HeyVacay - Privacy Policy
Last updated: September 23, 2025
Definition
Flightistic LLC d/b/a HeyVacay ("HeyVacay," "we," "us," or "our") values your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit or use our websites, mobile apps, and related tools and services (collectively, the "Platform"). It also describes your privacy rights and how to exercise them.
Scope (V1): HeyVacay is a hotel-only booking engine in V1. We do not sell flights in V1. Accommodations are provided by independent properties and authorized travel distribution partners. We do not use GDS; we source rates through partners (e.g., wholesalers/aggregators) and properties. If and when we add additional products (e.g., flights or AI chat), we will update this Policy and, where required, present additional notices or obtain consent.
Quick Summary (Key Points)
What we collect. Contact details, booking details (names, passport details, and other required details for booking), payment information (processed by payment partners), device/usage/cookie data, preferences, communications, and (if provided) limited accessibility or dietary notes.
How we use it. To operate and secure the Platform; process bookings; provide support; personalize experiences; run analytics and improve services; conduct lawful marketing; and comply with legal obligations.
How we share. With service providers (hosting, payments, support, security, analytics); accommodation providers and distribution partners to fulfill bookings; measurement/advertising partners (where enabled—you can opt out); authorities where required; and in corporate transactions.
Your choices. Manage cookies; opt out of marketing and targeted ads; access/port/correct/delete data; object to or restrict certain processing; and appeal decisions as applicable.
Security & retention. We use reasonable technical and organizational safeguards and retain data as long as needed for the purposes described and legal duties.
International transfers. Data may be processed in the U.S. and other countries with appropriate transfer safeguards.
0. Definitions (Plain-English)
• Personal information / personal data: Information that identifies, relates to, describes, or can reasonably be linked to you or your household.
• Processing: Any operation on personal information (collecting, storing, using, sharing, etc.).
• Controller: The entity that decides how and why personal data is processed (that's HeyVacay for the Platform).
• Processor / service provider: A vendor that processes data for us under contract.
• Targeted advertising / cross-context behavioral advertising: Ads based on your activity across sites/apps over time.
• Sensitive personal information: Certain categories like precise geolocation; government IDs; and information about health or disabilities you share with us to fulfill accessibility requests. We avoid collecting SPI unless you provide it for a specific purpose.
1. Who We Are & How to Contact Us
Controller: Flightistic LLC d/b/a HeyVacay.
Email (privacy requests & questions): privacy@heyvacay.co
If you reside outside the U.S., HeyVacay remains your data controller for the Platform. If EU/UK targeting or monitoring later applies, we will appoint an EU/UK representative and update this section.
2. Information We Collect
We collect information in three ways: (a) you provide it; (b) we collect it automatically; and (c) we receive it from other sources (e.g., payment processors, distribution partners, fraud-prevention providers).
2.1 Information you provide directly
• Identification & contact: name, passport information, email, phone, postal address; traveler names; account credentials (passwords are hashed/salted).
• Booking details: destination, property, room type, dates, rate plan, inclusions, cancellation/payment rules, preferences/requests (e.g., bed type).
• Payment details: cardholder name, billing address, card token/last-4 (full PAN handled by our PCI-DSS-compliant payment processor; we do not store full PANs).
• Communications & content: emails, chats, support tickets, call recordings and/or transcripts (where permitted by law and disclosed), reviews, survey responses, and attachments you upload (e.g., screenshots).
• Companions: If you book for others, you provide their details. Please share this Policy with them.
• Verification (limited/conditional): If required to prevent fraud or comply with law, we may request government ID or similar.
2.2 Information collected automatically
• Device & usage: IP address; device IDs; browser/app info; pages/screens viewed; clicks; search parameters; referring/exit URLs; timestamps; language; general location derived from IP.
• Diagnostics & logs: crash/error reports; performance metrics; session IDs.
• Cookies/SDKs: pixels, tags, local storage, and mobile identifiers for functionality, analytics, personalization, and advertising. See Section 9.
• Approximate vs. precise location: We may infer approximate location from IP. We access precise location only if you grant permission in your device/app.
2.3 Information from third parties
• Accommodation providers & distribution partners: booking/confirmation details, room type, rate and tax/fee breakdowns, and policy data to fulfill your stay.
• Payment processors & fraud tools: authorization responses, tokenization, risk scores, chargeback data.
• Analytics/marketing providers: attribution and campaign metrics; inferred interests where permitted.
• Identity/security providers: signals to help prevent spam, abuse, or unauthorized access.
