Flightpadi Privacy Policy

Version: 2.0
Effective date: 29 September 2026

Key points

This summary is provided for convenience. The full policy below governs.

  • We process passenger, contact, travel-document, payment-reference and communication data to book, ticket and support your travel.
  • We share passenger data with airlines and booking systems to issue tickets, and with service providers acting on our instructions. We do not sell personal data.
  • Card payments are processed by Paystack. We do not receive or store full card numbers.
  • Our WhatsApp assistant, Ava, uses artificial intelligence. You may request a human at any time.
  • We use analytics and advertising technologies to understand how our websites are used and to measure our ads. Clause 10 explains how to control them.
  • You have rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent, and the right to complain to the Nigeria Data Protection Commission.

1. Introduction and scope

1.1 This Privacy Policy (“Policy”) explains how Flightpadi Ltd, a company incorporated in Nigeria with registration number RC 8165743 and registered with the Nigerian Civil Aviation Authority as a travel agency (NCAA/ATR/TAC.2406) (“Flightpadi”, “we”, “us” or “our”), collects, uses, discloses, retains and otherwise processes personal data, and describes the rights available to Data Subjects in respect of that processing.

1.2 This Policy applies to personal data processed in connection with:

  • (a) the websites at flightpadi.com and me.flightpadi.com;
  • (b) our WhatsApp, web chat, email, SMS and telephone channels, including our automated assistant, Ava;
  • (c) Flightpadi accounts, saved passenger profiles and the PadiMiles loyalty programme; and
  • (d) any other service that links to or references this Policy (together, the “Services”).

1.3 This Policy does not apply to the processing of personal data by airlines, payment providers or other third parties acting as independent Data Controllers. Their processing is governed by their own privacy notices (see clause 8.1).

1.4 Personal data of our employees, job applicants and suppliers is processed under separate notices provided to those individuals.

1.5 This Policy should be read together with our Terms of Service and Refund & Cancellation Policy.

1.6 We process personal data in accordance with the Nigeria Data Protection Act 2023 (“NDPA”), the General Application and Implementation Directive 2025 (“GAID”) issued by the Nigeria Data Protection Commission (“NDPC”), and other applicable law.

2. Definitions

In this Policy:

  • “Consent” means any freely given, specific, informed and unambiguous indication of a Data Subject’s wishes, by a statement or clear affirmative action, signifying agreement to the processing of personal data relating to them.
  • “Data Controller” means a person who, alone or jointly with others, determines the purposes and means of processing personal data.
  • “Data Processor” means a person who processes personal data on behalf of, or at the direction of, a Data Controller.
  • “Data Subject” means an identified or identifiable individual to whom personal data relates, including a customer, a passenger booked by a customer, and a person who contacts us.
  • “Passenger” means any person named on a booking, whether or not that person made the booking.
  • “Personal data” means any information relating to an identified or identifiable individual.
  • “Processing” means any operation performed on personal data, whether or not by automated means, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, transmission, restriction, erasure or destruction.
  • “Sensitive personal data” has the meaning given in the NDPA and includes data concerning health.

Other terms defined in the NDPA have the same meaning in this Policy.

3. Data Controller and Data Protection Officer

3.1 Flightpadi is the Data Controller of the personal data described in this Policy, except where clause 8.1 states otherwise.

3.2 Contact details:

4. Personal data we collect

4.1 Data you provide to us

  • (a) Passenger data: title, first name, middle name, last name, date of birth and passenger type as defined by the airline (adult, child or infant). Gender is derived from the selected title because airlines require it.
  • (b) Travel-document data: passport number, nationality and passport expiry date, where required by the airline or destination, or where you choose to provide them.
  • (c) Contact data: email address, telephone number and WhatsApp number.
  • (d) Account data: details used to create and access a Flightpadi account, saved passenger profiles, and PadiMiles and referral information.
  • (e) Communications data: the content of messages, voice notes, images, documents and calls you exchange with us or with Ava, and related metadata such as time and channel.
  • (f) Feedback data: survey responses, ratings and reviews.
  • (g) Special-assistance data: information about health, mobility or other needs that you choose to provide so that we can request assistance from an airline.
  • (h) Consent records: your acceptance of our terms, including the version accepted, the time of acceptance and the name entered, and your marketing preferences.

