Skip to content

Privacy Policy

Effective date: October 8, 2026

This Privacy Policy explains how Travel Code, Inc. ("Travel Code", "we", "us"), 1307 Rodman St, Hollywood, FL 33019, USA, collects and uses personal information in connection with Travel Risk API: the website travelriskapi.com, the API at api.travelriskapi.com and the developer dashboard (the "Service"). Travel Code is the controller of this information. For Travel Code's other products, see the Travel Code privacy notice.

Travel Risk API is a developer product. It serves data about countries, airports, airlines and flights. It does not require, and we ask you not to send, personal information about travellers in API requests.

1. Information we collect

Account information. Your email address when you create an API key or sign in to the dashboard, the API keys issued to you, your plan and its status.

Billing information. For paid plans, payments are processed by Stripe. We receive a customer and subscription reference, plan, billing status and the details Stripe shares with merchants, such as country and the last four digits of a card. We do not receive or store full card numbers.

API usage logs. For each API request we record the key used, endpoint, method, response status, response time, date and time, and the IP address it came from. We use these to enforce quotas, bill, prevent abuse and keep the Service reliable.

Request parameters. Values you send, such as country codes, airport codes or flight numbers, are processed to answer the request.

Website and dashboard data. Our servers log standard technical information such as IP address, browser user agent and pages requested. We use Google Analytics to understand how visitors use the website; it sets its own cookies and collects information such as pages viewed and approximate location. The dashboard uses a strictly necessary session cookie to keep you signed in.

Communications. Messages you send to us, and records of service emails we send you, such as key delivery, quota warnings and billing notices.

2. How we use information

  • to provide the Service, issue keys and authenticate requests;
  • to measure usage, enforce quotas and rate limits, and bill;
  • to send service emails about your account, keys, quotas, billing and material changes to the Service;
  • to secure the Service, detect and prevent fraud and abuse;
  • to understand and improve the Service and the website;
  • to comply with legal obligations and enforce our Terms of Service.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We may occasionally email account holders about significant new Travel Risk API features; you can opt out at any time.

Legal bases (EEA and UK). Performance of our contract with you (account, keys, API, billing); our legitimate interests in securing, measuring and improving the Service and in communicating with business users; compliance with legal obligations; and your consent where required, for example for analytics cookies in jurisdictions that require it.

3. Service providers

We share personal information only with providers that process it on our behalf to run the Service:

Provider Purpose Location
DigitalOcean Hosting and databases United States
Stripe Payments and subscriptions United States
Amazon Web Services (SES) Sending service emails United States
Google (Analytics) Website analytics United States
RapidAPI Marketplace billing and key management, only if you subscribe through RapidAPI United States

We may also disclose information if required by law, to protect the rights and safety of our users, Travel Code or others, or as part of a merger, acquisition or sale of assets, in which case this Policy continues to apply.

4. International transfers

The Service is operated from the United States. If you use it from outside the United States, your information will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

5. Retention

  • Account and billing records: while your account is active, and afterwards as long as needed for tax, accounting and legal purposes.
  • API usage logs, including IP addresses: up to 13 months, then deleted. Aggregated usage counts without IP addresses may be kept longer.
  • Server logs of the website: short-term, for security and troubleshooting.

6. Security

We protect information with encryption in transit (HTTPS), access controls and restricted administrative access. More about Travel Code's security practices is available at the Trust Center. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your rights

Depending on where you live, including under the GDPR, the UK GDPR and US state privacy laws such as the CCPA, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to withdraw consent. We will not discriminate against you for exercising these rights.

To make a request, email legal@travel-code.com from the address on your account. We respond within the time required by applicable law, usually within 30 days. You may also lodge a complaint with your local data protection authority.

8. Children

The Service is intended for businesses and developers and is not directed to children under 16. We do not knowingly collect personal information from children.

9. Changes to this Policy

We may update this Policy. We will post the updated version on this page with a new effective date and, for material changes, notify account holders by email.

10. Contact

Travel Code, Inc. · 1307 Rodman St, Hollywood, FL 33019, USA Privacy requests: legal@travel-code.com · Product and support: api@travel-code.com