Effective Date: August 5, 2026 · Last Updated: August 5, 2026
Business Class Vault a part of Vault Travel Group LLC ("Business Class Vault," "we," "us," or "our"), is a United States–based air travel consolidator specializing in Business Class and First Class airfare. We arrange and issue airline tickets through net-fare agreements with airline partners and through our licensed advisor team.
This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. It applies to:
Collectively, these are the "Services."
If you do not agree with this Policy, please do not use the Services.
A note about air travel: booking an international premium-cabin ticket is not an anonymous transaction. Airlines and governments require identity, passport, and itinerary data before a ticket can be issued or a border crossed. Sections 4, 6, and 8 explain this in detail.
This summary is for convenience only and does not replace the full Policy below.
Enquiry and lead information Name, email address, telephone number, country of residence, preferred contact method and time, origin and destination cities, travel dates, cabin class, number of passengers, budget range, trip purpose, and any free-text notes you include in a form, chat, or email.
Traveler and booking information For every person on a booking, we may collect:
Payment informationCardholder name, billing address, card type, and transaction amount. Full card numbers, expiry dates, and security codes are entered into and processed by our PCI DSS–compliant payment providers and airline ticketing systems. Where a card authorization form is required by an airline, it is handled under restricted access and retained only as long as the airline's chargeback and settlement window requires.
Special category / sensitive information. Some travel requests inherently involve sensitive data — wheelchair or mobility assistance, oxygen or medical equipment, service animal travel, dietary or religious meal codes, or unaccompanied minor arrangements. We collect this only when you volunteer it and use it solely to arrange the service requested with the airline and airport. See Section 6.
Communications The content of your emails, live chat transcripts, WhatsApp and SMS threads, contact form submissions, review or complaint correspondence, and recordings of telephone calls with our advisors.
Optional submissions Testimonials, survey responses, referral details, and content you post on our social channels.
When you visit businessclassvault.com we and our analytics and advertising partners may collect:
If you provide us with another traveler's information, you confirm that you are authorized to do so, that you have made that person aware of this Privacy Policy, and that you have obtained any consent required for us to process their information — including any sensitive information such as accessibility or medical assistance needs. We will treat the lead traveler or booker as the point of contact for the reservation unless you tell us otherwise.
Telephone calls. Business Class Vault operates an advisor-led call center. Calls to and from our team may be monitored or recorded for quality assurance, advisor training, dispute resolution, fraud prevention, and to create an accurate record of the fare, fare rules, and authorizations agreed during the call.
We are headquartered in California, a two-party consent jurisdiction. You will be notified at the start of a recorded call. If you do not wish to be recorded, tell your advisor and we will either stop the recording or continue the conversation by email or chat. Declining recording will not prevent you from receiving a quote, though certain card authorizations may need to be completed in writing instead.
Live chat.Our website chat is operated using a third-party customer messaging platform. Chat transcripts, along with the page and device context of the conversation, are stored on that provider's infrastructure and are accessible to our advisors and support team.
WhatsApp and SMS. When you contact us on WhatsApp or provide a mobile number and opt in, we may communicate with you via WhatsApp Business or SMS about your quote and booking. Message content on WhatsApp is also processed by Meta under its own terms. Message and data rates may apply. You may opt out of marketing messages at any time by replying STOP or by telling your advisor; we will still send transactional messages that relate to a live booking.
We use personal information to:
Where the UK GDPR or EU GDPR applies to our processing, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Quoting, ticketing, and servicing your booking | Performance of a contract, or steps taken at your request before entering a contract |
| Payment processing and settlement | Contract; legal obligation |
| Government passenger data transmission (APIS, Secure Flight, border authorities) | Legal obligation; substantial public interest |
| Accessibility, medical assistance, and meal requests | Explicit consent |
| Fraud prevention, security, and record keeping | Legitimate interests; legal obligation |
| Call recording | Legitimate interests, or consent where required |
| Direct marketing by email or messaging | Consent, or legitimate interests for existing customers on similar services |
| Advertising and analytics cookies | Consent |
| Service improvement and advisor training | Legitimate interests |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object to that processing at any time (Section 12.3).
We treat the following as sensitive and apply heightened controls:
We use sensitive personal information only for the purposes described in this Policy — arranging and servicing your travel, meeting legal obligations, and preventing fraud. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for advertising or profiling.
Under the California Privacy Rights Act, our use of sensitive personal information falls within the purposes permitted by Cal. Civ. Code § 1798.121(a) and its implementing regulations, and therefore we do not offer a separate "Limit the Use of My Sensitive Personal Information" link. You may still contact us with any request regarding this data.
