse uploaded or forwarded confirmations and let you review details before saving them to a trip.
- To complete bookings, refunds, support requests and payment operations you request, and mobile data when that service launches.
- To send account, booking, security, refund, trip and service messages.
- To prevent fraud, abuse, account takeover, payment misuse and service attacks.
- To debug, maintain, improve and measure the service, using the least sensitive data practical.
- To comply with tax, accounting, sanctions, travel, payment, consumer-protection and other legal obligations.
7. When we share data
We share data only where needed for the service, where you direct us, or where the law requires it:
- Airlines, airline ticketing partners, airline booking systems and travel suppliers - to search, book, issue, change, cancel, support or refund travel you choose.
- Travel-requirement data providers - to check entry, transit and document rules. We send only the details needed to answer the question, such as nationality, document type, issuing country, expiry and your route. We do not send your name, passport number or document images for these checks.
- Payment processors and fraud-prevention providers - to process payments, refunds, chargebacks and payment security checks.
- Document-reading and parsing providers - to read documents, screenshots, PDFs or emails you choose to scan, upload or forward.
- Insurance partner - when paxID offers travel insurance and you choose it, to quote, sell and support your policy. The insurance partner handles claims, refunds and payments under its own privacy notice.
- Mobile-network partners - when mobile data launches, to provide, operate, troubleshoot and support your eSIM and your mobile-data balance.
- Cloud, database, storage, email, push notification, analytics, monitoring and support providers - to host, secure, observe and support paxID.
- Authorities, regulators, courts, banks or dispute bodies - where legally required or necessary to protect paxID, users or others.
- Business transfer parties - if we are involved in a merger, financing, acquisition, reorganisation or sale, subject to confidentiality and applicable law.
We do not sell your personal data. We do not use your travel or document details for advertising.
8. Cookies, analytics and marketing
We may use essential cookies, local storage or similar technologies to operate the website and apps. If we use optional analytics, advertising or marketing technologies that require consent in your region, we will ask for that consent before using them. You can unsubscribe from marketing emails at any time; service, security, booking, refund and account messages may still be sent where needed.
9. International transfers
paxID OÜ is registered in Estonia and may use providers in the United States, United Kingdom, European Economic Area and other countries. Where personal data is transferred internationally, we use appropriate safeguards such as adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, data-processing agreements, transfer risk assessments, and technical safeguards such as encryption in transit and at rest.
10. Retention
We keep personal data only as long as needed for the purposes described above. Account records are kept while your account is active and for any legally required period after closure. Traveller profiles, trip records, searches, uploads and forwarded confirmations are kept until you delete them, delete your account, or they are no longer needed for the service, support, legal, tax, dispute or security purposes. Payment, refund, tax and fraud records may be kept longer where required by law or payment-network rules. We may keep de-identified or aggregated data that no longer identifies you.
11. Your choices and rights
You can view, correct and delete your traveller profiles, documents, trips and account directly in paxID, on the website or in the apps. Depending on where you live, you may also have rights to access, correct, delete, port, restrict or object to processing of your personal data, and to withdraw consent where processing is based on consent. To make a request, email [email protected].
12. Security
We protect personal data with encryption in transit and at rest, access controls that limit each part of the service to the data it needs, restricted and logged access to sensitive fields, redaction of sensitive values from application logs and error reports, retention limits, and contractual security obligations on our providers. On supported devices you can require a fingerprint or face check before sensitive actions. No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal data, we will assess it and notify you and the relevant authorities where the law requires.
13. Children and family travel
paxID is not directed to children under 16, and children may not create their own accounts unless local law allows it and a parent or guardian provides any required consent. Adults may store details for children or other travellers they are authorised to manage. If you add another person's data, you are responsible for having the right to do so.
14. Changes and contact
We may update this policy as the product, providers and law evolve. We will revise the date above and notify you of material changes where required. Questions: [email protected].