Privacy Policy
This Privacy Policy (“Policy”) describes how Grace Journeys LLC dba Zipper (“Zipper,” “we,” “our,” or “us”) collects, uses, discloses, and otherwise processes personal information, as well as the rights and choices individuals may have regarding such personal information.
For additional information about the privacy choices you may have regarding your personal information, please review the Your Privacy Choices section below.
By using our Services (as defined below), you agree that your personal information will be handled as described in this Policy. Your use of our Services and any dispute over privacy is subject to this Policy and our Terms of Service, including their applicable terms governing limitations on damages and the resolution of disputes.
1. Scope
Except as otherwise described below, this Policy applies to our online and offline personal information processing activities including, but not limited to: users of our mobile applications for iOS and Android (the “App”), which are the primary way to access our services; visitors to our website where this Policy is posted, including https://zipper.travel (the “Site”); individuals who sign up for, or create an account with us to access and use certain features of our services; individuals who register for or participate in our events, surveys, research, and promotions conducted by us; individuals who subscribe to receive news, information, and marketing communications and materials from us; current, former, and prospective business partners, and service providers; and individuals who communicate or otherwise interact or engage with us or the services available through our App, Site, or other online services (collectively referred to as the “Services”).
2. Personal Information Collected
We collect personal information directly from you, from third-party sources, and automatically through your use of the Services. The personal information we collect varies depending upon your use of our Services and our interactions with you.
Personal Information Collected Directly. We may collect the following personal information directly from you:
- Communications and Interactions. When you
communicate or interact with us or our Services, including if you sign
up for our newsletter, complete forms on our Site, interact with our
social media pages, post a product review or testimonial, submit content
to the Services, or otherwise engage with us, we may collect your
name, email address, phone number, or other similar
identifiers, as well as your message, the nature of your inquiry, and
any other information you choose to provide.
- Account and Profile Information. When you sign in
or create an account in connection with our Services, we may collect
your name, email address, phone number, as well
as any other information used in connection with accessing your account
or that you otherwise submit to us through your account.
- Travel Profile and Identifiers. To enable travel
bookings and reservations, we may collect standard travel identifiers
and related details, such as your date of birth, gender, passport
details (such as passport number, nationality, issuing country, and
expiration date) or other government-issued identification details,
Known Traveler Number (such as for TSA PreCheck), redress number,
loyalty and frequent traveler program numbers, and other similar
information required by travel suppliers to complete your
reservations.
- Purchases and Payments. When you make a purchase or
payment through our Services, we may collect information such as payment
type, credit card and other payment card details, billing information,
and details of the
travel products and services purchased, as well as any other financial
or commercial-related information necessary to enable our
Services.
- Chat, AI Assistants, and Phone Support. We may
collect information you submit through the chat functions, AI
assistants, and phone support we make available through the Services.
We record and keep these conversations, including support calls, so
that we can provide support, maintain a record of what you requested
and we agreed to, and review and improve how we provide support.
- Responses and Feedback. If you participate in
surveys, questionnaires, or research activities or initiatives conducted
by us, such as for market research, user satisfaction, or other similar
purposes, we may collect your responses and feedback, and any other
information you choose to provide.
- Preferences and Other Requests. We may collect
information about your preferences, including communications
preferences, preferences related to your use of our Services, and any
other preferences or requests you provide when interacting with
us.
- Business Development Information. To assess and pursue potential business opportunities, we may collect and receive personal information about current, former, and prospective business partners, and vendors and service providers, including contact information and other similar identifiers, company and professional-related information, and communications records.
Personal Information Collected from Third Parties. We may collect and receive personal information from third party sources, such as business partners, operating systems, public databases, customers and other users, and service providers or other third parties who provide services or perform functions on our behalf. We may collect the following information from third-party sources:
- Referral Information. We may offer users the
ability to invite friends or refer other users to access or use our
Services. In doing so, we may collect and receive certain personal
information about individuals referred to our Services.
- Connected Services. If you connect a third-party
account or service to the Services (for example, your Google account),
we receive information from that service as needed to provide the
features you enable. The provider’s own privacy policy and settings
govern its handling of your information. For information about how we
handle data received from Google APIs, see Section 7.