4.2 Data about other people

Where you provide personal data about another person, such as a fellow Passenger, you confirm that:

  • (a) you are authorised to provide it;
  • (b) you have informed that person of this Policy; and
  • (c) where that person is a child, you are their parent or legal guardian or are acting with that person’s authority.

We process such data only for the purposes of the booking concerned and the related support.

4.3 Data generated through your use of the Services

  • (a) Booking data: searches, selected flights, fares, booking references, airline record locators (PNR), ticket numbers and booking status.
  • (b) Transaction data: amount, currency, payment reference, payment channel and status and, where supplied by the payment provider, card type, issuing bank and the last four digits of the card.
  • (c) Technical and usage data: IP address, device and browser type, operating system, referring page, pages viewed, interactions, and cookie or similar identifiers. This also includes session-replay data and advertising identifiers (see clause 10).

4.4 Data we receive from third parties

  • (a) booking status, schedule changes, ticket and record-locator information from airlines and booking systems;
  • (b) payment confirmation and fraud-screening outcomes from Paystack; and
  • (c) delivery and read-status information from messaging providers.

4.5 Sensitive personal data. We do not require sensitive personal data to provide the Services. We process data concerning health only where you provide it and give explicit Consent, solely to arrange assistance with the relevant airline, and we disclose it only to that airline.

4.6 Consequences of not providing data. Passenger and contact data are necessary to make a booking. Airlines and immigration authorities require them. If you do not provide them, we cannot complete the booking. Where the airline or destination requires travel-document data, failure to provide it may result in the airline refusing carriage.

5. Purposes and lawful bases of processing

5.1 We process personal data only where a lawful basis under the NDPA applies. The table below sets out each purpose and its lawful basis.

Purpose Categories of data Lawful basis
Searching, pricing, reserving and ticketing flights; taking payment Passenger, travel-document, contact, booking, transaction Performance of a contract with you, or steps taken at your request before entering into a contract
Sending confirmations, e-tickets, receipts, payment reminders and service notices Contact, booking, transaction Performance of a contract
Customer support, including changes, cancellations and refund requests for bookings made through Flightpadi All relevant categories Performance of a contract
Operating accounts, saved passengers and PadiMiles Account, passenger, booking Performance of a contract
Operating Ava and quality-reviewing conversations Communications, booking Performance of a contract; legitimate interests in accurate and efficient service
Fraud prevention, payment reconciliation, duplicate-booking detection and information security Transaction, booking, technical Legitimate interests in protecting customers and our business
Service analytics and improvement using aggregated or de-identified data Booking, technical Legitimate interests
Post-travel feedback requests Contact, booking, feedback Legitimate interests in service quality (you may object at any time)
Direct marketing by email, SMS or WhatsApp Contact, booking history, preferences Legitimate interests in marketing similar travel services to people who have booked or enquired with us (you may object at any time); otherwise Consent
Advertising measurement, custom audiences and retargeting Technical, hashed contact, booking events Legitimate interests in measuring and improving our advertising (you may object at any time). We will ask for Consent once our cookie preference tool is available.
Requesting special assistance from airlines Special-assistance data Explicit Consent
Accounting, tax, regulatory reporting and responding to lawful requests Booking, transaction, consent records Compliance with a legal obligation
Establishing, exercising or defending legal claims All relevant categories Legitimate interests; compliance with a legal obligation

5.2 Where we rely on legitimate interests, we have considered and concluded that those interests are not overridden by your rights and freedoms. You may request details of that assessment by contacting the Data Protection Officer.

5.3 We will not process personal data for a purpose incompatible with the purpose for which it was collected, unless we have informed you and a lawful basis applies.

6. Consent

6.1 Where we rely on Consent, we obtain it through a clear affirmative action, such as ticking an unticked box. We do not treat silence, pre-ticked boxes or continued use of the Services as Consent.

6.2 You may withdraw Consent at any time, as easily as you gave it, by using the unsubscribe link in an email, by replying STOP on WhatsApp, or by contacting the Data Protection Officer. Withdrawal does not affect the lawfulness of processing carried out before it.

