Layover AI Privacy Policy
Layover AI (“we”, “us”, or “our”) is committed to protecting user privacy. We are a Hong Kong–based travel planning platform targeting adults (18+) in Hong Kong and the APAC region. This Privacy Policy explains how we collect, use, share, and secure your personal data. We comply with Hong Kong’s Personal Data (Privacy) Ordinance (PDPO) and strive to follow international best practices (e.g. EU GDPR principles). In accordance with PDPO, you have the right to ask whether we hold personal data about you, to obtain a copy of that data, and to correct any inaccuracies.
Information We Collect
We collect only the data needed to provide and improve our services. The categories of information we gather include:
- Account and Profile Data: Registration details such as name, email address, login credentials, and (if you use Google Sign-In) basic profile info (name, email) received from Google.
- Travel Inputs: Your travel itinerary details, such as destinations, dates, number of travelers, trip preferences or interests. These help us generate personalized trip recommendations.
- Booking Information: When you use Layover AI to book flights, hotels, or other services, we may collect booking confirmations, reservation codes, and travel itinerary details. (We do not store full payment card details; those are handled by payment processors.)
- User-Generated Content: Any content you provide on the platform – for example, reviews, ratings, comments, or photos you upload.
- Device and Usage Data: Technical data about your device and how you use our service. This may include IP address, device type, browser type, operating system, pages you view, search queries, and session logs.
- Location Information: If you use our map or location-based features, we may collect geographic location data (e.g. GPS data or map queries) to help plan routes or suggest nearby attractions.
- Cookies and Tracking Data: We use cookies and similar technologies to improve site functionality and measure usage. Cookies are small text files stored on your device that track website interactions. We use first-party cookies for necessary features (like keeping you signed in) and may use third-party analytics cookies (e.g. Google Analytics) to collect anonymized usage statistics.
All personal data we collect is directly related to the purposes described in this policy. We do not collect excessive or unrelated information and, in line with PDPO DPP1, only collect data that is necessary for the specified functions.
How We Use Your Data
We use the information we collect for the following purposes:
- Provide and Improve Our Service: We use your account, travel, and booking data to operate the Layover AI platform. For example, we create and manage your user profile, fulfill travel planning requests, process bookings, and customize trip recommendations.
- Personalization: We may personalize the content you see (e.g. suggesting relevant attractions or itinerary ideas) based on your travel inputs and preferences. We may use Google Maps APIs to suggest routes and nearby points of interest.
- Communication: We use your contact information (email) to send you important updates, confirmations of bookings, account notifications, and responses to your inquiries or feedback. With your consent, we may send you promotional emails or newsletters; you can opt out of such marketing communications at any time.
- Analytics and Research: We analyze aggregate usage data to understand how the service is used and to improve our features and performance. For example, we use analytics tools to conduct troubleshooting, measure user engagement, and optimize our website and app.
- Compliance and Protection: We may use personal data to comply with legal obligations or protect our legal interests (e.g. preventing fraud, enforcing our terms of service, or responding to lawful requests by government authorities).
We will not use your personal data for any purpose that is incompatible with the original collection purpose, unless we obtain your consent. For instance, we do not engage in unsolicited direct marketing without explicit permission. In all cases, data use is in line with PDPO DPP3 and your informed consentpcpd.org.hk.
Cookies and Analytics
Cookies: We use cookies and similar tracking technologies to enhance your experience. Cookies are defined as “small files stored in a website user’s device” that allow the site to remember your preferences and track performance. Our first-party cookies (set by Layover AI) enable core functionality and help secure your session. We may also use third-party cookies (such as Google Analytics cookies) to collect anonymous statistics about site usage. These cookies are primarily for analytics and performance; we do not use cookies to personally identify you. You can control or disable cookies through your browser settings, but note that disabling cookies may limit certain features of the platform.
Analytics Tools: We use industry-standard analytics tools (like Google Analytics) to monitor how users interact with Layover AI. These tools collect information such as the pages you visit, the length of visits, and your geographical region. This data is used only in aggregate form to improve our service and is not used to identify you personally.
