Privacy

What we store, for how long, and what we never do with it.

Written to be read, not to be survived. If anything here is unclear, ask us and we will fix the wording.

The short version

Who is who

If you are a Relay customer, you are the controller of the traveller data you send, and Relay is a processor acting on your instructions. If you are a traveller whose booking passed through a Relay customer, your relationship is with them; we will forward any request you send us to the relevant customer.

What we collect

Order data you send to the API

For each order: your own order identifier, and the three views of it — amounts, currencies, routes, departure dates, passenger names, refund and capture status, processor and supplier names, and charge identifiers. Passenger names and travel dates are personal data. We ask for them because a name or date mismatch is one of the failures Relay exists to detect; if you can detect what you need without sending names, send fewer fields — a field you omit is never treated as a mismatch.

Account data

Your email address, an optional display name and company name, and which authentication provider you used. Passwords, when used, are hashed by Supabase Auth and never visible to us.

Operational data

API key hashes, key last-used timestamps, webhook endpoints and their signing secrets, and records of raw provider webhooks when you connect a provider.

Enquiries

If you use the contact or API-access forms, we keep what you typed so we can reply.

What we do not collect

How long we keep it

On account deletion, order data is removed by database cascade — deleting the workspace deletes its orders, keys, webhooks and connections with it.

Who can see it

Your workspace's data is readable only by members of that workspace, enforced by row-level security in PostgreSQL (see Security). No other customer can query it. Relay staff — currently one person — can technically reach the database for support and debugging; we access customer data only when needed to fix something, and we would rather you ask us to look than assume we already have.

Subprocessors

We will update this list before adding another one.

International transfers

Data is processed in the United States. If you are in the EEA or UK and that matters for your compliance position, raise it before sending live data — a different deployment region is a conversation, not a blocker.

Your rights

Access, correction, export, deletion, and objection. Email yduan2435@gmail.com or use the contact form. We respond within seven days and confirm in writing when it is done. There is no charge and no form to fill in.

Changes

If we change anything material, we will email account holders rather than quietly updating the date at the bottom of this page.

Last updated 1 September 2026. Contact: yduan2435@gmail.com