Legal

Privacy Policy

How Last Leg Jet collects, uses, shares and protects personal information, and the rights you have over it under Australian and New Zealand privacy law.

DRAFT — pending legal review. This document has not yet been reviewed by counsel and may change before launch. Last updated 21 August 2026.

1. Who we are and what this policy covers

Last Leg Jet Pty Ltd ("Last Leg Jet", "we", "us") operates the Last Leg Jet marketplace. This Privacy Policy explains how we handle personal information when you use our website, applications and services.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we handle personal information about individuals in New Zealand, we also comply with the Privacy Act 2020 (NZ) and its Information Privacy Principles. Where the GDPR or UK GDPR applies to you, the "Your rights" section describes the additional rights you may have.

2. What we collect

We collect the following kinds of personal information:

  • Account information: name, email address, phone number, password hash, role and organisation.
  • Booking information: passenger names, the number of passengers, itinerary, booking reference and special requirements you choose to tell us.
  • Payment information: amount, currency, payment method and a provider reference. Card numbers are entered directly with our payment provider and are never stored by us. For cryptocurrency payments we store the asset, amount, destination address and transaction reference.
  • Operator compliance information: AOC, insurance and airworthiness documents, aircraft registrations and images uploaded by operators.
  • Security information: email verification status, two-factor authentication status (we store the shared secret in encrypted form and never the codes you enter), sign-in times and IP addresses.
  • Usage and device information: pages viewed, searches, browser type, approximate location derived from IP address, and error diagnostics collected by our monitoring tools.
  • Communications: messages you send us through the contact form, email or support channels.

3. How we use it

We use personal information to:

  • create and secure your account, including sending verification emails and enforcing two-factor authentication;
  • show search results, place seat holds and process bookings and payments;
  • pass passenger details to the operator of the flight so that it can perform the contract of carriage and meet aviation security requirements;
  • send booking confirmations, itinerary updates, cancellation notices and refund notices;
  • verify operators and monitor that their compliance documents remain current;
  • detect fraud, abuse and security incidents, and keep an audit trail of administrative actions;
  • improve the Platform, diagnose errors and measure performance;
  • comply with legal obligations, including aviation, tax, anti-money-laundering and consumer protection laws.

4. Who we share it with

We share personal information only as needed to run the service:

  • Operators: the operator of a flight receives the passenger and contact details for that booking. Operators are independent organisations and handle your information under their own privacy policies.
  • Payment providers: Stripe (cards and Klarna), PayPal and Coinbase Commerce (cryptocurrency) process payments on our behalf and receive the information required to do so.
  • Infrastructure and tooling: our cloud hosting, email delivery, file storage and error monitoring providers, which act on our instructions under contract. Some of these providers store data outside Australia and New Zealand, including in the United States.
  • Regulators and authorities: where required by law, for aviation security, or to respond to lawful requests.
  • Business transfers: if Last Leg Jet is acquired or merges, personal information may be transferred to the successor, subject to this policy.

5. Overseas disclosure

Our primary hosting region is Sydney, Australia (ap-southeast-2). Some providers listed above process data in other countries. Before disclosing personal information overseas we take reasonable steps to ensure the recipient is bound by obligations substantially similar to the APPs and the NZ Information Privacy Principles, including through contractual clauses, and we remain accountable for that information as required by APP 8 and IPP 12.

6. Security and retention

We protect personal information with encryption in transit and at rest, access controls tied to staff roles, audit logging of administrative actions, and two-factor authentication for administrator accounts. No system is perfectly secure; if we become aware of an eligible data breach we will notify affected individuals and the relevant Commissioner as required by the Notifiable Data Breaches scheme (AU) or the Privacy Act 2020 (NZ).

We keep booking and payment records for seven years to meet tax and accounting obligations. Account information is kept while your account is open and for a reasonable period afterwards to resolve disputes. Operator compliance documents are kept while the operator is listed and for two years after. Diagnostic logs are kept for 90 days. When information is no longer needed we delete or de-identify it.

7. Cookies and analytics

We use a strictly necessary session cookie ("llj_token") to keep you signed in. It is HTTP-only and is not used for advertising. We may use privacy-respecting analytics and error monitoring that collect aggregate usage data and technical diagnostics; these do not build advertising profiles. We do not use third-party advertising cookies.

8. Your rights

You can access and correct the personal information we hold about you, and request that we delete it, by contacting us at the address below. We will respond within 30 days. We may need to verify your identity and may decline a request where the law requires us to keep the information (for example booking records). If we decline, we will tell you why.

If the GDPR or UK GDPR applies to you, you also have the rights to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. Our legal bases are performance of a contract (bookings), legitimate interests (security, fraud prevention and service improvement) and legal obligation.

You can opt out of non-essential emails using the link in the email. Transactional messages about your bookings and account security cannot be opted out of while you hold a booking or account.

9. Children

The Platform is intended for adults. Passenger details for children travelling on a booking are provided by the adult making the booking and are used only to perform that booking.

10. Complaints

If you have a concern about how we have handled your personal information, contact our privacy officer at the address below. We will acknowledge your complaint within five business days and aim to resolve it within 30 days. If you are not satisfied you may complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, in New Zealand, the Office of the Privacy Commissioner (privacy.org.nz).

11. Changes to this policy

We will update this policy as the service changes. The date at the top shows the current version. Material changes will be notified by email or on the Platform before they take effect.