- Telco Data. We may receive information from telecommunications carriers and telco data aggregators that is used to assess the risk profile of a phone number, such as the line type (e.g., mobile, landline, VoIP, or pre-paid), active status, current and previous carriers, call forwarding settings, contract and account type, SIM swap history, porting history, and the city and country where the phone number was initially registered. We may also receive confirmation of whether the personal data you provide matches personal data held by your phone carrier, and whether the device you are using is registered on the carrier network with the phone number you provide.
Personal Information Collected Automatically. We may automatically collect or derive personal information related to your use of our Services, including through the use of cookies, pixel tags, and other similar technologies. This may include:
- Device and Browsing Information. When you use our
Services, we may collect browser type, domain name, page views, access
times, date/time stamps, operating system, language, device type, unique
ID, Internet service provider, referring and exiting URLs, clickstream
data, and other similar device and browsing information. In our App,
this includes your device's model, operating system version, and device
settings such as language, timezone, and accessibility settings, along
with the App's version.
- Device Integrity and Installation Identifiers. To
protect accounts and prevent fraud, our App may collect installation
identifiers and device integrity information. The installation
identifiers are random values we generate; they are not derived from
your device's hardware and cannot be used to recognize your device
elsewhere. The integrity information is produced by your device with
the involvement of the platform provider (Apple or Google): App Attest
attestations and DeviceCheck tokens on iOS, and Play Integrity
verdicts and hardware key attestation certificates on Android. We use
this information solely for security and fraud prevention. We do not
use it for advertising or to track you across other companies' apps or
websites.
- Activity and Usage. We may collect activity
information related to your use of the Services, such as information
about the links clicked, searches, features used, items viewed, time
spent within the Services, your interactions with us within the
Services, and other similar activity and usage information.
- Location Information. We may collect or derive
general location information, such as through your IP address.
Additionally, with your permission, we may collect geolocation
information from your device. You may turn off location data sharing
through your device settings. We may use a service provider to map your
IP address to an approximate location; we send that provider only your
IP address and no other information about you. We do not share
location information associated with you with any third party, with
one exception: for payment processing and fraud prevention, including
3D Secure authentication, we may share your IP address (which can
reveal approximate location) and your billing address with our payment
service providers, the card network, and the card issuer associated
with your card. We never share any other
location information with these parties. Some features may rely on service
providers of location-based information, such as weather and traffic
conditions; we send those providers only anonymized location points
from which all associated information has been removed, including your
IP address and any identifiers that could link the location to
you.
- Derived or Inferred Information. We may derive information about you based upon the information we collect automatically and from other sources. For example, information about your preferences that is inferred from your interactions with us.
For more information about our use of cookies and other similar technologies, please see the Cookies and Other Tracking Mechanisms section below.
3. How We May Use Personal Information
We may collect, use, disclose, and otherwise process personal information for the following purposes:
- Services and Support. To enable our Services,
communicate with you about your use of the Services, provide
troubleshooting, technical support, and for similar support purposes,
respond to your inquiries, fulfill your requests, send you
administrative information such as changes to our terms and policies,
and otherwise run our day-to-day operations.
- Account Creation and Management. To enable account
creation and management, including allowing you to create a profile and
set preferences.
- Analytics and Improvement. To better understand how
users access and use the Services, and for other research and analytical
purposes, such as to evaluate, develop, and improve our Services and
business operations, and for internal quality control and training
purposes.
- Artificial Intelligence and Machine Learning. To
develop, train, and improve our artificial intelligence and machine
learning features. We train models using only anonymized and
deidentified data, and you may opt out of the use of your data for
model training in your account settings. We never use Google User Data
to train artificial intelligence or machine learning models.
- Customization and Personalization. To tailor
content we may send or display on the Services, including to offer
location customization and to otherwise personalize your experiences and
offerings.
- Marketing and Promotions. For marketing and
promotional purposes. For example, to send you promotional information
about our Services, including information about sales, discounts, and
new offerings, as well as any other information that you sign up to
receive.
