Privacy policyLast updated

Your data, your customers' data, and how we treat both

Flyby runs the AI agent and dashboard your travel agency uses to talk to its customers. This policy explains what we collect, why, who helps us process it, and the choices you have.

Who is responsible for what
  1. 1

    Your agency

    Controller

    Decides why and how its customers' data is used.

  2. 2

    Flyby

    Processor

    Stores and processes it on the agency's instructions.

  3. 3

    Sub-processors

    Under contract

    Hosting and AI providers that help us run the service.

The short version

  • We never sell data

    Not yours, not your customers'. No data brokers, no ad networks.

  • No training on your data

    Flyby does not train AI models on your conversations or catalog.

  • Your customers, your data

    Your agency controls its customers' data. We process it only to run the service for you.

  • Credentials stay encrypted

    Meta tokens and app secrets are encrypted at rest with AES-256-GCM.

  • Deleted when you leave

    Close your account and your data is deleted within 30 days, and from backups within 90.

  • No ad trackers

    Only the cookies needed to sign you in and remember your language.

01

Who we are and what this policy covers#

Flyby ("Flyby", "we", "us") is a software service for travel agencies, available at flyby.world. It includes the agency dashboard, the AI agent, the website chat widget, each agency's public page, and the integrations agencies connect for WhatsApp, Messenger and Instagram (together, the "Service").

This policy applies to the people who use the Service on behalf of an agency (owners, managers and moderators), to visitors of our website, and, in the limited way described in section 2, to the customers who message an agency through the Service.

02

Our role: controller or processor#

Data protection law separates the party that decides how personal data is used (the controller) from the party that processes it on someone else's behalf (the processor). Which one we are depends on the data:

Agency account data
Names, emails and roles of the people who sign up and work in the dashboard, plus billing details. Flyby is the controller and this policy applies directly.
Agency customer data
Messages, contact details, trip requirements, leads, bookings and payment records of the customers who contact an agency. The agency is the controller and Flyby is the processor. We use this data only to provide the Service to that agency, following its configuration and instructions.
Aggregated data
Statistics that don't identify any person or agency, such as total message volume across the platform. We use it to run and improve the Service.

If you are a customer of an agency and want to know how your data is used, the agency's own privacy notice applies first. See section 12.

03

Information we collect#

Information you give us

  • Account details: name, email address, password (stored only as a secure hash), language preference and phone number if you add one.
  • Agency profile: agency name, logo, contact details, working hours, currency, public page content and team invitations.
  • Catalog and knowledge: packages, prices, departures, services, FAQs and the instructions you give the AI agent.
  • Billing details: plan, invoices and the billing contact. Card details are handled by our payment provider and are not stored by Flyby.
  • Support messages and feedback you send us.

Information processed for your agency's customers

  • Conversation content from the chat widget, your public page, WhatsApp, Messenger and Instagram, including any files or images customers send.
  • Contact details the customer shares or the channel provides, such as name, phone number, profile name or channel ID.
  • Trip details captured by the AI or your team: destination, dates, number of travellers, budget and interests.
  • Records your team creates: leads, notes, tasks, bookings, payments and invoices.

Channel credentials

When you connect your own Meta app, we store the access token, app secret, and the IDs of your WhatsApp number, Facebook Page or Instagram account. These credentials are encrypted at rest (AES-256-GCM) and are used only to send and receive your agency's messages.

Information collected automatically

  • Technical logs: IP address, browser, device type, and timestamps, kept for security, debugging and abuse prevention.
  • Usage data: which features are used and AI usage counts, so we can apply plan quotas and improve the product.
  • Public page analytics: to show agencies how many people visit their public page, we store a daily visitor hash made from a rotating salt. We don't store the visitor's IP address, and the hash can't be used to recognise the same visitor on another day.
04

How we use information#

  • To provide the Service: route messages, generate AI replies, qualify leads, notify your team and show everything in your dashboard.
  • To manage accounts, roles, billing, AI quotas and plan limits.
  • To keep the Service secure: detect abuse, prevent fraud, verify webhooks and investigate incidents.
  • To support you when you contact us, and to send service emails such as invitations, usage warnings and billing notices.
  • To understand how the product is used, in aggregate, so we can fix problems and improve it.
  • To comply with legal obligations and enforce our Terms of service.
05

How the AI agent processes conversations#

To write a reply, the AI agent needs context. When a customer messages your agency, we send the relevant part of the conversation, your catalog and your agent instructions to a large language model through OpenRouter, which routes the request to model providers such as Anthropic (Claude) and Google (Gemini).

