FlightMoneyBack.eu
AVG / GDPR

Privacy policy

Last updated: 28 juli 2026

Data controller

Twilper (trading as FlightMoneyBack.eu), sole proprietorship registered at Merelstraat 64, 8916 AX Leeuwarden, KvK 98440217, VAT NL005332508B94. Contact: privacy@flightmoneyback.eu.

What data do we process?

  • Identification: first and last name, date of birth, nationality;
  • Contact: email, phone number, postal address;
  • Financial: IBAN + account holder name (solely for payout identification);
  • Flight data: flight number, date, route, PNR booking reference, ticket class, delay facts;
  • Audit: IP address and timestamp of authorisation agreement (legal evidence).

Purposes

  1. Assessing whether EU261 applies to the flight and calculating the claim amount;
  2. Preparing and sending the claim letter to the airline;
  3. Tracking correspondence, neutral reminders and a competent enforcement or ADR route only after policy review;
  4. Recording the Stripe payment mandate and collecting the success fee after a confirmed payout;
  5. Complying with statutory record-keeping obligations (VAT, KvK).

Legal basis

Processing is based on:

  • Performance of a contract (Art. 6(1)(b) GDPR) - executing the claim service you requested;
  • Legal obligation (Art. 6(1)(c) GDPR) - fiscal administration;
  • Legitimate interest (Art. 6(1)(f) GDPR) - IP logging for fraud prevention and legal evidence.

Who do we share your data with?

  • Airline: claim letter including name, IBAN, flight data and proof of authorisation;
  • Stripe: to store the payment mandate and collect the success fee after a confirmed payout;
  • Resend: transactional email delivery as a processor;
  • Aerodatabox / RapidAPI: flight number + date only (no personal data) for flight status verification;
  • National enforcement body or ADR entity: only after confirming that the entity is competent for the incident and country;
  • Tax authorities: VAT administration via Twilper sole proprietorship.

We never sell your data to third parties for marketing purposes.

Retention periods

  • Claim files, consents and correspondence: for as long as necessary for the contract, applicable national periods and the substantiation of legal claims;
  • Financial administration: 7 years (statutory fiscal obligation);
  • Magic-link tokens: maximum 24 hours after issuance;
  • Inactive accounts without claims: deleted after 12 months of inactivity upon request.

Your rights

Under the GDPR, you have the right to:

  • Access to your personal data (Art. 15);
  • Rectification of inaccurate data (Art. 16);
  • Erasure ('right to be forgotten', Art. 17) - except data required for an ongoing claim or fiscal obligation;
  • Restriction of processing (Art. 18);
  • Object to processing (Art. 21);
  • Data portability (Art. 20).

Requests can be sent to privacy@flightmoneyback.eu. We will respond within 30 days. Complaint about our handling of personal data? You can report it to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP).

Cookies

Essential cookies secure login, language choice and case files. First-party funnel measurement, GA4/GTM and any configured marketing pixels load only after you grant analytics consent. Declining does not affect the claim service; your choice is stored for one year and can be reset by deleting the cookie.

Security

Personal data is stored encrypted (TLS in transit, encryption-at-rest on managed Postgres). Passwords are hashed with bcrypt. Access is limited to authorised admin of Twilper sole proprietorship.