Sharing and Third-Party Services
Service Providers: To operate the platform, we share your data with trusted third-party service providers. For example, we use cloud hosting (e.g. AWS or Google Cloud) to store data, email services (e.g. SendGrid) to send notifications, customer support tools to assist you, and payment processors when handling bookings. We also rely on Google services (Maps API for location features, Google for Sign-In) and ensure they receive only the data necessary for their function. All such service providers act as data processors on our behalf. Under PDPO, a data user must ensure that processors comply with data protection requirements by contractual means. We require our providers to protect your data in accordance with PDPO and our policies.
Travel Partners: If you book travel (flights, hotels, etc.) through Layover AI, we may share relevant booking and contact details with the travel service providers to fulfill your reservation. For example, we may send your reservation information to an airline or hotel. This sharing is limited to what is necessary to complete the booking you have requested.
Analytics and Advertising: We do not sell or rent your personal data. We may share aggregated or anonymized usage statistics with partners for analytics purposes, but such data cannot be used to identify you. We do not engage in behavioral advertising without consent.
Legal Compliance: We may disclose personal data if required by law (e.g. a court order or legal process), or if we believe it is necessary to prevent illegal activities or protect our legal rights.
In all cases, we limit disclosure to what is required and we use contractual and technical safeguards to protect your data. When data is transferred to third parties (some of which may be located outside Hong Kong), we take steps to ensure compliance with PDPO and applicable data transfer laws.
Data Security
We implement robust security measures to protect your personal data. In accordance with PDPO’s DPP4, we take “all practicable steps to protect personal data” against unauthorized or accidental access, loss, or misuse. These measures include: encrypting data in transit using HTTPS/TLS; storing sensitive information in encrypted databases; restricting access to your data to authorized personnel only; using secure firewalls and intrusion detection; and conducting regular security assessments and audits. We also train our staff on data protection principles. While no system is completely foolproof, we strive to maintain industry-standard safeguards to keep your information secure.
Data Retention
We retain your personal data only as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations. In accordance with PDPO DPP2 and Section 26, we “erase personal data that is no longer required for the purpose” for which it was collectedpcpd.org.hk. If you request that we delete your personal data (and there is no legal requirement to retain it), we will do so promptly.
Your Rights and Choices
You have rights over your personal data. In particular:
- Access and Correction: You may request a copy of the personal data we hold about you and ask us to correct any inaccuracies. This is your right under PDPO. We will respond to your request within a reasonable time frame.
- Deletion: You can request deletion of your personal data. We will erase your data if it is no longer needed for the purpose collected, unless we are legally required to retain it.
- Withdrawal of Consent: If we rely on your consent for any data processing (e.g. marketing communications), you may withdraw that consent at any time by contacting us.
- Cookie Choices: You can refuse or delete cookies via your browser settings at any time. (Refer to your browser’s help pages for instructions.)
- Data Portability: While not explicitly provided under PDPO, we strive to assist with portability requests where feasible.
To exercise any of these rights, please contact us as below. We will not charge you for handling a data access or correction request, unless permitted by law to do so.
Children and Minors
Layover AI is intended for users aged 18 or older. We do not knowingly collect personal data from children under 18. If we learn that we have inadvertently received information from a user under 18, we will delete such information as soon as possible. Parents or guardians should supervise minors’ use of online services; children under 18 should not create an account or use Layover AI without parental consent.
International Considerations
Because Layover AI operates online, your data may be transferred internationally (for example, to servers operated by our cloud providers or third-party tools outside Hong Kong). We take steps to protect your data wherever it is processed. When transferring data out of Hong Kong (or the EU/UK, if applicable), we rely on contractual safeguards or comply with any required transfer mechanisms to ensure adequate protection in line with PDPO and international standards.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we do, we will post the revised policy on our website with a new effective date. We encourage you to review this policy periodically. Your continued use of Layover AI after any changes means you accept the updated terms.
Contact Information
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:
Email: hello@layover-ai.com
We will do our best to address your inquiry. You also have the right to lodge a complaint with the Hong Kong Privacy Commissioner for Personal Data if you believe your data protection rights have been violated.