LaaSy, Inc.
Unified Privacy Policy
Covering LaaSy Perks (leisure travel) and LaaSy Business Travel.
Last modified: 8.05.2026
How to read this Policy
This Policy covers two products operated by LaaSy, Inc.: LaaSy Perks (our leisure travel and cashback rewards platform) and LaaSy Business Travel (our corporate booking and travel management platform). Most sections apply to both products. Where a section applies only to one product, it is clearly labeled:
- Perks only Applies only to LaaSy Perks users.
- Business Travel only Applies only to corporate travelers and companies.
- Both Applies to users of either or both products.
If you use both products through a unified account, this entire Policy applies to you.
Section 1Who We Are and How to Contact Us
This Privacy Policy is issued by LaaSy, Inc. (“LaaSy,” “we,” “us,” or “our”), a Delaware corporation. LaaSy operates two consumer and business-facing products under a single legal entity:
- LaaSy Perks — a leisure travel and cashback rewards platform available at home.laasyperks.com
- LaaSy Business Travel — a corporate travel booking and management platform available at laasy.co
Contact information
For all privacy-related questions, requests, or complaints, contact our Privacy Team:
| Contact method | Details |
|---|---|
| Email (Privacy) | privacy@laasy.co |
| Email (Business Travel) | businesstravel@laasy.co |
| Mailing address | LaaSy, Inc., 1151 Walker Rd Ste 100, #678, Dover, DE 19904 |
| Registered agent address | 1151 Walker Rd Ste 100, #678, Dover, DE 19904 |
Section 2Scope of This Policy
This Policy applies to Personal Data (defined below) collected through:
- The LaaSy Perks website and portal (home.laasyperks.com) and all services provided thereon;
- The LaaSy Business Travel platform (laasy.co and dev.cbt.laasy.co) and all services provided thereon;
- Any unified or combined application that integrates both Perks and Business Travel functionality;
- Email, SMS, in-app messaging, and other electronic communications sent through or in connection with either Service; and
- Interactions with our customer support, sales, and implementation teams.
This Policy does not apply to information collected by third-party websites, applications, or services that are linked from our platforms but operated independently. Those parties' own privacy policies govern their data practices.
Section 3Information We Collect
We collect information that alone or in combination with other information could be used to identify you ("Personal Data"). The categories we collect depend on which product(s) you use.
3.1 Information You Provide Directly Both
- Account registration details: name, email address, phone number, mailing address, date of birth, organization, and title
- Authentication credentials: passwords (stored in hashed form only), security questions
- Profile preferences: travel preferences, seat preferences, meal preferences, loyalty program numbers
- Payment information: credit card details, billing address (collected by and transmitted directly to our payment processors; not stored on LaaSy servers in raw form)
- Communications: records of your correspondence with us, including support requests
- Feedback, survey responses, and product reviews
3.2 Booking and Travel Information Both
- Flight, hotel, car rental, and ground transportation bookings
- Itinerary details and travel history
- Passenger names, dates of birth, gender markers (where required by airline or border agency)
- Frequent flyer numbers and loyalty program identifiers
- Special service requests (accessibility needs, dietary requirements, seating preferences)
We also collect:
- Passport and government-issued ID details (number, country of issue, expiry date, nationality) when required for international travel bookings. This data is treated as Sensitive Personal Data and is subject to the enhanced protection measures described in Section 9.
- Visa and entry documentation information.
- Travel policy compliance data (approval workflows, spending limit adherence).
- Expense and cost-center allocation data.