6.3 We keep records of Consent given and withdrawn, so that we can demonstrate compliance.

7. Artificial intelligence, automated processing and profiling

7.1 Ava. Ava is an automated assistant that responds to messages sent to Flightpadi on WhatsApp. Ava may search fares, answer questions and prepare bookings. For this purpose, message content, including transcribed voice notes and images, is processed by third-party artificial-intelligence model providers acting as our Data Processors (see Schedule 1).

7.2 Safeguards.

  • (a) Ava does not take payment or complete a booking without your express confirmation.
  • (b) Our staff may review conversations and intervene.
  • (c) You may ask to speak to a person at any time.
  • (d) The service through which we access AI models does not use your data to train models. We use model providers whose terms for paid API use do not permit training on customer data. Providers may keep data for a limited period, typically up to thirty (30) days, for security and abuse monitoring.
  • (e) Your booking confirmation and e-ticket are the authoritative record of your booking.

7.3 No solely automated decisions. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Where automated fraud or payment checks flag a transaction, a member of our team reviews it before any adverse action is taken.

7.4 Profiling for advertising. We use booking and website events to measure advertising and to build audiences on advertising platforms (see clause 10.3). This does not produce legal or similarly significant effects. You may object at any time (see clause 13).

8. Disclosure of personal data

8.1 Independent Data Controllers. The following recipients determine their own purposes and means of processing, and process personal data under their own privacy notices:

  • (a) Airlines: the airline operating your flight receives passenger, travel-document and contact data to carry you. Airlines may be legally required to disclose passenger data to border-control, customs and security authorities of the countries of departure, transit and arrival.
  • (b) Booking systems and consolidators: the flight-booking technology partners and global distribution systems through which reservations are made and tickets issued.
  • (c) Paystack: for its own regulatory, anti-money-laundering and fraud-prevention obligations.
  • (d) Meta Platforms: when you use WhatsApp, Meta processes data under its own terms. When you use our websites, Flightpadi and Meta are jointly responsible for collecting that data on our websites and sending it to Meta through the Meta Pixel and Conversions API. Meta alone is responsible for its processing after it receives the data.

8.2 Data Processors. We engage service providers that process personal data on our behalf and on our documented instructions, under written terms requiring confidentiality, appropriate security and compliance with the NDPA. The categories of Data Processors are listed in Schedule 1.

8.3 Legal and regulatory disclosure. We may disclose personal data where required by law, court order or a lawful request from a competent authority, or where necessary to establish, exercise or defend legal claims, prevent fraud, or protect the vital interests of any person.

8.4 Corporate transactions. In the event of a merger, acquisition, reorganisation or sale of all or part of our business, personal data may be disclosed to the prospective or actual acquirer. The disclosure will be made under confidentiality obligations, and the data will remain subject to protections equivalent to those in this Policy.

8.5 No sale. We do not sell personal data, or make it available to third parties for their own marketing.

9. Cross-border transfers

9.1 Certain recipients process personal data outside Nigeria, including in the European Union, the United Kingdom and the United States. These include airlines, booking systems and the Data Processors listed in Schedule 1. International bookings also necessarily involve airlines and authorities in other countries.

9.2 We transfer personal data outside Nigeria only in accordance with Part VIII of the NDPA, including where:

  • (a) the recipient is subject to a law, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism that affords an adequate level of protection;
  • (b) the transfer is necessary for the performance of a contract with you, or for the implementation of pre-contractual measures taken at your request; or
  • (c) you have given Consent after being informed of the possible risks.

9.3 You may request information about the safeguards applicable to a particular transfer by contacting the Data Protection Officer.

10. Cookies and similar technologies

10.1 We use cookies, pixels, software development kits and similar technologies (“Cookies”) on our websites.

Category Purpose Examples Basis
Strictly necessary Maintain search, booking and login sessions; security; load balancing Session cookie; security cookies Necessary to provide the service you request; no Consent required
Analytics Measure traffic and usage. Clarity also provides session replays and heatmaps. Google Analytics (_ga, _ga_*); Microsoft Clarity (_clck, _clsk) Legitimate interests (Consent once our cookie preference tool is available)
Advertising Measure ad performance, build audiences and show relevant ads Meta Pixel (_fbp, _fbc) Legitimate interests (Consent once our cookie preference tool is available)

10.2 We are introducing a cookie preference tool that will let you accept or reject non-essential Cookies. Until it is available, you can block or delete Cookies through your browser settings, opt out of Google Analytics using Google’s browser add-on (tools.google.com/dlpage/gaoptout), and manage Meta advertising in your Meta ad preferences. Parts of the Services may not work without strictly necessary Cookies.

