Trestavia.com and Trestavia Travels are official registered trade names owned and operated by People Information LLC.
People Information LLC, operating as Trestavia Travels (“Trestavia,” “we,” “our,” or “us”), is committed to protecting your privacy and handling your personal information with transparency, integrity, and care. This Privacy Policy describes what personal information we collect, why we collect it, how we use and share it, and the rights available to you when you use trestavia.com (the “Site”) or any service we provide.
By accessing or using the Site or our services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Site.
We may update this Privacy Policy at any time. You can determine when it was last revised by checking the “Last updated” date above. Continued use of the Site after any update constitutes your acceptance of the revised policy.
Quick Navigation
- 1. Information We Collect
- 2. How We Use Your Information
- 3. Legal Basis for Processing
- 4. How We Share Your Information
- 5. Booking for Other Travelers
- 6. Cookies & Advertising Technologies
- 7. Google Ads & Conversion Tracking
- 8. Do Not Track
- 9. Data Security
- 10. Data Retention
- 11. International Data Transfers
- 12. Your Privacy Rights
- 13. California Residents — CCPA
- 14. Children's Privacy
- 15. Phishing & Identity Theft Awareness
- 16. Third-Party Links
- 17. Data Breach Notification
- 18. Changes to This Policy
- 19. Contact Us
1. Information We Collect
Information you provide directly
- Identity & contact information: Full legal name, email address, phone number, billing address, and mailing address.
- Booking & passenger information: Passenger names (as they appear on government-issued ID), dates of birth, nationality, passport or travel document numbers, expiry dates, travel dates, origin and destination airports, cabin class, and special service requests (meal preferences, seat selection, wheelchair assistance, frequent flyer numbers).
- Payment information:Credit or debit card details (card number, cardholder name, expiry date, billing ZIP/postal code) are collected solely to authorize and process your booking. Card data is tokenized via NMI’s secure infrastructure, Inc. using end-to-end encryption. We do not store full card numbers on our servers.
- Communications: Messages, inquiries, complaints, or requests submitted by phone, email, web form, or any other channel.
- Traveler preferences: Optional information such as travel insurance interest, preferred airlines, seat type preferences, and loyalty program memberships.
Information collected automatically
- Usage data: Pages visited, flight search queries, links clicked, time spent on each page, booking funnel steps completed, and the referring website or advertisement that brought you to us.
- Device & technical data: IP address, browser type and version, operating system, screen resolution, device type, and time zone.
- Cookies and similar technologies: See Section 6 for a full description of our cookie practices.
Information from third-party sources
We may periodically receive information about you from business partners, advertising networks (such as Google), or other independent third-party sources — for example, updated contact information, fraud-prevention signals, or demographic data used to improve the relevance of our advertising. We combine this information with data we already hold and use it only in accordance with this Privacy Policy.
2. How We Use Your Information
We use your personal information for the following purposes:
- To process, confirm, manage, and fulfill your flight booking and related services.
- To send booking confirmations, e-tickets, itinerary updates, and schedule change notifications.
- To communicate with you in response to inquiries, complaints, or service requests.
- To verify your identity and prevent fraudulent or unauthorized transactions.
- To comply with airline ticketing requirements, tax obligations, and other applicable laws.
- To manage your account, process billing, and provide travel notifications.
- To improve the Site, our services, and customer experience using aggregated, anonymized analytics.
- To measure the effectiveness of our advertising campaigns using anonymized conversion data.
- To send promotional communications about exclusive fares or travel offers — only if you have expressly opted in. You may unsubscribe at any time.
- To resolve disputes, enforce our Terms of Service, and investigate suspected violations.
- To prevent, detect, and investigate fraud, security incidents, or other illegal activities.
We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects. We do not use your search history or browsing behavior to adjust the prices displayed to you. All fares are fetched live from airline inventory at the time of each search.