3.3 Automatically Collected Information Both
When you access and use our Services, we may automatically collect:
- Device identifiers: IP address, device type and model, operating system version, browser type and version, mobile carrier
- Usage data: pages viewed, features accessed, search queries, click patterns, session duration, crash reports
- Location data: general geographic location inferred from IP address; precise GPS location only if you grant permission
- Transaction data: booking status, payment status, cashback balances, transaction history, reconciliation records, withdrawal history
- Performance data: launch times, error rates, load times
- Email information: delivery, opens, and clicks
3.4 Information from Third Parties Both
We receive Personal Data from the following categories of third parties:
- Travel service providers (airlines, hotels, car rental companies): booking confirmations, schedule changes, cancellation data
- Payment processors: transaction status, fraud signals
- Identity and compliance verification providers: KYC/AML data for financial transaction compliance
- Analytics providers: aggregated usage patterns
Your Company may provide us with your name, email address, employee ID, cost center, travel policy tier, and approval authority level as part of onboarding. Your Company controls this data and may update or delete it by contacting us at businesstravel@laasy.co.
Section 4How We Use Your Information
We use Personal Data only for the purposes described in this Policy or as otherwise disclosed to you at the time of collection.
4.1 Service Delivery and Operations Both
- Providing, maintaining, optimizing, and improving our platforms and services
- Processing bookings and transactions with third-party providers
- Authenticating your identity and managing your account
- Responding to your requests and otherwise communicating with you about your bookings, account, and changes to our services and policies
- Providing you with customer support
- Detecting and fixing bugs and other issues with our platforms and services
- Detecting and preventing fraud, unauthorized access, and policy violations
- Maintaining the safety, security, and integrity of our platforms, services, IT systems, architecture, networks, databases, and other technology assets
- Protecting the rights, interests, and safety of us, you, and any third parties, and to exercise and defend our rights
- Creating anonymous, de-identified, or aggregated datasets ("Aggregated Information"). Such datasets would not be Personal Data subject to this Privacy Policy
- For any reason that we described to you when collecting your Personal Data, or for any reason for which you've provided us with your consent
4.2 Cashback, Rewards, and Loyalty Perks only
- Processing and crediting Cashback earned on Eligible Transactions
- Managing your Wallet balance and withdrawal requests
- Matching your purchases to Vendor commission records
- Calculating and reporting taxable earnings as required by law
- Identifying and preventing Cashback fraud
4.3 Corporate Travel Management Business Travel only
- Processing bookings on behalf of your Company in compliance with its travel policy
- Sharing booking details, travel activity, expense data, and profile information with your Company for business, accounting, compliance, and reporting purposes
- Processing virtual corporate card (VCC) charges
- Providing duty-of-care and traveler tracking features if purchased by your Company
- Supporting approval workflows and out-of-policy booking flagging
4.4 Marketing and Communications Both
With your consent or as otherwise permitted by applicable law, we may use your information to:
- Send promotional communications about our services and partner offers
- Personalize content and recommendations based on your travel history, activity, purchases, and preferences
- Conduct surveys and collect feedback
You may opt out of marketing communications at any time using the unsubscribe link in emails or by replying STOP to SMS messages.
4.5 Legal and Compliance Purposes Both
We may use your information to:
- Comply with applicable laws, regulations, court orders, and governmental requests
- Enforce our Terms of Use and contractual obligations
- Comply with OFAC, AML, and sanctions screening requirements
- Respond to law enforcement inquiries with appropriate legal process
Section 5Data Segregation: Leisure vs. Business Travel Data
Why this section matters
If you use both LaaSy Perks and LaaSy Business Travel — whether through a unified account or separately — it is important that you understand which data from each product can be seen by whom. We maintain logical and technical separation between your personal leisure data and your employer-visible business travel data.
5.1 What Your Employer Can and Cannot See
If you use LaaSy Business Travel through your Company, the following data segregation principles apply:
| Data type | Visible to your Company? | Notes |
|---|---|---|
| Corporate bookings and itineraries | Yes | Per your Company's agreement with LaaSy |
| Travel policy compliance status | Yes | Approval workflows, out-of-policy flags |
| Expense and cost-center data | Yes | For accounting and reimbursement |
| Duty-of-care location (if enabled) | Yes | Only if purchased by Company |
| Personal Perks cashback balance | No | Isolated from corporate data |
| Personal leisure bookings | No | Unless booked on a corporate account |
| Personal wallet / payment info | No | Never shared with employer |
| Your Perks profile and preferences | No | Treated as personal data only |
5.2 Technical Segregation
LaaSy maintains logical data separation between personal (Perks) and corporate (Business Travel) data through:
- Separate data namespaces and access control layers for corporate vs. personal account data
- Role-based access controls ensuring corporate administrators can access only corporate-scoped records
- Audit logging of all data access by corporate administrators
- Field-level encryption for sensitive personal data (passport details, payment information)
If you book personal travel through your Company's Business Travel account (where permitted by your Company), those bookings are governed by your Company's agreement and may be visible to your employer. You are responsible for understanding your Company's policies before making personal bookings through a corporate account.
