Legal

Privacy Policy

How we collect, use, and protect your personal information.

Last updated: May 1, 2026

1. Introduction

This Privacy Policy describes how Onward Travel LLC, d/b/a Cloud Fares ("we," "us," "our") collects, uses, and protects your personal information when you visit cloud-fares.com (the "Website") or use our services. By using our Website or services, you consent to the practices described in this policy. We are committed to safeguarding the privacy of our users and complying with all applicable data protection laws.

2. Information We Collect

We collect information from multiple sources to provide and improve our services:

  • Personal information you provide directly: name, email address, phone number, travel dates and preferences, passport details (when required for booking), and payment information
  • Automatically collected information: IP address, browser type and version, device information, operating system, pages visited, time spent on pages, referral URLs, and clickstream data
  • Cookies and tracking technologies: We use cookies, web beacons, and similar technologies to collect usage data. See our Cookie Policy for full details.
  • Third-party sources: We may receive information from analytics providers (such as Google Analytics), advertising platforms, and social media services
  • Communication records: Records of your correspondence with our travel consultants, including emails, chat messages, and phone call notes
  • Any additional information you choose to share in special requests, feedback forms, or notes

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Processing and fulfilling your travel quote requests and bookings
  • Communicating with you about quotes, itineraries, booking confirmations, changes, and support
  • Providing personalized travel recommendations based on your preferences and history
  • Improving our Website, services, and user experience through analytics and usage patterns
  • Sending promotional offers, travel deals, and marketing communications (with your consent; you may opt out at any time)
  • Preventing fraud, unauthorized access, and other illegal activities
  • Complying with legal obligations, including tax reporting and regulatory requirements

4. How We Share Your Information

We do NOT sell your personal information. We may share your data with the following categories of recipients only as necessary to provide our services:

  • Airlines and travel suppliers: To fulfill your bookings and reservations
  • Payment processors: PCI-DSS Level 1 certified payment service providers handle the processing of all card transactions. Cloud Fares does not store, process, or transmit full primary account numbers (PAN) on its own systems; payment card data is captured directly into the processor's secure environment
  • Analytics and advertising partners: To understand site usage and measure advertising effectiveness (subject to your cookie consent preferences)
  • Technology service providers: Who assist in operating our platform, including hosting, email, and customer support tools
  • Legal authorities: When required by law, court order, subpoena, or to protect our rights, property, or safety

All third-party partners are contractually obligated to protect your data and use it only for the purposes we specify. We require them to maintain appropriate security measures.

5. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies to enhance your experience, analyze traffic, and deliver relevant content. Cookies are small text files stored on your device that help us recognize you and remember your preferences. We categorize cookies as: strictly necessary (required for site functionality), analytics/performance (help us understand site usage), functional (remember your preferences), and marketing (used for personalized advertising). You can manage your cookie preferences at any time through our cookie consent tool or your browser settings. For full details about the specific cookies we use and how to manage them, please see our Cookie Policy at cloud-fares.com/cookie-policy.

6. Data Retention

We retain your personal information for as long as necessary to provide our services and fulfill the purposes outlined in this policy. Booking records and associated financial data may be retained for up to 7 years to comply with tax, legal, and regulatory requirements. Marketing preferences are retained until you withdraw consent. Analytics data is retained in aggregated, anonymized form. You may request deletion of your data at any time, subject to our legal obligations.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Right to access: Request a copy of the personal information we hold about you
  • Right to correction: Request correction of inaccurate or incomplete data
  • Right to deletion: Request that we delete your personal information (subject to legal retention requirements)
  • Right to opt out of marketing: Unsubscribe from promotional communications at any time via the unsubscribe link in emails or by contacting us
  • Right to opt out of sale/sharing: For residents of states with applicable privacy laws, you may opt out of any sale or sharing of personal information for targeted advertising purposes
  • Right to data portability: Request a copy of your data in a structured, commonly used format
  • Right to non-discrimination: We will not discriminate against you for exercising any of your privacy rights

To exercise any of these rights, please contact us at privacy@cloud-fares.com. We will respond to verified requests within the timeframes required by applicable law.