3. Legal Basis for Processing
Where applicable law requires a legal basis for processing your personal information (such as the EU General Data Protection Regulation, GDPR), we rely on the following:
- Contract performance: Processing necessary to complete your booking, issue your e-ticket, and provide the services you requested.
- Legal obligation: Processing required to comply with applicable laws, including tax regulations, anti-money-laundering rules, and airline reporting requirements.
- Legitimate interests: Processing necessary for fraud prevention, website security, business analytics (in anonymized form), and improving our services — where your interests do not override ours.
- Consent: Processing based on your explicit consent, such as receiving promotional marketing emails. You may withdraw consent at any time without affecting the lawfulness of prior processing.
4. How We Share Your Information
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
We may share your information with the following categories of recipients:
- Airlines and Global Distribution Systems (GDS): Passenger information (names, passport details, travel dates) is transmitted to the relevant airline and/or GDS as required to search, reserve, and ticket your flights. These parties may have their own data retention and privacy obligations under aviation law. We restrict their use of your email address to fulfillment of your reservation only.
- Payment processors — NMI (Network Merchants Inc.):Tokenizes and vaults card data under NMI’s PCI-DSS Level 1 certified infrastructure and Privacy Policy.
- Email delivery — Resend, Inc.: Delivers transactional confirmation emails on our instruction. No independent use of your email data is permitted.
- Fraud prevention & identity verification services: Third-party providers that help us identify and prevent unauthorized transactions. These providers process data only under our instruction.
- Analytics — Google Analytics (GA4): We use Google Analytics to understand how visitors use the Site. Data is collected with IP anonymization enabled and used only in aggregated, non-identifiable form.
- Advertising networks — Google Ads: We use Google Ads conversion tracking and, where applicable, remarketing features. See Section 7 for full details.
- Legal authorities: We may disclose information in response to a valid subpoena, court order, regulatory request, or as otherwise required by applicable law. We will notify you of such disclosure where legally permitted.
- Business transfers: In the event of a merger, acquisition, divestiture, or sale of all or substantially all of our assets, your information may be transferred as part of that transaction, subject to equivalent privacy protections.
- Aggregated or anonymized data: We may share anonymized, aggregated statistical information (e.g., popular routes, booking volumes) with business partners and advertisers. This data cannot be used to identify you.
All third-party service providers are contractually required to protect your information and may only use it for the specific services they perform on our behalf.
5. Booking for Other Travelers
When you book travel for other passengers through Trestavia, you will be asked to provide personal information about those individuals. By doing so, you confirm that you have obtained their consent to share their personal information with us and to have it processed in accordance with this Privacy Policy. Access to view or modify other passengers’ booking information is available only through your account or by contacting us directly.
6. Cookies & Advertising Technologies
We use cookies, pixel tags, and similar technologies to operate and improve the Site, analyze usage, and deliver relevant advertising. The categories we use are:
- Strictly necessary cookies: Essential for the Site to function (session management, booking flow state, security tokens). These cannot be disabled without impairing core functionality.
- Performance & analytics cookies: Google Analytics (GA4) measures page views, user flows, and feature usage. All data is collected under IP anonymization. You may opt out at any time using the Google Analytics Opt-out Browser Add-on.
- Advertising & conversion cookies: Google Ads conversion tracking records when a user who clicked one of our advertisements completes a booking. Remarketing cookies allow Google to show Trestavia advertisements to users who have previously visited our Site on other websites. These cookies expire after 90 days and do not contain personally identifiable information. See Section 7.
- Functional / preference cookies: Remember your search preferences (trip type, cabin class, passenger count). Expire within 30 days.
Important — no dynamic pricing via cookies: We never use cookies or tracking data to raise the prices you see. Every fare is fetched live from airline inventory at the time of your search. Your browsing history has no effect on the fares displayed.
You may manage or disable non-essential cookies through our cookie consent banner, your browser settings, or the following opt-out tools:
Disabling advertising or analytics cookies will not affect your ability to search or book flights on trestavia.com.