Section 6Disclosure and Sharing of Your Information
We do not sell your Personal Data. We may share your Personal Data in the following circumstances:
6.1 Service Providers Both
We share data with third-party vendors and service providers who help us operate our platforms. These include:
- Cloud hosting and infrastructure providers (data stored in the United States)
- Payment processors and virtual card issuers
- Analytics, remarketing, retargeting, and performance monitoring providers
- Customer support platforms
- Email and SMS communication providers
- Identity verification and KYC/AML providers
- Travel content aggregators and GDS providers (e.g., Sabre)
All service providers are bound by contractual obligations to protect your data and use it only for the purposes we specify.
6.2 Travel Service Providers Both
To complete your bookings, we share the information necessary with airlines, hotels, car rental companies, ground transportation providers, and other travel service providers. The information shared is limited to what is required to make the booking and is governed by those providers' terms and conditions.
6.3 Your Company Business Travel only
As described in Sections 4.3 and 5.1, we share corporate booking data, travel activity, compliance status, and related information with your employer as your Company's service provider. The scope of data shared is governed by LaaSy's agreement with your Company. You acknowledge that your Company — not you personally — is LaaSy's customer for Business Travel services.
6.4 Business Transfers Both
In the event of a merger, acquisition, restructuring, sale of assets, or similar corporate transaction, your Personal Data may be transferred to the successor entity. We will notify you of any such transfer and any material changes to this Policy.
6.5 Legal Obligations and Safety Both
- To comply with court orders, legal process, and government or regulatory requests
- To enforce our Terms of Use and other agreements
- To protect the rights, property, or safety of LaaSy, our users, or third parties
- To comply with OFAC, AML, and applicable sanctions regulations
Section 7Cookies and Tracking Technologies
We use cookies, web beacons, pixel tags, and similar technologies to operate our platforms, understand usage, and support marketing efforts. Below is a description of the categories we use and a disclosure of specific cookies in use.
7.1 Cookie Categories Both
- Strictly necessary cookies: Required for the platform to function. Cannot be disabled. Do not collect personal data for marketing.
- Functional cookies: Remember your preferences (language, region, saved search criteria). Disabling these may affect your experience.
- Analytics cookies: Help us understand usage patterns, diagnose issues, and improve the platform. Data is aggregated.
- Marketing cookies: Used to deliver relevant offers and measure campaign effectiveness. Enabled only with your consent where required by law.
7.2 Cookie Table Both
The following cookies are currently in use on our platforms. This table is updated as cookies are added or removed:
| Cookie name | Type | Owner | Purpose | Retention |
|---|---|---|---|---|
| session_token | Strictly necessary | LaaSy | Authentication and session management | 2 hours |
| csrf_token | Strictly necessary | LaaSy | Cross-site request forgery protection | Session |
| _laasy_pref | Functional | LaaSy | User preferences (language, region) | 12 months |
| _ga | Analytics | Google Analytics | Usage analytics and behavior tracking | 24 months |
| _gid | Analytics | Google Analytics | Session-level analytics | 24 hours |
| _fbp | Marketing | Meta / Facebook | Ad targeting and conversion tracking | 90 days |
| stripe_mid | Strictly necessary | Stripe | Fraud detection for payment processing | 12 months |
You may control cookie preferences through your browser settings or via any cookie preference center we make available. Note that disabling strictly necessary cookies will impair or prevent use of our Services. To manage Do Not Track preferences, visit your browser's privacy settings. We currently do not respond to Do Not Track signals.