We use cookies, pixels, tags, SDKs, and local storage. Categories:
| Category | Purpose | Examples |
|---|---|---|
| Strictly necessary | Site security, load balancing, form integrity, fraud prevention, consent state | Session cookies, CSRF tokens, bot protection |
| Functional | Remembering preferences, live chat continuity, currency and language | Chat platform cookies, preference cookies |
| Analytics | Understanding traffic, route page performance, and conversion paths | Google Analytics 4, server-side and session analytics |
| Advertising | Measuring campaigns, building audiences, and retargeting | Google Ads, Microsoft Advertising, Meta Pixel, Reddit Pixel and their conversion APIs |
Advertising and analytics identifiers may be transmitted to those platforms both from your browser and from our servers via conversion APIs. Where required by law, these are set only after you consent through our cookie banner.
Managing cookies: use our cookie preferences control on businessclassvault.com, your browser settings, or the industry opt-out tools listed in Section 9. Blocking strictly necessary cookies may prevent parts of the site from working.
We do not sell personal information for monetary consideration. We disclose it as follows.
To issue your ticket we transmit traveler names, dates of birth, contact details, passport and document data, loyalty numbers, seat and service requests, and payment or form-of-payment data to the operating and marketing airlines, and where relevant to airport service providers, private aviation operators, and ground handlers. Once transmitted, the airline or supplier processes your data as an independent controller under its own privacy policy.
Air travel is subject to mandatory passenger data transmission. Depending on your itinerary, your information may be provided to:
We cannot issue an international ticket without meeting these requirements.
Payment gateways, acquiring banks, card networks, and issuing banks; fraud screening, identity verification, and chargeback representment providers.
Vetted vendors acting on our instructions under written contracts, including: cloud hosting and CDN, CRM and marketing automation, live chat and messaging platforms, telephony and call recording, email delivery, analytics and advertising platforms, accounting and tax advisors, insurance providers, and legal counsel.
If Business Class Vault is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be disclosed to counterparties and their advisors under confidentiality obligations, and may transfer as part of that transaction. We will notify you of any resulting material change to this Policy.
To travel companions, corporate travel managers, family members, insurers, or third parties you ask us to communicate with.
See Section 9. Sharing hashed identifiers with advertising platforms for audience matching and conversion measurement may be classified as "sharing" or "targeted advertising" under certain US state privacy laws.
Business Class Vault advertises on Google, Microsoft/Bing, Meta (Facebook and Instagram), Reddit, and other networks, and uses their measurement tools. This may include uploading hashed email addresses or phone numbers, and importing offline conversion events from our CRM, so that platforms can measure which campaigns produced genuine bookings.
We do not use sensitive personal information, passport data, or accessibility information for advertising.
You may opt out by:
Opting out stops interest-based targeting; you will still see general advertising, and you will still receive transactional messages about a live booking.
Every marketing email includes an unsubscribe link. You may also reply STOP to marketing SMS or WhatsApp messages, or contact us directly. Opting out of marketing does not stop operational messages about a ticket you have booked.
Business Class Vault is based in the United States and our infrastructure and advisors are located in the United States and other countries. Air travel by its nature requires transferring your data across borders — to airlines, GDS platforms, airports, and government authorities in every country on your itinerary. Those countries may not provide the same level of data protection as your home jurisdiction.
Where we transfer personal information from the EEA, UK, or Switzerland, we rely on:
You may request further information about our transfer safeguards using the contact details in Section 17.
We retain personal information only as long as necessary for the purposes it was collected, and to meet legal, tax, accounting, and settlement obligations.
| Data | Typical retention |
|---|---|
| Enquiries that do not convert to a booking | Up to 24 months from last contact, then deleted or anonymized |
| Booking and ticketing records, including traveler and passport data | Duration of travel plus the period required by ARC/BSP, tax, and accounting rules — generally 7 years from the date of the transaction |
| Payment records and card authorization forms | As required for settlement, refund, and chargeback windows; card authorization forms are securely destroyed once those windows close |
| Call recordings and chat transcripts | Generally 12–24 months, longer where a dispute, claim, or investigation is open |
| Marketing preferences and suppression lists | Retained indefinitely so we can honor your opt-out |
| Website analytics and advertising identifiers | Per the retention settings of each platform, typically 14–26 months |
| Legal, regulatory, or dispute files | Until the matter and all appeal periods conclude |
Where deletion is not immediately possible, we isolate and secure the data until deletion is feasible.
Regardless of where you live, you may ask us to:
We honor these requests subject to the legal retention obligations in Section 11 and to our need to keep records connected to a ticket that has been issued.
