LaaSy, Inc.

Unified Privacy Policy

Covering LaaSy Perks (leisure travel) and LaaSy Business Travel.

Last modified: 8.05.2026

How to read this Policy

This Policy covers two products operated by LaaSy, Inc.: LaaSy Perks (our leisure travel and cashback rewards platform) and LaaSy Business Travel (our corporate booking and travel management platform). Most sections apply to both products. Where a section applies only to one product, it is clearly labeled:

  • Perks only Applies only to LaaSy Perks users.
  • Business Travel only Applies only to corporate travelers and companies.
  • Both Applies to users of either or both products.

If you use both products through a unified account, this entire Policy applies to you.

Section 1Who We Are and How to Contact Us

This Privacy Policy is issued by LaaSy, Inc. (“LaaSy,” “we,” “us,” or “our”), a Delaware corporation. LaaSy operates two consumer and business-facing products under a single legal entity:

  • LaaSy Perks — a leisure travel and cashback rewards platform available at home.laasyperks.com
  • LaaSy Business Travel — a corporate travel booking and management platform available at laasy.co

Contact information

For all privacy-related questions, requests, or complaints, contact our Privacy Team:

Contact methodDetails
Email (Privacy)privacy@laasy.co
Email (Business Travel)businesstravel@laasy.co
Mailing addressLaaSy, Inc., 1151 Walker Rd Ste 100, #678, Dover, DE 19904
Registered agent address1151 Walker Rd Ste 100, #678, Dover, DE 19904

Section 2Scope of This Policy

This Policy applies to Personal Data (defined below) collected through:

  • The LaaSy Perks website and portal (home.laasyperks.com) and all services provided thereon;
  • The LaaSy Business Travel platform (laasy.co and dev.cbt.laasy.co) and all services provided thereon;
  • Any unified or combined application that integrates both Perks and Business Travel functionality;
  • Email, SMS, in-app messaging, and other electronic communications sent through or in connection with either Service; and
  • Interactions with our customer support, sales, and implementation teams.

This Policy does not apply to information collected by third-party websites, applications, or services that are linked from our platforms but operated independently. Those parties' own privacy policies govern their data practices.

Section 3Information We Collect

We collect information that alone or in combination with other information could be used to identify you ("Personal Data"). The categories we collect depend on which product(s) you use.

3.1 Information You Provide Directly Both

  • Account registration details: name, email address, phone number, mailing address, date of birth, organization, and title
  • Authentication credentials: passwords (stored in hashed form only), security questions
  • Profile preferences: travel preferences, seat preferences, meal preferences, loyalty program numbers
  • Payment information: credit card details, billing address (collected by and transmitted directly to our payment processors; not stored on LaaSy servers in raw form)
  • Communications: records of your correspondence with us, including support requests
  • Feedback, survey responses, and product reviews

3.2 Booking and Travel Information Both

  • Flight, hotel, car rental, and ground transportation bookings
  • Itinerary details and travel history
  • Passenger names, dates of birth, gender markers (where required by airline or border agency)
  • Frequent flyer numbers and loyalty program identifiers
  • Special service requests (accessibility needs, dietary requirements, seating preferences)
Business Travel only

We also collect:

  • Passport and government-issued ID details (number, country of issue, expiry date, nationality) when required for international travel bookings. This data is treated as Sensitive Personal Data and is subject to the enhanced protection measures described in Section 9.
  • Visa and entry documentation information.
  • Travel policy compliance data (approval workflows, spending limit adherence).
  • Expense and cost-center allocation data.