- Research and Surveys. To administer surveys and
questionnaires, such as for market research or user satisfaction
purposes.
- Planning and Managing Events. For event
planning and other management-related purposes, such as registration,
attendance, connecting you with other event attendees, and contacting
you about relevant events and Services.
- Security and Protection of Rights. To protect the
Services and our business operations, and to protect our rights or those
of our stakeholders; to prevent and detect fraud, unauthorized
activities and access, and other misuse; where we believe necessary to
investigate, prevent, or take action regarding illegal activities,
suspected fraud, situations involving potential threats to the safety or
legal rights of any person or third party, or violations of our Terms of
Service.
- Compliance and Legal Process. To comply with
applicable legal or regulatory obligations, including as part of a
judicial proceeding, to respond to a subpoena, warrant, court order, or
other legal process, or as part of an investigation or request, whether
formal or informal, from law enforcement or a governmental
authority.
- Auditing, Reporting, and Other Internal Operations.
To conduct financial, tax, and accounting audits, audits and assessments
of our operations, including our privacy, security, and financial
controls, as well as for risk and compliance purposes. We may also use
personal information to maintain appropriate business records and
enforce our policies and procedures.
- Business Transactions. To assess and implement mergers, acquisitions, reorganizations, bankruptcies, and other business transactions such as financings.
4. Disclosures of Personal Information
We may disclose the personal information we collect for the purposes described above and as follows:
- Vendors and Service Providers. We may disclose
personal information we collect to our service providers, processors,
and others who perform functions on our behalf. These may include, for
example, cloud infrastructure and content delivery providers, payment
service providers, and communications and messaging providers. Service
providers process personal information on our behalf and under our
instructions, and when this Policy states that we do not share
information with third parties, processing by our service providers in
that capacity is not such sharing. Our service providers are bound by
written agreements, including data processing terms, that require them
to safeguard personal information, restrict them to using it only to
provide their services to us, and prohibit them from selling it or
using or disclosing it for their own purposes, and our core
infrastructure providers maintain independently audited security
certifications such as SOC 2 and ISO 27001.
- Payments and Fraud Prevention. We may share transaction
and billing information, your IP address, and technical information
about your device (such as its model and operating system) with our payment
service providers, Datatrans AG
(PCI Proxy) and Stripe,
and, when a payment is processed with 3D Secure authentication, with
the card network and card issuer associated with your card, for
payment processing and fraud prevention. These
parties may also use this
information to operate and improve their fraud detection services in
accordance with their own privacy policies. Other than your IP address
and billing address, we never share location information with these
parties.
- Travel Suppliers and Distribution Systems. To
fulfill your travel bookings and reservations, we share booking
information (such as traveler names, contact details, dates of birth,
passport or other identification details where required, loyalty
program numbers, and payment details) with travel suppliers,
aggregators, and distribution systems, including airlines, hotels,
cruise lines, tour operators, ground transportation providers,
accommodation wholesalers, and global distribution systems. Travel
suppliers are independent third parties, not our service providers, and
their use of your information is governed by their own privacy policies
and terms.
- Affiliates and Subsidiaries. We may disclose
personal information we collect to our affiliates or subsidiaries who
will use and disclose this personal information in accordance with this
Policy.
- Corporate Travel Clients. If you access the
Services through an arrangement with your employer or another
organization, such as a corporate travel program, we may disclose
information related to your bookings and use of the Services to that
organization, or to others at its direction.
- Advertising Platforms (Retargeting). We may share
limited contact information or identifiers, such as your email
address, with advertising platforms solely to show you advertisements
for Zipper on other websites, apps, and services. We never share Google
User Data, location information, or the details of your travel for this
purpose. You may opt out of this sharing as described in the Your Privacy Choices section
below.
- Compliance and Legal Obligations. We may disclose
personal information to third parties to comply with our legal and
compliance obligations and to respond to legal process. For example, we
may disclose information in response to subpoenas, court orders, and
other lawful requests by regulators and law enforcement, including
responding to national security or law enforcement disclosure
requirements. This may include regulators, government entities, and law
enforcement as required by law or legal process.
