Skip to content

Privacy Policy and Data Protection Notice

Last updated: May 23, 2026 · Yellsy LLC · Data Controller

🔒

Yellsy LLC is a United States company committed to strong privacy standards. For users located in the European Economic Area, we apply GDPR-aligned data handling practices. We never sell your personal data. All sensitive information is fully encrypted at rest using AES-256-GCM and securely transmitted using TLS 1.3. This document explains clearly and honestly what data we collect, why we collect it, and what rights you have over it.

1. Who We Are and How to Reach Us

1.1 Data Controller

Yellsy LLC ("Company", "we", "us", or "our") is the Data Controller responsible for the personal data collected through the travel concierge platform operated at yellsy.com and all associated automated services (collectively, the "Platform"). As Data Controller, we determine the purposes and the means by which your personal data is processed.

1.2 Contact for Privacy Matters

Yellsy LLC — Privacy Team

contact@yellsy.com

For all data access, correction, deletion, and complaint requests. We respond within thirty (30) calendar days.

1.3 Applicable Legal Framework

Yellsy LLC is incorporated in the United States and is therefore primarily subject to US federal and state privacy laws. However, because we provide services to users globally and process personal data belonging to residents of the European Economic Area, GDPR obligations also apply to us in respect of those users. The following framework governs the rights you hold and the standards we apply:

🇪🇺 EEA Residents

The General Data Protection Regulation (GDPR) applies directly to the processing of your personal data. All rights under Articles 15 to 22 are enforceable against us.

🇺🇸 California Residents

The California Consumer Privacy Act (CCPA) and its amendment (CPRA) apply. You hold specific rights to know, delete, correct, and opt out of the sale of your data.

🌍 All Other Users

We voluntarily extend equivalent privacy rights to all users worldwide as a matter of company policy, regardless of where applicable law requires it or not.

2. Legal Bases for Processing

We process your personal data only when a recognized legal basis applies. We do not collect data speculatively or beyond what is genuinely necessary.

The legal bases below are drawn from the GDPR framework and apply directly to the processing of personal data belonging to users located in the European Economic Area. For users outside the EEA, these same principles guide our data practices under applicable US and international privacy laws.

Performance of a Contract — Art. 6(1)(b) GDPR

The collection of your identity, passport, and contact information is necessary to execute the automated travel bookings and mandates you request through the Platform. Without this data, we cannot issue valid airline tickets or hotel reservations on your behalf.

Legal Obligation — Art. 6(1)(c) GDPR

We must retain financial records, transactional logs, and fraud prevention verifications to comply with applicable accounting, tax, and international travel security regulations.

Legitimate Interests — Art. 6(1)(f) GDPR

We process diagnostic and behavioral analytics to secure our platform, detect fraudulent chargebacks, monitor API performance, and optimize our automated booking flows. These interests do not override your fundamental rights and freedoms.

Consent — Art. 6(1)(a) GDPR

Where we wish to send you optional communications, travel recommendations, or marketing messages, we will ask for your explicit consent beforehand. You may withdraw consent at any time through your account settings.

3. Personal Data We Collect

We collect only the data that is strictly necessary to deliver the travel concierge services you request. Below is a transparent breakdown of each category:

Identity and Travel Documents

Legal full name as it appears on your government issued identification, date of birth, gender, nationality, passport number, passport expiration date, and country of issuance. This data is required by airlines and global booking systems to issue valid travel documents.

Contact Information

Email address, telephone number, billing address, and where provided, emergency contact details. Your email address is used for booking confirmations, security alerts, and account communications.

Travel Preferences

Cabin seat preferences, meal restrictions, baggage choices, preferred airlines, maximum connections, and airport transfer specifications. These are stored as part of your comfort profile to personalize your booking experience.

Financial and Subscription Data

Stripe customer identifier, subscription plan, payment status, and commission tracking data. We never store raw card numbers, CVV codes, or full bank account details. All payment data is captured directly and exclusively by Stripe.

Technical and Diagnostic Data

IP addresses, login timestamps, device type, browser configuration, session duration, and automated concierge conversation logs. This data is used exclusively for security monitoring, fraud detection, and platform improvement.

Payment Audit Records

For each financial transaction, we retain an immutable record including the IP address, browser fingerprint, device type, and a cryptographic hash of the authorization text you accepted at checkout. These records are retained for 540 days and then permanently deleted. Legal basis: legitimate interests for dispute resolution and fraud prevention.

4. How We Use Your Data

Your data is used exclusively to operate the Platform and deliver the travel services you have requested. We do not use your data for purposes incompatible with those disclosed here.

