MYAIRADVOCATE

Privacy Policy

Version 2026-08-draft-1 · Last updated August 2026 · Contact: nathan@myairadvocate.com

1. Who we are

MyAirAdvocate ("we," "us"), operated by Nathan Zarcaro, Massachusetts, USA, provides flight-disruption monitoring and claim-preparation software for travel agents. Contact for anything in this policy: nathan@myairadvocate.com.

2. Two kinds of data — a distinction that matters

Account data (yours): name, agency name, email, phone, settings, and billing status. We are the controller of this data.

Client and passenger data (your clients'): booking confirmations you forward or enter — passenger names, flight details, booking references, and contact details you choose to add. We process this on your behalf and on your instructions, as your service provider. You are responsible for having the authority to share it with us.

3. How we use data

To run the service: parsing itineraries, monitoring flights, detecting disruptions, scoring and preparing claims, sending the alerts and communications you configure, billing, support, and keeping an audit log of communications sent. We do not sell personal data, and we do not use your clients' data for advertising.

4. Service providers (subprocessors)

We use a small set of providers to operate: Supabase (database, authentication, hosting of functions), Vercel (web hosting), Stripe (payments — card details go to Stripe, never to us), Resend (email delivery and inbound forwarding), Twilio (SMS, where enabled), flight- and weather-data providers (including AeroDataBox, FlightAware, and Visual Crossing), and Anthropic (AI parsing of itinerary text). Each receives only what its function requires.

5. Retention

Account data is kept while your account is active and for a reasonable period afterward for legal and accounting purposes. Booking and claim records are kept while relevant to the claim windows they support (EC261/UK261 limitation periods run up to six years), or until you delete them or instruct us to.

6. Security

Data is encrypted in transit, access is restricted by role-based rules at the database layer, and payment credentials are handled entirely by Stripe. No system is perfectly secure; we will notify affected users of a breach as the law requires.

7. Your choices and rights

You can access and update account data in the portal, export or delete booking data, and close your account. Depending on where you or your clients are located, additional statutory rights may apply (access, correction, deletion, portability, objection); write to us and we will honor them. For client data, we act on the instructions of the agency that submitted it.

8. Children

The service is for business use by adults. Passenger records may include minors' names within a family booking submitted by an agent; we process these solely as part of that booking.

9. Changes

Material changes to this policy will be versioned and presented for acceptance; the current version and date always appear at the top of this page.