Privacy Policy
We're committed to protecting your personal data and being transparent about how we use it.
Last updated: January 1, 2026 | Effective: January 1, 2026
AeroSphere ("we", "our", or "us") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. Please read it carefully.
1. Information We Collect
We collect information you provide directly to us and information generated through your use of our services:
| Category | Data Collected | Source |
| Account Information | Name, email address, phone number, password (hashed) | Registration form |
| Booking Data | Passenger names, flight preferences, travel dates, seat selection | Booking process |
| Payment Information | Transaction ID, payment status (card details are NOT stored) | Razorpay gateway |
| Communication | Messages sent via Contact Us form, support emails | Contact form |
| Usage Data | Pages visited, session duration, browser type, IP address | Server logs |
2. How We Use Your Information
- To process and confirm flight bookings and payments
- To send booking confirmations, invoices, and flight updates via email
- To verify your identity during account registration (OTP)
- To respond to your support queries and contact form messages
- To improve our platform based on usage patterns and feedback
- To detect and prevent fraud, unauthorized access, and abuse
- To comply with legal obligations under applicable Indian law
3. Information Sharing
We do not sell, trade, or rent your personal data to third parties. We share information only in these limited circumstances:
- Payment Processors: Razorpay receives transaction data to process payments. They are PCI-DSS compliant and have their own privacy policy.
- Email Service Providers: We use SMTP (Gmail) to send transactional emails. Email addresses are transmitted but not stored by third parties beyond delivery.
- Legal Requirements: We may disclose information when required by law, court order, or government authority.
- Business Transfers: In the event of a merger or acquisition, your data may be transferred to the new entity under the same privacy protections.
4. Data Security
We implement industry-standard security measures to protect your data:
- All web traffic is encrypted using HTTPS/TLS
- Passwords are hashed using bcrypt — we cannot read your password
- CSRF tokens protect all forms from cross-site request forgery
- Sessions are managed with HttpOnly, Secure cookies
- Payment card details are never stored on our servers
- Database access is restricted to authorised internal services only
While we take every precaution, no internet transmission is 100% secure. Please use a strong, unique password for your account.
5. Cookies & Tracking
We use the following cookies:
- Session Cookies: Required for login and booking flow. These expire when you close your browser.
- Preference Cookies: Store your dark/light mode preference (saved in localStorage, not sent to server).
We do not use advertising cookies or third-party tracking scripts. You can disable cookies in your browser settings, but this may affect site functionality.
6. Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Update inaccurate data via your Profile settings or by contacting support
- Deletion: Request deletion of your account and associated data (subject to legal retention requirements)
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing of your data for direct marketing
To exercise any of these rights, please contact us via the Contact Us page. We will respond within 30 days.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Specific retention periods:
- Account information: Until account deletion, plus 6 months
- Booking and payment records: 7 years (legal/tax requirements)
- Support messages: 2 years
- Server access logs: 90 days