Information We Collect
2.1 Account and Profile Information
- Full name
- Email address
- Mobile phone number
- Date of birth
- Profile photograph
- Payment-related information, processed exclusively by our third-party payment providers
2.2 Identity Verification (KYC)
Airceleo uses Persona Identities, Inc. ("Persona") as our independent identity-verification processor. When you complete KYC, Persona collects and processes the following on Airceleo's behalf:
- A photograph of a government-issued identity document (passport, driver's licence, or national ID).
- A live selfie used to generate a short-lived facial template that Persona compares to the photo on your ID. This is biometric data under the Digital Personal Data Protection Act, 2023 and the California Consumer Privacy Act.
- Limited device-level signals Persona's SDK collects to detect document tampering and replay attacks (e.g. screen-recording, deep-fake liveness checks).
Where the data lives. Airceleo never sees, stores, or has access to your raw selfie video, raw biometric template, or unredacted identity-document image. Persona stores those artefacts on its own infrastructure (primarily United States data centres) and shares only a verification outcome with us (approved, rejected, or needs-review) together with the redacted fields necessary to populate your account (full name, date of birth, country of issuance).
Retention. Persona retains your KYC submission for the period required to comply with anti-money-laundering, fraud-prevention, and tax laws applicable to Airceleo and to Persona, typically up to seven (7) years after your account is closed. You may request deletion before that statutory period expires, and Persona will delete data not subject to a legal retention obligation. To exercise this right, write to support@airceleo.com or use the in-app deletion control at Settings → Privacy Rights.
Airceleo does not conduct independent criminal background checks. Raw identity documents are not retained on Airceleo's systems beyond what is needed to display your KYC status to you in the app.
2.3 Platform Activity
We collect information generated through your use of the Platform, including:
- User role (Sender or Traveler)
- Item categories and declared values
- Status of coordination arrangements
- Payment transaction references
- Platform activity logs
2.4 In-App Messaging
Airceleo provides in-app messaging between Senders and Travelers to coordinate their arrangement.
- Messages are transmitted over TLS (HTTPS) between your device and our servers.
- Messages are stored on our infrastructure provider, which encrypts data at rest at the storage layer using industry-standard practices.
- Airceleo does not currently offer end-to-end encryption. Authorized Airceleo personnel and our infrastructure provider can technically access message content where strictly necessary for system maintenance, security, abuse investigation, or legal compliance.
Airceleo does not actively monitor or read user messages in the ordinary course of operating the Platform.
We retain message metadata, including timestamps, sender and recipient identifiers, and delivery status.
You acknowledge that:
- Recipients can copy, forward, screenshot, or share messages.
- Airceleo cannot guarantee confidentiality once information has been shared with another user.
- You should not transmit financial account numbers, government identification, or other highly sensitive information through in-app chat.
2.5 Device and Usage Information
We may automatically collect:
- Device type and operating system
- IP address
- App version
- Log and diagnostic data
2.6 Location Information
Airceleo does not perform real-time tracking of users or items. Limited location information, such as a city or route endpoint, may be voluntarily provided by users to facilitate coordination.
2.7 Flight Documents (Boarding Passes)
When you list a flight as a traveler, we require you to upload your boarding pass or e-ticket. This is collected solely for our security and compliance check (to confirm the flight is genuine and that you are actually travelling the route you have listed) and to auto-fill your itinerary (route, dates, airline, and flight number) so you do not have to re-type it.
Your boarding pass is transmitted over an encrypted connection and stored in a private, access-controlled bucket. It is never shown to other users, never sold, and never shared with third parties except where strictly required to verify your trip or comply with the law. A boarding pass on its own cannot be used to travel or impersonate you. Airlines match the pass against government-issued photo ID and your passport at the gate, so a copy held by us carries no boarding privilege.
We extract only the structured itinerary fields needed for your listing. You may replace the document at any time before submitting, and it is deleted in accordance with our retention schedule (Section 7) once it is no longer needed for the security check or any related dispute window.
2.8 Login Security Alerts and Approximate Location
To protect your account against unauthorised access, our systems monitor failed sign-in attempts. Where a number of failed attempts are made against your account within a short period, we temporarily lock the account and send a security-alert email to the address on file, informing you of the attempts and providing a link to reset your password.
So that you can assess whether the activity was your own, that email states the time of the attempts and an approximate location (typically a city, region, and country) derived from the Internet Protocol (IP) address from which the attempts originated. To obtain this approximate location, we transmit only the IP address to an independent IP-geolocation service (ipwho.is); we do not transmit your name, email address, account identifier, or any other personal information, and the lookup is performed solely in connection with such a security event. The location returned is approximate and is provided to you for informational purposes only.
We carry out this processing in reliance on our legitimate interest in safeguarding the security of your account and the Platform (Article 6(1)(f) of the General Data Protection Regulation and equivalent provisions of other applicable data-protection laws, including Section 7 of the Digital Personal Data Protection Act, 2023). Because the geolocation service receives a single, transient technical data point and no account identifiers, it is not provided with information that would enable it to identify you.