SoarSign in

Privacy Policy

Last updated · August 12, 2026

Acceptance

By creating an account, signing in, or using any part of Soar, you accept this Privacy Policy in full and consent to every collection, use, transfer, storage, and disclosure described here. If you do not agree, you must not use Soar.

What we collect

We collect everything you give us and everything we need to operate the service, including: phone number, name, date of birth, email, passport and travel-document details, payment instrument tokens, device identifiers, IP address, browser and operating-system data, approximate location, search history, booking history, support correspondence, and any other information you submit. We may also collect data from airlines, payment processors, identity-verification providers, fraud-prevention services, analytics providers, and publicly available sources.

How we use it

We use your data to operate, improve, secure, personalise, and market the service; to execute bookings; to comply with legal, tax, regulatory, and law-enforcement obligations; to detect and prevent fraud, abuse, and security incidents; to enforce our Terms; and for any purpose disclosed at the point of collection or to which you consent.

Marketing communications

By creating an account, you agree that we may send you marketing and promotional email — such as product news, offers, deals, and travel inspiration and tips — to the email address associated with your account. You can opt out of marketing email at any time from Settings → Notifications → Email, or by using the unsubscribe link in any marketing message, and we will action your request promptly. Opting out of marketing does not stop transactional and service messages we send to operate your account and bookings — including booking confirmations, itinerary and schedule changes, check-in reminders, refund and payment notices, and security or verification messages — which you will continue to receive while you hold an account.

Who we share with

We share data with airlines, accredited travel and booking providers, payment processors, SMS and identity-verification providers (including Twilio), cloud-infrastructure providers, analytics and observability vendors, fraud-prevention services, professional advisors, and any successor entity in the event of a merger, acquisition, financing, reorganisation, bankruptcy, or sale of assets. We disclose data when required by law, subpoena, court order, regulatory request, or to protect our rights, property, users, or the public. We do not sell personal information for monetary consideration; certain transfers may, however, qualify as "sharing" under specific privacy statutes, and you consent to those transfers by using Soar.

Connected agents and MCP clients

If you connect Soar to an AI assistant or another Model Context Protocol (MCP) client, that client may send Soar your search requests, travel preferences, and instructions on your behalf. Soar returns the account, itinerary, offer, and booking information needed to complete the tools you authorize. The client provider may separately process or retain that information under its own privacy policy. Review the tool request before approving account changes, payments, or bookings, and disconnect the integration when you no longer use it.

We record limited MCP reliability and security information, such as authorization outcomes, tool names, response status, duration, and protocol version. We do not intentionally include bearer tokens, raw payment credentials, passport numbers, or complete tool arguments in that telemetry.

International transfers

Soar operates globally. Your data may be transferred to, stored in, and processed in jurisdictions outside your country of residence, including the United States, where data-protection laws may differ from those in your jurisdiction. By using Soar, you consent to these transfers.

Retention

We retain data for as long as we deem necessary to provide the service, comply with legal and audit obligations, resolve disputes, and enforce our agreements — which may extend well beyond account closure. Anonymised, aggregated, and de-identified data may be retained indefinitely.

Security

We use commercially reasonable safeguards but make no guarantee of security. No system is impenetrable. You use Soar at your own risk and accept that any transmission or storage of data carries inherent risk that we cannot eliminate.

Your choices

You may request access, correction, export, or deletion of your data via Profile → "Download my data" / "Delete account" or by emailing privacy@flysoar.ai. We will honour valid requests to the extent required by applicable law and may decline or limit requests where an exemption applies, where verification fails, or where retention is necessary for legal, security, or operational reasons. Deletion may take up to ninety days to propagate and may not extend to backups, logs, or anonymised data.

Children

Soar is not directed to children under 16 and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will take appropriate action.

Cookies & tracking

We and our service providers use cookies, SDKs, pixels, and similar technologies for authentication, security, analytics, and performance. By using Soar you consent to these technologies to the maximum extent permitted by law.

Changes

We may update this Privacy Policy at any time. Material changes take effect upon posting. Continued use of Soar after a change constitutes acceptance. You are responsible for reviewing the current version.

No warranties

Nothing in this Privacy Policy creates a contract, warranty, or legal obligation beyond what is mandated by applicable law. To the maximum extent permitted by law, Soar disclaims all liability arising from the collection, use, transfer, loss, or disclosure of data.

Contact

Privacy questions: privacy@flysoar.ai.