Privacy policy
Last updated 22 September 2026
This page is not ready to publish
LEGAL_ENTITY_NAME, LEGAL_ABN and LEGAL_ADDRESS, and have these terms reviewed by a lawyer, before taking bookings from the public.[not configured] ([not configured]) handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what we collect through The Sky Hero, why, and what you can do about it.
What we collect
- Search details. Origin, destination, dates, traveller counts and cabin. These are in the page URL and are not tied to your identity.
- Traveller details, when you book. Name, date of birth, and the gender shown on the travel document. Airlines require these to issue a ticket.
- Contact details. Email and phone number, used for confirmations and disruption notices.
- Booking records. Your itinerary, booking reference, amount paid and the status of the booking.
- Technical information. IP address and request metadata, used for rate limiting, fraud prevention and diagnosing errors.
What we do not collect
We do not store card numbers. Card details are captured by our payment provider and never persist on our servers. We do not hold passport numbers unless an airline specifically requires one for a route, in which case it is passed straight through and not retained.
We do not sell personal information, and we do not share it with advertisers.
Why we collect it
To make and service your booking, to meet our obligations to you and to the airline, to prevent fraud, and to keep the site working. We do not use your information for anything else without asking you first.
Who we share it with
- The operating airline and our flight-booking provider (Duffel). Necessary to issue a ticket. The airline handles your information under its own privacy policy.
- Our payment provider. To process your payment.
- Our hosting and database providers. Who store data on our behalf under contract.
- Law enforcement or regulators, where we are legally required to.
Overseas disclosure
Booking a flight necessarily discloses traveller details to airlines and systems overseas, including in the United States, the United Kingdom and the European Union. Some destinations also require advance passenger information by law. By booking, you consent to this disclosure, which cannot be avoided if the ticket is to be issued.
How long we keep it
Booking records are kept for seven years, which is the period we are required to retain transaction records for tax and audit purposes. Technical logs are kept for a much shorter period and contain no traveller names or contact details — where we need to correlate requests, we store a one-way pseudonym rather than an email address.
Security
Traffic is encrypted in transit. Booking records are held in a database that is not reachable from the public internet and is accessible only to our server. Access to operational tooling is restricted and read-only.
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
Cookies
We use one cookie, and only for staff signing in to the operations view. There are no advertising cookies and no third-party trackers on the booking funnel.
Accessing and correcting your information
Email hello@theskyhero.com.au and we will provide a copy of what we hold about you, or correct it, within 30 days. We may need to verify your identity first.
Complaints
Raise it with us at hello@theskyhero.com.au and we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes
We will post any update here with a new date at the top. Contact us if anything here is unclear.
[not configured] · [not configured]
[not configured]