3.3 Automatically Collected Information Both

When you access and use our Services, we may automatically collect:

  • Device identifiers: IP address, device type and model, operating system version, browser type and version, mobile carrier
  • Usage data: pages viewed, features accessed, search queries, click patterns, session duration, crash reports
  • Location data: general geographic location inferred from IP address; precise GPS location only if you grant permission
  • Transaction data: booking status, payment status, cashback balances, transaction history, reconciliation records, withdrawal history
  • Performance data: launch times, error rates, load times
  • Email information: delivery, opens, and clicks

3.4 Information from Third Parties Both

We receive Personal Data from the following categories of third parties:

  • Travel service providers (airlines, hotels, car rental companies): booking confirmations, schedule changes, cancellation data
  • Payment processors: transaction status, fraud signals
  • Identity and compliance verification providers: KYC/AML data for financial transaction compliance
  • Analytics providers: aggregated usage patterns
Business Travel only

Your Company may provide us with your name, email address, employee ID, cost center, travel policy tier, and approval authority level as part of onboarding. Your Company controls this data and may update or delete it by contacting us at businesstravel@laasy.co.

Section 4How We Use Your Information

We use Personal Data only for the purposes described in this Policy or as otherwise disclosed to you at the time of collection.

4.1 Service Delivery and Operations Both

  • Providing, maintaining, optimizing, and improving our platforms and services
  • Processing bookings and transactions with third-party providers
  • Authenticating your identity and managing your account
  • Responding to your requests and otherwise communicating with you about your bookings, account, and changes to our services and policies
  • Providing you with customer support
  • Detecting and fixing bugs and other issues with our platforms and services
  • Detecting and preventing fraud, unauthorized access, and policy violations
  • Maintaining the safety, security, and integrity of our platforms, services, IT systems, architecture, networks, databases, and other technology assets
  • Protecting the rights, interests, and safety of us, you, and any third parties, and to exercise and defend our rights
  • Creating anonymous, de-identified, or aggregated datasets ("Aggregated Information"). Such datasets would not be Personal Data subject to this Privacy Policy
  • For any reason that we described to you when collecting your Personal Data, or for any reason for which you've provided us with your consent

4.2 Cashback, Rewards, and Loyalty Perks only

  • Processing and crediting Cashback earned on Eligible Transactions
  • Managing your Wallet balance and withdrawal requests
  • Matching your purchases to Vendor commission records
  • Calculating and reporting taxable earnings as required by law
  • Identifying and preventing Cashback fraud

4.3 Corporate Travel Management Business Travel only

  • Processing bookings on behalf of your Company in compliance with its travel policy
  • Sharing booking details, travel activity, expense data, and profile information with your Company for business, accounting, compliance, and reporting purposes
  • Processing virtual corporate card (VCC) charges
  • Providing duty-of-care and traveler tracking features if purchased by your Company
  • Supporting approval workflows and out-of-policy booking flagging

4.4 Marketing and Communications Both

With your consent or as otherwise permitted by applicable law, we may use your information to:

  • Send promotional communications about our services and partner offers
  • Personalize content and recommendations based on your travel history, activity, purchases, and preferences
  • Conduct surveys and collect feedback

You may opt out of marketing communications at any time using the unsubscribe link in emails or by replying STOP to SMS messages.

4.5 Legal and Compliance Purposes Both

We may use your information to:

  • Comply with applicable laws, regulations, court orders, and governmental requests
  • Enforce our Terms of Use and contractual obligations
  • Comply with OFAC, AML, and sanctions screening requirements
  • Respond to law enforcement inquiries with appropriate legal process

Section 5Data Segregation: Leisure vs. Business Travel Data

Why this section matters

If you use both LaaSy Perks and LaaSy Business Travel — whether through a unified account or separately — it is important that you understand which data from each product can be seen by whom. We maintain logical and technical separation between your personal leisure data and your employer-visible business travel data.

5.1 What Your Employer Can and Cannot See

If you use LaaSy Business Travel through your Company, the following data segregation principles apply:

Data typeVisible to your Company?Notes
Corporate bookings and itinerariesYesPer your Company's agreement with LaaSy
Travel policy compliance statusYesApproval workflows, out-of-policy flags
Expense and cost-center dataYesFor accounting and reimbursement
Duty-of-care location (if enabled)YesOnly if purchased by Company
Personal Perks cashback balanceNoIsolated from corporate data
Personal leisure bookingsNoUnless booked on a corporate account
Personal wallet / payment infoNoNever shared with employer
Your Perks profile and preferencesNoTreated as personal data only

