Privacy Policy & Data Protection Notice
How JetBluePartners safeguards your personal and travel information across all touchpoints.
1 Introduction & Data Controller Information
At JetBluePartners (“we,” “us,” or “our”), we recognize that planning travel involves sharing intimate personal details: where you are journeying, whom you are traveling with, dietary restrictions, and identity verification credentials. We take the stewardship of this sensitive information with the utmost gravity and institutional responsibility.
This Privacy Policy applies to all personal information collected through our website (https://www.jetbluepartners.com), mobile web interfaces, airport check-in kiosks, in-flight satellite connectivity portals, and interactions with our customer support center.
For the purposes of the European Union General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and applicable global privacy statutes, the Data Controller responsible for your personal information is:
Attn: Data Protection Officer (DPO)
29-10 Queens Plaza North, Long Island City, NY 11101
Email: support@jetbluepartners.com
2 Categories of Personal Information We Collect
We collect personal data directly from you, automatically through your device interactions, and from authorized third-party travel distribution channels:
2.1 Passenger Identification & Contact Details
- Full legal name, honorific, gender, and date of birth;
- Email address, physical mailing address, and mobile phone number;
- Passport number, country of issuance, expiration date, and international visa authorization codes;
- TSA Known Traveler Number (KTN) and Redress Number (for expedited domestic security screening).
2.2 Reservation & Travel Itinerary Data
- Flight reservation codes (PNRs), e-ticket numbers, origin/destination airports, and flight dates;
- Cabin class, selected seat numbers, and baggage check-in tracking records;
- Special Service Requests (SSRs), such as dietary meal choices (which may indirectly reflect religious beliefs or medical conditions), wheelchair assistance, or service animal transport declarations.
2.3 Payment & Billing Records
Payment card brand, cardholder name, billing postal address, and truncated payment card digits (last four numbers). Full primary account numbers (PAN) and CVV security codes are securely processed directly by PCI-DSS Level 1 certified payment gateways and are never retained on our application servers.
2.4 Technical Telemetry & Device Information
Internet Protocol (IP) addresses, browser type, operating system version, referring URLs, device hardware identifiers, mobile network data, and diagnostic session metrics collected while using our digital booking systems or connecting to our complimentary aircraft Wi-Fi networks.
3 Legal Grounds for Processing (GDPR Article 6 & 9)
Under international privacy frameworks, we only process your personal data where a valid lawful basis exists:
- Performance of a Contract (Art. 6(1)(b)): Necessary to issue your e-ticket, manage flight check-in, process baggage handling, transport you to your destination, and execute our Contract of Carriage.
- Compliance with Legal & Regulatory Obligations (Art. 6(1)(c)): Mandatory data submissions required under civil aviation safety laws, customs regulations, TSA Secure Flight rules, and tax statutes.
- Legitimate Business Interests (Art. 6(1)(f)): Detecting payment fraud, ensuring IT infrastructure cybersecurity, improving flight schedules, and assessing customer service performance.
- Explicit Consent (Art. 6(1)(a) & Art. 9(2)(a)): For optional marketing subscriptions and the processing of special category health data (e.g. medical clearance for oxygen concentrators or mobility assistance).
4 How We Use Your Personal Information
Your information is utilized strictly for legitimate aviation and travel operations:
- Fulfilling Flight Bookings: Generating boarding passes, administering seat assignments, verifying government photo IDs at boarding gates, and handling baggage routing.
- Operational Communications: Sending essential, non-marketing flight status updates, gate change alerts, schedule irregularity notifications, and baggage carousel announcements via SMS, email, or push notifications.
- Customer Care & Dispute Resolution: Responding to guest inquiries, processing fee waivers, resolving delayed baggage claims, and administering ticket refunds.
- Safety & Airworthiness: Calculating aircraft weight and balance distributions, monitoring cabin security, and complying with FAA emergency passenger manifest mandates.
- Opt-In Marketing: Delivering curated travel promotions, seasonal flight deals, and newsletter updates (only when you have provided prior consent, with unsubscribe links in every email).
5 Sharing & Third-Party Disclosures
We share personal data solely under the following operational circumstances:
- Codeshare & Interline Airlines: If your journey involves connecting segments operated by partner carriers, your passenger name record (PNR) is shared to ensure seamless through-ticketing and baggage transfers.
- Global Distribution Systems (GDS): Certified travel booking networks (such as Sabre and Amadeus) used by corporate travel planners and travel agents.
- Ground Service Partners: Airport terminal operators, baggage handlers, and catering providers who fulfill flight ground operations.
- Payment Gateways & Cloud Infrastructure: Highly secure cloud storage providers (AWS, Google Cloud) and payment card networks operating under strict Data Processing Agreements (DPAs).
