Privacy Policy
Fly Explore Traveltech Private Limited · Flyett platform
1. Introduction
Fly Explore Traveltech Private Limited (“we”, “us”, “our”) operates the Flyett platform (“Platform”, “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Platform, including our website, applications, and APIs. By using Flyett, you consent to the practices described here. If you do not agree, please do not use the Service.
2. Data Controller
The data controller is Fly Explore Traveltech Private Limited (legal name as registered with the Ministry of Corporate Affairs: FLY EXPLORE TRAVELTECH PRIVATE LIMITED; CIN: U79110TS2025PTC207091). For questions about this policy or your personal data, write to our Grievance Officer, Nagaraju Kandukuri, at grievance@flyett.com, or by post to our registered office shown in the Terms of Service. See our Grievance Redressal page for response times.
3. Data We Collect
We collect information necessary to provide and improve the Service, enforce our terms, and comply with law.
3.1 Account and identity
When you register or are invited: name, email address, role (e.g. user, tenant admin, system admin), and tenant/organisation association. We may store profile data such as display name.
3.2 Usage and product data
How you use the Platform: workflows you create and run, API configurations, provider settings, API key metadata (not the secret itself), environment choices (e.g. sandbox/production), and logs related to authentication and API usage. We use this to operate the Service, troubleshoot, and improve features.
3.3 Billing and plans
Subscription and plan assignment, billing cycle, currency and region preferences, invoice and payment status, and display preferences (e.g. timezone, display currency). We do not store full payment card numbers on our servers; payment processing may be handled by third-party payment providers.
3.4 Technical and device data
IP address, browser type and version, device information, and general usage metrics. We may use cookies and similar technologies as described in the Cookies section below.
4. How Features Use Your Data
The Platform includes the following areas; here is how they use data:
4.1 Authentication and accounts
We use Firebase Authentication (or equivalent). Your email and account data are used to sign you in, enforce roles (user, tenant admin, system admin), and associate you with a tenant. Account creation may be triggered by invite or registration.
4.2 Tenants and organisations
Tenant name, ID, status, and aggregate stats (e.g. user count, workflow count) are stored. Tenant admins and system admins can manage tenant settings. Data is isolated per tenant where applicable.
4.3 Workflows and workflow studio
Workflow definitions (nodes, edges, configuration), versions, and execution metadata are stored so you can design, run, and expose workflows. Workflow execution may involve calling third-party travel APIs using credentials you or your tenant configure.
4.4 APIs and integrations
API catalog, provider configurations, master provider and URL configs, and service catalog data are used to power integrations. API keys (hashed or masked where appropriate) and OAuth-related data are stored to authenticate API requests.
4.5 Billing and plans
Plan constraints, currency rates, region pricing, and discount codes are used to determine what features and limits apply to your tenant. Invoices, due dates, and payment status are used for billing and to enforce access (e.g. restricting API access when a subscription is overdue).
4.6 User and provider management
User lists, roles, and provider request/approval data are stored and used to manage access and provider onboarding within the Platform.
5. Legal Basis for Processing
We process personal data where necessary for performance of our contract with you (or your organisation), for our legitimate interests (e.g. security, product improvement, fraud prevention), to comply with legal obligations, or with your consent where we have asked for it explicitly.
6. Cookies and Similar Technologies
We use cookies and similar technologies to provide the Service, maintain sessions, and improve experience.
6.1 Strictly necessary
Required for the Platform to function: e.g. authentication session, security tokens, load-balancing or routing. These cannot be disabled if you use the Service.
6.2 Functional
Preferences such as language, timezone (for display), or UI state (e.g. sidebar collapsed) so the Service behaves as you expect across visits.
6.3 Analytics and marketing
On flyett.com we use Google Analytics to count visits and page views, and HubSpot for marketing. Neither runs until you allow it in the cookie banner. Your choice is stored in your browser and recorded against an anonymous visitor id.
6.4 Third-party cookies
Third-party services (e.g. authentication provider, hosting, analytics) may set their own cookies. Their use is governed by their respective privacy policies.
6.5 Your choices
You can accept or reject analytics and marketing cookies in the cookie banner, and change your choice at any time from "Cookie settings" in the footer; withdrawing removes their cookies. You can also block cookies in your browser settings. Blocking strictly necessary cookies may prevent you from using the Platform.
7. Sharing and Disclosure
We may share data with: (a) service providers who assist in hosting, analytics, authentication, or payment processing, under strict confidentiality and data-processing terms; (b) authorities when required by law or to protect rights and safety; (c) affiliates or in connection with a merger or sale, subject to notice and this policy where required by law.
8. Retention
We retain data for as long as needed to provide the Service, enforce our terms, and comply with legal obligations. Account and usage data are typically retained while your account (or your tenant’s) is active and for a reasonable period thereafter. Logs and backup data may be retained according to our internal retention schedule.
9. Security
We implement technical and organisational measures to protect your data, including encryption in transit, access controls, and secure development practices. You are responsible for keeping your credentials and API keys secure.
10. Your Rights
Depending on your location, you may have rights to access, correct, delete, or port your personal data, or to object to or restrict certain processing. You may also have the right to lodge a complaint with a supervisory authority. To exercise these rights, write to grievance@flyett.com. Travellers can also ask for their data to be deleted at booking.flyett.com/privacy/delete-my-data, which confirms identity with a one-time code; invoices and the name on them are kept for 8 years as tax law requires. In India you may complain to the Data Protection Board of India. We will respond within the timeframes required by applicable law.
11. International Transfers
Data may be processed in India and in other countries where our service providers operate. We ensure appropriate safeguards (e.g. standard contractual clauses or equivalent) where required by applicable law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on the Platform and, where required, notify you (e.g. by email or in-app notice). The “Last updated” date at the bottom indicates when the policy was last revised. Continued use of the Service after changes constitutes acceptance of the updated policy.
Last updated: 4 October 2026