DestinationsItinérairesAéroportsAttractionsHôtelsBlogPartners
EN·ES·FR
Se connecter
Legal

Privacy Policy

Dernière mise à jour: September 2026

Data controller: AeroRide Inc. (a Delaware Corporation), 1401 Pennsylvania Ave. STE 105, Wilmington, Delaware 19806, USA — contact: info@aeroride.app. This policy applies to website visitors, registered users, and passengers using the Aeroride website, mobile app, and APIs, in Costa Rica, other countries, and future U.S. services (including California).

1. Data we collect

Identification data: full name, ID or passport number, and date of birth (if applicable), to verify identity and process bookings.

Contact data: email, phone number, and postal address, for booking confirmations, invoices, operational communications, and support.

Payment data: we do not store full card numbers (PAN). Payments are processed via tokens from our payment gateway (Stripe), compliant with PCI standards.

Travel data: departure date/time, origin, destination, service type, and travel preferences, used to manage bookings and issue e-tickets.

Biometric data: if facial recognition or similar is used for check-in/verification, it is used exclusively for identity verification at checkpoints.

Sensitive data: health or other sensitive information is collected only if voluntarily provided (e.g., for special assistance), with explicit consent and strict security measures.

2. Why we process your data

Execution of the transportation contract: managing bookings, ticket issuance, and itinerary changes.

Billing and payments: invoicing, transaction verification, and accounting reconciliation.

Identity verification and fraud prevention, and customer support (inquiries, changes, cancellations).

Operational notifications: reminders, schedule updates, check-in/boarding information.

Marketing and advertising (newsletters, promotions, remarketing) only with your prior consent.

Service analysis and improvement, based on our legitimate interest in improving routes, pricing, and internal processes.

Legal compliance and security: retaining information for fiscal, tax, accounting, and regulatory obligations.

3. Legal basis for processing

Contract execution — necessary to fulfill our contractual obligations to you (bookings, ticketing, billing).

Consent — for marketing communications and non-essential cookies; you may withdraw consent at any time.

Legitimate interest — for fraud prevention, service security, internal improvement, and legal-claims defense.

Legal obligation — when law requires data retention or reporting (fiscal, accounting, regulatory).

We comply with Costa Rican data protection law and, for U.S./California users, with CCPA/CPRA.

4. International transfers

Your data may be stored and processed on servers in Costa Rica, the United States, or other countries where our providers operate (e.g., Google Cloud, AWS); Stripe (U.S.) handles payment data under high security standards.

Cross-border transfers rely on Standard Contractual Clauses or equivalent guarantees, your explicit consent where required, and an adequacy assessment under Costa Rica’s Data Protection Law. All transfers are encrypted and covered by confidentiality agreements.

5. Your rights

You may access, rectify, delete, object to, restrict, or port your data, and withdraw consent at any time, by writing to info@aeroride.app or our online contact form. We respond within legal timeframes (e.g., 30 days).

California residents (CCPA/CPRA) additionally have the right to know data categories collected, correction, restriction of sensitive-data use, opt-out from sharing/sale, and non-discrimination for exercising these rights.

6. Data retention

Accounting/legal documents: at least 5 years (Costa Rican and U.S. fiscal law), longer if required by litigation or audits.

Booking/travel data: typically 2–5 years after your last interaction. Contact/profile data: up to 2 years after inactivity.

Consent and cookies: retained until revoked; session cookies deleted on browser close, persistent cookies per their defined lifespan. Data is deleted or anonymized once no longer necessary.

7. Security

Encryption in transit (TLS/SSL) and at rest (AES-256), secure authentication (strong passwords, MFA for employees), role-based access, and audit logging. Servers are hosted on AWS/Google Cloud in the U.S. and/or Costa Rica under confidentiality agreements.

8. Cookies and providers

Essential cookies require no prior consent; analytics and marketing/remarketing cookies are installed only with your consent, manageable via browser settings or our Cookies page.

External providers who may access data on our behalf: Stripe (payments), AWS/Google Cloud (hosting), Mailchimp/SendGrid/Twilio (email/SMS), Google/Facebook (login and remarketing, with consent). No data is shared for unrelated purposes.

9. Sale of data / CCPA

We do not sell personal information. If this were to change, California users may exercise a "Do Not Sell My Info" opt-out via a link on our website, as required by the CCPA.

10. Breach notification

In case of a data breach: containment, risk assessment, correction, and notification. Costa Rica: PRODHAB and affected users notified within 5 business days. U.S.: per applicable state law (e.g., California SB-24, typically 30–45 days).

11. Minors

Our services are not directed to minors. We do not knowingly collect data from children under 13 (COPPA); California law requires opt-in consent for ages 13–16 and parental consent under 13. Unauthorized minor data is deleted and accounts closed.

12. Aviation and regulatory compliance

We comply with Costa Rica’s Ley General de Aviación Civil / RAC-119, U.S. FAA/DOT privacy requirements, and ICAO Annex 9 (Facilitation) on Passenger Name Record data. We may share limited passenger data with authorized aviation or border authorities strictly for compliance, immigration, or public-safety purposes.

13. Contact and complaints

Contact us at info@aeroride.app. In Costa Rica, the supervisory authority is the Agencia de Protección de Datos de los Habitantes (PRODHAB), Centro Negocios SIGMA Building A, San Pedro (Montes de Oca), tel. +506 2202-7900.

In the United States, the Federal Trade Commission (FTC) oversees consumer privacy federally; California users may also contact the California Privacy Protection Agency or the Office of the California Attorney General.

14. Updates to this policy

This Privacy Policy is reviewed annually or upon any substantial change in our data practices or applicable law. Updates are dated and posted in the app and website; you will be notified of material changes and may be asked to renew consent where required by law.

Terms of Use