Legal
Privacy Policy
How Last Leg Jet collects, uses, shares and protects personal information, and the rights you have over it under Australian and New Zealand privacy law.
1. Who we are and what this policy covers
Last Leg Jet Pty Ltd ("Last Leg Jet", "we", "us") operates the Last Leg Jet marketplace. This Privacy Policy explains how we handle personal information when you use our website, applications and services.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we handle personal information about individuals in New Zealand, we also comply with the Privacy Act 2020 (NZ) and its Information Privacy Principles. Where the GDPR or UK GDPR applies to you, the "Your rights" section describes the additional rights you may have.
2. What we collect
We collect the following kinds of personal information:
- Account information: name, email address, phone number, password hash, role and organisation.
- Booking information: passenger names, the number of passengers, itinerary, booking reference and special requirements you choose to tell us.
- Payment information: amount, currency, payment method and a provider reference. Card numbers are entered directly with our payment provider and are never stored by us. For cryptocurrency payments we store the asset, amount, destination address and transaction reference.
- Operator compliance information: AOC, insurance and airworthiness documents, aircraft registrations and images uploaded by operators.
- Security information: email verification status, two-factor authentication status (we store the shared secret in encrypted form and never the codes you enter), sign-in times and IP addresses.
- Usage and device information: pages viewed, searches, browser type, approximate location derived from IP address, and error diagnostics collected by our monitoring tools.
- Communications: messages you send us through the contact form, email or support channels.
3. How we use it
We use personal information to:
- create and secure your account, including sending verification emails and enforcing two-factor authentication;
- show search results, place seat holds and process bookings and payments;
- pass passenger details to the operator of the flight so that it can perform the contract of carriage and meet aviation security requirements;
- send booking confirmations, itinerary updates, cancellation notices and refund notices;
- verify operators and monitor that their compliance documents remain current;
- detect fraud, abuse and security incidents, and keep an audit trail of administrative actions;
- improve the Platform, diagnose errors and measure performance;
- comply with legal obligations, including aviation, tax, anti-money-laundering and consumer protection laws.
5. Overseas disclosure
Our primary hosting region is Sydney, Australia (ap-southeast-2). Some providers listed above process data in other countries. Before disclosing personal information overseas we take reasonable steps to ensure the recipient is bound by obligations substantially similar to the APPs and the NZ Information Privacy Principles, including through contractual clauses, and we remain accountable for that information as required by APP 8 and IPP 12.
6. Security and retention
We protect personal information with encryption in transit and at rest, access controls tied to staff roles, audit logging of administrative actions, and two-factor authentication for administrator accounts. No system is perfectly secure; if we become aware of an eligible data breach we will notify affected individuals and the relevant Commissioner as required by the Notifiable Data Breaches scheme (AU) or the Privacy Act 2020 (NZ).
We keep booking and payment records for seven years to meet tax and accounting obligations. Account information is kept while your account is open and for a reasonable period afterwards to resolve disputes. Operator compliance documents are kept while the operator is listed and for two years after. Diagnostic logs are kept for 90 days. When information is no longer needed we delete or de-identify it.
8. Your rights
You can access and correct the personal information we hold about you, and request that we delete it, by contacting us at the address below. We will respond within 30 days. We may need to verify your identity and may decline a request where the law requires us to keep the information (for example booking records). If we decline, we will tell you why.
If the GDPR or UK GDPR applies to you, you also have the rights to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. Our legal bases are performance of a contract (bookings), legitimate interests (security, fraud prevention and service improvement) and legal obligation.
You can opt out of non-essential emails using the link in the email. Transactional messages about your bookings and account security cannot be opted out of while you hold a booking or account.
9. Children
The Platform is intended for adults. Passenger details for children travelling on a booking are provided by the adult making the booking and are used only to perform that booking.
10. Complaints
If you have a concern about how we have handled your personal information, contact our privacy officer at the address below. We will acknowledge your complaint within five business days and aim to resolve it within 30 days. If you are not satisfied you may complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, in New Zealand, the Office of the Privacy Commissioner (privacy.org.nz).
11. Changes to this policy
We will update this policy as the service changes. The date at the top shows the current version. Material changes will be notified by email or on the Platform before they take effect.