- Security and Protection of Rights. We may disclose
personal information where we believe it is necessary to protect the
Services, our rights and property, or the rights, property, and safety of
others. For example, we may disclose personal information in order to
(i) prevent, detect, investigate, and respond to fraud, unauthorized
activities and access, illegal activities, and misuse of the Services,
(ii) situations involving potential threats to the health, safety, or
legal rights of any person or third party, or (iii) enforce, and detect, investigate, and take action in response to violations of, our Terms of
Service. We may also disclose information, including personal
information, related to litigation and other legal claims or proceedings
in which we are involved.
- In Support of Business Transfers. If we, or our
affiliates are, or may be acquired by, merged with, or invested in by
another company, or if any of our assets are, or may be, transferred to
another company, whether as part of a bankruptcy or insolvency
proceeding or otherwise, we may transfer the information we have
collected from you to the other company. We may also share certain
personal information as necessary prior to the completion of such a
transaction or corporate transactions such as financings or
restructurings, to lenders, auditors, and third-party advisors,
including attorneys and consultants, as part of due diligence or as
necessary to plan for a transaction.
- Aggregate and Deidentified Information. We may use
aggregate and deidentified information related to our business and the
Services for our business purposes, including quality control,
analytics, research, development, and business reporting, and we may
disclose aggregate information, such as usage statistics, to describe
our business and the Services. We may also share deidentified
information with third parties; you may opt out of this sharing in
your account settings, and we will exclude your data from future
sharing of deidentified information. We maintain such information in
deidentified form, do not
attempt to reidentify it, and require any recipient to commit to the
same. If you opt out of artificial intelligence and machine learning
model training, deidentified information derived from your data is also
excluded from model training.
5. Cookies and Other Tracking Mechanisms
We use cookies, pixels, local storage, log files, and other mechanisms to automatically collect browsing, activity, device, and similar information within our Services. We use this information to, for example, analyze and understand how users interact with our Services; identify and resolve bugs and errors in our Services; assess, secure, protect, optimize, and improve the performance of our Services; conduct marketing and analytics activities; and personalize content in our Services. Our App does not include third-party advertising or analytics SDKs, and the only third-party SDKs that send your information to anyone other than us are for secure, PCI-compliant collection of payment details and for payment fraud prevention. To manage your preferences regarding cookies and other tracking mechanisms within our Services, please see Your Privacy Choices below.
Cookies. Cookies are small text files that your browser stores on your device at our request. Some cookies make it easier for you to navigate our Services, while others enable a faster log-in process, support the security and performance of the Services, or allow us to understand activity and usage within the Services.
Pixel Tags. Pixel tags (sometimes called web beacons) are tiny invisible images embedded in web pages or emails that tell us when the content has been loaded. We may use them within our Services to understand user activity, manage content, and compile usage statistics, and in emails we send to measure open and response rates.
Browser Local Storage. Local storage is a browser feature that lets a website store data on your device that persists after you close your browser. We may use it to keep you signed in and to cache information so that pages load faster when you return. You can clear local storage through your browser settings.
First-Party Analytics. Information about how our Services are used, along with our logs and usage statistics, is collected and processed entirely by us using our own systems. We do not use third-party analytics providers, and we do not share this information with third-party analytics companies. Technical information about your device and your transactions is shared with our payment service providers solely for payment processing and fraud prevention, as described in Section 4.
6. SMS/Text Messaging Program
This Section 6 applies to personal information collected, used, or disclosed in connection with our SMS, MMS, RCS, or other text messaging programs (“Messaging Program”), specifically mobile phone numbers, text messaging opt-in data, and consent records (collectively, “Mobile Information”). To the extent any other provision of this Policy conflicts with this Section 6 with respect to Mobile Information, this Section 6 controls. Additional terms applicable to our Messaging Program are set forth in our SMS/MMS Terms.
No Sale or Sharing of Mobile Information for Marketing. No Mobile Information will be shared with third parties or affiliates for marketing or promotional purposes. We do not sell, rent, lease, or otherwise transfer your mobile phone number, text messaging opt-in data, or consent records to any third party for such purposes.
