Legal
Effective Date: January 1, 2025 · Last Updated: May 5, 2026
On This Page
2.1 Information You Provide — and Why We Need It
| Data Type | What We Collect | Why It Is Required |
|---|---|---|
| Full Name | First, middle, last name | Required by airlines to issue tickets |
| Date of Birth | Day, month, year | Airline and visa identity verification |
| Gender | As stated on travel document | Required by some airlines and border agencies |
| Nationality | Country of citizenship | Required for visa check and booking rules |
| Email Address | Primary contact email | Booking confirmations, e-tickets, support |
| Phone Number | Mobile/home number | Urgent travel alerts and OTP authentication |
| Passport Number | Full document number | Mandatory for international flight bookings |
| Passport Expiry Date | Expiry date of travel document | Validity check required by airlines |
| Issuing Country | Country that issued the passport | Required in GDS booking records |
| Billing Address | Street, city, state, ZIP, country | Payment processing and fraud prevention |
| Payment Method | Card type, last 4 digits, expiry — see note below | Processing transactions only |
| Travel Preferences | Cabin class, meal preference, frequent flyer numbers | Personalising your booking experience |
| Account Password | Stored as a one-way bcrypt hash — never in plain text | Secure account access |
Important — Payment Data
We do NOT store your full credit or debit card number on our servers. Card data is transmitted directly to our PCI-DSS compliant payment processors. FlyEthio retains only the card type, last four digits, and expiry month/year for reference purposes.
2.2 Information Collected Automatically
When you visit flyethio.com or use our mobile app, we automatically collect:
2.3 Information Received from Third Parties
The table below maps each purpose to the data we use and the legal basis (relevant for GDPR/UK GDPR users).
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Process and fulfil bookings | Name, passport, contact, payment details | Contract performance |
| Issue e-tickets & confirmations | Name, email, booking reference | Contract performance |
| Communicate booking changes | Email, phone number | Contract / Legitimate interest |
| Customer support | Name, email, booking data, correspondence | Contract / Legitimate interest |
| Fraud prevention & security | Payment info, IP address, device data | Legitimate interest / Legal obligation |
| Sending promotional emails | Email address | Consent — opt-out available at any time |
| Improve site & app features | Usage data, analytics, crash reports | Legitimate interest |
| Legal & regulatory compliance | Any data as required by law | Legal obligation |
You may withdraw consent for marketing communications at any time by clicking "Unsubscribe" in any email or contacting info@flyethio.com.
Depending on your location, you have the following rights over your personal data:
| Right | What It Means |
|---|---|
| Access | Request a full copy of the personal data we hold about you |
| Correction | Request correction of inaccurate or incomplete data |
| Deletion | Request deletion of your data (subject to legal retention requirements) |
| Portability | Receive your data in a structured, machine-readable format |
| Restriction | Ask us to pause processing your data in certain circumstances |
| Objection | Object to processing based on legitimate interests or for direct marketing |
| Withdraw Consent | Withdraw consent at any time where processing is consent-based |
| Opt-Out of Marketing | Unsubscribe from promotional emails at any time via the link in the email |
For US residents (California / CCPA & Virginia / VCDPA)
You have the right to know what categories of personal information we collect and disclose. We do not sell your personal information. You will not be discriminated against for exercising these rights.
For EU / UK residents (GDPR / UK GDPR)
You have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK or your national Data Protection Authority in the EU) if you believe we have not handled your data lawfully.
To exercise any right, email privacy@flyethio.com or info@flyethio.com with subject line "Privacy Rights Request". We will verify your identity and respond within 30 days (45 days for complex requests under CCPA).