Use less data. Protect it more.
FareSift is a Michai Media product. Ordinary beta use does not request passport numbers, known-traveler numbers, full payment-card numbers, CVV, or protected health information. An activated live booking asks only for the traveler facts the selected airline offer requires.
Data we use
Trip constraints, signed-in traveler preferences, watch rules and observations, AI decision runs and feedback, support requests, subscription intent, limited Stripe billing identifiers, launch-list consent, optional service requests, outbound seller clicks, referrals, and minimized product events. If native booking is activated, FareSift processes legal name, title, booking gender, date of birth, email, phone, offer and order identifiers, total, route, carrier, order state, and issuer booking reference for the travelers in that order.
Attribution and browser storage
FareSift uses a signed, HttpOnly first-party visitor pseudonym for up to 90 days so rate limits, anonymous feedback, privacy controls, and first-party measurement remain tied to the same browser without storing the cookie value in analytics. A referral first-touch code may also remain for up to 90 days. Global Privacy Control or Do Not Track prevents persistent visitor attribution and first-party analytics collection.
Public-page affiliate tooling
On a small allowlist of public marketing and editorial pages, Travelpayouts Drive may inspect page context, observe interaction signals, use browser storage, rewrite eligible travel links, or place affiliate tools. It is excluded from search results, accounts, admin, checkout, payment, booking, support, legal, and private-trip pages and suppressed for Global Privacy Control or Do Not Track.
Why we use it
To operate the product, calculate traveler-specific cost, save searches, produce deterministic recommendations, measure reliability, attribute eligible referrals, respond to support, manage subscriptions, enforce legitimate fare eligibility, create an explicitly authorized order, send confirmation, reconcile provider state, and service a booking.
Payment and AI boundary
Duffel’s hosted card form and 3-D Secure handle airfare card details; Stripe-hosted Checkout handles FareSift subscriptions. FareSift does not receive or store the complete card number or CVV. Direct identifiers, payment hints, passport-like tokens, known-traveler numbers, accessibility or dietary details, and raw documents must be removed before any production AI call. Prices, eligibility, rules, payment identifiers, and transactions remain outside generative-model authority.
Retention and choices
Signed-in users can download attributable FareSift records and request deletion from the account page. Anonymous visitors can use the controls below for the current signed browser pseudonym. Signed-in deletion pseudonymizes narrowly retained billing and audit evidence, and separately pseudonymizes terminal production flight-order evidence while removing its encrypted contact. A non-reversible email suppression prevents renewed contact. An active subscription must be canceled first. A pending, confirmed, or otherwise serviceable production flight order must be resolved before deletion so FareSift does not erase its contact and abandon an airline obligation.
Your pseudonymous activity stays within reach.
Download or delete records linked to this browser’s signed visitor pseudonym. Signed-in account data uses the controls on the account page.
Deletion boundary
Self-service deletion covers FareSift’s application database. It does not itself cancel or delete records held independently by an authentication provider, Duffel, airline, seller, payment processor, email provider, or affiliate network. Operator model-control records and global provider-event hashes are not traveler account records. Using FareSift again after deletion may create new activity.
Storage and processors
Application records use the managed database. The booking-contact duplicate is encrypted with a context-bound envelope; complete card data is excluded. Duffel processes enabled flight search, card authentication, order creation, and airline servicing. Stripe processes activated FareSift subscription payments. Resend processes enabled transactional correspondence. Travelpayouts processes limited eligible public-page affiliate activity and cached discovery requests when its separate gates are enabled. Each live provider is identified before its data is represented as active inventory.
Regulated-data boundary
FareSift is not currently a HIPAA covered entity or business associate and does not claim HIPAA compliance. A regulated use case requires a separate legal determination, approved vendors, agreements, and validated controls before activation.