Permitted Service Provider Disclosures. We may disclose Mobile Information to subcontractors, vendors, and service providers that perform functions on our behalf solely as necessary to operate the Messaging Program, including messaging platform providers, SMS aggregators, telecommunications carriers, customer support providers, and technical infrastructure providers. These service providers are prohibited from using Mobile Information for their own marketing or promotional purposes, or for any purpose unrelated to delivering the services you have requested.
Travel Supplier Disclosures. To fulfill your travel bookings and reservations, we may share mobile phone numbers with travel suppliers (including airlines, hotels, cruise lines, tour operators, ground transportation providers, accommodation wholesalers, and global distribution systems) to allow the supplier to communicate with you about your reservation. Travel suppliers are independent third parties, not our service providers, and their use of your phone number is governed by their own privacy policies and terms.
Scope of Your Consent. Your consent to receive text messages from us under our Messaging Program applies solely to communications from us. Travel suppliers with whom we share your information to fulfill your bookings may separately contact you regarding your travel, subject to their own policies and any consent you have provided to them directly. We do not transfer your consent to our Messaging Program to any travel supplier, third party, affiliate, or other business.
Legal Disclosures. We may disclose Mobile Information when required by law, legal process, subpoena, court order, or governmental request, or where we reasonably believe disclosure is necessary to protect our rights, property, or the safety of any person, in accordance with Section 4. These disclosures are not subject to the marketing-purposes restriction above.
7. Google User Data
This Section 7 applies to information we receive from Google APIs (“Google User Data”) when you choose to connect your Google account to the Services. To the extent any other provision of this Policy conflicts with this Section 7 with respect to Google User Data, this Section 7 controls.
Data We Access. With your consent, granted through Google’s OAuth consent flow, we request the following access:
- Gmail (read-only). We access your Gmail messages on
a read-only basis solely to identify and extract travel loyalty and
rewards program membership numbers (such as frequent flyer and hotel
loyalty program numbers) so that we can save them to your wallet within
the Services, display them to you, and apply them to your travel
bookings to help you receive the rates and points associated with your
memberships. We do not read, use, or process your email for any other
purpose.
- Google Calendar (read and write). We read your calendar events to display your schedule alongside your travel itineraries in the app, and we create and update calendar events on your behalf to add itinerary items (such as flights and hotel stays) to your calendar.
How We Use Google User Data. We use Google User Data solely to provide and improve the user-facing features described above. We do not use Google User Data for advertising or marketing purposes of any kind, we never share it with advertising platforms, and we do not use it to train artificial intelligence or machine learning models.
Storage. We do not store your Gmail messages or Google Calendar event data in our databases or logs; this data is processed transiently to provide and improve the features described above. We store only the loyalty program membership numbers identified from your messages, which are saved to your wallet within the Services and remain subject to the restrictions described in this Section 7.
Limited Use. Zipper’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Sharing. We do not transfer Google User Data to third parties except: (i) as necessary to provide the user-facing features described above, with your consent (for example, when you make a booking, we share the relevant loyalty program membership numbers from your wallet with the travel supplier, such as an airline or hotel, to apply your membership to the reservation, and we use service providers, such as cloud hosting providers, that process data on our instructions to operate the Services); (ii) for security purposes, such as investigating abuse; (iii) to comply with applicable law; or (iv) as part of a merger, acquisition, or sale of assets, after obtaining your explicit prior consent. We never sell Google User Data, never transfer it to data brokers, advertising platforms, or information resellers, and never use it to determine creditworthiness or for lending purposes.
Human Access. Our personnel do not read your Gmail messages or Google Calendar data except: (i) with your affirmative agreement to view specific messages or data; (ii) as necessary for security purposes, such as investigating a bug or abuse; (iii) as necessary to comply with applicable law; or (iv) where the data has been aggregated and is used for internal operations in accordance with applicable law.
Revoking Access and Deletion. You can disconnect your Google account from the Services at any time, or revoke Zipper’s access via Google Security Settings. You may also request deletion of loyalty numbers saved to your wallet or any other associated data by contacting us at privacy@zipper.travel.