Section 8Automated Decision-Making and AI-Powered Features
ADM and AI disclosure
LaaSy uses artificial intelligence and automated processing to power several platform features. Where these systems produce decisions that significantly affect you, we may be required under applicable law to disclose this and, in some cases, to offer you the right to request human review.
8.1 AI-Powered Features in Use Both
LaaSy uses automated processing and machine learning in the following contexts:
| Feature | How AI is used | Human oversight |
|---|---|---|
| Trip Planner | Recommends itineraries based on your preferences and travel history | You approve all bookings |
| Disruption Management | Detects disruptions and suggests rebooking options automatically | You confirm rebooking |
| Loyalty Optimization | Analyzes booking patterns to maximize rewards accrual | Advisory only; no auto-action |
| Fraud Detection | Flags unusual account activity for review | Human review before account action |
| Travel Policy Compliance | Automatically flags out-of-policy bookings for approval | Human approver in workflow |
| Support Resolution | AI triage routes support tickets and suggests resolutions | Human agent review available |
| Expense Reconciliation | Matches receipts and charges to bookings automatically | Finance team review |
8.2 Your Rights Regarding Automated Processing Both
You have the right to:
- Be informed when a significant decision affecting you has been made using solely automated means
- Request human review of any automated decision that significantly affects your rights or interests
- Object to automated profiling for marketing purposes
To exercise these rights, contact privacy@laasy.co with the subject line "Automated Decision Review Request."
Section 9Data Storage, Retention, and Security
9.1 Storage Location Both
All Personal Data is stored in the United States using cloud infrastructure provided by trusted third-party vendors who implement industry-standard security controls. By using our Services, you consent to the transfer and storage of your data in the United States.
9.2 Data Retention Both
We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal obligations, or to resolve disputes. The following general retention periods apply:
| Data category | Retention period | Basis |
|---|---|---|
| Active account data | Duration of account + 3 years | Contractual and legal obligation |
| Booking and transaction records | 7 years from transaction date | Tax and financial regulation |
| Passport / government ID data | Duration of booking + 90 days | Minimum necessary; then deleted |
| Payment processing records | As required by PCI DSS | Legal obligation |
| Marketing opt-in/out records | 3 years from last interaction | Compliance with consent laws |
| Fraud and security logs | 5 years | Legitimate interest / legal |
| Cashback / Wallet transaction history | 7 years from transaction date | Tax reporting obligation |
| Support interaction records | 2 years from resolution | Service improvement and legal |
9.3 Security Measures Both
LaaSy implements the following security measures to protect your Personal Data:
- Encryption in transit using TLS 1.2 or higher for all data transmitted between clients and our servers
- Encryption at rest for all databases containing Personal Data
- Field-level encryption for Sensitive Personal Data (passport numbers, payment card data, government IDs)
- PII vault architecture with strict access controls for identity and travel document data
- Role-based access controls limiting employee and system access to Personal Data on a need-to-know basis
- Regular security assessments, penetration testing, and vulnerability management
- Incident response procedures including breach notification within legally required timeframes
Despite these measures, no method of internet transmission or electronic storage is completely secure. We cannot guarantee absolute security of your Personal Data transmitted through our Services.
Section 10Your Privacy Rights
Depending on your jurisdiction, you may have the following rights with respect to your Personal Data. We respond to all verified requests within 30 days (or as otherwise required by applicable law).