6 Mandatory Government & Aviation Security Disclosures
Aviation security is regulated by strict federal and international law. We are legally required to disclose passenger information to public authorities under the following programs:
- TSA Secure Flight Program: Under 49 C.F.R. Part 1560, we must transmit your full legal name, date of birth, and gender to the U.S. Transportation Security Administration for watch list matching prior to flight departure.
- Advance Passenger Information System (APIS): For international flights departing, arriving, or transiting the United States, we are required by U.S. Customs and Border Protection (CBP) and foreign immigration authorities to submit passenger manifest records (including passport data and temporary accommodation addresses).
- Emergency Passenger Manifests: In the event of an aviation incident or civil defense emergency, passenger contact and next-of-kin information is provided to the National Transportation Safety Board (NTSB) and emergency services.
7 International & Cross-Border Data Transfers
Because JetBluePartners operates international routes, your personal data may be transferred to and processed in servers located outside the European Economic Area (EEA), the United Kingdom, or your home jurisdiction.
Whenever we transfer personal information internationally, we enforce robust safeguards in compliance with GDPR Chapter V, including the European Commission’s Standard Contractual Clauses (SCCs), UK International Data Transfer Addendums, and certified data privacy frameworks, ensuring your data receives equivalent protection regardless of destination.
8 Data Retention Periods & Security Architecture
8.1 Retention Schedules
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:
- Financial & Billing Records: Retained for seven (7) years following transaction completion to satisfy IRS, corporate audit, and DOT accounting rules.
- Passenger Manifest & Flight Records: Retained in accordance with FAA and TSA aviation security archiving mandates (typically 12 to 36 months).
- Customer Support Communications: Retained for twenty-four (24) months to ensure quality assurance and follow-up support continuity.
- Marketing Profiles: Retained until consent is withdrawn via unsubscribe or erasure request.
8.2 Security & Encryption Protocols
We employ industry-leading administrative, technical, and physical safeguards:
- Encryption in Transit: All data exchanged with our servers is encrypted using modern Transport Layer Security (TLS 1.3) protocols.
- Encryption at Rest: Database repositories and cloud backups are encrypted using military-grade AES-256 standards.
- Access Control: Zero-trust network architectures, multi-factor authentication (MFA), and role-based least privilege controls limit employee access to passenger records.
9 Your Comprehensive Privacy Rights
Regardless of your geographic location, JetBluePartners extends universal respect to your fundamental privacy rights:
Request a comprehensive copy of the personal data, flight history, and profile records we hold about you.
Correct inaccurate, outdated, or incomplete personal information on your profile or active bookings.
Request deletion of your data when no longer required, subject to mandatory civil aviation record retention laws.
Receive your flight booking records in a structured, commonly used, and machine-readable format (JSON/CSV).
Opt-out of non-essential marketing emails, tailored advertisements, and profiling with a single click.
You will never receive diminished service, higher flight fares, or penalties for exercising your privacy rights.
To submit a formal request to access, rectify, port, or erase your personal information, email our Data Protection Officer directly at support@jetbluepartners.com with the subject line “Privacy Rights Request”. We fulfill verified requests within thirty (30) days without cost.
10 California Privacy Rights Notice (CCPA / CPRA)
This section applies specifically to California residents under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively “CPRA”).
- No Sale or Sharing of Personal Information: We do NOT sell your personal information, nor do we share your personal information with third parties for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: We only collect sensitive personal information (such as passport numbers or health assistance data) to perform air travel services contracted by you. We do not use sensitive personal information for inferring consumer characteristics.
- Global Privacy Control (GPC): Our web platforms recognize and respect automated browser-based opt-out signals such as Global Privacy Control (GPC).
12 Children’s Privacy & Unaccompanied Minors
We do not knowingly collect personal data from children under thirteen (13) years of age without verified parental or legal guardian consent. When a child travels as a ticketed passenger or participates in our Unaccompanied Minor service, we collect only information necessary to ensure child safety, flight manifesting, and authorized airport guardian handover.
13 Data Protection Officer & Regulatory Inquiries
If you have questions, feedback, or grievances regarding our data privacy practices, our Data Protection Officer is available to assist you:
Attn: Chief Privacy Officer & DPO
29-10 Queens Plaza North, Long Island City, NY 11101
Email: support@jetbluepartners.com
General Privacy Inquiries: info@jetbluepartners.com
Toll-Free Inquiries: +1 (800) 538 2583
Customer Service: +1(844) 586-2234
If you reside within the European Union or United Kingdom and believe your privacy concerns have not been adequately addressed, you maintain the right to lodge a formal complaint with your local Data Protection Authority (e.g., the Information Commissioner's Office in the UK or the relevant EU DPA).