> For the complete documentation index, see [llms.txt](https://docs.flip.to/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.flip.to/policies/platform/privacy-and-security-overview.md).

# Privacy and Security Overview

The Flip.to platform takes several measures to ensure data is securely collected and remains private, and is compliant with GDPR, CCPA and ADA.

***

## Certifications and Audits

Flip.to maintains a **SOC 2 Type 1** report. A **SOC 2 Type II** examination is underway. The report and our supporting policy set—covering information security, access control, encryption and key management, change management, risk management, vendor management, HR security, security awareness, incident response, and disaster recovery testing—are available to customers and prospective customers under NDA. Contact <help@flip.to> to request the package.

Separately, our infrastructure providers maintain their own certifications. Microsoft Azure meets a broad set of international and industry-specific compliance standards, such as ISO 27001, HIPAA, FedRAMP, SOC 1 and SOC 2, as well as country-specific standards like Australia IRAP, UK G-Cloud, and Singapore MTCS. These are our providers' certifications, not Flip.to's, and are listed here only to describe the environment the platform runs in.

***

## Architecture

The Flip.to platform is hosted on Microsoft Azure, Google Cloud and Cloudflare: Azure for the core platform, Google Cloud for the analytics pipeline and data warehouse, and Cloudflare for CDN, DNS, WAF, hosting and storage.

The complete list of third parties that process customer personal data on our behalf, what each is used for, and the processing location for each, is published at [Sub-Processors](/policies/platform/sub-processors.md). Customers with specific data residency requirements should raise them during scoping.

***

## Data Handling

### Data Scope

Data collected is limited in scope to the most basic traveler information and is configured by the customer. Flip.to does not have access to, collect or use any traveler’s financial information.

### Data Transfer

All data transfers between the transaction engine and Flip.to are encrypted over a secure connection (HTTPS). Breached encryption protocols are disabled at the server level, requiring all client browser transmission to be done over a trusted protocol.

### Data Access

Flip.to maintains a strict security policy to ensure that users can only access and manipulate data based on the permissions granted to them.

### Data Ownership

All data collected by Flip.to is solely owned by customers, and Flip.to can only use data on behalf of its customers. Data is not shared among customers or transferred to any third party without explicit consent of the relevant customer.

### Data Usage

All data collected by Flip.to is subject to the rules and regulations of the country or regions laws regarding email usage. Customers are responsible for complying with all usage information that is collected regarding email addresses in future marketing. Flip.to will work with customers to ensure collection of the data is compliant with the rules and regulations of the country or regional laws regarding email usage. However, it is incumbent on the customer to honor the usage of the data.

### PII Data Collection

**What is collected depends on the product.** Spacetime, our analytics platform, collects **no personal data at all**—no names, no email addresses, not even a reservation or CRS transaction identifier. It operates on transactional and behavioral data only, by design. Discovery and Advocacy do process traveler personal data, as described below.

Personal Data is any information that relates to an identified or identifiable individual. For Discovery and Advocacy, Personal Data can be collected from a third-party (for instance, the transaction engine) or can be provided by travelers such as:

* When a traveler submits a form while planning their trip, Flip.to receives their first name and email address.
* When a traveler completes a transaction, Flip.to receives their full name, email address and reservation number.
* When a traveler submits a story, Flip.to receives their photo, quote and caption.
* When a traveler shares plans or their story to their social networks, Flip.to receives their social network account ID and the

  post ID (if available).
* When a social connection of a traveler submits a form, Flip.to receives their full name and email address.

### PII Data Usage

Personal Data received is only used on behalf of the customer. Flip.to does not distribute or sell Personal Data to third-parties.

***

## Data Protection

### Infrastructure Level Controls

* Utilizing Azure Defender to protect against irregular activity & vulnerabilities.
* Automated server patches, anti-malware and anti-virus
* DDoS Protection.
* Using Auditing & Threat Detection.
* Access to the servers requires two-step verification (also known as two-factor authentication), and can only be performed from authorized locations.
* Clear separation between web and database servers, the latter only being accessible by the application within the confines of the datacenter network.
* Flip.to employees are uniquely identified when accessing confidential information and are given limited access to only the accounts that they are actively managing.
* Public access to Flip.to web servers and communication can only be established with common Internet ports (80 and 443).
* Sensitive data is always encrypted when stored.
* All communications over the App Service are encrypted.

### Database Level Controls

* Using SQL Azure for additional protection.
* Using Auditing & Threat Detection.
* Using ongoing Vulnerability Assessments.
* Backups are secured and encrypted.
* Short-term point-of-time backups stored for 35 days.
* Long-term weekly backups are stored for 52 weeks.
* Databases use Transparent Data Encryption (TDE).

### Application Level Controls

* Maintain documentation on overall application architecture, process flows, and security features.
* Employ secure programming guidelines in the development of applications.
* Multi-tier architecture each maintained with minimum privileges possible.
* Using the strictest security configurations available to Microsoft-based web applications.
* Central authentication and authorization mechanism.
* Encryption of sensitive information.
* Central validation of all input based on strict guidelines of data type, format and content.
* Central handling of untrusted uploaded images.
* Central handling of errors and limiting the data being sent back to clients.
* Limit cookie usage and cookie permissions; cookies are used only for the purposes disclosed in the [Privacy Policy](/policies/platform/privacy-policy.md).
* Forcing HTTPS for any sensitive data exchanged between client and server.
* Central guards against injection attacks.
* Central guards against click-jacking attacks on all pages not meant to be loaded inside an iframe.
* Automated tests during the development process.
* A mix of automated and manual tests once application updates are deployed.

### Website & Booking Engine Integration Strategies

* Details passed on the URL are encoded.
* All data collected is passed to Flip.to over HTTPS.
* All data passed to Flip.to is validated for syntax, format and content.
* Data is validated against our backend to ensure authenticity.
* Data sent back to client is directly from the backend, and does not include any information supplied from the original caller.

***

## Privacy Compliance and International Transfers

Flip.to is compliant with GDPR (General Data Protection Regulation) and CCPA (California Consumer Privacy Act), and uses proactive measures to ensure that its customers employ best privacy practices to meet the strict privacy requirements while using the Flip.to platform.

Flip.to acts as a **Processor** on behalf of its customers, who act as Controller. The terms governing that relationship—including the safeguards relied on for transfers of personal data out of the EEA, the UK and Switzerland—are set out in our [Data Processing Agreement](/policies/legal/data-processing-agreement.md), which incorporates:

* The **EU Standard Contractual Clauses** (Commission Implementing Decision (EU) 2021/914) for transfers subject to the EU GDPR;
* The **UK International Data Transfer Addendum** for transfers subject to the UK GDPR;
* Equivalent safeguards for transfers of personal data of data subjects in Switzerland.

The DPA also commits Flip.to to **security incident notification within 72 hours**, a 30-day advance notice and objection right on new sub-processors, and audit rights.

Flip.to's participation in the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. Data Privacy Framework is described in the [Privacy Policy](/policies/platform/privacy-policy.md), which is the authoritative statement of our DPF commitments.

***

## ADA Compliance

All integrations and components of the Flip.to platform are designed to be accessible by all users, including individuals with sight, hearing, and other disabilities; adhering to the World Wide Web’s Consortium’s Web Content Accessibility Guidelines 2.2 Level AA (WCAG 2.2 AA).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.flip.to/policies/platform/privacy-and-security-overview.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