7. Google Ads & Conversion Tracking
We advertise on Google Search and other Google properties. In connection with those campaigns, we use the following Google technologies:
- Google Ads Conversion Tracking: When you click a Trestavia advertisement on Google and subsequently complete a booking, a conversion cookie is set by Google to measure the effectiveness of our ad. This cookie contains no personal information. It expires after 90 days. The conversion data we receive is aggregated and does not identify individual users.
- Google Ads Remarketing: We may use the Google Ads remarketing feature to display Trestavia advertisements to users who have previously visited our Site. Google uses cookies stored on your browser to serve these ads. You may opt out of personalized advertising by visiting Google’s Ad Settings or www.aboutads.info.
- Google Consent Mode: Our Site implements Google Consent Mode v2, which adjusts how Google tags operate based on your cookie consent choices. If you decline advertising cookies, conversion pings are sent in a cookieless, modeled format only — no personal data is transmitted.
Google’s use of advertising data is governed by Google’s Privacy Policy. We do not transmit personally identifiable information to Google for advertising purposes without your explicit consent.
8. Do Not Track
Some browsers offer a “Do Not Track” (DNT) signal to express that you do not wish to be tracked across websites. Because there is currently no universally accepted technical standard for honoring DNT signals, our Site does not currently alter its behavior in response to DNT browser settings. You may use the opt-out tools listed in Section 6 to control advertising-related tracking.
9. Data Security
We implement a layered set of administrative, technical, and physical security controls to protect your personal information:
- Encryption in transit: All data exchanged between your browser and our servers is protected by TLS 1.2 / TLS 1.3 (HTTPS).
- Encryption at rest: Sensitive database fields are encrypted at rest on our hosting infrastructure.
- Payment security: Card data is handled exclusively by NMI’s PCI-DSS Level 1 certified infrastructure. We never store raw card numbers on our servers.
- Access controls: Access to personal data is restricted to authorized personnel who require it for their job function. All access is logged.
- Cloudflare protection: Our Site is protected by Cloudflare’s DDoS mitigation and Web Application Firewall.
- Ongoing monitoring: We monitor our systems for unauthorized access, anomalous activity, and known vulnerabilities.
No method of transmission over the internet is 100% secure. While we use industry-leading practices to protect your data, we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
10. Data Retention
We retain your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required by law:
- Booking records & passenger data: 7 years, to comply with U.S. tax, airline reporting, and travel industry regulations.
- Payment records: 7 years, for tax and accounting compliance. Raw card data is never stored.
- Customer service communications: 3 years from the date of the last interaction.
- Marketing consent records: Until you withdraw consent, plus an additional 3 years as proof of consent.
- Analytics & usage data: 26 months (Google Analytics default retention).
- Cookie data: As defined for each cookie type in Section 6.
When retention periods expire, data is deleted or irreversibly anonymized. You may request earlier deletion (see Section 12), subject to legal retention obligations.
11. International Data Transfers
Trestavia Travels is based in the United States. If you access our Site from outside the U.S., your information will be transferred to and processed in the U.S., which may not have data protection laws equivalent to your home country.
Where we transfer personal data originating from the European Economic Area (EEA), United Kingdom, or Switzerland to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or another lawful transfer mechanism. For further details on our transfer safeguards, please contact us at support@trestavia.com.
When you provide us with personal information to book travel, you acknowledge and consent to the transfer of that information to the U.S. and to the relevant airline, as required to complete your reservation.
12. Your Privacy Rights
Depending on your location, you may have the following rights with respect to your personal information. To exercise any of these rights, contact us at support@trestavia.com. We will respond within 30 days (or as required by applicable law). We may need to verify your identity before fulfilling your request.
- Right of access: Receive a copy of the personal data we hold about you, including the categories, sources, purposes, and recipients.
- Right to correction (rectification): Request correction of inaccurate or incomplete personal data.
