Privacy

Last updated 23 September 2026

What we collect, why we collect it, who else sees it, and how long we keep it. Nothing is sold to advertisers or data brokers, ever.

Searching

A search is a destination, dates and party size. They live in the URL rather than in an account, which is why a search is shareable and why we do not need to know who you are to run one. Results are cached for a short time — minutes for prices, a day for place names — so that two people asking the same question do not cost the supplier two calls. The cache holds no personal data.

Booking

Hotels. Your name, email, phone number, the ages of any children, any special requests you choose from our list, and the state on your billing address. Name, email, phone and party go to the hotel through its distributor (LiteAPI), because a reservation cannot exist without them.

Flights. We do not currently sell flights. What follows governs flight bookings made while we did. For every passenger: title, name as on their travel document, date of birth and the gender marker on that document; plus one email and phone number for the booking and the state on your billing address. The passenger details and contact go to the airline through its distributor (Duffel), because airlines refuse to ticket without them and match them at the gate.

Payment. Card details are entered into a form served by Stripe and go to Stripe directly; they never reach our servers. We keep the card brand, its last four digits and the statement descriptor, for your receipt. The billing state is kept as the basis on which we agreed to sell.

We keep booking records for seven years after the trip: tax and accounting law requires it, and a refund or a dispute can arrive long after travel.

Signing in and saved travellers

Signing in uses a link sent to your email; there is no password. We store your email and a hashed session identifier. Your browser holds the session in a cookie that lasts thirty days, and our Android app holds it on your phone for the same thirty days. Travellers you choose to save — each one's title, name, date of birth and gender marker as a travel document shows them, with an email address and phone number — are stored against your account until you remove them or delete your account. Checkout does not fill them in for you.

Price alerts

A price watch stores the route, dates and party size you asked us to watch, the price you saw, and your email so we can tell you when it falls. The email we send about it is a commercial message and every one carries a one-click way to stop them. Deleting the watch deletes all of this.

Email

Confirmations, cancellation notices, sign-in links and price alerts are sent through our mail provider, who sees the message and the address it goes to in order to deliver it. Replies to them, and anything you write to [email protected], go to that address, which our mail provider holds for us.

Support and our staff

When you email [email protected], our system reads your message and its attachments from that one folder of our mailbox and files it as a support case. It cannot send, change or delete mail. Our staff can also open a case when you call us, and note what was said.

We keep a support conversation, including its emails, our staff's notes on it and any files you send, for two years after it is closed, then delete it. A conversation waiting on your reply closes after 30 days without one. For mail our system does not file (automatic replies, mailing lists), we keep only the sender and subject, for 90 days. So that no message is ever filed twice, we also keep a note of which messages our system has read: our mail provider's identifier for each one and the date, nothing of the message itself. Notes our staff make about a booking are kept with the booking record.

Staff can see your booking, its cancellation, our checks with the hotel and your conversations with us. They cannot see our payment references. Staff can resend your confirmation and, with the code we email you, cancel at your request. Every action is recorded with the staff member who took it, and a cancellation also with the reason they gave.

We never ask for your card number. If a document you send shows one, we remove it. When you claim under our Fee Promise we keep the bill with the conversation, and our decision, and the PayPal email or Venmo handle you give us for the payment, with the booking record.

Deleting a conversation removes it from our live records; copies in our backups remain until those backups are replaced.

Analytics and error reporting

We keep an anonymous record of how the site is used, on our own server. Nothing is sent to a third party for it, no cookie is set, and there is nothing to accept or decline. For each visit it records:

  • the website you came from, by name only — for example google.com — never the page you were on or what you searched for there;
  • the campaign tags on the link you followed (utm_source, utm_medium and utm_campaign), and whether it came from an ad platform, without that platform's click identifier;
  • the pages you view, in order and with the time, with anything after the “?” removed and booking references and other identifiers in the address replaced by a placeholder;
  • the city a search was for — never a ZIP code;
  • the buttons, links, tabs and filters you click, by what they say, and where a link leads;
  • whether your device is a phone, a tablet or a computer;
  • when a payment is refused, the reason your bank or Stripe gave and whether you paid by card, Link, Apple Pay, Google Pay or another wallet — never any part of the card;
  • roughly where you are: the country, state and city that our network provider, Cloudflare, associates with your connection. We receive these as place names from Cloudflare, which works them out from your IP address; we never receive or keep the address itself for this, nor the coordinates or postal code Cloudflare can also supply. It is approximate, and on a mobile network it can be a different city or state from the one you are in.

When a payment fails we may also be emailed about it, so we can help: what was being booked, the dates and the amount. To find those, a refusal inside the card field is sent with the checkout's identifier, which we use to look the checkout up and, where Stripe answers, to check the failure with Stripe, and do not keep. If the failure comes after your card was accepted, that email also includes the name and email address you entered. We are not emailed about a card number you had not finished typing, nor more than a few times about one checkout. If your card is accepted and no booking follows, our twice-daily check of unused rate holds tells us that too, without your name.

Separately, and without any visit identifier, we count which hotels have their rooms opened (the hotel and the city searched, and whether it was the website or the app), and, for each search, how many days ahead it was, how many nights and how many people it was for — never the dates themselves.

It never records what you type into a field, what a drop-down menu is set to, or whether a box ends up ticked. On checkout, booking, sign-in and account pages, which can show your own name, it notes that a control was used, and where a link leads, but not what the control said. Your IP address and your browser's full description of itself are read to tell automated crawlers from people and to stop one source flooding the record; neither is stored. The approximate place above comes to us from Cloudflare as a country, state and city, and is the only part of where you are that the record keeps.