10.3 Conversions API. We also send event data directly from our servers to Meta through its Conversions API. This may include the event type (for example, a search, a started booking or a purchase), the booking value and currency, your IP address, browser identifiers, and your email address and telephone number in hashed form (irreversibly transformed using SHA-256 before transmission). Meta uses this data to match events to its users and to measure and improve advertising. We do not send travel-document data, dates of birth or payment-card data to Meta.

11. Retention

11.1 We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting or reporting requirements, and then securely delete or irreversibly anonymise it.

Data Retention period
Booking, transaction and invoice records, and records of acceptance of terms Six (6) years from the end of the financial year in which the booking was made
Travel-document data on a booking Passed to the airline to issue your ticket and not kept in our booking records. Technical logs that may contain it are access-restricted.
Travel-document data saved to an account profile Until you delete it or close your account
Account, saved passenger and PadiMiles data For the life of the account, and three (3) years after last activity
Communications with Ava and our team Twenty-four (24) months after the last message. Voice notes, images and documents: ninety (90) days. This includes any special-assistance information you share with us.
Consent and opt-out records For as long as the related processing continues, and three (3) years after
Security and system logs Up to one hundred and eighty (180) days
Analytics data Google Analytics: up to fourteen (14) months. Microsoft Clarity: up to thirty (30) days for recordings.

11.2 We may retain personal data for longer than the periods above where required by law, or where reasonably necessary to establish, exercise or defend a legal claim. In that case, we retain only the data relevant to the obligation or claim, and only for as long as it applies.

12. Security and personal data breaches

12.1 We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, having regard to the nature of the data and the risks of the processing. These measures include:

  • encryption of data in transit;
  • network firewalls and web-application protection;
  • role-based access controls and activity logging;
  • contractual data protection terms with our service providers; and
  • outsourcing card processing to a PCI-DSS-compliant payment provider.

12.2 No method of transmission or storage is entirely secure, and we cannot guarantee absolute security.

12.3 If a personal data breach is likely to result in a risk to the rights and freedoms of Data Subjects, we will notify the NDPC within seventy-two (72) hours of becoming aware of it. Where the breach is likely to result in a high risk, we will also notify affected Data Subjects without undue delay, in plain language, with a description of the breach, its likely consequences, and the measures taken and recommended.

13. Your rights

13.1 Subject to the conditions and exemptions in the NDPA, you have the right to:

  • (a) Access: obtain confirmation of whether we process your personal data, a copy of it, and information about the purposes, recipients, retention and source of the processing;
  • (b) Rectification: have inaccurate personal data corrected and incomplete data completed;
  • (c) Erasure: have personal data erased where it is no longer necessary, where Consent is withdrawn and no other lawful basis applies, where you have objected successfully, or where it has been processed unlawfully;
  • (d) Restriction: have processing restricted while accuracy or an objection is being verified, or where processing is unlawful and you prefer restriction to erasure;
  • (e) Objection: object to processing based on legitimate interests. You may object to direct marketing at any time, and we will stop.
  • (f) Portability: receive personal data you provided to us in a structured, commonly used and machine-readable format, and have it transmitted to another Data Controller where technically feasible, where processing is based on Consent or contract and carried out by automated means;
  • (g) Withdrawal of Consent: withdraw Consent at any time, without affecting prior lawful processing;
  • (h) Automated decisions: not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to obtain human intervention, express your view and contest the decision; and
  • (i) Complaint: lodge a complaint with the NDPC (see clause 17).

13.2 How to exercise your rights. Send a request to [email protected] or message us on WhatsApp, stating the right you wish to exercise and, where relevant, the booking reference.

13.3 Verification. To protect your data, we may ask you to verify your identity before acting on a request. Normally we do this by a one-time code sent to the email address or telephone number on the booking or account. We will not ask for more information than is necessary to verify you.

13.4 Authorised representatives. A person may make a request on your behalf if they provide evidence of their authority, such as a signed authorisation or a power of attorney. A parent or legal guardian may exercise rights on behalf of a child.

