Privacy
Privacy, route by route.
TheWingScan compares flight offers and redirects you to an airline or travel partner to complete a booking. We do not sell tickets or collect payment-card details. Accounts, planning tools, messages, and the optional passenger-manifest flow do process the data described below.
Last updated
31 July 2026
1. Product boundary
Search and review happen on TheWingScan. Checkout, payment, ticketing, refunds, and booking management happen on the booking provider’s site under that provider’s terms and privacy policy. TheWingScan does not receive your card number, PNR, or booking confirmation from that handoff.
2. Information processed
- Account and session data. Better Auth stores your name, email, verification status, authentication accounts, and database-backed sessions. Session records can include expiry, IP address, user agent, and sign-in tokens.
- Profile data. You can add a username, display name, avatar, bio, date of birth, phone number, country, city, language, travel style, home airport, emergency contact, website, and social handles. Phone verification stores short-lived OTP records.
- Public profile data. Public profiles are off by default. If enabled, your username, display name, avatar, bio, country, city, language, travel style, home airport, website, social handles, earned badges, membership date, and a verified phone number can be visible at your public profile URL. Date of birth and emergency contact are not in the public-profile response.
- Search and fare data. A search contains route, dates, traveller counts, cabin, and filters. Responses can be cached by search criteria. Route-and-price observations are retained in the price index without a user ID, and booking redirects record provider, route, date, currency, and amount without a user ID.
- Saved searches and fare alerts. These retain the criteria you choose, labels, target price, status, check history, and delivery records until you delete them or delete your account.
- Messages and shared trips. Direct messages, conversation membership, shared-trip criteria, participants, votes, names used for voting/chat, and trip chat messages are stored so those features work.
- Optional co-passenger manifest. A passenger can submit a name, optional date of birth, optional contact fields, meal and seat preferences, and an optional Aadhaar, passport, or PAN value through a private bearer link. Government-ID values are encrypted with AES-256-GCM before database storage. The owner-authenticated status view returns masked IDs; the clipboard handoff contains names and dates of birth only.
- Nearest-airport location. The homepage requests browser geolocation only after you use its nearest-airport control. Explore currently requests it when that page mounts. If you grant permission, coordinates are sent to the same-origin airport endpoint to resolve an IATA code; no location-history row is written to the database.
3. How information is used
- Run search, revalidation, handoff, alerts, saved searches, and account recovery.
- Render profiles, badges, messages, shared trips, votes, and passenger progress.
- Build route-level price history and recent destination-interest signals.
- Protect mutation endpoints, enforce product limits, and diagnose failures.
- Send verification, password-reset, alert, or phone-verification messages you request.
We do not use account or passenger data to sell advertising profiles.
4. Cookies and local browser state
The current product uses two categories of strictly necessary cookies:
- Authentication cookies. Better Auth uses cookies for sign-in, session, OAuth, verification, and security state. Disabling them prevents authenticated features from working.
- Notice acknowledgement.
thewingscan_consentstores a version, acknowledgement flag, and timestamp for about one year so the cookie notice stays dismissed on that device.
There are no theme or intro-animation cookies. The homepage intentionally suppresses the cookie notice to preserve its three-element composition; other routes can show it. The product does not currently install advertising or third-party analytics cookies.
5. Service providers and external requests
- Ignav. Receives flight search criteria, not your TheWingScan account identity, to return and revalidate offers and booking links.
- Booking providers. Receive your browser request when you choose a booking link. TheWingScan does not append profile or passenger-manifest data to that redirect.
- Neon and Upstash. Host PostgreSQL data, Redis cache entries, and signed QStash jobs used by the service.
- ZeptoMail and Vonage. Process email addresses or phone numbers and the message required for email delivery or optional phone verification.
- Google. Processes OAuth data if you choose Google sign-in.
- Explore sources. Pexels, Wikipedia, Wikivoyage, WeatherAPI, and OpenTripMap receive destination names or coordinates from server-side enrichment requests; they do not receive your account identity. CartoDB map tiles are requested by the browser when you open the map and can receive ordinary network metadata such as your IP address and tile request.
- Telegram. Can receive route-and-fare deal posts when operator notifications are configured; those posts contain no account or passenger data.
6. Sharing and access
- Direct messages are available only to authenticated conversation participants.
- A shared-trip link is a bearer link: anyone who has it can view the trip and can vote or post trip chat. Signed-in visitors can join the trip in their inbox.
- A co-passenger link is also a bearer link and is intentionally available without sign-in. The public page receives route metadata and anonymous slot-completion state only. Full masked status and the handoff bundle require the invite owner’s authenticated session.
Share bearer links only with intended participants.
7. Retention and deletion
- Account-linked records. Remain while the account is active unless you delete an individual saved search or alert. Account deletion removes the user and records connected by database cascade, including sessions, profiles, saved searches, alerts, badges, direct-message participation, and owned passenger invites.
- Passenger invites. Access expires after 30 days and closed invites stop accepting submissions. Expiry blocks product access; it does not itself promise immediate physical deletion of the database row. Owner account deletion cascades to the invite and passenger rows.
- Shared trips. Product access expires after 30 days, after four hours without activity, or when the owner ends the trip. Access expiry does not itself delete the public trip rows.
- Route observations and redirects. Price-history and booking-redirect rows do not contain a user ID and can be retained for fare comparison, trending, and operations.
- Consent acknowledgement. Expires after about one year unless replaced or cleared in your browser.
8. Security boundaries
Production traffic uses HTTPS. Sensitive mutations use session checks and same-origin validation where applicable. Government-ID fields use authenticated AES-256-GCM encryption at rest, owner views mask the value, and owner passenger endpoints use no-store responses. No system can guarantee absolute security; private trip and passenger links should be treated like passwords while active.
9. Your controls
- Edit profile fields and disable public-profile visibility.
- Pause or delete fare alerts and delete saved searches.
- End a shared trip you created.
- Delete your account from Profile.
- Clear the consent cookie or authentication cookies in your browser.
For a privacy question, email privacy@thewingscan.com.
10. Children and passenger details
Accounts are intended for people aged 13 or older. A trip organiser may use the passenger manifest for a child travelling with them. The person sharing or submitting that data is responsible for having authority to provide it and for limiting the bearer link to the intended travel group.
11. Changes and contact
We will update the date above when this disclosure changes. Privacy questions can be sent to privacy@thewingscan.com; general support can be sent to support@thewingscan.com.