Privacy Policy

Last updated 2026-09-28 · Deutsche Fassung

SeatPair is built so that there is almost nothing to protect. There are no accounts, no passwords, and no need to tell us who you are. This page describes exactly what does get stored and how to get rid of it.

1. Who is responsible

Hardik Jesani (SeatPair)
Parkstraße 44, 13585 Berlin, Germany
hardik@seatpair.com

2. What we store when you list a seat

  • Flight number and departure date
  • Your seat number and the seat type you would move to — or, if you hold a window or aisle, the middle seat you want. If you enter a travel companion's seat, we only use it to check that request; it is not stored.
  • Your preference switch (sitting next to someone)
  • Departure and arrival airport, if you scanned a boarding pass
  • The language you were using
  • A random 12-character token, which becomes the address of your listing page and is the only thing that identifies it
  • If you scan your boarding pass or type your booking reference: a scrambled code derived from it, so you can get your listing back from another phone. Your phone combines the booking reference with the flight, date and seat and turns that into a one-way fingerprint; only the fingerprint is sent, and we scramble it again with a secret key before storing it. It cannot be turned back into your booking reference, and it is deleted with your listing.

3. What we deliberately do not store

  • Your name — even when you scan a boarding pass that contains it
  • Your booking reference (PNR) itself — only the scrambled code described above — nor your ticket number or frequent flyer number
  • The boarding pass itself; the barcode is decoded on your device and never uploaded
  • Any account, password or persistent identifier
  • Your email address — SeatPair never asks for one

4. Boarding pass scanning

The camera scan runs entirely in your browser. The barcode is decoded on your phone, and only these are sent to us: flight number, departure date, seat number, the two airport codes and the scrambled booking-reference code described in section 2. Your name, your booking reference itself and everything else the barcode contains stay in the browser and are never transmitted.

5. Notifications

If you turn on notifications, your browser gives us an anonymous push endpoint — a URL issued by Google, Apple, Mozilla or Microsoft depending on your browser. It is not an email address, it does not identify you, and we cannot use it to reach you anywhere except in this browser. It is deleted together with your listing. This is based on your consent (Art. 6(1)(a) GDPR) and you can withdraw it at any time in your browser settings.

6. Technical data

To stop one person flooding a flight with fake listings, we store a salted, one-way hash of your IP address (for IPv6, of its network part) alongside the listing. It is not reversible to an IP address, and the salt changes hourly, so the same connection produces a different hash the next hour. We never store the IP address itself. Legal basis: our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR).

When you press “List my seat”, Cloudflare Turnstile checks that the request comes from a person and not from a script. For this check Cloudflare processes your IP address and technical details of your browser and connection (such as the user agent and TLS fingerprint). Most people never see it; occasionally it asks you to tick a box. We only receive a pass or fail answer. Cloudflare does not use the check to identify or profile you, but may use the signals to improve its bot detection. The check runs only on the listing form. Legal basis: our legitimate interest in keeping fake listings out, so they cannot wreck real swaps (Art. 6(1)(f) GDPR). Whatever the check reads from or stores on your device is strictly necessary for the service you asked for (§ 25(2) No. 2 TDDDG).

Our hosting provider keeps short-lived request logs for operational security, as any web server does. If traffic looks automated, it may first ask your browser to complete a short security check.

7. How long we keep things

  • Listings and matches: automatically deleted after your flight's departure day. Not archived, not anonymised — deleted.
  • Push subscriptions: deleted with the listing they belong to.
  • Reports of a failed swap: kept up to 90 days so we can spot repeat abuse.

You can delete your listing yourself at any time from your listing page.

8. Who processes data for us

  • Vercel Inc. — hosting and delivery. Our functions run in the Frankfurt (fra1) region.
  • Supabase — the PostgreSQL database, hosted in the EU.
  • Cloudflare — the Turnstile check on the listing form (section 6) and Web Analytics (see below).
  • Push services (Google, Apple, Mozilla, Microsoft) — only if you enable notifications, and only to deliver the notification itself.

Where a provider is based outside the EU, transfers are covered by the European Commission's Standard Contractual Clauses.

9. Analytics

We use Cloudflare Web Analytics, which sets no cookies, stores no device identifiers and does not fingerprint visitors. It counts page views and referrers in aggregate only. Because it accesses no information on your device, it needs no consent banner under § 25 TDDDG. Your listing page (the /s/… link) is never measured, so its address never reaches Cloudflare.

10. Cookies and local storage

SeatPair sets no cookies of its own. The security checks in section 6 may store a short-lived token in your browser to remember that you passed; that is strictly necessary to protect the service and is used for nothing else. Your browser's local storage is used for one thing: to remember the link to your own listing so you can find it again if you close the tab. That value stays on your device and is never sent to us. Clearing your browser data removes it.

11. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interest. Because listings carry no identifier tied to you, the practical way to exercise erasure is the delete button on your listing page — or send us the listing link by email and we will remove it.

You also have the right to complain to a supervisory authority. The competent one for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin.

12. Changes

If this policy changes, the date at the top changes with it. Since we hold no email addresses for listings, we cannot notify you individually — please check back if it matters to you.