Travel

The industry files

One booking becomes several files: the seller, the carrier, the booking system behind them, and the border authorities of every country on your route. The file outlasts the trip by years, mostly on the companies' own judgement of what is necessary.

The read at a glance

Tracking priority Recommended

Border systems and booking platforms both keep a copy of your passport.

If it leaks High

A leak exposes your passport, your itinerary, and where you stayed.

Expect it kept Years

Booking and border records are kept for years under travel and immigration rules.

Identity demanded ID documents

Travel requires passport or ID; hotels and borders often add a face check.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

If it leaks

A travel file says where you were, when, and who you were with, with the passport or ID number attached. It is enough to place you somewhere you would rather not be placed, long after the trip.

What repeats in the policies

Who else is told

The state is on the list, whichever way you travel

Cross a border and the carrier collects your passport and hands it to the border authorities of every country on your route, framed as their legal demand rather than the carrier's choice. Stay somewhere and lodging law takes over: the hotel keeps a register naming you and opens it to the police. The border file runs longest, five years with UK and EU authorities and up to fifteen where it reaches the US.

Where it goes

One trip becomes several files

A single booking rarely stays with one company. The seller passes your details to the airline or rail operator, to the booking system behind them, and to any hotel, transfer or extra you added. Each keeps its own record under its own policy, so a request to the company you booked with does not reach the rest of the trip.

What stays

The file outlasts the trip by years

How long the file is kept is usually their judgement rather than a number: many policies say only that they hold it as long as necessary. Where a number does appear it is tied to the years a legal claim could be brought: several keep the travel record for six and a half, or even ten, years after you last travelled. Closing the account does not shorten it.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoIdentity DocumentsBrowsing & ActivityPurchasesFinancial Account Profile · maybeLocation · maybePhotos & Biometrics · maybeHealth · maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Where you go Highly likely

Bookings map exactly where you go and when.

Health Possible

Special assistance and visa medicals sit in the file.

What lawfully stays after you leave

Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.

Policing / immigration records Law sets it years, sometimes decades

Policing and immigration records carry very long statutory retention.

Guest register records Law sets it about 1 to 3 years

Lodging laws make hotels keep a guest register and open it to the police.

Identity and age-check records They set it as long as they choose

To prove they checked your age or identity and to block known fraud, sometimes held by a separate verification company.

Tax and accounting records Law sets it about 6 years

Tax and company law makes them keep billing and payment records.

Records tied to a live or potential dispute They set it the limitation period of the claim

They can keep records to defend a live or possible legal claim.

Who wants this data

More than two hundred airlines settle their tickets through a single clearing house that major carriers own. It packaged over a billion travel records, names, full itineraries and payment details, and sold them to border and immigration agencies, under a contract that barred those agencies from naming it as the source. More than half the world's flights pass through that settlement, so your itinerary can reach that market without you ever dealing with the clearing house.

Sold or shared Likely

Travel patterns are valuable to advertisers and partners.

AI training Moderate

Booking and border data feeds risk and facial systems.

Even anonymised, this can still be you

Passport data identifies you outright, and itineraries are mobility traces, where four time-and-place points single out 95% of people (de Montjoye et al., 2013).

Name, date of birth, postcode Typical

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces Sometimes

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

Payment patterns Typical

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

Face and voice Sometimes

A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.

Browsing fingerprint Typical

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.

The move An objection tells them to use your data to run the service and nothing more.

“we do not sell your personal information”

“we do not sell your personal information”

Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.

The move Use the do-not-sell switch where there is one, and put an objection in writing as well.

“service providers, partners, and affiliates”

“service providers, partners, and affiliates”

This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.

The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.

“aggregated or de-identified information”

“aggregated or de-identified information”

Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.

The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

“retained as long as necessary, or as required by law”

They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.

The move Which reasons apply to you, and how long each runs, is a request of its own.

“you grant us a licence to use your content”

“you grant us a licence to use your content”

This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.

The move Their terms say whether the licence ends when the account does. Close the account and log the date here.

“Advance Passenger Information, shared with border authorities to meet the immigration requirements of the countries we fly to”

“Advance Passenger Information, shared with border authorities to meet the immigration requirements of the countries we fly to”

Collecting your passport or ID document, its number, nationality and dates, and passing it to the border authorities of every country on your route. The hand-over is framed as those countries' legal demand rather than the carrier's choice, so it is not something you opt out of.

The move No request to the carrier pulls the passport data back from the border authorities that hold it. The record marks that the hand-over happened.

“they will be the data controller and their privacy notice will apply”

“they will be the data controller and their privacy notice will apply”

Passing your booking to another company, the operator, the booking system, a hotel or a transfer firm, which then becomes the record's own keeper under its own policy. The company you booked through steps out of responsibility for that copy.

The move A request to the company you booked with reaches only its own copy; the operator, the booking system and the extras each hold a separate file.

“we create a customer profile for you, used to group similar customers together into customer segments”

“we create a customer profile for you, used to group similar customers together into customer segments”

Building a lasting file from your travel history, searches, purchases and details about you, kept apart from any single booking and used to target offers. A few policies go further and say this profile helps set the rates you are shown.

The move A request surfaces the profile held beside your bookings and what feeds it.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply.