Privacy Policy
Version 1.0
Last updated: August 2026. This policy explains how Rover Stopover collects, uses, and protects your personal information.
1. Introduction
This Privacy Policy explains how Rover Stopover ("we", "us", "our") collects, uses, shares, and protects your personal data when you use our website and booking platform (the "Service").
2. Data We Collect
- Account & identity data: full name, email address, phone number, nationality, gender, and date of birth (where you choose to provide it in your profile).
- Flight & travel data: flight number, departure and arrival airports and times, and your onward ("next") flight details — entered manually, or extracted from a boarding pass/ticket image or PDF you choose to upload via an AI document-processing service. An uploaded file is sent to that service for one-time extraction and is not stored by us afterward; only the extracted flight fields are saved.
- Booking & route data: your selected tour stops, tour duration, number of passengers, total route distance and duration (calculated via a mapping/route-optimization service using the airport and stop locations), and price paid.
- Cancellation & refund data: if you request a cancellation or refund, we store the reason you provide. If your refund type requires proof (for example, an airline cancellation notice), you may optionally attach an image or PDF; like an uploaded boarding pass, that attachment is forwarded once for review and is not stored by us afterward.
- Payment data: we do not collect or store your full card or payment account details ourselves — payment is handled entirely by our third-party payment processor. We store only the resulting order/transaction reference and payment status.
- Phone verification data: your phone number is verified by SMS one-time passcode before a booking can be submitted; we record that verification and, temporarily, the passcode sent.
- Uploaded images (admin-managed content only): photos of tour stops are stored in our cloud storage for display purposes. This does not include user-uploaded boarding passes or refund proof-of-cancellation attachments, which are never stored (see above and below).
- Technical data: IP address, device/browser information, and basic usage logs, collected for security (bot/fraud protection) and reliability purposes.
3. How We Use Your Data
We use your data for the following purposes, and, where applicable law requires it, on the following legal bases:
- Creating and managing your account, extracting and tracking your flight, calculating and fulfilling your layover tour booking, processing payments and refunds, and sending booking/payment/account-related emails — necessary to perform our contract with you.
- Verifying your phone number by SMS — based on your consent, given each time you request a verification code.
- Detecting fraud and abuse, and keeping the Service secure — our legitimate interest in protecting the Service and its users.
- Retaining certain records after your account is closed — necessary to comply with legal, tax, and accounting obligations.
4. Third-Party Service Providers
We rely on trusted third-party providers to operate the Service, each processing only the data necessary for its function. We describe each by its role below rather than by brand name, except where we are contractually required to name a specific provider.
- Payment processor — handles your payment at checkout. Your payment and any refund are subject to that processor's own user agreement and privacy terms, available on their website at the time you pay.
- Third-party sign-in — if you choose to sign in using a third-party account instead of creating a password, authentication is handled by that provider; we receive only your resulting account session, name, and email.
- Google Maps Platform — used to display maps and calculate tour routes, distances, and durations. We name this provider specifically because Google's own terms require it: your use of these mapping features is subject to the Google Maps End User Terms and the Google Privacy Policy. We do not send Google any personally identifying information about you — only place identifiers and coordinates needed to calculate your route. If you are located in the European Economic Area, Switzerland, or the UK, we do not send your data to Google's core mapping services in a way that identifies you.
- Bot-protection service — a challenge shown on our login/signup pages to block automated abuse.
- Database, authentication & account storage provider — hosts your account and booking data on our behalf as a data processor.
- AI document-processing service — used only if you choose to upload a boarding pass/ticket, to extract flight/passenger details. We do not retain the original file afterward.
- SMS/messaging provider — sends the one-time verification passcode to your phone number. By requesting a code you consent to receive that message; message and data rates may apply. We retain a record of that consent as required by applicable SMS regulations.
- Flight-tracking data provider — supplies real-time flight position, delay, and arrival data.
- Cloud storage provider — stores admin-managed tour-stop photos, and separately provides general web-traffic security.
- Email service provider — sends booking confirmations, refund notices, and account-related emails.
5. Data Retention
- Flight-tracking data (live position, ETA, delay information) is deleted within 30 days of being received.
- Booking records (flight details, selected tour stops, route distance/duration, price, payment reference) are retained for as long as your account is active, and afterward for accounting, tax, and dispute-resolution purposes, as described below.
- Account deletion: requesting deletion immediately deactivates your account and blocks login. For up to 30 days, this can still be reversed by contacting support. After 30 days, your personal information (name, contact details) is anonymized. Records that must be kept for legal, tax, or dispute purposes (such as completed booking and payment records, and legal-consent history) are retained for a longer period required by law before final deletion.
- Backups: we keep periodic backups of our database for disaster-recovery purposes only — they are never accessed to look up or process your data for any other reason. A backup taken before your data was anonymized or deleted may still contain it for a limited time after; all backups are automatically overwritten on a rolling schedule, with none retained longer than 6 months.
- Consent records for legal-document acceptance and SMS verification are kept for as long as needed to demonstrate compliance, even after other account data is anonymized.
6. Cookies & Tracking
We use essential cookies/local storage to keep you signed in and remember your booking progress. We use a bot-detection challenge (a privacy-focused alternative to traditional CAPTCHAs) to protect login and signup from automated abuse.
7. Data Security
We use industry-standard measures to protect your data, including encrypted connections (HTTPS), database-level access controls that restrict each user's data to their own account, and secure, httpOnly session cookies.
8. Your Rights
You can access and update most of your account information directly from your dashboard, and request account deletion at any time (see Section 5). Depending on applicable law (including the UAE's Personal Data Protection Law and, where applicable, GDPR), you may also have the right to:
- request a copy of the personal data we hold about you, in a portable format;
- ask us to correct inaccurate or incomplete data;
- ask us to restrict certain processing of your data;
- object to processing we carry out based on our legitimate interests; and
- withdraw consent at any time where we rely on your consent (for example, phone verification) — this does not affect the lawfulness of processing already carried out before you withdraw it.
Contact us using the details below to exercise any of these rights. If you are located in the European Economic Area, Switzerland, or the UK, you also have the right to lodge a complaint with your local data protection supervisory authority. In the event of a data breach affecting your personal data, we will notify you and the relevant authorities without undue delay, as required by applicable law.
9. Children's Privacy
The Service is not directed at children, and we do not knowingly collect personal data from anyone below the minimum age required to independently travel and enter into a binding booking in their jurisdiction.
10. International Data Transfers
Our service providers operate infrastructure in multiple countries, including the United States. By using the Service, you understand your data may be processed outside your home country. Where a provider processes data originating from the European Economic Area, Switzerland, or the UK, that transfer is made under Standard Contractual Clauses or another legally recognized transfer safeguard required under applicable law.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected in a new version number, and where required, you'll be notified and asked to re-acknowledge before continuing to use the Service.
12. Contact Us
Questions about this Privacy Policy can be sent to [email protected] or via WhatsApp at +971 50 922 4965.