  • We send only what's needed to produce the reply and qualify the lead.
  • Flyby does not train or fine-tune AI models on your conversations, catalog or customer data.
  • AI replies can be wrong. Your team can see every conversation, take over at any time, and should review important information before confirming a booking.
06

Legal bases for processing#

Where the law requires a legal basis, we rely on:

  • Contract: to provide the Service you signed up for.
  • Legitimate interests: to secure, maintain and improve the Service, as long as those interests aren't overridden by your rights.
  • Legal obligation: to keep financial records and respond to lawful requests.
  • Consent: where we ask for it, for example browser notifications. You can withdraw consent at any time.

For agency customer data, the agency is responsible for having its own legal basis for collecting it and for informing its customers.

07

Sharing and sub-processors#

We share data only with the providers that help us run the Service, under contracts that require them to protect it and use it only for that purpose. We host the Service with reputable cloud providers:

  • Supabase

    Purpose
    Database, authentication and file storage
    Data involved
    All Service data
  • Vercel

    Purpose
    Web hosting and delivery
    Data involved
    Requests and technical logs
  • OpenRouter

    Purpose
    Routing requests to AI models
    Data involved
    Conversation context sent for replies
  • Anthropic, Google

    Purpose
    AI models that generate replies
    Data involved
    Conversation context sent for replies
  • Meta (at your direction)

    Purpose
    WhatsApp, Messenger and Instagram delivery
    Data involved
    Messages on the channels you connect
  • Payment and email providers

    Purpose
    Subscription payments and service emails
    Data involved
    Billing contact and account emails

Other disclosures

  • Within your agency: people in your team see data according to their role. Moderators, for example, only see qualified leads.
  • Legal requests: if required by law or a valid order from a competent authority. Where allowed, we'll tell the affected agency first.
  • Business transfer: if Flyby is merged or acquired, data may transfer to the new owner under the same protections. We'll notify you before that happens.
08

International transfers#

Our providers may store or process data outside your country, including in the European Union and the United States. When data leaves Egypt, the Gulf or the EU, we rely on providers with strong security commitments and on the safeguards the applicable law requires, such as contractual protections.

09

How long we keep data#

  • While your account is active: we keep your data for as long as you use the Service. Your team can delete conversations, contacts and other records from the dashboard at any time.
  • After you close your account: we delete your agency's data within 30 days. Copies in backups are removed within 90 days as the backups rotate.
  • Billing records: invoices and payment records are kept as long as tax and accounting law requires.
  • Security logs: kept for a limited period, then deleted or anonymised.
10

How we protect data#

  • Encryption in transit (HTTPS/TLS) everywhere, and encryption at rest by our hosting providers.
  • Meta access tokens and app secrets encrypted with AES-256-GCM before they are stored.
  • Every incoming Meta webhook is checked against your app secret's signature before we process it.
  • Each agency's data is isolated at the database level with row-level security, and team roles limit who sees what.
  • Least-privilege access for our own team, and regular backups.

No system is perfectly secure. If a breach affects your data, we will notify you without undue delay and tell you what we're doing about it, as the law requires.

11

Your rights#

Depending on where you live, laws such as Egypt's Personal Data Protection Law No. 151 of 2020, the EU GDPR, Saudi Arabia's PDPL and the UAE's PDPL give you rights over your personal data. These may include the right to:

  • Know what data we hold about you and get a copy.
  • Correct inaccurate data.
  • Ask us to delete your data.
  • Object to or restrict certain processing.
  • Receive your data in a portable format.
  • Withdraw consent you gave earlier.
  • Complain to your data protection authority, such as Egypt's Personal Data Protection Centre.

To use any of these rights, email privacy@flyby.world. We may need to confirm your identity first, and we'll respond within 30 days.

12

If you are a customer of an agency#

If you messaged a travel agency that uses Flyby, that agency decides how your data is used. Please contact the agency first with any request about your data.

If you can't reach the agency, write to privacy@flyby.world and tell us which agency you contacted. We'll pass your request to them and help them respond.

13

Cookies and local storage#

  • Essential cookies keep you signed in and secure your session.
  • Preference cookies remember your language.
  • Local storage in the chat widget remembers the customer's open conversation on that device, so it continues after a page refresh.
  • Service worker: the installable app (PWA) caches app files on your device so it loads faster. If you allow it, it also shows browser notifications.
  • No advertising cookies
  • No cross-site tracking pixels
  • No selling of browsing data
14

Children#

The Service is for businesses and is not meant for anyone under 18. We don't knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

15

Third-party services#

When you connect WhatsApp, Messenger or Instagram, Meta also processes those messages under its own terms and privacy policy. Links to other websites are governed by their own policies. Read our Messaging policy for how the Meta channels work with Flyby.

16

Changes to this policy#

We may update this policy as the Service or the law changes. We'll change the "last updated" date above, and for important changes we'll notify account owners by email or in the dashboard before they take effect.

17

Contact us#

For privacy questions and requests: privacy@flyby.world. For anything else: support@flyby.world.

Write to us and a real person will reply. Privacy requests are answered within 30 days.

Flyby is software for travel agencies. We don't sell trips or hold trip payments.