• Social/media sign-ins (if you choose to link): basic profile identifiers and tokens necessary for sign-in.
Minors: Our Platform is not directed to children. See Section 10.
3. Why & How We Use Information (Purposes & Legal Bases)
We process personal information for the purposes below. Where a legal basis is required (e.g., EEA/UK), we rely on: performance of a contract; legitimate interests (balanced against your rights); consent (for certain cookies/marketing/precise location); and legal obligations (tax, accounting, AML/sanctions, consumer protection).
1. Provide the Platform & fulfill bookings. Create/manage accounts; process payments; send confirmations, receipts, and updates; manage cancellations/changes; provide support. Bases: contract; legitimate interests; legal obligations.
2. Communicate with you. Transactional/service messages and, where permitted, marketing (email/SMS/push). Bases: contract; legitimate interests; consent (where required).
3. Personalize & improve. Remember preferences; tailor results/sort order; suggest filters; run A/B tests; perform analytics and diagnostics. Bases: legitimate interests; consent (non-essential cookies/ads).
4. Security, fraud, and abuse prevention. Detect/prevent fraud, spam, and misuse; protect accounts and Platform integrity; investigate incidents. Bases: legitimate interests; legal obligations.
5. Compliance & governance. Tax and accounting; regulatory reporting; responding to lawful requests; enforcing agreements; maintaining records. Bases: legal obligations; legitimate interests.
6. Research & development. Surveys; de-identified/aggregated analytics to understand trends and improve services. Bases: legitimate interests.
7. Programs, credits & incentives. Administer HeyVacay Credit, promotions, and service-recovery credits (see Section 8 and Section 12). Bases: contract; legitimate interests; consent (if required).
We do not use sensitive personal information to infer characteristics for marketing.
5. Automated Decision-Making & AI
• V1 approach. We use automated systems for routine tasks (fraud detection and scoring, security signals, personalization, ranking/relevance, traffic quality, and support triage). We do not make decisions with legal or similarly significant effects solely by automated means.
• Human review. We include human oversight for escalations and where required by law, and you may request human review of certain outcomes where applicable.
• V2 preview. If we introduce conversational assistants or additional AI features in a future version, we will update this Policy and present any additional notices/controls required by law.
6. International Data Transfers
We are based in the United States and work with providers/partners worldwide. When transferring personal data internationally, we use appropriate safeguards (e.g., Standard Contractual Clauses, transfer impact assessments, and technical/organizational measures). Where local law requires additional steps or certifications, we implement them. We are not currently self-certified under the Data Privacy Framework; if that changes, we will update this Policy.
7. Security
We implement reasonable administrative, technical, and physical safeguards designed to protect personal data, including:
• Encryption in transit; hardened networking; least-privilege and access controls; MFA for privileged access.
• Environment isolation; secure key management; logging and monitoring; vulnerability management and patching cadence.
• Secure development practices; change management; vendor risk management; workforce privacy/security training.
• Payment processing by PCI-DSS-compliant providers; we do not store full card PANs.
No system is 100% secure. Please use a unique password and keep your credentials confidential. If we become aware of a data incident that may affect you, we will notify you and regulators as required by law.
8. Your Rights & Choices (Global)
Your rights depend on your location but may include the right to access, correct, delete, port, restrict certain processing, object to processing (including marketing), and withdraw consent (where applicable). You also have choices about cookies, targeted ads, and communications.
How to exercise rights (all regions): Email privacy@heyvacay.co. We will verify your request using reasonable methods (e.g., email verification, account login, or matching limited information we already hold) and respond within the time required by law. You may designate an authorized agent where permitted (we may require proof of authority and your verification).
Marketing choices:
• Email: click Unsubscribe in any marketing email.
• SMS: reply STOP to opt out; HELP for help. (Message/data rates may apply.)
• Push: manage in device/app settings.
• Transactional/operational messages (e.g., booking confirmations) will still be sent.
Non-discrimination: We will not discriminate against you for exercising rights. Where a program offers a different price or benefit reasonably related to the value of your data (e.g., Credits), see Section 12.
10. Children & Teens
The Platform is not directed to children under 16 (or the age defined by local law). You must be 18+ to create an account or book. Adult users may provide minor guest details solely to complete a booking (e.g., child name/age). If you believe a child provided personal data without appropriate consent, contact privacy@heyvacay.co and we will delete it as required by law.
We do not knowingly sell/share personal data of consumers under 16.