- Right to deletion (erasure): Request that we delete your personal data, subject to legal retention requirements. We will inform you if deletion is not possible for a specific record.
- Right to restrict processing: Request that we limit how we use your data while a correction or objection is being resolved.
- Right to data portability: Receive your personal data in a structured, machine-readable format to transfer to another provider, where technically feasible.
- Right to object: Object to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of prior processing.
- Opt out of marketing: Unsubscribe from promotional emails at any time using the unsubscribe link in each email or by emailing us. We will process your request within 10 business days.
- Right to lodge a complaint: If you believe we have not complied with applicable data protection law, you have the right to lodge a complaint with your national or state data protection supervisory authority.
13. California Residents — California Consumer Privacy Act (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights regarding your personal information:
- Right to know: The categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose for collecting it, and the categories of third parties with whom we share it.
- Right to delete: Request deletion of personal information we have collected about you, subject to certain exceptions.
- Right to correct: Request correction of inaccurate personal information.
- Right to opt out of sale or sharing: We do not sell or share your personal information for cross-context behavioral advertising. If this practice changes, we will update this Policy and provide a “Do Not Sell or Share My Personal Information” link.
- Right to limit use of sensitive personal information: We use sensitive information (passport numbers, payment data) only as necessary to complete your booking. We do not use it for other commercial purposes.
- Right to non-discrimination: We will not discriminate against you for exercising any CCPA right.
To submit a CCPA request, email support@trestavia.com or call +1-800-779-8593. We will acknowledge your request within 10 business days and respond within 45 calendar days (extendable by an additional 45 days with notice).
California residents may also have rights under the California Travel Consumer Restitution Fund (TCRF). See our Terms of Service §19 for full details.
14. Children’s Privacy
Our Site is not directed to, and we do not knowingly collect personal information from, children under the age of 13. We do not sell travel products for purchase by children acting independently. If a parent or guardian believes that a child under 13 has provided us with personal information without consent, please contact us immediately at support@trestavia.com and we will promptly delete that information from our records.
15. Phishing & Identity Theft Awareness
Trestavia Travels will never request your credit card number, account password, or full passport number via an unsolicited email, SMS, or social media message. We will only contact you by email or phone in direct response to an inquiry you have made or a booking you have placed.
If you receive a communication that claims to be from Trestavia and asks for sensitive information in an unsolicited manner, do not respond — report it to support@trestavia.com immediately. For general guidance on phishing and identity theft, visit the Federal Trade Commission or FTC phishing guidance.
16. Third-Party Links
Our Site may contain links to third-party websites, including airline booking portals, travel advisory pages, and mapping services. These websites operate under their own privacy policies, which we do not control and are not responsible for. We encourage you to review the privacy policy of any website you visit before providing personal information.
17. Data Breach Notification
In the event of a security incident that results in the unauthorized access or disclosure of your personal information, we will:
- Assess the nature and scope of the incident promptly.
- Notify affected individuals and relevant regulatory authorities within the timeframes required by applicable law (e.g., 72 hours under GDPR; the timeframe required under applicable U.S. state breach notification laws).
- Provide clear information about what data was involved, the likely consequences, and the steps we are taking to address the incident and prevent recurrence.
18. Changes to This Privacy Policy
We may update this Privacy Policy at any time by posting the revised version on this page with an updated “Last updated” date. For material changes — such as new categories of data collection or new sharing practices — we will provide a prominent notice on the Site and, where we have your email address on file, notify you directly. Your continued use of the Site following notification of a material change constitutes your acceptance of the updated policy.
19. Contact Us
For any privacy-related questions, access requests, deletion requests, or complaints, please contact our Privacy team:
Trestavia Travels — PrivacyPeople Information LLC (DBA Trestavia Travels)
1350 W Van Buren St APT 1014
Phoenix, AZ 85007
support@trestavia.com
+1-800-779-8593 (24 hours · 7 days a week)