Privacy Policy
Version 1.0 · July 2026
Contents
Introduction
This Privacy Policy explains how TKTZ.FLY Inc. ("TKTZ", "we", "the Platform") collects, uses, shares, and protects personal information relating to you when you use the website and the services at www.tktz.io (the "Service"). Please read it carefully. Your use of the Service confirms that you have read and understood this Policy.
1. The Nature of the Platform and Its Effect on Your Data
TKTZ is a technology marketplace (a platform) that connects users with airline-ticket suppliers and wholesalers. TKTZ is not the seller of the ticket. The purchase of the ticket and the contractual relationship are concluded with the supplier/wholesaler, and payment is collected and processed by that party. Consequently, where an order is placed, some of your information (including passenger details) is transferred to the relevant supplier, who processes it as an independent data controller in accordance with its own privacy policy. We recommend that you also review the policy of the supplier through which the order is placed.
2. Scope
This Policy applies to users of the Service in Israel, in the European Economic Area (EEA) and the United Kingdom, and in the United States. Depending on your place of residence, additional rights may apply to you — see Section 10. In the event of a conflict between a general provision and a jurisdiction-specific provision, the jurisdiction-specific provision shall prevail for residents of that jurisdiction.
3. What Data We Collect
We collect the following types of information:
- Identification and contact details: name, email address, telephone number, and details you provide when opening an account or contacting us.
- Passenger details for transferring an order to a supplier: name as it appears on the travel document, passport/ID number, date of birth, and nationality — to the extent required by the supplier/carrier to issue the ticket. This information may be considered “information of special sensitivity” under Israeli law.
- Usage and trading data: searches, routes, views, price quotes, buy/bid offers, and your activity history on the marketplace.
- Technical data: IP address, device and browser identifiers, operating system, usage data and logs, and cookies (see Part C).
- Communications and support: correspondence, service inquiries, and feedback.
We do not collect and do not process your payment data (credit-card number, security code, etc.). Payment is made directly with the supplier/wholesaler and is processed by it or by its payment processor. To the extent you provide payment details, they are provided to the supplier and not to us.
4. Purposes of Processing and Legal Basis
We process personal information for the following purposes and on the following legal bases (as applicable under the law that governs you):
- Providing the Service and operating the marketplace, including transferring orders to suppliers — for the performance of our engagement with you, or based on your consent.
- Improvement, security, and fraud prevention — based on our legitimate interest in operating a safe and reliable marketplace.
- Mailings and direct marketing — based on your consent, which may be withdrawn at any time (see Section 11).
- Compliance with legal obligations — including customer-identification obligations, anti-money-laundering requirements, and regulatory requirements (see Part E).
The provision of information by you is voluntary; however, certain information is required to complete an order, and without it we will be unable to provide part of the Service.
5. Disclosure of Information to Third Parties
We are not “data brokers.” We may disclose personal information to the following parties, to the extent necessary:
- Suppliers and wholesalers for the purpose of carrying out the order and issuing the ticket. From the moment of transfer, the supplier processes the information as an independent controller and its policy applies.
- Infrastructure and service providers acting on our behalf (hosting/cloud, analytics, communications, support) — as processors on our behalf, subject to confidentiality and security undertakings.
- Competent authorities — where required by law, by judicial order, or to protect rights, property, or safety.
- In the context of a corporate transaction — a merger, acquisition, capital raise, or RTO transaction, subject to the maintenance of confidentiality and appropriate safeguards.
6. Cross-Border Transfers of Information
Our activity is cross-border, and therefore information may be processed or stored outside your country of residence, including in Israel, the European Union, and the United States. We have taken measures to ensure an adequate level of protection:
- Transfers from the EEA/UK: Israel is currently recognized by the European Union as a country with an adequate level of protection (adequacy), so the transfer of information from the EEA to Israel is permitted without an additional mechanism. Onward transfers (including to the U.S. or to suppliers outside adequacy countries) are carried out on the basis of recognized mechanisms under Chapter V of the GDPR — including Standard Contractual Clauses (SCCs) and/or relevant adequacy decisions.
- Transfers from Israel: are carried out in accordance with the Protection of Privacy Regulations (Transfer of Information to Databases Abroad).
For any question regarding the applicable transfer mechanism and to obtain a copy of the safeguards, you may contact us using the details in Section 14.