| Right | Description | How to exercise |
|---|---|---|
| Right to know / access | Request confirmation of whether we process your data and obtain a copy of it | Email privacy@laasy.co |
| Right to correct | Request correction of inaccurate or incomplete Personal Data | Account settings or email |
| Right to delete | Request deletion of your Personal Data (subject to legal exceptions) | Email privacy@laasy.co |
| Right to restrict processing | Request that we limit how we process your data under certain conditions | Email privacy@laasy.co |
| Right to data portability | Receive your Personal Data in a machine-readable format | Email privacy@laasy.co |
| Right to object | Object to processing for direct marketing or based on legitimate interests | Email or unsubscribe link |
| Right to human review | Request human review of automated decisions (see Section 8) | Email with subject line noted in Section 8.2 |
| Right to withdraw consent | Withdraw consent where processing is consent-based, without affecting prior processing | Account settings or email |
| Right to opt out of cross-context behavioral advertising | Opt out of behavioral tracking for targeted advertising | Account settings or email |
| Right to opt out of profiling | Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer | Account settings or email |
| Right to limit the disclosure of sensitive data | Limit certain uses and disclosures of sensitive personal information | Account settings or email |
| Right to revoke consent | Revoke consents previously given | Account settings or email |
| Right to exercise opt-outs through a universal opt-out mechanism | Request that we honor browser or device-level opt-out preference signals, often for sale and targeted advertising | Browser or device privacy settings |
We may ask you to verify your identity before processing a rights request. We do not charge a fee for most requests, though we reserve the right to charge a reasonable fee or decline requests that are manifestly unfounded, excessive, or repetitive.
Section 11California Residents — Additional Disclosures
If you are a California resident, the following additional disclosures apply under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the California Civil Code.
11.1 Categories of Personal Information Collected (CCPA)
- Identifiers (name, email, IP address, device ID)
- Commercial information (transaction history, cashback records, booking data)
- Internet or electronic network activity information (usage data, clickstream data)
- Geolocation data (general location inferred from IP; precise location with consent)
- Professional or employment-related information Business Travel only employer, title, cost center
- Sensitive personal information Business Travel only passport / government ID, partial payment card data
11.2 Do Not Sell or Share My Personal Information
LaaSy does not sell your Personal Information for monetary consideration. We may share certain data with advertising partners for cross-context behavioral advertising, which the CCPA/CPRA treats as "sharing." You have the right to opt out of such sharing by contacting us at privacy@laasy.co or using any opt-out mechanism we make available.
11.3 Shine the Light
Under California Civil Code Section 1798.83, California residents may request, once per calendar year, information about Personal Data we disclosed to third parties for their direct marketing purposes. Submit requests in writing to privacy@laasy.co or to our mailing address in Section 1.
11.4 Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights.
Section 12International Users and Data Transfers
LaaSy is based in the United States and our Services are directed at users in the United States. However, it may be possible to access our Services outside of the United States. Because our Services are not intended to be used outside of the United States, we do not guarantee the transfer of any data collected from users accessing the Services from any jurisdiction outside the United States (an "Outside Jurisdiction") will include the safeguards that may be required by such Outside Jurisdiction. If you access our Services from an Outside Jurisdiction, your Personal Data will be transferred to and processed in the United States, which may not provide the same level of data protection as the Outside Jurisdiction.
Section 13Children's Privacy
Our Services are intended for adults only. We do not knowingly collect Personal Data from children. If we learn that we have collected Personal Data from a child under 18 without verified parental consent, we will delete that information promptly.
This Policy is in compliance with the Children's Online Privacy Protection Act (COPPA). If you are a parent or guardian and believe your child under 13 has provided Personal Data to us, please contact us at privacy@laasy.co.
Section 14Third-Party Links and Services
Our platforms may contain links to third-party websites, applications, and services that are not operated by LaaSy. When you click on such links and proceed to a third-party site, that party's privacy policy governs the collection and use of your data. LaaSy is not responsible for the privacy practices of third parties.
Third-party services accessible through our platforms include, but are not limited to: airline booking portals, hotel reservation systems, car rental booking sites, Vendor e-commerce sites (Perks), and payment gateway pages. We encourage you to review the privacy policies of any third-party service you access through our platforms.
Section 15Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Posting a notice on our platform with a "Last modified" date at the top of this Policy
- Sending an email notification to the address associated with your account (if any), at least 30 days before the change takes effect for material changes
Your continued use of the Services after the effective date of the updated Policy constitutes your acceptance of the changes. We encourage you to review this Policy periodically to stay informed about our privacy practices.
The date this Policy was last modified is identified at the top of this document. You are responsible for ensuring we have a current and deliverable email address for you.