  • Service delivery: account management, price monitoring, automated booking execution, and booking confirmation notifications.
  • Identity and document transmission: forwarding your passport data and personal identifiers to airline and hotel booking systems as required to issue valid travel documents.
  • Security and fraud prevention: detecting unauthorized access attempts, brute force protection, IP based login alerts, and chargeback fraud analysis.
  • Legal and regulatory compliance: financial record keeping, dispute resolution evidence, and fulfillment of statutory obligations.
  • Transactional communications: sending one-time passwords, booking confirmations, price alert notifications, and security alerts. We do not send marketing emails without your explicit prior consent.
  • Platform improvement: aggregated and anonymized usage analytics to improve the reliability, speed, and quality of our automated services.

5. Data Sharing and Third Party Transmissions

Yellsy LLC does not sell, rent, or lease your personal data to any marketing broker, advertising network, or data aggregator. To execute your travel packages, our platform acts as a technological intermediary and must transmit your data to the following verified partners, under strict contractual and security obligations:

Duffel

Airline ticket issuance — receives your passport data and identity for booking confirmation.

Hotelbeds

Hotel and transfer reservations — receives your name and stay details to secure accommodation.

Stripe

Payment processing — captures all card data directly. Yellsy LLC never touches your raw payment details.

Resend

Transactional email delivery — booking confirmations, alerts, and security codes.

Twilio

SMS two factor authentication — sends verification codes to your registered phone number.

Cloudflare

Content delivery network, bot management, and DDoS protection.

Oracle Cloud / Amazon Web Services

Secure cloud hosting — your encrypted data is stored across enterprise-grade global data centers.

Legal and regulatory authorities

Disclosed only when compelled by a court order, regulatory requirement, or applicable law.

We never sell your personal data. Ever.

6. International Data Transfers

Travel booking inherently requires cross-border data flows. When you request a booking through Yellsy LLC, your personal identifiers may be transmitted to, stored in, and processed by partners located outside your country of residence, including countries that may not offer the same level of data protection as your home jurisdiction. By confirming a purchase, you grant Yellsy LLC an explicit mandate to execute these international transfers solely for the purpose of delivering your travel contracts. For EEA users, all transfers to countries that do not offer adequate data protection are governed by Standard Contractual Clauses approved by the European Commission, or equivalent safeguards under applicable data protection law. Our Data Processing Agreement, available at yellsy.com/legal/dpa, governs our processor relationships in detail.

7. Data Retention

We retain your personal data only for as long as is necessary to fulfill the purpose for which it was collected, to handle potential post travel claims, or to comply with mandatory legal obligations. The following retention periods apply:

Account data

Duration of your account plus five (5) years following closure, for legal compliance purposes.

Booking and travel records

Ten (10) years from the date of the transaction, in compliance with applicable accounting and tax regulations.

Security and login logs

Twelve (12) months from the date of the event.

Payment audit records

540 days (eighteen months) from the transaction date, then permanently and irreversibly deleted.

Consent records

Until you withdraw your consent, plus three (3) years for evidence of compliance.

Once retention periods expire, your personal data is automatically anonymized or securely and permanently purged from our operational database systems.

8. Security and Encryption

Yellsy LLC enforces a strict security protocol with no exceptions. All user data is encrypted and access is controlled on a strict need to know basis. Below are the technical measures we maintain:

🔒 Encryption at rest

Every piece of personal data stored in our databases — including identity fields, passport data, date of birth, contact information, and passenger lists — is encrypted using AES-256-GCM, the same standard used by financial institutions and government agencies.

🔒 Encryption in transit

All connections between your device, our servers, and our third party API endpoints are protected using TLS 1.3. Unencrypted connections are not accepted.

🔒 Password security

Passwords are hashed using a strong one-way hashing algorithm with a unique salt. Plaintext passwords are never stored anywhere in our systems.

🔒 Access control

Access to production systems is restricted to authorized personnel, protected by multifactor authentication, and logged continuously. No employee has standing access to decrypted customer records.

🔒 Payment isolation

Raw card numbers, CVV codes, and bank account details are captured exclusively by Stripe and never pass through or touch Yellsy LLC servers at any stage.

9. Automated Processing and Decision-Making

Yellsy LLC operates an automated booking platform. When you activate the autobook feature, our systems make automated decisions to select and confirm travel offers on your behalf, based on the preferences and budget you have explicitly defined. These automated decisions directly affect your financial commitments. EEA users hold the specific right under Art. 22 GDPR to request human review of any automated booking decision, to express their point of view, and to contest the outcome. We voluntarily extend this same right to all users worldwide. To request a human review, contact us at contact@yellsy.com. You may also disable the autobook feature at any time through your dashboard settings, which will require your manual approval before any booking is confirmed.