Categories of personal information collected in the last 12 months:
| CCPA category | Collected | Source | Disclosed for a business purpose to |
|---|---|---|---|
| Identifiers (name, email, phone, IP, account IDs) | Yes | You; website; ad platforms; partners | Airlines, GDS, processors, service providers |
| Customer records (Cal. Civ. Code § 1798.80) — billing address, payment data | Yes | You; payment processors | Payment providers, airlines, accountants |
| Protected classifications (age, gender, nationality) | Yes | You | Airlines, government authorities |
| Commercial information (bookings, quotes, purchase history) | Yes | You; airlines; GDS | Airlines, settlement bodies, service providers |
| Internet and network activity | Yes | Cookies and analytics | Analytics and advertising platforms |
| Geolocation (approximate, IP-derived) | Yes | Website | Analytics and advertising platforms |
| Audio and electronic information (call recordings, chat transcripts) | Yes | You | Telephony, chat, and CRM providers |
| Professional information (employer, corporate travel account) | Sometimes | You; corporate accounts | Airlines, corporate travel managers |
| Sensitive personal information (passport and ID numbers, financial account data, health or accessibility data, precise dietary/religious meal codes) | Yes | You | Airlines, government authorities, payment providers |
| Inferences (route and cabin preferences, travel frequency) | Yes | Derived from the above | Advertising platforms (non-sensitive only) |
Selling and sharing. We do not sell personal information for money. We do share identifiers, internet activity, geolocation, and non-sensitive inferences with advertising platforms for cross-context behavioral advertising. We do not knowingly sell or share the personal information of consumers under 16.
Your California rights: to know, access, correct, delete, obtain a portable copy, opt out of sale/sharing, limit sensitive data use (see Section 6), and be free from discrimination for exercising your rights. You may use an authorized agent with written permission and verification.
Shine the Light (Cal. Civ. Code § 1798.83): we do not disclose personal information to third parties for their own direct marketing purposes.
You have the rights of access, rectification, erasure, restriction, portability, and objection — including an absolute right to object to direct marketing — plus the right to withdraw consent at any time without affecting prior processing, and the right not to be subject to solely automated decisions with legal or similarly significant effects. We do not make such automated decisions about you.
You may lodge a complaint with your national supervisory authority or, in the UK, the Information Commissioner's Office. We ask that you contact us first so we can try to resolve it.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, and other states with comprehensive privacy laws have rights to access, correct, delete, obtain a copy, and opt out of targeted advertising, sale, and certain profiling. Where the law provides an appeal process, you may appeal a denied request by replying to our decision; we will respond within the statutory period and, if we deny the appeal, tell you how to contact your state Attorney General.
Residents of Canada may request access to and correction of their personal information under PIPEDA and equivalent provincial legislation, and may withdraw consent subject to legal and contractual restrictions.
Email privacy@businessclassvault.com, call (877) 273-3899, or write to the address in Section 17. Please include your full name, the email address or phone number associated with your enquiry or booking, and, if applicable, your booking reference.
We will verify your identity before acting — for booking records this may require matching details in the reservation. We will respond within 45 days (California and most US states), extendable by a further 45 days with notice, or within one month under the GDPR, extendable by two further months for complex requests. There is no charge unless a request is manifestly unfounded or excessive.
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data we handle, including TLS encryption in transit, encryption at rest for stored booking records, role-based access controls, least-privilege access for advisors, multi-factor authentication on internal systems, secure handling procedures for passport and card authorization documents, vendor due diligence, and staff training on data handling and social engineering.
Card data is processed through PCI DSS–compliant providers and airline ticketing systems. We will never ask you to send full card numbers or security codes by email, SMS, WhatsApp, or chat. If you receive such a request claiming to be from Business Class Vault, do not respond — contact us at (877) 273-3899.
No method of transmission or storage is completely secure. If a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by law.
The Services are intended for adults. We do not knowingly collect personal information directly from children under 13, and we do not knowingly sell or share the personal information of anyone under 16.
We do process children's information as passengers when an adult books family travel or an unaccompanied minor service. That information is provided by the booking adult, who confirms they have authority to provide it, and is used only to arrange and service the travel.
If you believe a child has provided us information directly, contact privacy@businessclassvault.com and we will delete it.
The Services link to airline sites, private aviation operators, payment pages, review platforms, and social networks. Once you leave businessclassvault.com, this Policy no longer applies. Airlines and other travel suppliers are independent controllers of the data they receive and process it under their own privacy policies, which we encourage you to read before travel.
We may update this Policy to reflect changes in our practices, technology, or the law. The "Last Updated" date at the top will change and the revised Policy will be posted at businessclassvault.com. Where a change is material — for example a new category of disclosure or a new purpose for sensitive data — we will provide prominent notice on the site and, where required, seek your consent or notify you by email before it takes effect.
Prior versions are available on request.
Vault Travel Group LLC
3166 Genesis way, Milton, GA,
30004-5136, USA
Privacy enquiries: privacy@businessclassvault.com
General enquiries: info@businessclassvault.com
Telephone: (877) 273-3899
Website: https://businessclassvault.com