5.2 Technical Segregation

LaaSy maintains logical data separation between personal (Perks) and corporate (Business Travel) data through:

  • Separate data namespaces and access control layers for corporate vs. personal account data
  • Role-based access controls ensuring corporate administrators can access only corporate-scoped records
  • Audit logging of all data access by corporate administrators
  • Field-level encryption for sensitive personal data (passport details, payment information)

If you book personal travel through your Company's Business Travel account (where permitted by your Company), those bookings are governed by your Company's agreement and may be visible to your employer. You are responsible for understanding your Company's policies before making personal bookings through a corporate account.

Section 6Disclosure and Sharing of Your Information

We do not sell your Personal Data. We may share your Personal Data in the following circumstances:

6.1 Service Providers Both

We share data with third-party vendors and service providers who help us operate our platforms. These include:

  • Cloud hosting and infrastructure providers (data stored in the United States)
  • Payment processors and virtual card issuers
  • Analytics, remarketing, retargeting, and performance monitoring providers
  • Customer support platforms
  • Email and SMS communication providers
  • Identity verification and KYC/AML providers
  • Travel content aggregators and GDS providers (e.g., Sabre)

All service providers are bound by contractual obligations to protect your data and use it only for the purposes we specify.

6.2 Travel Service Providers Both

To complete your bookings, we share the information necessary with airlines, hotels, car rental companies, ground transportation providers, and other travel service providers. The information shared is limited to what is required to make the booking and is governed by those providers' terms and conditions.

6.3 Your Company Business Travel only

As described in Sections 4.3 and 5.1, we share corporate booking data, travel activity, compliance status, and related information with your employer as your Company's service provider. The scope of data shared is governed by LaaSy's agreement with your Company. You acknowledge that your Company — not you personally — is LaaSy's customer for Business Travel services.

6.4 Business Transfers Both

In the event of a merger, acquisition, restructuring, sale of assets, or similar corporate transaction, your Personal Data may be transferred to the successor entity. We will notify you of any such transfer and any material changes to this Policy.

6.5 Legal Obligations and Safety Both

  • To comply with court orders, legal process, and government or regulatory requests
  • To enforce our Terms of Use and other agreements
  • To protect the rights, property, or safety of LaaSy, our users, or third parties
  • To comply with OFAC, AML, and applicable sanctions regulations

Section 7Cookies and Tracking Technologies

We use cookies, web beacons, pixel tags, and similar technologies to operate our platforms, understand usage, and support marketing efforts. Below is a description of the categories we use and a disclosure of specific cookies in use.

7.1 Cookie Categories Both

  • Strictly necessary cookies: Required for the platform to function. Cannot be disabled. Do not collect personal data for marketing.
  • Functional cookies: Remember your preferences (language, region, saved search criteria). Disabling these may affect your experience.
  • Analytics cookies: Help us understand usage patterns, diagnose issues, and improve the platform. Data is aggregated.
  • Marketing cookies: Used to deliver relevant offers and measure campaign effectiveness. Enabled only with your consent where required by law.

7.2 Cookie Table Both

The following cookies are currently in use on our platforms. This table is updated as cookies are added or removed:

Cookie nameTypeOwnerPurposeRetention
session_tokenStrictly necessaryLaaSyAuthentication and session management2 hours
csrf_tokenStrictly necessaryLaaSyCross-site request forgery protectionSession
_laasy_prefFunctionalLaaSyUser preferences (language, region)12 months
_gaAnalyticsGoogle AnalyticsUsage analytics and behavior tracking24 months
_gidAnalyticsGoogle AnalyticsSession-level analytics24 hours
_fbpMarketingMeta / FacebookAd targeting and conversion tracking90 days
stripe_midStrictly necessaryStripeFraud detection for payment processing12 months

You may control cookie preferences through your browser settings or via any cookie preference center we make available. Note that disabling strictly necessary cookies will impair or prevent use of our Services. To manage Do Not Track preferences, visit your browser's privacy settings. We currently do not respond to Do Not Track signals.

