Privacy
Privacy Policy
Last updated August 31, 2026.
Fly with Derek uses this website to receive requests for personal review of premium-flight itineraries. This notice describes the data handled by the current site implementation and the services used to deliver and protect a request.
What information we collect
- Quote request data: trip type, origin and destination for each leg, travel dates, traveler count, cabin and flexibility preferences, name, email, preferred contact method, optional phone or WhatsApp number, optional notes, and privacy acknowledgement.
- Technical data: normal request information such as IP address and browser headers can be processed by hosting and security services. Vercel Analytics is present for aggregate site usage.
- Local form state: the browser may keep itinerary structure and travel preferences in session storage so a page refresh is less disruptive. Contact details, notes, and acknowledgement are not stored there by this site.
- Anti-abuse data: when configured, rate limiting uses an IP-derived key and Cloudflare Turnstile verifies a challenge token before submission.
Why we use it
- To review and respond to your request using the contact method you select.
- To deliver request and confirmation emails and preserve an operational record of the conversation.
- To reduce spam and abuse through validation, a honeypot, rate limiting, and optional human verification.
- To understand aggregate site use and improve the experience without intentionally sending form contact details or notes to analytics.
Services used by the site
- Resend — sends the advisor notification and customer confirmation email.
- Vercel — hosts the site and provides aggregate analytics.
- Cloudflare Turnstile — verifies the form when the integration is configured.
- Upstash Redis — stores short-lived rate-limit counters when configured; otherwise the API uses an in-memory fallback.
Each service processes data under its own terms and privacy notice. Their deployment regions, account settings, and retention controls can vary with the production configuration.
How long we keep it
The site code does not define the retention period for delivered email or provider account records. Rate-limit windows are configured for ten minutes. Browser session storage normally lasts for the tab session and can be cleared through browser controls. Provider retention follows the production account settings and applicable requirements.
Cookies
The application code does not add advertising cookies. Hosting, analytics, or anti-abuse services may process technical identifiers according to their current notices and the production configuration.
Your rights
Depending on the law that applies to you, you may have rights to ask about, correct, or delete personal data and to object to or restrict some processing. Use the contact options below to make a request.
Security
Production hosting is configured for HTTPS and security headers. The form validates and sanitizes its payload, limits request size, and applies anti-abuse controls. The site does not request payment-card or passport data. No internet transmission or storage system can be promised as completely secure.
Changes to this policy
We may update this policy as services change. The "last updated" date at the top reflects the most recent version. Material changes will be highlighted.
Contact
Privacy questions can be sent through the request form or discussed by phone at +1 (786) 706-4828.