Privacy Policy
Last updated: 16 June 2026
AirportDate (operated by AI Lora, “we”, “us”) helps people meet around their travels. That only works if you trust us with your data, so this policy explains plainly what we collect, why, who we share it with, how long we keep it and what control you have — for users anywhere in the world. For privacy questions or to exercise your rights, contact privacy@airportdate.com. AI Lora is the data controller responsible for your personal data.
The short version
- Your location is always approximate — the airport, terminal and zone you choose at check-in, or the city and dates of a trip you add. We never collect or share exact GPS by default.
- We ask for each permission separately, at the moment it unlocks a feature — never as a bundle, never pre-ticked. Review or withdraw any of them anytime in Settings → Consents.
- Your phone number is never shown to other users.
- Deleting your account is a hard delete, not a hidden deactivation.
- We do not sell your personal data, and we do not use it to train third-party AI models.
What we collect
- Account data — email address, date of birth and phone number. Needed to run your account, verify you are a real person, and enforce our 18+ rule.
- Profile data— display name, photos, bio, gender, who you're interested in, home city, travel intents and the trips you add. Shown to other users; you choose what to add.
- Sexual orientation (optional) — a special category of data, collected only if you add it for dating, with your explicit consent, and deletable anytime.
- Verification data — a live selfie compared against your profile photos, which also estimates your age (biometric data, processed only with your explicit consent). Optionally a passport or driving licence, or a workplace/crew credential, if you request a verification that needs it. Identity/credential images are matched and then deleted — we keep the result, not the document.
- Airport check-ins and trips — the airport, terminal and zone you choose, your trip mode, and optionally a destination, dates or flight number. Approximate by design; never GPS coordinates. Your flight number is kept private to you and never shown to other users.
- Messages and activity — your chats, likes, matches, blocks and reports, so the product works and so we can act on abuse.
- Payment data — handled by our payment processor. We never see or store your full card number.
- Device and technical data — IP address, device/browser type and similar data needed for security, fraud prevention and to make the Service work; and analytics (anonymous usage events) only if you allow analytics in the cookie banner or Settings.
Boarding passes
If you scan a boarding pass, we extract the flight details and then delete the image. We keep the extracted text (flight number, times, terminal), not the picture.
How we use your data, and our lawful bases
Running your account, check-ins, trips and matching is necessary to provide the service you signed up for (contract). Biometric selfie verification and the optional orientation field are special-category data processed only with your explicit consent. Other optional features — push notifications, non-essential email, analytics, AI processing of your profile, live trip sharing, proximity and precise-location features in our native app, and crew verification — each have their own consent, asked when you first use the feature and withdrawable at any time. Fraud prevention, safety and abuse moderation, and meeting our legal duties (including online-safety and child-protection obligations) rely on our legitimate interests and legal obligations. Where we rely on consent, withdrawing it does not affect processing already carried out, and may switch off the related feature.
How we share data, and who processes it for us
We share your profile and presence with other users as needed for the Service (for example, your card in Discover or an overlap on a trip), according to your visibility settings. We use a small set of vetted processors to run AirportDate, each receiving only what its job requires: Supabase (database, authentication, storage), Vercel (hosting), Resend (transactional email), Stripe (payments), an SMS provider via Supabase (verification codes), AWS (selfie face-match and liveness), OpenAI (boarding-pass text extraction and content-moderation fallback), ElevenLabs (optional voice features), Aviationstack (live flight data), Google Places (airport points of interest), Sentry (error monitoring, with personal data scrubbed) and PostHog (analytics, only with your consent, no personal data). We may also disclose data where required by law, to respond to lawful requests, to protect users' safety, to detect or prevent fraud or abuse, or in connection with a corporate transaction (with this policy continuing to apply). We do not sell your personal data.
International data transfers
AirportDate is operated from the United Kingdom and used worldwide, and our processors may store or process data in the UK, the European Economic Area, the United States and elsewhere. Where we transfer personal data across borders, we use appropriate safeguards recognised under applicable law — such as the UK International Data Transfer Agreement / Addendum, the EU Standard Contractual Clauses, or transfers to countries with an adequacy decision — so your data keeps an equivalent level of protection.
How we protect your data
We use encryption in transit, access controls, row-level security on our database, scrubbing of sensitive data from error logs, and the data-minimisation principles described above. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security; please use a strong, unique password and keep your account credentials confidential.
How long we keep it
We keep your data while your account is active. Boarding-pass and verification images are deleted immediately after they are processed. Expired check-ins stop being visible automatically, and past trips age out of discovery. If you delete your account, your data is hard-deleted — we keep only what the law requires us to keep (for example certain payment or safety records, for the period the law specifies).
Automated processing
We use automated systems to estimate age from your verification selfie, to match your selfie to your photos, and to flag patterns of abuse (such as mass-liking) for human review. These do not make legally significant decisions about you on their own; a person reviews enforcement actions. You can ask us about any of this at the address above.
Your rights
Depending on where you live, you may have rights to access, correct, export (portability), delete, restrict or object to the processing of your personal data, and to withdraw consent. Export and deletion are built into Settings — you don't need to email anyone, but you can contact privacy@airportdate.com to exercise any right. We will not discriminate against you for using these rights.
- UK / EEA / Switzerland (GDPR):the rights above, plus the right to lodge a complaint with your supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).
- California and other US states:rights to know, access, correct and delete your personal information, and to opt out of any “sale” or “sharing” — we do not sell or share personal information in that sense.
- Elsewhere: if your local law gives you privacy rights, contact us and we will honour them.
Age
AirportDate is for adults only. We check your date of birth at signup and use age estimation during selfie verification. We do not knowingly collect data from anyone under 18; if we learn that we have, we remove the account and the data.
Changes and language
If this policy changes in a way that matters, we will tell you in the app or by email before it takes effect, and the cookie banner will re-ask for any choices it covers. This policy may be offered in several languages for convenience; if there is any conflict, the English version governs to the extent the law allows.