Written to be read, not to be survived. If anything here is unclear, ask us and we will fix the wording.
If you are a Relay customer, you are the controller of the traveller data you send, and Relay is a processor acting on your instructions. If you are a traveller whose booking passed through a Relay customer, your relationship is with them; we will forward any request you send us to the relevant customer.
For each order: your own order identifier, and the three views of it — amounts, currencies, routes, departure dates, passenger names, refund and capture status, processor and supplier names, and charge identifiers. Passenger names and travel dates are personal data. We ask for them because a name or date mismatch is one of the failures Relay exists to detect; if you can detect what you need without sending names, send fewer fields — a field you omit is never treated as a mismatch.
Your email address, an optional display name and company name, and which authentication provider you used. Passwords, when used, are hashed by Supabase Auth and never visible to us.
API key hashes, key last-used timestamps, webhook endpoints and their signing secrets, and records of raw provider webhooks when you connect a provider.
If you use the contact or API-access forms, we keep what you typed so we can reply.
ch_1P…, never the instrument behind it.On account deletion, order data is removed by database cascade — deleting the workspace deletes its orders, keys, webhooks and connections with it.
Your workspace's data is readable only by members of that workspace, enforced by row-level security in PostgreSQL (see Security). No other customer can query it. Relay staff — currently one person — can technically reach the database for support and debugging; we access customer data only when needed to fix something, and we would rather you ask us to look than assume we already have.
We will update this list before adding another one.
Data is processed in the United States. If you are in the EEA or UK and that matters for your compliance position, raise it before sending live data — a different deployment region is a conversation, not a blocker.
Access, correction, export, deletion, and objection. Email yduan2435@gmail.com or use the contact form. We respond within seven days and confirm in writing when it is done. There is no charge and no form to fill in.
If we change anything material, we will email account holders rather than quietly updating the date at the bottom of this page.
Last updated 1 September 2026. Contact: yduan2435@gmail.com