Privacy policy
Last updated: July 12, 2026
Data controller
Twilper (trading as FlightMoneyBack.eu), sole proprietorship registered at Merelstraat 64, 8916 AX Leeuwarden, KvK 98440217, VAT NL005332508B94. Contact: privacy@flightmoneyback.eu.
What data do we process?
- Identification: first and last name, date of birth, nationality;
- Contact: email, phone number, postal address;
- Financial: IBAN + account holder name (solely for payout identification);
- Flight data: flight number, date, route, PNR booking reference, ticket class, delay facts;
- Audit: IP address and timestamp of authorisation agreement (legal evidence).
Purposes
- Assessing whether EU261 applies to the flight and calculating the claim amount;
- Preparing and sending the claim letter to the airline;
- Tracking correspondence, neutral reminders and a competent enforcement or ADR route only after policy review;
- Recording the Stripe payment mandate and collecting the success fee after a confirmed payout;
- Complying with statutory record-keeping obligations (VAT, KvK).
Legal basis
Processing is based on:
- Performance of a contract (Art. 6(1)(b) GDPR) - executing the claim service you requested;
- Legal obligation (Art. 6(1)(c) GDPR) - fiscal administration;
- Legitimate interest (Art. 6(1)(f) GDPR) - IP logging for fraud prevention and legal evidence.
Who do we share your data with?
- Airline: claim letter including name, IBAN, flight data and proof of authorisation;
- Stripe: to store the payment mandate and collect the success fee after a confirmed payout;
- Resend: transactional email delivery as a processor;
- Aerodatabox / RapidAPI: flight number + date only (no personal data) for flight status verification;
- National enforcement body or ADR entity: only after confirming that the entity is competent for the incident and country;
- Tax authorities: VAT administration via Twilper sole proprietorship;
- Railway: our hosting provider; the database holding your case runs on their infrastructure;
- Sentry: error reports from the application, without IP addresses and without the contents of your request;
- Google: only if you sign in with your Google account, and after you consent to statistics;
- Language model for case review: reviews your case for anything still missing and drafts the questions about it. Your name, address and bank account never go there; your own account of the trip does.
We never sell your data to third parties for marketing purposes.
Transfers outside the EU
Your case is held in the EU. Two things sometimes go beyond it. An airline outside the EU receives the claim letter, because otherwise the claim cannot be filed. And the language model that reviews your case for missing details runs outside the EU; your name, address and bank account stay here. If you want to know which party and which country that is, ask us at privacy@flightmoneyback.eu and we will tell you.
Retention periods
- Claim files, consents and correspondence: for as long as necessary for the contract, applicable national periods and the substantiation of legal claims;
- Financial administration: 7 years (statutory fiscal obligation);
- Magic-link tokens: maximum 24 hours after issuance;
- Inactive accounts without claims or payments: automatically deleted after 12 months of inactivity.
Your rights
Under the GDPR, you have the right to:
- Access to your personal data (Art. 15);
- Rectification of inaccurate data (Art. 16);
- Erasure ('right to be forgotten', Art. 17) - except data required for an ongoing claim or fiscal obligation;
- Restriction of processing (Art. 18);
- Object to processing (Art. 21);
- Data portability (Art. 20).
Requests can be sent to privacy@flightmoneyback.eu. We will respond within 30 days. Complaint about our handling of personal data? You can report it to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP).
Cookies
Essential cookies secure login, language choice and case files. First-party funnel measurement, GA4/GTM and any configured marketing pixels load only after you grant analytics consent. Declining does not affect the claim service; your choice is stored for one year and can be reset by deleting the cookie.
Security
Personal data is stored encrypted (TLS in transit, encryption-at-rest on managed Postgres). Passwords are hashed with bcrypt. Access is limited to authorised admin of Twilper sole proprietorship.