Privacy notice — FlyBest travel assistant connector

Version 2026-09-29. DRAFT for review by the agency before publication.

Who is responsible

  • FlyBest (flybest.org), an independent travel advisor based in California, USA, operates the connector and is responsible for the sign-up, connection and booking records described here. Contact for privacy questions and requests: flybestorg@gmail.com.
  • Hotel reservations are placed on the accreditation of Coastline Travel Advisors, a licensed California host agency, which receives a copy of each booking.
  • What we collect

  • To sign up: your e-mail address, which we use to send a 6-digit code. We derive a pseudonymous connection identifier from the address with a server-held key. The identifier does not display your address, but we can match it to you through our own records, so it remains personal data. The address itself is stored in the connection list and in the access- and refresh-token records for your connection, so the connection can be revoked or contacted.
  • To prevent abuse: the IP address and time of each sign-up request, kept for one hour; the number of codes sent and sign-ups completed per day.
  • From your assistant: we do not receive your chat transcript. We receive what your assistant sends in each tool request: the place, dates and party size for a search, and, when it asks for a payment page, the guest name, e-mail address, phone number if given, and stay details. Booking requests are passed to our booking service and to the reservation system (Sabre) to make the reservation. For public connections, the connector records selected facts from each hotel tool request: the place, hotel, dates, party size, search and rate options, the outcome and, for a failed request, an error code and the error message with names, e-mail addresses, phone numbers and long numbers removed, against the pseudonymous connection identifier. The usage log also records currency conversion amounts and currencies, and trip tool calls with the trip list number and cancellation switches. It never records the guest name, e-mail address, phone number, loyalty number, reservation reference or card details.
  • On the payment page: your card details, which are sent to the reservation system to make the booking. We keep only the last four digits, the exact wording of the terms you ticked and the time you ticked them, together with a snapshot of the rate's policy. The page also asks for the e-mail address our booking messages should go to; that address is kept with the booking record and is separate from the guest's address on the reservation.
  • Bookings: the hotel, dates, confirmation number, reservation reference and status of each booking made on your connection, in a bookings list that only your connection can see through the assistant.
  • Logs: the service log records which tool was called by which connection identifier and when, with selected public usage facts kept separately for 90 days to see how the service is used and to fix failures; the service log is kept in a size-limited system journal that currently holds a few days to a few weeks. Web-server logs record the IP address, requested address and time of every request and are rotated daily and kept for 14 days.
  • Why, and on what basis

  • To make and manage the hotel reservations you ask for, to send you booking confirmations, to prevent abuse of the service, to see how the public service is used and to fix failures, and to keep the booking records a licensed travel agency must keep.
  • Where EU or UK data-protection law applies: we process the information needed for your connection and your bookings to perform our agreement with you; we keep abuse-prevention and security records for our legitimate interest in protecting the service; usage records are kept for our legitimate interest in running the service and fixing failures; information about other guests on a booking is processed because it is necessary to make the reservation you request; booking records are kept to meet the agency's record-keeping duties.
  • Who sees it

  • The hotel you book and its reservation system (Sabre), which receive the booking details and the card.
  • Coastline Travel Advisors, the host agency: each booking made on a public connection is e-mailed to the agency mailbox with the guest and contact details, hotel, dates, confirmation and the terms you ticked, and is recorded in the agency's Sabre profile remarks, which is how the agency fulfils and supports the booking.
  • Our providers: Google Cloud, which hosts the connector on a server in the United States and stores the nightly backups (US-WEST2, Los Angeles); Google's Gmail service, through which FlyBest sends sign-up codes and booking copies from flybestorg@gmail.com.
  • We do not sell personal data, and we do not share it for advertising.
  • Where it is processed

  • FlyBest is based in the United States and the connector runs there. The hotel you book, and its reservation system, process your booking in the country where they operate. If you use the connector from another country, your information is transferred to the United States and to the hotel's country to make the booking you asked for. Google Cloud and Sabre publish their own transfer safeguards; ask us if you need details.
  • How long

  • Sign-up codes: deleted within an hour of expiring. Sign-up IP records: one hour. Daily usage counters: the current day only.
  • Access tokens: 7 days; refresh tokens: 90 days; both are deleted when they expire or when the connection is revoked. The connection list entry (e-mail and identifier) is kept while the connection exists and deleted on request.
  • Payment pages that never became a booking: deleted after 30 days.
  • Booking records (the booking, the terms you ticked, the last four digits, the policy snapshot): kept for as long as the agency's accreditation and tax record-keeping rules require, then deleted; ask us for the current period. The copy e-mailed to the agency mailbox and the remarks in the agency's Sabre profile are kept under the agency's own record-keeping rules.
  • Messages we send you (booking confirmation, cancellation, reminder, an expired payment page): a copy of each message is kept for 60 days so that it can be re-sent if delivery fails, then reduced to a record that it was sent (no content). The booking timeline (which step happened when, with the booking references, no message contents and no addresses) is kept with the booking record.
  • Backups: booking data is backed up nightly; each backup is deleted after 60 days. A record deleted from the live system can remain in a backup until that backup expires.
  • Logs: public usage logs 90 days (older daily files are removed on the next day with a tool call); web-server logs 14 days; the service journal is size-limited (currently a few days to a few weeks).
  • Your choices and rights

  • You can see and cancel the bookings made on your connection through the assistant.
  • To revoke your connection, ask what we hold about you, correct it, or ask us to delete it, e-mail flybestorg@gmail.com. There is no self-service deletion page. Revoking a connection does not cancel hotel bookings and does not by itself erase booking records; we will tell you what we can delete, what the agency must keep, and why. Disconnecting the connector in your AI client stops it from being used but does not delete our records.
  • Depending on where you live you may also have the right to receive a copy of your data, to restrict or object to some processing, and to complain to your data-protection authority. We may ask for proportionate information to verify your identity before acting on a request.
  • California residents: you may ask what personal information we hold, and ask us to correct or delete it, without being treated differently for asking. We do not sell personal information and do not share it for cross-context behavioural advertising.
  • Children: the connector is for adults. We do not knowingly create a connection for anyone under 18; adults may include children as guests on a booking and should give only the details the reservation needs (such as ages for occupancy and rates).
  • Cookies

  • After you sign up, the authorisation page sets one functional cookie, fb_invite_grace, so that the same browser can repeat the connection step for 15 minutes; it is limited to the /authorize address, marked Secure and HttpOnly, and then expires. The sign-up and payment pages set no tracking cookies. The public website flybest.org has its own notice.
  • Changes

  • We date every change to this notice and publish it at this address.