11. Data Retention
We retain personal data for as long as reasonably necessary for the purposes in this Policy, including to:
• provide the Platform and fulfill bookings;
• comply with tax, accounting, and other legal obligations;
• resolve disputes, secure our systems, and enforce agreements.
Typical retention (subject to change based on legal duties):
• Account profile & preferences: while your account is active, plus up to 3 years after last activity.
• Booking/transaction records: 7 years (or longer where tax/accounting/regulatory requirements apply).
• Customer support records (emails/chats/call recordings): 2–3 years for quality, training, audit, and dispute resolution.
• Analytics/telemetry logs: 12–24 months in identifiable form, then aggregated/de-identified.
• Marketing contact history: while subscribed and up to 2 years after opt-out for compliance.
When data is no longer needed, we delete or de-identify it per our retention schedule and backup cycles.
12. HeyVacay Credit, Promotions & Notice of Financial Incentive
From time to time, we may offer HeyVacay Credit or similar promotional incentives (e.g., sign-up, referral, or service-recovery credits).
• What is it? Unless specified otherwise, 1 Credit = USD $1 applied to eligible bookings. Credits have no cash value, are non-transferable, may expire (e.g., after 24 months), and may include minimum spend, blackout dates, or property exclusions. Credits cannot be sold.
• Enrollment & withdrawal: Participation is voluntary. You may opt out by contacting us; existing Credits remain subject to the offer terms.
• Value of data: The value of personal information (e.g., email, booking history) is reasonably related to the incentive provided, considering expected redemption, engagement, and program costs.
• Non-discrimination: We will not discriminate against you for exercising privacy rights. Different prices or levels of service reasonably related to the value of your data are permitted by law for such programs.
13. Region-Specific Supplements (U.S. + International)
The following supplements apply in addition to the general Policy where local laws grant additional rights or impose specific duties.
13.A California (CCPA/CPRA)
• Notice at collection (what we collect & why): We collect identifiers (e.g., name, email), commercial information (bookings), internet/usage data, general geolocation, audio/chat recordings (support), and inferences for personalization. Sources include you, your devices, our partners, and service providers. Purposes and retention are described in Sections 2–3 and 11.
• Sensitive personal information: We do not use/disclose SPI for purposes that require a right to limit under CPRA (e.g., we use accessibility notes only to fulfill requests).
• Selling/Sharing: We do not sell personal information for money. Some disclosures to ad/analytics partners may be considered "sharing" for cross-context behavioral advertising. Opt out via Cookie Preferences or by sending a GPC signal; you may also email privacy@heyvacay.co with "Do Not Sell or Share."
• Your rights: Know/access, correct, delete, portability, opt out of sale/sharing, and non-discrimination. Submit requests via privacy@heyvacay.co. We will verify your identity and respond within statutory timeframes. Authorized agents are honored with appropriate proof.
• Financial incentives: See Section 12 (HeyVacay Credit).
13.B Colorado (CPA)
• Rights: Access, correction, deletion, portability, and opt-out of targeted advertising, sale, and certain profiling.
• How to opt out: Use Cookie Preferences, send a GPC signal, or email privacy@heyvacay.co.
• Appeals: If we deny your request, reply to our decision email with "Appeal." We will respond within 45 days stating the reasons and how to contact the Colorado AG.
13.C Virginia, Connecticut, Utah, Nevada, Texas, Oregon, Montana, Delaware, Indiana, Iowa, Tennessee (and similar U.S. laws)
• You may have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, sale, or certain profiling. We provide a unified email channel (privacy@heyvacay.co) and cookie-level opt-outs (including GPC) to exercise these rights where available.
• Nevada "Do Not Sell": Email privacy@heyvacay.co with "Nevada Do Not Sell" in the subject. We do not sell personal information for monetary consideration.
13.D EEA/UK/Switzerland (GDPR-style)
• Legal bases: contract (fulfilling bookings), legitimate interests (security, personalization, product improvement, relationship management), consent (non-essential cookies/marketing/precise location), and legal obligations (tax/accounting/regulatory).
• Your rights: access, rectification, erasure, restriction, objection (including to direct marketing), and portability; withdraw consent at any time (without affecting prior processing). Submit requests via privacy@heyvacay.co.
• Transfers: We use SCCs and other safeguards (see Section 6). We will appoint an EU/UK representative if/when required and update this Policy.
13.E Canada, Australia, New Zealand, and Other Regions
We will honor applicable rights (e.g., access and correction) and comply with local consent and marketing rules. Contact privacy@heyvacay.co to exercise your rights.
