Skip to content
N8GoTravel

Legal

Privacy policy

Last updated 5 September 2026

This policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have under the UK GDPR and EU GDPR.

1. Who we are

N8Go Travel, a trading name of Incipio Holdings Limited (registered in England & Wales, Reg. No. 16817623), is the data controller for the personal data described here. You can contact us about data protection at privacy@n8go.travel.

2. What we collect and why

We collect the following categories of data:

  • Account data. Your email address, name, and a hashed password. Needed to give you an account. Lawful basis: performance of a contract.
  • Booking data. Traveller names, dates of birth where an airline requires them, contact details, and booking references. Needed to make bookings on your behalf. Lawful basis: performance of a contract.
  • Payment data. We do not store card numbers. Stripe processes payments and returns only a token and the last four digits. Lawful basis: performance of a contract, and legal obligation for transaction records.
  • Preferences and activity. Your onboarding answers and which trip ideas you save or skip, used to personalise what we show you. Lawful basis: legitimate interests, and you can reset this at any time.
  • Destinations you search for. A light record of the flights and hotels you search for while signed in (just the destination and when, never the full search or your results), used to show you more relevant offers. Never recorded for a guest checkout. Lawful basis: legitimate interests, same as preferences and activity above, and you can turn this off or clear it at any time from your account’s privacy settings.
  • Marketing email. If you opt in, your email address is used to send Daily Deals, our occasional email about genuine savings we’ve found. Lawful basis: consent. Off by default, and every email includes a one-click unsubscribe that works whether or not you’re signed in.
  • Trip planning conversations. What you tell the trip planner, used to produce your itinerary. Lawful basis: performance of a contract.
  • Membership and billing data.Whether you hold a paid Membership, your tier, and billing history. Payment card data itself is handled by Stripe as described below. Lawful basis: performance of a contract.
  • Points, Travel Wallet and Marketplace data. Your N8Go Points and Travel Wallet Credit balances and history, and records of Marketplace purchases (insurance, eSIMs, lounge access, parking and transfers), including the trip details needed to quote an insurance price. Lawful basis: performance of a contract.
  • Cookie consent record. The choice you make in our cookie banner, together with an approximate timestamp and IP address, kept so we can demonstrate compliance with cookie law if ever required. Lawful basis: legal obligation.
  • Family sharing data. If you invite someone to a family sharing seat, we process the email address you provide to send the invitation and, once accepted, that it links to your Membership. If you are invited, we process the email address the invitation was sent to, to confirm it matches your account. Lawful basis: performance of a contract.

3. Automated processing

We use Anthropic’s Claude API to turn your description of a trip into search criteria, and to write short explanations of why an option was chosen. This shapes what we suggest to you; it does not make a decision with legal or similarly significant effects about you, and it never sets a price. Prices always come from the airline or accommodation provider.

Personalisation of your homepage feed is likewise a ranking of editorial content, not a decision about you.

4. Who we share data with

  • Airlines and accommodation providers provide the traveller details required to make a booking you have asked us to make.
  • Duffel and RateHawk. The distribution platforms through which those bookings are made.
  • Stripe. For payment processing.
  • Anthropic. Trip planning conversation content, for generating itineraries.
  • Resend. Your email address, to send booking confirmations, membership and price-alert emails, and family sharing invitations.
  • Marketplace suppliers. Where an insurance underwriter or other Marketplace supplier is named at the point of purchase, the details they need to provide that product (see our Marketplace terms).
  • Google Analytics. Only if you accept analytics cookies (see our Cookie policy). Aggregated usage measurement, to understand which parts of the service work well.
  • TikTok. Only if you accept advertising cookies (see our Cookie policy). Lets TikTok measure whether its ad campaigns led to a visit.

We do not sell personal data. Advertising cookies are set only with your consent.

5. International transfers

Some of our processors are located outside the UK and EEA. Where that is the case, the transfer is covered by UK International Data Transfer Agreements or EU Standard Contractual Clauses, together with additional safeguards where required.

6. How long we keep it

  • Account data: while your account is open, then 12 months.
  • Booking and payment records: 7 years, to meet tax and accounting obligations.
  • Trip planning conversations: 24 months.
  • Preference and activity data: until you reset it or close your account.
  • Destinations you search for: up to 6 months on a rolling basis, or until you clear it or turn tracking off, whichever is sooner.
  • Marketing email opt-in: until you unsubscribe or close your account.
  • Membership, Points, Travel Wallet and Marketplace purchase records: 7 years, for the same accounting reasons as bookings and payments.
  • Family sharing invitations: while the seat is active, then 12 months.

7. Your rights

You have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, and to receive it in a portable format. You can exercise these by emailing privacy@n8go.travel.

Where we rely on legitimate interests, which covers personalisation, you may object at any time and we will stop.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office (ico.org.uk), or to your local supervisory authority if you are in the EEA.

8. Security

Passwords are hashed with Argon2id. Card data never reaches our servers. Access to production data is restricted and logged.

Privacy policy · N8Go Travel