Your bookings, your data,
your control.
When you book on FareEagle, you hand us money, travel dates, and personal information. This page explains — in plain terms — how we protect all three, and what commitments we've made to you about them.
We never store your card
Card details never touch our servers. PCI-DSS certified gateway handles every transaction.
We don't sell your data
Not to advertisers, not to aggregators, not to anyone. Your data is used to deliver your booking.
You can export or delete anytime
Under DPDP Act 2023, you have rights — we built the controls to make them easy.
We disclose what happens
If something goes wrong, we tell affected users directly — not six months later in a press release.
Your card never touches
our servers.
Payment data flows directly from your browser to a PCI-DSS certified payment gateway. FareEagle is told whether the charge succeeded — nothing more.
Here is exactly what happens when you pay on FareEagle:
You enter your card details into an iframe served directly by our PCI-DSS compliant payment provider. The iframe runs on their domain, not ours. When you click Pay, your card data travels from your browser straight to their vault — never through FareEagle.
We receive only a transaction token and a success/failure signal. Even our engineers cannot read your card number from any system we control. If our database were to ever be breached, there are no card numbers in it to steal.
- PCI-DSS compliant gatewayCertified under the Payment Card Industry Data Security Standard
- TLS 1.2+ on every connectionEnd-to-end encryption from your browser to the gateway
- OTP on every transactionMandatory two-factor confirmation per RBI digital payment guidelines
- Card numbers are never loggedNo CVV, no PAN, no expiry date in application logs or backups
- Price shown = price chargedThe amount you confirm is the amount authorised — no post-purchase adjustments
Built for the DPDP Act
from the ground up.
India's Digital Personal Data Protection Act, 2023 sets a high bar for how companies handle personal data. We built FareEagle to meet it — not to retrofit it later.
DPDP isn't just a compliance checkbox for us. It's the operational framework for how we handle every piece of personal data — from the moment you sign up, through every booking, to eventual account deletion.
Under DPDP, we act as a Data Fiduciary — the entity legally responsible for how your data is used. You are the Data Principal, and you have rights we're obligated to honour. Below is how we meet each of them.
Specific, clear, free consent
We ask for consent in plain language at the exact point we need the data — not bundled in a 10,000-word policy.
You can see what we have
Download your full data export from your account at any time, in JSON format.
You can fix what's wrong
Edit or update any personal data directly in your account settings.
You can ask us to forget you
One-click account deletion. We retain only what law requires — for example, tax records — and purge the rest.
You can raise a complaint
Our appointed Grievance Officer responds within statutory timelines. Contact below.
You can name a successor
Designate someone to exercise your rights if you're unable to do so yourself.
Minimum data. Maximum
transparency.
We collect only what's required to complete your booking and meet our legal obligations. Nothing more.
Data we collect
- Name, email, phoneRequired for ticket delivery, booking confirmations, and support
- Date of birth & genderRequired by airlines for ticket issuance
- Passport / ID detailsOnly for international bookings, per DGCA rules
- Travel history on FareEagleYour past bookings, so you can view, modify, or rebook
- Device / browser metadataFor fraud detection and bug diagnostics
- Transaction recordsRetained per GST and RBI rules (typically 7 years)
Data we don't collect
- Your credit or debit card numbersNever stored on our servers. Handled exclusively by our payment gateway.
- Social media profiles or contactsWe don't scrape your network or address book.
- Location when the app isn't openNo background tracking. No advertising IDs.
- Biometric dataNo face, fingerprint, or voice captures.
- Data from third-party brokersWe don't buy, enrich, or append data from outside vendors.
- Information from children under 18Per DPDP Act, we do not knowingly collect data from minors.
If someone steals your card,
we try to catch it first.
Every FareEagle booking is screened in real-time before payment is authorised. If the signals don't line up, the booking is held for review — not silently processed and refunded later.
Our fraud engine is built for the patterns Indian travellers actually face: stolen card numbers used on mule bookings, automated velocity attacks, and coordinated account takeovers.
We look at the combination of signals, not any single one. A new device logging in from a new city isn't automatically suspicious — that's you on vacation. But a new device, a card that's been used four times in the last hour, an IP range associated with datacenter traffic, and a booking for tomorrow in a distant city? That's a pattern we hold.
When a booking is flagged, we don't silently charge your card and refund you later. We either block the transaction outright or hold it for human review within minutes. You're never on the hook for a charge we couldn't verify.
If a fraudulent charge does slip through: tell us within 24 hours, and we'll reverse it immediately. No forms in triplicate, no waiting for RBI chargeback timelines to resolve on their own. That's a FareEagle commitment, above what the payment network requires.
Six things you can do,
right now.
Every right DPDP gives you, we've built into your account. No phone calls, no paperwork — just buttons.
Request a full export of everything we hold about you.
Email grievance@fareeagle.com from your registered address with the subject "Data Export Request." We deliver a complete JSON export of your profile, bookings, preferences, and derived data within 30 days, per DPDP Act §11 requirements.
Correct any information you believe is wrong.
Profile details, saved passengers, stored travel documents — all editable directly. Changes are logged for audit but not surfaced to anyone but you.
Delete your account and associated data.
Email grievance@fareeagle.com from your registered address with the subject "Account Deletion Request." We retain only what's legally required (GST records, tax filings under Indian statute) and fully purge the rest. Confirmation within 30 days per DPDP Act §12 timelines.
Control every notification you receive.
Email, SMS, WhatsApp — opt in or out of each independently. Transactional messages (booking confirmations, e-tickets) are the only ones that can't be disabled, as required for service delivery.
Revoke consent for non-essential processing.
Marketing emails, personalised recommendations, trend analysis — all separately revocable at any time, with no impact on your ability to continue booking.
File a formal grievance with our Grievance Officer.
Appointed under DPDP Act and IT Intermediary Rules, 2021. Write to grievance@fareeagle.com with details of your concern. Statutory response timelines apply.
If something goes wrong,
we'll tell you.
Under Indian law — both the DPDP Act 2023 and CERT-In's 6-hour reporting rule — we're obligated to disclose security incidents. We treat this as the minimum, not the ceiling.
Our commitment to affected users:
If an incident affects your data, you will receive a direct notification to your registered email within the statutory window. That notification will tell you exactly what happened, exactly what data was affected, what we're doing about it, and what you should do.
We won't bury it in a press release six months later. We won't describe it in vague language that hides the scope. If your card was exposed, we'll tell you "your card number was exposed." If your booking history was exposed, we'll tell you that too.
If you believe your FareEagle account has been compromised, email security@fareeagle.com or call our support line. We treat these reports as P0 and respond within hours.
Found a vulnerability?
Tell us first.
If you're a security researcher, developer, or user who has found a genuine security issue in FareEagle, we want to hear from you before anyone else does. We commit to the following in return:
- We'll acknowledge your report within 48 hours.
- We won't take legal action against researchers acting in good faith under the guidelines below.
- We'll tell you when the issue is fixed, and credit you publicly if you want.
Guidelines for good-faith reporting: test only on your own accounts, don't access other users' data, don't disrupt service, and give us a reasonable window to fix before public disclosure (typically 30 days).
More about FareEagle.
Who we are and why we built FareEagle.
Our position, our principles, our company identity — and the commitments we hold ourselves to.
Read the About pageHow FareEagle is built — AI, APIs, and architecture.
Aira, MCP server, real-time fare engine, and the infrastructure we run ourselves.
Read the Technology page