14. Verification, Authorized Agents & Appeals (U.S.)
• Verification: Depending on your request, we may verify via email link, account login, or matching limited data you provide to information we already hold. For high-risk requests (e.g., deletion of sensitive data), we may require stronger verification.
• Authorized agents: If you use an agent, we may require proof of authorization (e.g., signed permission) and your verification.
• Appeals: If we decline your request, you may appeal by replying to our decision email with "Appeal." We will explain our decision and provide regulator contact details where required.
15. Third-Party Sites, Integrations & Social Features
Our Platform may include third-party links, widgets, embedded content, or sign-in options. Using these may allow those parties to collect information directly from your browser/device under their own privacy policies. Review their practices and settings to understand your choices. We are not responsible for the privacy practices of third parties.
16. User-Generated Content (UGC)
If you submit reviews, ratings, photos, or other UGC, that content may be public to other users or visible to the property you booked. Do not include personal information you do not want to be public. We may moderate UGC for quality, security, or policy reasons.
17. De-Identified & Aggregated Data
We may create and use de-identified or aggregated data for analytics, research, and reporting. We commit to maintain and use de-identified data without attempting to re-identify it, except as permitted by law.
18. Accessibility
We are committed to making our privacy disclosures accessible. If you need this Policy in an alternative format, email privacy@heyvacay.co.
19. Changes to This Policy
We may update this Policy to reflect changes in our services, legal requirements, or privacy practices. We will post the updated date at the top and, where required, provide advance notice of material changes (e.g., prominent notice or email). Continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
20. Contact Us
Questions, requests, or complaints about privacy: privacy@heyvacay.co
Appeals: reply to our decision email and include "Privacy Appeal" in the subject line.
Appendix A – Category Map (California Notice at Collection Matrix)
Below is a high-level matrix mapping categories of personal information to sources, purposes, disclosure/sharing, and retention. This supplements Sections 2–4 and 11.
Identifiers: name, email, phone, postal address; account ID. Sources: you; your device; partners. Primary Purposes: account, booking, support, security, marketing (where permitted). Disclosed to: service providers; properties/partners; payment/banks. Sale/Sharing: No sale; sharing for ads may occur where enabled. Typical Retention: Account life + up to 3 years.
Customer Records: booking history, itineraries, payment token/last-4. Sources: you; payment processor; partners. Primary Purposes: process bookings, payments, support, compliance. Disclosed to: service providers; properties/partners; payment/banks. Sale/Sharing: No. Typical Retention: Bookings: 7 years.
Commercial Info: viewed properties, searches, preferences. Sources: you; your device. Primary Purposes: personalize content, analytics. Disclosed to: service providers; analytics/measurement. Sale/Sharing: Sharing may apply. Typical Retention: 12–24 months (logs).
Internet/Network: IP, device IDs, pages viewed, clicks. Sources: your device; SDKs. Primary Purposes: security, analytics, personalization, ads. Disclosed to: service providers; analytics/ads. Sale/Sharing: Sharing may apply. Typical Retention: 12–24 months (logs).
Geolocation: approx. from IP; precise only with consent. Sources: your device. Primary Purposes: show relevant content; fraud/security. Disclosed to: service providers. Sale/Sharing: No sale; sharing may apply for ads. Typical Retention: 12–24 months.
Audio/Electronic: support call recordings, chat transcripts. Sources: you. Primary Purposes: support quality, training, dispute resolution. Disclosed to: service providers. Sale/Sharing: No. Typical Retention: 2–3 years.
Inferences: preferences from activity. Sources: us; analytics. Primary Purposes: personalize results, messaging. Disclosed to: service providers; ads/measurement (if enabled). Sale/Sharing: Sharing may apply. Typical Retention: 12–24 months.
Sensitive PI (limited): accessibility/dietary notes (if provided). Sources: you. Primary Purposes: fulfill specific requests. Disclosed to: properties/partners; service providers. Sale/Sharing: No. Typical Retention: As needed for booking, then delete or minimize.
We do not knowingly sell/share the personal information of consumers under 16.
Appendix B – Request Handling Timelines (Reference)
• Access/Deletion/Correction: Typically 45 days (extensions as permitted).
• Portability: Provided in a commonly used, machine-readable format where required.
• Appeals (e.g., CO/VA): 45–60 days depending on the state.
Appendix C – Communications Policy (CAN-SPAM / SMS)
• Marketing emails include a working unsubscribe link and a valid postal address in the footer (PO Box or commercial mailbox acceptable).
• SMS marketing: obtain opt-in where required; provide STOP / HELP instructions; maintain opt-out logs.
— End of Policy —