8. CalOPPA Compliance

In compliance with the California Online Privacy Protection Act (CalOPPA), we make the following disclosures:

  • This privacy policy is accessible via a conspicuous link containing the word "Privacy" on our homepage and throughout the Website
  • Users may visit our Website anonymously without being required to provide personal information
  • This privacy policy page will be updated to reflect any changes to our data practices, with the "Last Updated" date revised accordingly
  • Users will be notified of material policy changes on this page
  • Users can request changes to their personal information by emailing us at the address provided in the Contact section
  • We honor Do Not Track (DNT) browser signals — when DNT is enabled, we will not track your activity across third-party websites

9. State Privacy Rights

Residents of certain U.S. states have additional privacy rights under their respective state laws:

  • California (CCPA/CPRA): California residents have the right to know what personal information is collected and how it is used; the right to delete personal information; the right to opt out of the sale or sharing of personal information; and the right to non-discrimination for exercising these rights. To submit a request, email us at privacy@cloud-fares.com or call us at +1 (888) 555-0123
  • Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other states: Residents of states with comprehensive privacy laws may have similar rights, including the right to access, correct, delete, and opt out of certain processing activities. We extend these rights to all users regardless of location where practicable.
  • To exercise your state privacy rights, contact us using the information in the Contact section below. We may need to verify your identity before processing your request.

We do not sell personal information as defined under the CCPA/CPRA. We do not use sensitive personal information for purposes beyond what is necessary to provide our services.

10. Children's Privacy

Our Website and services are not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take steps to delete that information as promptly as possible. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@cloud-fares.com so we can take appropriate action.

11. International Transfers

Onward Travel LLC is based in the United States, and your personal information may be processed and stored in the United States. If you access our Website or services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the U.S., where data protection laws may differ from those of your jurisdiction. By using our Website or services, you consent to the transfer of your information to the United States. We take appropriate safeguards to ensure that your personal information remains protected in accordance with this Privacy Policy.

12. EEA, UK, and Swiss Residents (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following additional disclosures apply under the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Act on Data Protection.

  • Controller: Onward Travel LLC, 5830 E 2nd St, Ste 7000 #22411, Casper, WY 82609, is the controller of your personal information for the purposes of GDPR
  • Lawful bases for processing (Art. 6 GDPR): (a) performance of a contract — to provide quotes, issue tickets, and support your booking; (b) compliance with legal obligations — tax, anti-fraud, and aviation-security record-keeping; (c) legitimate interests — improving our services, fraud prevention, and direct marketing of similar services to existing clients (you may object at any time); (d) consent — for marketing communications to new prospects, non-essential cookies, and any optional add-on services
  • Categories of recipients: airlines and travel suppliers, our PCI-DSS certified payment processors, IT and hosting providers, professional advisors, and law enforcement when legally required
  • International transfers: when your data is transferred from the EEA/UK/Switzerland to the United States, we rely on the EU Standard Contractual Clauses (and the UK Addendum / Swiss equivalent) approved by the European Commission, together with supplementary technical and organizational measures
  • Your rights: in addition to the rights listed in Section 7, you have the right to restrict processing, the right to object to processing based on legitimate interests, the right to withdraw consent at any time (without affecting the lawfulness of processing carried out before withdrawal), and the right to lodge a complaint with your local data protection authority
  • EU/UK queries: contact privacy@cloud-fares.com. We respond to verified GDPR requests within one calendar month, extendable by two further months for complex requests as permitted by Art. 12(3) GDPR

13. SMS / Text Message Consent (TCPA)

If you provide us with a mobile telephone number, you consent to receive transactional and operational SMS messages from Cloud Fares related to your booking — for example, ticket-issuance confirmations, schedule changes, gate updates, and check-in reminders. We do not send marketing SMS without separate, express written consent that complies with the U.S. Telephone Consumer Protection Act (TCPA) and FCC rules.

  • Message frequency varies based on your booking activity. Message and data rates may apply, set by your mobile carrier
  • Reply STOP to any message at any time to opt out of further SMS. Reply HELP for assistance, or contact hello@cloud-fares.com
  • We do not share or sell your mobile number with third parties for their own marketing purposes
  • If you change or relinquish your mobile number, please notify us so that future messages are not directed to a subsequent holder of the number

14. Security

We implement industry-standard security measures to protect your personal information, including encryption of data in transit (TLS/SSL), secure server infrastructure, access controls, the use of PCI-DSS Level 1 certified payment processors so that we never directly handle full payment-card numbers, and regular security assessments. While we strive to protect your data using commercially reasonable measures, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law (including, where applicable, within 72 hours under Art. 33 GDPR).

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. We will notify you of any material changes by posting the updated policy on our Website with a revised "Last Updated" date. We encourage you to review this policy periodically. Your continued use of our Website or services after any changes constitutes your acceptance of the updated policy.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

  • Email: privacy@cloud-fares.com
  • Phone: +1 (888) 555-0123
  • Mail: Onward Travel LLC, 5830 E 2nd St, Ste 7000 #22411, Casper, WY 82609