Legal

Privacy Policy

Effective July 2026 · hushpay.ai

Hushpay, Inc. is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, how we use and protect it, who we share it with, and what rights you have over it. It applies globally to all users of the Hushpay website and mobile application, regardless of where you are located.

01Who Is Responsible for Your Data

Hushpay Inc., a Delaware corporation with its principal address at 1000 Brickell Avenue, STE 715, Miami, FL 33131, United States (Office: +1 (928) Hushpay), is the data controller of your personal data collected through the Service. Our privacy contact is: privacy@hushpay.ai.

Where Hushpay processes personal data on behalf of partner venues or airline partners, Hushpay acts as a data processor under those partners' instructions. This Privacy Policy governs Hushpay's own data controller activities.

02What Data We Collect

2.1 Data you provide directly

Account data (name, email, phone, date of birth, country of residence), payment method details processed by our PCI-DSS certified partners, communications with our support team, and any survey responses you provide.

2.2 Data we collect automatically

Device and technical data (IP address, device type, OS, app version, unique device identifier), usage data (features used, screens viewed, session duration, in-app search queries) and venue and flight preferences derived from your activity.

2.3 Data we receive from third parties

03How We Use Your Data

We use your personal data to operate the Service, process payments, prevent fraud, provide customer support, personalise Tonight Feature recommendations and Smart Feed rankings, send you relevant Hushpay communications, and comply with legal obligations under financial services, AML and data protection law.

04Sharing Your Data

Hushpay does not sell your personal data to third parties. We share your personal data only in the circumstances described below.

4.1 Service providers

4.2 Partner venues and airline partners

Where necessary to facilitate a booking or access arrangement, we may share limited transaction data (such as booking reference and relevant access details) with the relevant partner. We do not share your payment card details with partner venues or airlines.

4.3 Legal and regulatory disclosure

We may disclose your personal data where required by law, court order, regulatory authority or government agency, or where we believe disclosure is necessary to protect the rights, property or safety of Hushpay, our members, or the public.

4.4 Business transfers

In the event of a merger, acquisition, financing or sale of assets involving Hushpay, your personal data may be transferred to the acquiring entity, subject to that entity's commitment to honour this Privacy Policy or provide equivalent protections.

4.5 Aggregated and anonymised data

We may share aggregated or anonymised data (from which you cannot be identified) with business partners, research institutions or the public for analytical and research purposes.

05International Data Transfers

Hushpay is headquartered in the United States. Your personal data may be transferred to and processed in countries other than the one in which you reside, including the United States. These countries may have data protection laws that differ from those in your jurisdiction.

When we transfer personal data from the EEA, the UK, or Switzerland to countries not recognised as providing an adequate level of data protection, we rely on appropriate transfer mechanisms including Standard Contractual Clauses (SCCs) and Data Processing Agreements incorporating applicable transfer safeguards. For transfers from the UAE (DIFC/ADGM), Saudi Arabia (PDPL), Canada (PIPEDA), or other jurisdictions with cross-border requirements, we apply equivalent contractual safeguards.

06Data Retention

We retain account data for the duration of your account plus 7 years after closure for legal and regulatory compliance and dispute resolution. Transaction and payment data are retained for the periods required by financial services regulation. Usage and analytics data are retained in aggregated form for service improvement.

07Your Rights

Depending on your jurisdiction, you may have some or all of the following rights in relation to your personal data. We honour these rights globally to the fullest extent practically possible: access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent.

We will respond to all verifiable data rights requests within 30 days (or the period required by applicable law). For complex requests, we may extend this period by a further 30 days with notice. We may need to verify your identity before processing a request.

08Legal Bases for Processing (EEA / UK / Equivalent Jurisdictions)

09Cookies and Tracking Technologies

We use strictly necessary cookies for session management, security and authentication, plus analytics and preference cookies to improve the Service. You can manage preferences through the cookie consent tool on our website or through your browser and device settings. We do not respond to browser Do Not Track signals but we do honour opt-out requests made through our privacy contact.

10Payment Data and Financial Security

Hushpay takes the security of payment data extremely seriously. We do not store raw payment card numbers on our servers. All card processing is handled by PCI-DSS compliant third-party processors (Stripe, NymCard, or Fyatu). Hushpay receives only limited, tokenised transaction data necessary to operate the Service.

JIT virtual cards created for Member Access Windows are single-use, time-limited, and restricted to the specific partner venue by Merchant ID. They cannot be used at other merchants and expire automatically after the access window closes.

11Crypto and Digital Asset Data (Phase 2)

When the crypto wallet feature becomes available, Hushpay will collect and process your digital wallet address and on-chain transaction data to facilitate USDT/USDC funding of your JIT cards. This data will be subject to AML screening. We do not have access to your private keys and do not custody your digital assets.

12Data Security

No method of transmission or storage is 100% secure. If we become aware of a data security incident affecting your personal data, we will notify you and relevant authorities as required by applicable law.

13Children's Privacy

The Service is not directed at children under 18 (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal data from children. If you believe we may have data about a child, please contact us at privacy@hushpay.ai.

14Regional Supplements

14.1 European Economic Area and United Kingdom

EEA and UK users have rights under the GDPR / UK GDPR and may lodge a complaint with their local supervisory authority.

14.2 United States (California)

California residents have rights under the CCPA/CPRA including access, deletion, correction and the right not to be discriminated against for exercising those rights.

14.3 United Arab Emirates

Hushpay processes personal data in compliance with UAE Federal Decree-Law No. 45 of 2021 and, where applicable, the DIFC Data Protection Law and ADGM Data Protection Regulations.

14.4 Canada

Canadian users are covered by PIPEDA and applicable provincial privacy laws. Complaints may be lodged with the Office of the Privacy Commissioner of Canada (priv.gc.ca).

14.5 Saudi Arabia

Saudi users are covered by the Personal Data Protection Law (PDPL). We apply appropriate cross-border transfer safeguards for data originating from Saudi Arabia.

15Changes to This Policy

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Policy. If you do not agree with the updated Policy, you should discontinue use of the Service and may request deletion of your data under Section 7.

16Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact our Privacy Team:

We aim to acknowledge all privacy enquiries within 5 business days and resolve them within 30 days (or the period required by applicable law).