8. Your Privacy Choices
We make available several ways that you can manage your privacy choices and submit privacy requests related to your personal information. Some of these choices are browser and device specific, which means that you need to set the preference for each browser and device you use to access our Services. In addition, if you delete or block cookies, you may need to reapply these preferences to each browser and/or device used to access our Services.
These options include:
- Account and Profile Information. You can review and
update some of the personal information we maintain about you by logging
into your account and updating your profile information directly within
our Services.
- Marketing Communications. We may send periodic
promotional emails or other similar communications to you, in accordance
with applicable law. You may opt-out of these communications by
following the instructions provided to you in the communication. If you
opt-out of receiving promotional content from us, we may still send you
communications about your account or any services you have requested or
received from us. Additionally, you can manage your communication
preferences in your account settings.
- Push Notifications. You can manage the type of push
notifications you receive from us by adjusting your device settings or
by modifying the settings within our Services.
- Cookie Settings. To prevent cookies from tracking
your activity on our Site or visits across multiple websites, you can
set your browser to block certain cookies or notify you when a cookie is
set; you can also delete cookies. The “Help” portion of the toolbar on
most browsers will tell you how to prevent your device from accepting
new cookies, how to have the browser notify you when you receive a new
cookie, or how to delete cookies. Visitors to our Site who disable
cookies will be able to browse the Site, but some features may not
function.
- Browser Signals/Do Not Track. Our Site currently
does not respond to “Do Not Track” signals. You may, however, disable
certain tracking as discussed in this section (e.g., by disabling
cookies).
- Retargeting. You may opt out of the sharing of
your contact information or identifiers with advertising platforms for
retargeting purposes in your account settings or by contacting us at privacy@zipper.travel.
- AI Training. You may opt out of the use of your
data for artificial intelligence and machine learning model training in
your account settings.
- Deidentified Information. You may opt out of the sharing of deidentified information derived from your data with third parties in your account settings.
9. External Links and Features
Our Service may contain links to third-party websites or features or provide certain third-party connections or integrated services. Any access to and use of such linked websites, features, or third-party services is not governed by this Policy. We are not responsible for the information practices of such third parties, including their collection, use, and disclosure of your personal information. You should review the privacy policies and terms for any third parties before proceeding to those websites or using those third-party features or services.
10. Children’s Privacy
Our Services are not designed for children, we do not knowingly allow children under 18 to create accounts, and we do not knowingly collect personal information directly from children under 18. When a parent, guardian, or other adult books travel for a child, we collect the traveler information needed to complete the booking (such as the child’s name, date of birth, and passport or other identification details) and use it solely to provide the requested travel services, including sharing it with travel suppliers as described in Section 4. If you are a parent or legal guardian and you believe we have collected your child’s information in violation of applicable law, please contact us using the contact information in the Contact Us section below.
11. Security
We have implemented safeguards intended to protect personal information from loss, misuse, unauthorized access, disclosure, alteration, or destruction. Please be aware that despite our efforts, no data security measures can guarantee security.
12. Additional Information for California Residents
Shine the Light Law
Under California’s “Shine the Light” law (Cal. Civ. Code § 1798.83), California residents who provide us certain personal information are entitled to request and obtain from us, free of charge, information about the personal information (if any) we have shared with third parties for their own direct marketing use. Such requests may be made once per calendar year for information about any relevant third-party sharing in the prior calendar year. To submit a “Shine the Light” request, email us using the Contact Us information below, and include in your request a current California address and your attestation that you are a California resident.
13. Changes to this Policy
This Policy is current as of the effective date set forth above. We may change this Policy from time to time, so please be sure to check back periodically. We will post any updates to this Policy on this page. If we make material changes to how we collect, use, or disclose the personal information we have previously collected, we will provide you prior notice, such as by emailing you or posting prominent notice on our website or within the Services. If we change how we handle Google User Data, we will notify you and obtain your consent before the change applies to your Google User Data.
14. Contact Us
If you have any questions or concerns regarding this Policy or our privacy practices, you may contact us at privacy@zipper.travel.