How FlyMidway handles your data
FlyMidway processes only the information needed to create shared travel searches, operate group decisions, provide requested preferences, and improve the service where you permit it.
Meetup and identity data
Names, departure locations, travel-party counts, votes, hotel suggestions, wishes, messages, reactions, and shared checklist activity are stored for the meetup. Anyone with its link may be able to view the meetup, so do not enter sensitive personal information.
Newsletter
When you subscribe, FlyMidway stores your normalized email address, locale, source, status, and consent time. The address is not sent to Vercel Analytics. You can request unsubscribe or deletion. Your subscription becomes active only after email confirmation; an unconfirmed request is deleted after 7 days.
Privacy choices
FlyMidway stores your category choice in a first-party cookie and records an anonymous consent identifier, selected categories, version, language, action, and timestamp in PostgreSQL. The receipt contains no email address, participant identity, or IP address.
Analytics
If allowed, Vercel Web Analytics receives anonymized page-view and product-event data such as the page path, referrer, approximate country, browser, device, and operating system; its visitor hash changes daily. FlyMidway also stores limited meetup product events in PostgreSQL with the related meetup, event name, permitted properties, and timestamp. These events contain no newsletter address, participant name or credential, recovery token, or raw IP address. Speed Insights additionally processes the page URL and real-user performance metrics, including loading speed, responsiveness, and visual stability.
Affiliate services
FlyMidway may earn a commission after you open a clearly identified partner link and complete a purchase. To prepare and attribute a requested redirect, FlyMidway records the provider, destination, target, creation and click time, and the related meetup, search, or participant where applicable. After the redirect, the named partner processes the request under its own notice. Travelpayouts Drive runs only after optional affiliate permission and never on meetup or outbound-redirect pages. The record also contains the total number of redirects and the first and most recent redirect times.
Viator activity content
For the Things to do section, FlyMidway sends the winning destination, shared travel dates, display language, and EUR currency to the Viator Partner API from the server. FlyMidway does not send participant names or browser identifiers to Viator for this content request. Product images are fetched from Viator or Tripadvisor media domains by FlyMidway's server-side image optimizer. Those media providers receive the optimizer's connection metadata, not participant browser identifiers. A partner redirect is created only after an intentional click.
Purposes and legal bases
Data you provide to create, join, or use a meetup and records needed to perform an intentional partner redirect are processed because they are necessary to perform the service you request (Article 6(1)(b) GDPR). Limited data about other group members entered by an authorized participant, affiliate attribution, security, abuse prevention, and essential operational logs are processed for the legitimate interests of enabling group planning, funding, and reliable operation (Article 6(1)(f)). Newsletter email, optional analytics, and Travelpayouts Drive are processed with consent (Article 6(1)(a)), which may be withdrawn at any time. Data are also processed where necessary to comply with a legal obligation (Article 6(1)(c)).
Processors and recipients
Data may be processed by FlyMidway's hosting, database, infrastructure, email, analytics, and travel-partner providers only where needed for the described purpose. Current core providers include Vercel for hosting and optional analytics, the configured PostgreSQL and Redis providers, Travelpayouts and the named booking partner after an intentional outbound action. Pexels supplies destination photos and OpenFreeMap supplies map tiles; these services may receive ordinary connection metadata when an asset is requested, but FlyMidway does not intentionally attach a participant identity. Resend processes newsletter delivery and subscription status for FlyMidway.
International transfers
Some providers may process data outside the European Economic Area. FlyMidway assesses the provider and relies on an adequacy decision or appropriate contractual safeguards where required. The current provider documentation and a copy or description of applicable safeguards can be requested using the privacy contact below.
Retention
A meetup is never automatically deleted before its planned return date. After return, a draft or failed meetup is scheduled after 30 inactive days and a completed or stale meetup after 90 inactive days; both then receive a further 30-day grace period. An organizer can extend protection by 180 days. Expired recovery links are removed after another 30 days. Unused affiliate redirects are deleted after 30 days, clicked records after 730 days, first-party analytics events after 395 days, and anonymous consent receipts after 1095 days. For used affiliate records, this period is counted from the most recent redirect. An unsubscribed or suppressed newsletter record is deleted after 30 days; an active address is kept until unsubscribe or a valid request. Expired flight cache entries are removed by the daily sweep. The exact meetup deletion date is shown to an authorized organizer.
Data supplied by other group members
A meetup creator or another authorized group member may enter a traveler's name, departure location, party size, hotel suggestion, wish, message, reaction, or checklist task. A traveler may also voluntarily share their passport issuing countries; they can turn sharing off at any time to remove those values from the server. The shared link gives each participant access to this information and to these privacy details. Do not enter passport numbers, health information, payment data, booking credentials, or other sensitive information.
Security and retention
Identity credentials are protected with secure tokens, HttpOnly cookies where applicable, and server-side hashes. To prevent abuse, FlyMidway temporarily stores in Redis a keyed pseudonymous identifier derived from the network address; the raw address is not stored in those rate-limit records. Access links should be treated as confidential. Manual deletion removes active database data immediately; any encrypted backup copy ages out through the database provider's contractually configured rotation and is not restored into the service. You may request the current backup regime using the contact below. FlyMidway applies technical and organizational safeguards, but no internet service can guarantee absolute security.
Required data and automated recommendations
Providing personal data is not a statutory requirement. A name or label, departure location, travel-party size, and travel dates are necessary for the corresponding meetup search or participation feature; without them FlyMidway cannot provide that feature. Newsletter, analytics, and affiliate-recommendation permissions are optional. FlyMidway automatically ranks travel variants using price, journey time, stops, timing, fairness metrics, and filters selected by users. These recommendations do not produce legal or similarly significant effects; the group chooses the result and each person decides whether to book.
Your choices and rights
You may request access, correction, deletion, restriction, objection, and data portability where applicable. You may withdraw consent without affecting earlier lawful processing and lodge a complaint with the Czech Office for Personal Data Protection or another competent supervisory authority. Rights affecting other group members may require identity verification and careful redaction.
Contact
The controller responsible for FlyMidway is JUSTEVERYWHERE s.r.o., Varšavská 715/36, Praha 120 00, Company ID: 19738544. Registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File 390855, since 20.09.2023. Privacy requests can be sent to pavel.vladimir.travnicek@gmail.com