Your browser makes up a random identifier when you arrive and keeps it in its own session storage, with the site and campaign tags you arrived with and a count of clicks recorded; all of it is emptied when the tab closes. It is not a cookie, it does not follow you between visits, and we never connect it to a booking, a name or an email address. Whether a visit reached our checkout or confirmation page is worked out from the pages it viewed, not from any booking.

Raw records are kept for 90 days and then deleted. Hourly and daily totals — how many searches, how many bookings, how many visits came from each kind of source and from each state and city, how far visits got, how often each control was clicked — are kept longer, and carry no visit identifier.

Cloudflare, the network that delivers this site, also measures page loads with Cloudflare Web Analytics. A script Cloudflare adds to our pages reports how long each page took to load, and Cloudflare counts page views and visits, broken down by page, by the website that linked to it, by country, and by device type, browser and operating system. Cloudflare states that Web Analytics uses no cookies or local storage, does not fingerprint visitors by IP address, browser description or anything else, and does not track individual visitors across the websites it serves. Every request to this site passes through Cloudflare's network, and Cloudflare's privacy policy covers what it does with that.

Server errors are recorded on our own server, grouped by the route that failed with any booking reference removed from it, and are not sent to any third party. Card details never reach our server, so they cannot be in one.

Preferences stored in your browser

Your filters, declared needs, the result you last selected on a search page and your colour scheme are kept in your browser's local storage. They never reach our servers. A half-completed checkout is kept in your browser's session storage so a crash does not cost you the form, and is cleared when the booking completes or the tab closes.

The Android app

Our Android app searches and books through the same servers as this website, so everything above applies to it as well. What is different:

  • It keeps the same anonymous record of use, with a random identifier the app makes up each time it is opened and holds only in its memory, so the identifier is gone when the app closes. It records the screens you open and the booking steps you reach, and never the buttons you tap. The approximate country, state and city described above are recorded for the app's visits in the same way.
  • It uses no advertising identifier. Each request it makes names the app and its version (for example NJSTravel-Android/1.0) where a browser would describe itself, and carries your phone's time zone so that a deadline is shown in your own time. We read the name to tell the app from a browser, and keep only the fact that it was the app and whether it ran on a phone or a tablet — never the version or the time zone.
  • Payments in the app are taken by Stripe's own Android software, and your card details go from it to Stripe directly, never to our servers. To prevent fraud, that software collects information about your device, which Stripe handles under Stripe's privacy policy.
  • Once you sign in or book, the app keeps your sign-in session on your phone, and for each booking made in the app, or opened in it from a booking email, its access key, reference, name and dates, so that booking opens from Trips without signing in. When you ask for a sign-in link in the app, it also keeps a code that lets it recognise that link as its own; the code is good only until the link expires.
  • While you are signed in, it keeps the last list of your trips it loaded — each booking's reference, name, dates, status and total, and the travellers and price watches you saved, with the travellers' names and dates of birth — so Trips opens with no signal, marked with when the list was loaded. It is forgotten when you sign out, when you delete your account, and when our server says your sign-in has ended.
  • It also keeps a copy of the few booking pages you opened most recently, so a booking can still be shown at a front desk with no connection. Signing out of the app, or deleting your account in it, deletes the saved booking pages; the access keys stay, because the bookings outlive the account and those keys still open them.
  • All of this is encrypted with a key held in Android's secure key storage and left out of your phone's backups, so none of it travels to another device inside one.
  • It remembers the last search you ran — the place, the dates, and how many adults, children and rooms, with each child's age — so the search form is filled in the next time you open it. That copy stays on your phone: it is never sent to us, it is left out of your phone's backups, dates that have passed are dropped rather than offered again, and clearing the app's storage or uninstalling it removes it.

Backups

Our booking database is backed up nightly. Each backup is encrypted with AES-256-GCM before it is written, so a copy that has been tampered with fails to restore rather than restoring quietly altered records, and copies are kept on our server and on a backup server at the same site.

Your rights

You can delete your account yourself, at any time, on the Delete your account page, or from Trips in our Android app. It deletes the travellers you saved and your price watches, ends every sign-in for your address on every device and cancels any sign-in link not yet used, straight away. It does not delete booking records, which we keep for the seven years described above; they are held against the email address a booking was made with, so signing in again with that address shows them again. It does not delete your conversations with our support team, which are kept as described under “Support and our staff”. Deleting your account does not cancel a booking.

For anything else, ask us: for a copy of what we hold about you, or for it to be corrected or deleted, and we will do it, with two limits. Deletion cannot extend to booking records we are legally required to retain, or to a booking that has not yet been travelled. And a support conversation is kept for two years after it is closed: when you ask, we remove the words of your messages and the files you sent, each replaced by a dated note that it was removed, but the record that the conversation took place, with its subject and the contact details it was opened with, stays until then. We respond within thirty days.

Who we are and how to reach us

TravelSyncro LLC, a New Hampshire limited liability company, of 221 Main St Ste N, Nashua, NH 03060.

Email [email protected], quoting your booking reference. Replies to any confirmation email reach the same place. Phone: (603) 207-1674.

These terms are awaiting legal review

These documents describe how this site actually behaves, sentence by sentence, and a travel-industry attorney is reviewing them. They are our plain statement of what we do, not legal advice.