BRIJ Digital Inc., a Delaware corporation (“BRIJ”, “we”), operates travel.brij.fi and is the data controller for the personal data described here. Contact: [email protected].
2. What we collect
Passenger details, provided at booking time: given and family name, date of birth, title, gender, email address, and phone number. This is the only identity data we ask for, and only because airlines require it to issue a ticket. We never ask for, and cannot store, passport or other identity-document numbers.
Saved travellers, if you choose to save them: the same seven fields above, stored against your wallet address so you do not retype them on every booking. Entries are created only when you explicitly ask us to remember someone — we never populate this list from your past bookings — and you can remove any entry at any time from the Travellers screen. Removing an entry deletes it from your saved list; it does not alter or erase bookings already made, which we must retain (see retention below).
Wallet addresses: the funding and refund wallet addresses attached to a booking intent, and the payer addresses of x402 payments.
Booking records: offers, intents, orders, escrow state, refund requests, and the customer support code.
Technical logs: IP addresses, request identifiers, timestamps, and request paths, kept for security and debugging.
3. What we use it for
Fulfilling bookings: passenger details are transmitted to our flight infrastructure provider and to the operating airline — this is necessary to issue a ticket and is the sole reason the data is collected.
Transactional email: booking-in-progress, booking-confirmed, and refund-request confirmations sent to the passenger email address.
Support and refunds: verifying refund requests against the support code and passenger name on file.
Wallet sign-in: proving control of your wallet by signing a message (no transaction, no fee) grants access to your own bookings and saved travellers. We issue a session token that expires after 7 days; there are no passwords and no accounts.
Security, fraud prevention, and compliance with legal obligations.
We do not sell personal data, and we do not use it for advertising.
4. Who we share it with
Flight infrastructure and airlines: passenger details, as required to create and manage the booking.
Email delivery provider: passenger email address and booking summary, to send transactional messages.
Encrypted off-site backups: booking records are included in routine database backups stored with a cloud storage provider.
Authorities: where required by applicable law.
5. The blockchain is public
Payments are settled on the Solana network. Wallet addresses, payment amounts, escrow accounts, and transaction history are public and permanent by design, visible to anyone, and cannot be altered or deleted by BRIJ. Do not use a wallet you are not willing to associate publicly with these transactions. No passenger identity data is written on-chain.
6. Retention
Booking and payment records are retained for as long as needed to service the booking (including refunds and disputes) and to meet legal, tax, and accounting obligations. Technical logs are retained for a shorter operational period. Backups roll over on a fixed retention schedule.
7. Security
Data is encrypted in transit, stored on access-restricted infrastructure, and access to a booking is gated by capability tokens (the intent id and the customer support code) rather than accounts. Keep those tokens secret; anyone holding them can read the booking.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal data, and to object to or restrict certain processing. Write to [email protected] and we will respond within a reasonable period. Note that we cannot modify on-chain data (see section 5) and may need to retain booking records where the law requires it.
9. Children
The Service is not directed at children. Passenger records for minors may only be submitted by an adult making a booking on their behalf.
10. Changes
We may update this policy; the current version is always published at this address with its last-updated date.