Privacy
Last updated 31 July 2026
Who is responsible for your data
PACHIFUNK OÜ, trading as Skyferra decides how and why your data is used, and is the controller of it. Registered address: Tornimäe tn 5, Tallinn, Harju maakond, 10145, Estonia.
What we hold
Only what the product needs to do its job:
- Your account: email address, and a display name if you set one.
- Your trips: what you booked, what you paid, the supplier reference, and the traveller or guest details the supplier required.
- Price history: every re-price we run against your trips and watched routes. This is what makes any claim about a saving evidenced rather than asserted.
- Savings and actions: money returned to you, and a log of what we did and when.
- Settings: your rebooking threshold, whether we may act unasked, and your notification preferences.
Your card
We never see or store your card number. Card details go from your browser to Stripe directly; we keep only Stripe’s token, the brand and the last four digits, which is what lets us show you which card a refund is going back to.
Who else sees it
Only the parties needed to make a booking happen, and only the part each one needs:
- Airlines, through our suppliers, receive the traveller details required to issue a booking.
- Stripe processes payments and refunds.
- Supabase stores the database and runs authentication.
- Our email provider sends the alerts and confirmations you receive.
We do not sell your data, and we do not share it for advertising. A complete, current sub-processor list belongs here before launch and does not exist yet.
Getting it back, and getting rid of it
The account page will export everything we hold about you as a JSON file, built from your own records at the moment you ask.
Deleting your account stops all watching immediately and erases your history rather than archiving it. Bookings already made stay with the airline. Deleting your account here does not cancel a trip.
A retention schedule for records we are obliged to keep after deletion, such as transaction records for tax and chargeback purposes, needs to be written and stated here before launch.
Why we are allowed to hold it
Most of it because we cannot do what you asked without it: performing our contract with you covers your account, your bookings, the traveller details an airline requires, and the price history that watching a trip consists of.
Our legitimate interests cover keeping the service secure, preventing fraud and abuse, and understanding failures well enough to fix them, balanced against your interests, which is why error reports carry no booking contents.
A legal obligation covers records we must keep as a merchant of record, such as transaction records for tax and accounting. Your consent covers anything optional, and you can withdraw it without affecting anything we did while it was given.
How long we keep it
Your account and its trips stay while the account exists. Delete the account and we erase your history rather than archiving it. Watching stops immediately and the rows go.
Two things outlive that, and only because they must. The first is money. Estonian accounting law makes us keep a record of every payment for seven years, so before we erase an account we copy out the amounts, the dates and the reference numbers. Your name, your email and your trips are not copied. What is left is a row of figures that cannot be traced back to you from anything we hold.
The second is bookings already made. Those stay with the airline, under their own retention, because they are the ones holding your travel.
Where it goes
Our processors, the database, payment, supply and email providers named above, may process data outside your country. Where that happens we rely on the transfer mechanisms those providers offer, such as standard contractual clauses, rather than moving data somewhere with no protection attached.
What you can ask us to do
You can ask us to:
- show you what we hold, and give you a copy in a portable form;
- correct anything wrong, traveller names especially, since airlines match them to documents;
- delete your account and its data, which you can also do yourself from the account page;
- stop or limit a particular use, including objecting to anything we do on the basis of legitimate interests;
- withdraw consent you have given.
Write to the support address at the bottom of this page and we will act within a month. If you think we have got it wrong you can complain to your data protection regulator, in Estonia, the supervisory authority for data protection, and we would rather you told us first so we can fix it.
Cookies and tracking
We set what is needed to keep you signed in and to keep the site secure, and nothing else. There is no advertising network here, no third-party analytics following you between sites, and nothing sold to anyone.
Children
Skyferra is not for under-18s and we do not knowingly hold their data. Children can of course be passengers on a booking an adult makes; those details are held as part of that booking and under the same rules as everything else here.
How it is protected
Every table holding your data is row-level-security protected, so one account cannot read another’s rows even if a query tried. The credentials that can bypass that live only on the server and are never sent to a browser.
Changes to this page
We update it as the product changes, and the date at the top says when. If a change materially affects how your data is used we will tell you directly rather than relying on you re-reading it.
Email we send
Alerts about price drops and watched routes follow your notification settings and respect quiet hours. Booking confirmations and receipts do not: they are records of a transaction, they carry the reference you check in with, and switching them off is not offered.
Written in plain English from how the product actually works, and kept in step with it. The figures here are read from the same source the engine enforces, so the two cannot quietly disagree. It describes our agreement with you; it is not legal advice about your own position.
Questions about any of this: help@skyferra.com.