7. Cookies and Tracking Technologies
We use cookies and similar technologies. Non-essential cookies are activated based on your consent, which you can manage at any time. For full details, see Part C — Cookie Policy.
8. Information Security
We take reasonable organizational and technological measures to protect the information (including access controls, encryption in transit, monitoring, and logging), in accordance with the Protection of Privacy Regulations (Information Security) and accepted standards. However, no system is entirely immune, and we cannot guarantee absolute security. In the event of a security incident requiring notification, we will act in accordance with applicable law.
9. Data Retention Periods
We retain personal information for as long as necessary to fulfil the purposes for which it was collected, including compliance with legal obligations (such as tax, accounting, and AML obligations), resolving disputes, and enforcing our rights. Specific retention periods:
- Account information: Retained for the duration of your account and for up to seven (7) years after account closure where necessary to comply with applicable legal, tax, accounting, regulatory, or recordkeeping obligations, or to establish, exercise, or defend legal claims.
- Booking, ticket, and transaction records: Retained for up to seven (7) years from the completion of the relevant transaction.
- Customer support communications: Retained for up to three (3) years after the support request is resolved, unless a longer retention period is necessary for legal claims or regulatory compliance.
- Payment information: We do not retain full payment card details. Payment information is processed and retained by our payment service providers in accordance with their legal and regulatory obligations. We may retain limited transaction metadata for up to seven (7) years.
- Marketing preferences and communications: Retained until you withdraw your consent or unsubscribe, or for up to two (2) years after your last interaction with us, whichever occurs first, unless a longer retention period is required by applicable law.
- Technical, security, and audit logs: Retained for up to twelve (12) months, unless a longer retention period is reasonably necessary for fraud prevention, security investigations, legal compliance, or the establishment, exercise, or defense of legal claims.
- Legal claims and compliance records: Retained until the applicable statute of limitations has expired and any related proceedings have been finally resolved. At the end of the period, the information will be deleted or anonymized.
10. Your Rights
Subject to the law applicable to you, you have the following rights. To exercise a right, contact us using the details in Section 14; we may verify your identity, and we will not discriminate against you for exercising a right.
10.1 Residents of Israel
In accordance with the Protection of Privacy Law, 5741–1981 (as amended by Amendment No. 13, which entered into force on 14 August 2025): the right to be informed about the collection of information and its purposes; the right to access information about you; the right to request the correction or deletion of information that is incorrect, incomplete, unclear, or out of date; and the right to request removal from a mailing list. If you are dissatisfied with the handling of your request, you may contact the Privacy Protection Authority.
10.2 Residents of the EEA and the UK (GDPR)
The right of access; the right to rectification; the right to erasure (“the right to be forgotten”); the right to restriction of processing; the right to data portability; the right to object to processing (including direct marketing); the right to withdraw consent at any time; and the right to lodge a complaint with a supervisory authority. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
10.3 Residents of the United States
Residents of states with comprehensive privacy legislation (including residents of California under the CCPA/CPRA) are entitled, subject to law: to know what information is collected and how it is used; to delete information; to correct information; to limit the use of sensitive information; and to opt out of the “sale” or “sharing” of personal information. We do not sell personal information for money. To the extent that a particular activity constitutes “sharing” for targeted-advertising purposes, you may opt out via sending a request to privacy@tktz.io, and we honor browser-based opt-out preference signals (GPC). The right to non-discrimination for exercising rights also applies. Residents of other states may enjoy comparable rights under the law of their state.
11. Direct Marketing
Where you have given your consent, we will send you mailings and updates. You may withdraw consent at any time via the unsubscribe link in the message or by contacting us, in accordance with Section 30A of the Communications Law (Telecommunications and Broadcasting) and applicable law.
12. Minors
The Service is intended for those aged 18 and over and is not directed at minors. We do not knowingly collect information from minors. If you become aware that a minor has provided us with information, please contact us and we will act to delete it in accordance with law.
13. Changes to the Policy
We may update this Policy from time to time. An updated version will be published on the website with an update date noted. A material change will be brought to your attention by reasonable means. Continued use after the update constitutes consent to the updated version.
14. Contact, Privacy Officer, and EU Representative
Database controller / Controller: TKTZ.FLY Inc., a Delaware corporation
Email for privacy inquiries: privacy@tktz.io
Privacy Officer / DPO: Tahel Shomron. Contact details: tahel@tktz.io