Section 8Automated Decision-Making and AI-Powered Features

ADM and AI disclosure

LaaSy uses artificial intelligence and automated processing to power several platform features. Where these systems produce decisions that significantly affect you, we may be required under applicable law to disclose this and, in some cases, to offer you the right to request human review.

8.1 AI-Powered Features in Use Both

LaaSy uses automated processing and machine learning in the following contexts:

FeatureHow AI is usedHuman oversight
Trip PlannerRecommends itineraries based on your preferences and travel historyYou approve all bookings
Disruption ManagementDetects disruptions and suggests rebooking options automaticallyYou confirm rebooking
Loyalty OptimizationAnalyzes booking patterns to maximize rewards accrualAdvisory only; no auto-action
Fraud DetectionFlags unusual account activity for reviewHuman review before account action
Travel Policy ComplianceAutomatically flags out-of-policy bookings for approvalHuman approver in workflow
Support ResolutionAI triage routes support tickets and suggests resolutionsHuman agent review available
Expense ReconciliationMatches receipts and charges to bookings automaticallyFinance team review

8.2 Your Rights Regarding Automated Processing Both

You have the right to:

  • Be informed when a significant decision affecting you has been made using solely automated means
  • Request human review of any automated decision that significantly affects your rights or interests
  • Object to automated profiling for marketing purposes

To exercise these rights, contact privacy@laasy.co with the subject line "Automated Decision Review Request."

Section 9Data Storage, Retention, and Security

9.1 Storage Location Both

All Personal Data is stored in the United States using cloud infrastructure provided by trusted third-party vendors who implement industry-standard security controls. By using our Services, you consent to the transfer and storage of your data in the United States.

9.2 Data Retention Both

We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal obligations, or to resolve disputes. The following general retention periods apply:

Data categoryRetention periodBasis
Active account dataDuration of account + 3 yearsContractual and legal obligation
Booking and transaction records7 years from transaction dateTax and financial regulation
Passport / government ID dataDuration of booking + 90 daysMinimum necessary; then deleted
Payment processing recordsAs required by PCI DSSLegal obligation
Marketing opt-in/out records3 years from last interactionCompliance with consent laws
Fraud and security logs5 yearsLegitimate interest / legal
Cashback / Wallet transaction history7 years from transaction dateTax reporting obligation
Support interaction records2 years from resolutionService improvement and legal

9.3 Security Measures Both

LaaSy implements the following security measures to protect your Personal Data:

  • Encryption in transit using TLS 1.2 or higher for all data transmitted between clients and our servers
  • Encryption at rest for all databases containing Personal Data
  • Field-level encryption for Sensitive Personal Data (passport numbers, payment card data, government IDs)
  • PII vault architecture with strict access controls for identity and travel document data
  • Role-based access controls limiting employee and system access to Personal Data on a need-to-know basis
  • Regular security assessments, penetration testing, and vulnerability management
  • Incident response procedures including breach notification within legally required timeframes

Despite these measures, no method of internet transmission or electronic storage is completely secure. We cannot guarantee absolute security of your Personal Data transmitted through our Services.

Section 10Your Privacy Rights

Depending on your jurisdiction, you may have the following rights with respect to your Personal Data. We respond to all verified requests within 30 days (or as otherwise required by applicable law).

RightDescriptionHow to exercise
Right to know / accessRequest confirmation of whether we process your data and obtain a copy of itEmail privacy@laasy.co
Right to correctRequest correction of inaccurate or incomplete Personal DataAccount settings or email
Right to deleteRequest deletion of your Personal Data (subject to legal exceptions)Email privacy@laasy.co
Right to restrict processingRequest that we limit how we process your data under certain conditionsEmail privacy@laasy.co
Right to data portabilityReceive your Personal Data in a machine-readable formatEmail privacy@laasy.co
Right to objectObject to processing for direct marketing or based on legitimate interestsEmail or unsubscribe link
Right to human reviewRequest human review of automated decisions (see Section 8)Email with subject line noted in Section 8.2
Right to withdraw consentWithdraw consent where processing is consent-based, without affecting prior processingAccount settings or email
Right to opt out of cross-context behavioral advertisingOpt out of behavioral tracking for targeted advertisingAccount settings or email
Right to opt out of profilingOpt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumerAccount settings or email
Right to limit the disclosure of sensitive dataLimit certain uses and disclosures of sensitive personal informationAccount settings or email
Right to revoke consentRevoke consents previously givenAccount settings or email
Right to exercise opt-outs through a universal opt-out mechanismRequest that we honor browser or device-level opt-out preference signals, often for sale and targeted advertisingBrowser or device privacy settings