10. Your Privacy Rights

The rights you hold depend on where you are located. Regardless of jurisdiction, Yellsy LLC is committed to honoring every request in a timely and transparent manner.

10.1 EEA Residents — Rights Under GDPR

If you reside in the European Economic Area, the General Data Protection Regulation applies to the processing of your personal data by Yellsy LLC. The following rights are legally enforceable against us:

Access

Art. 15 GDPR

Rectification

Art. 16 GDPR

Erasure

Art. 17 GDPR

Restriction

Art. 18 GDPR

Portability

Art. 20 GDPR

Objection

Art. 21 GDPR

Right to Access (Art. 15): You may request a complete export of the personal data we hold about you. We will provide this within thirty (30) calendar days.

Right to Rectification (Art. 16): You may request correction of inaccurate data. Note that corrections to already-issued airline tickets are governed by the carrier's own fare rules and may incur fees.

Right to Erasure (Art. 17): You may request deletion of your account and all associated personal data, provided there is no pending booking, financial dispute, or mandatory legal retention obligation. You can initiate account deletion directly from your dashboard settings.

Right to Portability (Art. 20): You may request your personal data in a structured, machine-readable format to transfer to another service provider.

Right to Object (Art. 21): You may object to processing based on legitimate interests, in particular for analytics and diagnostic purposes. We will cease such processing unless we can demonstrate compelling legitimate grounds.

Right to Lodge a Complaint: If you believe your rights have not been respected, you may lodge a complaint with the supervisory authority in your country of residence within the EEA.

10.2 California Residents — Rights Under CCPA/CPRA

If you reside in the state of California, the California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), grant you the following rights:

Right to Know

You may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.

Right to Delete

You may request deletion of personal information we have collected from you, subject to legal exceptions.

Right to Correct

You may request correction of inaccurate personal information we maintain about you.

Right to Opt Out of Sale

We do not sell personal information. This right therefore does not apply to our current practices, but we will honor it if our practices ever change.

Freedom from Discrimination

We will not discriminate against you for exercising any of the rights listed above. You will receive the same quality and pricing of service regardless of your privacy choices.

10.3 All Other Users — Yellsy Voluntary Policy

Regardless of your country of residence, Yellsy LLC voluntarily extends the following rights to every user worldwide as a matter of company policy. You may at any time request access to the personal data we hold about you, ask us to correct inaccurate information, request deletion of your account, or object to processing for marketing or diagnostic purposes. These requests will be treated with the same priority as requests made under formal legal frameworks.

How to Exercise Your Rights

To exercise any of the rights above, please email contact@yellsy.com with a description of your request. Identity verification will be required for sensitive requests. We will acknowledge your request within five (5) business days and complete it within thirty (30) calendar days.

11. Cookies and Tracking Technologies

Yellsy LLC uses only strictly necessary cookies required for session management, authentication, and platform security. We do not use advertising cookies, behavioral tracking pixels from other websites, or third party profiling technologies. No cookies are placed on your device for marketing purposes without your explicit prior consent. For a complete description of the cookies we use, their purpose, and their duration, please refer to our Cookie Policy.

12. Children's Privacy

The Platform is not directed at persons under the age of eighteen (18). Yellsy LLC does not knowingly collect personal data from minors. If you are a parent or guardian and believe that a minor has provided us with personal information without your consent, please contact us immediately at contact@yellsy.com and we will take prompt action to delete that information from our systems.

13. Security Incident Notification

In the unlikely event of a personal data breach likely to result in a high risk to your rights and freedoms, Yellsy LLC will notify affected users without undue delay and no later than seventy-two (72) hours after becoming aware of the breach. For EEA users, this commitment reflects our obligations under Art. 34 GDPR; we apply the same seventy-two hour notification window voluntarily to all users worldwide. The notification will describe the nature of the breach, the categories of data involved, the likely consequences, and the measures taken or proposed to address it. Where required by applicable law, we will also notify the competent supervisory authority within the same timeframe.

14. Modifications to This Policy

Yellsy LLC reserves the right to update or revise this Privacy Policy at any time to reflect changes in our data practices, new regulatory requirements, or updated API integrations. When material changes are made, we will notify you by email at least thirty (30) days before the revised policy takes effect. The "Last updated" date at the top of this page will always reflect the most current version. Your continued use of the Platform after the effective date of any update constitutes your acceptance of the revised policy. If you do not agree with a material change, you have the right to close your account before the effective date.

15. Contact and Data Requests

For any question regarding this Privacy Policy, to exercise a data protection right, or to report a concern, please contact us through the following channel. We are genuinely committed to responding promptly and transparently.

Yellsy LLC — Privacy Team

contact@yellsy.com

Response time: up to 30 calendar days · Data Processing Agreement · Cookie Policy

Questions? Contact us