Privacy Policy

What we collect, why, who sees it, and what we deliberately never collect.

Last updated: 19 July 2026

Draft — pending legal review. This page is a plain-language draft prepared for review by the site owner and their legal counsel. It is not yet final and may change. Notes for the reviewer appear in amber boxes like this one.

The short version

We collect the minimum needed to book your trip: your searches, the traveler name and email you give at checkout, and payment details for the coin you chose. We never see card numbers, we store no passwords, and we never ask for wallet private keys or seed phrases. We do not sell your data.

1. What we collect

  • Search queries — routes, dates, cities and traveler counts. These are sent to our travel-data providers to fetch live prices; they are not tied to your name.
  • Booking details — the name and email you enter at checkout, what you booked, the total, and a booking reference. Bookings are stored on our own server.
  • Payment details — which coin you chose, the amount, the receiving address and, once you pay, the transaction on the blockchain. Never your keys.
  • Sign-in details — if you sign in, the email and display name you give are kept in a cookie in your own browser (see the Cookie policy).
  • Messages — anything you send via the contact form, so we can reply.
  • Technical logs — standard web-server logs (IP address, browser type, pages requested), kept briefly for security and debugging.

2. What we never collect

  • Card numbers or bank details — we do not take card payments at all.
  • Passwords — sign-in is email-only, with no password to store or leak.
  • Wallet private keys or seed phrases — no legitimate page on this site will ever ask for them.

3. How we use your data

To fulfil and manage your booking, send you its status, answer support requests, keep the site secure and fraud-free, and understand aggregate usage so we can improve the product. That is the full list.

4. Who we share it with

  • Travel suppliers — the airline, hotel and the aggregators between us and them receive the traveler details needed to issue your ticket or reserve your room. Without this there is no booking.
  • Payments — Bitcoin and major coins are paid to infrastructure we run ourselves, so no payment company sees your booking. If you pay with a long-tail coin, a third-party payment processor handles that payment and receives the order reference, amount and coin; its own privacy policy applies to what it collects.
  • Analytics — we use Google Analytics to see aggregate site usage (pages visited, rough location, device type). Google acts as a processor for this data.
  • Bot protection — sign-in and contact forms are protected by Cloudflare Turnstile, which checks signals from your browser (including your IP address) to tell humans from bots.
  • Hosting — the site runs on servers we operate; standard hosting-level access applies.

We do not sell personal data and we do not share it with advertisers or data brokers.

For legal review: Counsel may prefer to name the long-tail payment processor and the travel-data providers explicitly here — several privacy regimes (e.g. GDPR Art. 13) expect recipients or categories of recipients to be identifiable. Also confirm whether a data-processing agreement is in place with each provider, and whether international-transfer language (SCCs etc.) is needed.

5. A note about blockchains

Payments you make on a public blockchain are, by design, public and permanent. Anyone can see the addresses and amounts involved, and neither you nor we can edit or delete that record. Deletion requests we honour (section 7) can cover our own records, but never the blockchain itself.

6. How long we keep it

Booking records are kept for as long as needed to support your trip and to meet tax and legal record-keeping duties, then deleted. Server logs are kept briefly. The sign-in cookie expires after 30 days.

For legal review: Replace with concrete retention periods once counsel confirms the applicable bookkeeping and tax retention rules for the operating jurisdiction.

7. Your rights

Email [email protected] to ask what we hold about you, to correct it, or to have it deleted. We will verify the request came from you and respond within a reasonable time.

For legal review: Counsel to add region-specific rights language (GDPR legal bases and supervisory-authority complaint right, UK GDPR, CCPA/CPRA disclosures) depending on where Bitfares markets, and to appoint an EU/UK representative if required.

8. Security

The site is served over HTTPS, the sign-in cookie is inaccessible to page scripts, and we simply hold less than most travel sites: no cards, no passwords, and non-custodial payment flows for Bitcoin and major coins, so there is no pool of customer funds to breach.

9. Children

Bitfares is not directed at children. You must be old enough to form a binding contract to book (booking a trip for a minor as their guardian is fine).

10. Changes and contact

If this policy changes, the date at the top changes with it. Questions: [email protected].