We may ask you to verify your identity before processing a rights request. We do not charge a fee for most requests, though we reserve the right to charge a reasonable fee or decline requests that are manifestly unfounded, excessive, or repetitive.

Section 11California Residents — Additional Disclosures

If you are a California resident, the following additional disclosures apply under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the California Civil Code.

11.1 Categories of Personal Information Collected (CCPA)

  • Identifiers (name, email, IP address, device ID)
  • Commercial information (transaction history, cashback records, booking data)
  • Internet or electronic network activity information (usage data, clickstream data)
  • Geolocation data (general location inferred from IP; precise location with consent)
  • Professional or employment-related information Business Travel only employer, title, cost center
  • Sensitive personal information Business Travel only passport / government ID, partial payment card data

11.2 Do Not Sell or Share My Personal Information

LaaSy does not sell your Personal Information for monetary consideration. We may share certain data with advertising partners for cross-context behavioral advertising, which the CCPA/CPRA treats as "sharing." You have the right to opt out of such sharing by contacting us at privacy@laasy.co or using any opt-out mechanism we make available.

11.3 Shine the Light

Under California Civil Code Section 1798.83, California residents may request, once per calendar year, information about Personal Data we disclosed to third parties for their direct marketing purposes. Submit requests in writing to privacy@laasy.co or to our mailing address in Section 1.

11.4 Non-Discrimination

We will not discriminate against you for exercising any of your CCPA/CPRA rights.

Section 12International Users and Data Transfers

LaaSy is based in the United States and our Services are directed at users in the United States. However, it may be possible to access our Services outside of the United States. Because our Services are not intended to be used outside of the United States, we do not guarantee the transfer of any data collected from users accessing the Services from any jurisdiction outside the United States (an "Outside Jurisdiction") will include the safeguards that may be required by such Outside Jurisdiction. If you access our Services from an Outside Jurisdiction, your Personal Data will be transferred to and processed in the United States, which may not provide the same level of data protection as the Outside Jurisdiction.

Section 13Children's Privacy

Our Services are intended for adults only. We do not knowingly collect Personal Data from children. If we learn that we have collected Personal Data from a child under 18 without verified parental consent, we will delete that information promptly.

This Policy is in compliance with the Children's Online Privacy Protection Act (COPPA). If you are a parent or guardian and believe your child under 13 has provided Personal Data to us, please contact us at privacy@laasy.co.

Section 14Third-Party Links and Services

Our platforms may contain links to third-party websites, applications, and services that are not operated by LaaSy. When you click on such links and proceed to a third-party site, that party's privacy policy governs the collection and use of your data. LaaSy is not responsible for the privacy practices of third parties.

Third-party services accessible through our platforms include, but are not limited to: airline booking portals, hotel reservation systems, car rental booking sites, Vendor e-commerce sites (Perks), and payment gateway pages. We encourage you to review the privacy policies of any third-party service you access through our platforms.

Section 15Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting a notice on our platform with a "Last modified" date at the top of this Policy
  • Sending an email notification to the address associated with your account (if any), at least 30 days before the change takes effect for material changes

Your continued use of the Services after the effective date of the updated Policy constitutes your acceptance of the changes. We encourage you to review this Policy periodically to stay informed about our privacy practices.

The date this Policy was last modified is identified at the top of this document. You are responsible for ensuring we have a current and deliverable email address for you.