13.5 Timeframe and fees. We will respond within thirty (30) days of receiving a verified request. Where a request is complex, or we receive several requests, we may extend this period by up to a further thirty (30) days, and will tell you of the extension and the reasons. We do not charge a fee, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline the request, with reasons.

13.6 Limitations. We may decline or limit a request where the NDPA permits, including where we must retain data to comply with a legal obligation, or to establish, exercise or defend a legal claim, or where fulfilling it would adversely affect the rights of others. Erasure of data held by us does not erase data held by airlines or other independent Data Controllers. We will tell you how to contact them.

14. Direct marketing

14.1 We may send marketing communications by email, SMS or WhatsApp about travel services similar to those you have booked or enquired about, or where you have consented to receive them.

14.2 You may opt out at any time by replying STOP to any WhatsApp message from us, by using the unsubscribe link in an email, or by contacting the Data Protection Officer. We will act on your request promptly.

14.3 Opting out of marketing does not affect service communications about a booking or account, which are necessary to perform our contract with you.

15. Your responsibilities

You agree to:

  • (a) provide accurate, complete and current personal data, and ensure that passenger names match the travel documents used for travel;
  • (b) comply with clause 4.2 when providing personal data about others;
  • (c) keep the one-time codes and credentials used to access your account confidential, and tell us promptly of any unauthorised use; and
  • (d) not send full payment-card details, PINs or passwords to us by WhatsApp, email or any other messaging channel. We will never ask for them. Payment must be made only through our secure payment pages.

16. Third-party websites and services

The Services may contain links to, or integrations with, websites and services operated by third parties, including airlines, Paystack, WhatsApp, Google, Microsoft and Meta. We are not responsible for their privacy practices, and we encourage you to read their privacy notices:

  • Paystack: paystack.com/privacy
  • WhatsApp: whatsapp.com/legal/privacy-policy
  • Meta: facebook.com/privacy/policy
  • Google: policies.google.com/privacy
  • Microsoft: privacy.microsoft.com/privacystatement

17. Complaints

17.1 If you have a concern about our processing of personal data, please contact the Data Protection Officer first. We will acknowledge your complaint within five (5) working days and aim to resolve it within thirty (30) days.

17.2 You have the right to lodge a complaint with the NDPC at any time:

  • Address: No. 5 Donau Crescent, off Amazon Street, Maitama, Abuja, Nigeria
  • Email: [email protected]
  • Website: ndpc.gov.ng

17.3 Nothing in this Policy limits any right you may have to seek a judicial remedy.

18. Children

18.1 In this Policy, a child is anyone under eighteen (18) years of age, even if an airline classes them as an adult passenger (usually from age 12).

18.2 A booking or account may be made only by a person aged eighteen (18) years or older.

18.3 We process personal data of children only where it is provided by a parent, legal guardian or another adult acting with appropriate authority, for the purpose of booking and supporting that child’s travel. We do not send marketing communications to children, or knowingly use children’s data for advertising.

18.4 If you believe we hold a child’s personal data without appropriate authority, please contact the Data Protection Officer and we will take prompt steps to delete it.

19. Changes to this Policy

19.1 We may update this Policy to reflect changes in our processing or in applicable law. The current version and its effective date are shown at the top of this page.

19.2 Where a change materially affects how we process your personal data, we will notify you by email or WhatsApp before the change takes effect. Where the change requires your Consent, we will ask for it.

20. General

20.1 This Policy is governed by the laws of the Federal Republic of Nigeria.

20.2 If there is any inconsistency between the Key Points summary and the remainder of this Policy, the remainder of this Policy prevails.

20.3 If this Policy is translated, the English version prevails.

20.4 If any provision of this Policy is found to be invalid or unenforceable, the remaining provisions continue in full force.

Schedule 1: Categories of Data Processors

Category Data processed Location
Cloud hosting and website security All categories held in our systems European Union; global delivery network
Payment processing (Paystack) Contact, transaction Nigeria and abroad
Messaging (WhatsApp Business) Contact, communications United States / global
SMS and email delivery providers Contact, message content Nigeria; United States
AI model providers Communications content United States
Analytics (Google Analytics, Microsoft Clarity) Technical and usage United States
Advertising measurement (Meta) Technical, hashed contact, booking events United States / global

We may update this Schedule as our providers change. A current list is available on request from the Data Protection Officer.