LoungePair Privacy Policy

Effective: 15 September 2026 (supersedes the version dated 8 September 2026)

This Privacy Policy explains how LoungePair collects, uses, shares, and protects personal information about you when you use our website, apps, or services (together, the “Services”). It also describes the rights you have over your personal information and how to exercise them.

It forms part of, and should be read together with, the LoungePair General Terms of Use, the Refund and Cancellation Policy, the Wallet Terms, the Gift Card Terms and Conditions, the Prebook Terms, and the LoungePair Plus Specific Terms of Use. Capitalized terms not defined here have the meaning given in the General Terms of Use.

If you have any questions about this Policy, contact us at privacy@loungepair.com.

1. Who We Are

LoungePair” (and “we”, “us”, and “our”) means the LoungePair group entity that contracts with you for a particular purchase or service, as identified at checkout and on your purchase confirmation. That entity is the data controller of personal information processed in connection with your purchase.

LoungePair group entities may share personal information between them where necessary to operate the Services, support you, and meet legal obligations. Intra-group transfers are governed by appropriate data sharing arrangements.

2. Scope and Summary

This Policy applies to:

  • visitors to the LoungePair website, mobile apps, and any tenant-branded sites we operate;

  • customers and prospective customers of the Services;

  • recipients of LoungePair Gift Cards (whose personal information may be provided to us by the gift card purchaser);

  • LoungePair Plus members; and

  • people who contact our support team or otherwise correspond with us.

It does not apply to:

  • third-party websites you reach through links on our Services (those services have their own privacy policies);

  • the practices of lounge operators after you arrive at a lounge (they have their own privacy policies);

  • the processing of payment card data, which is handled directly by our payment processor (Stripe) — we do not store your full card details.

In short: we collect personal information that’s necessary to run a marketplace for airport lounge access, deliver passes to you, process payments, support you when something goes wrong, and improve our Services. We don’t sell your personal information for marketing.

3. Personal Information We Collect

We collect the following categories of personal information:

Category

Examples

Identifiers

Name, email address, phone number, account ID, IP address, device identifiers, passport number

Account information

Username, hashed password, account preferences, communication settings

Booking and purchase data

Pass type, lounge selection, travel date and time (for Prebook bookings made for a specific date and time), order reference, transaction history, flight numbers

Financial data

Payment method type, last four digits of card, billing country, wallet and Gift Card Wallet balances, FlexiPass status, LoungePair Plus membership status

Communications

Support tickets, chat transcripts, email correspondence, feedback and reviews

Technical and usage data

Device type, browser, operating system, IP-derived location, error logs, referrer, query parameters passed from other websites, and (for a sample of sessions) a replay of how a page behaved — clicks, navigation, and layout — with text and form inputs masked

Marketing preferences

Email subscription status, marketing channel preferences, opt-out records

Recipient data (for Gift Cards)

Recipient’s name and email address, where provided by the purchaser

Identity verification data (where applicable)

Information needed to verify identity in connection with anti-fraud checks

Profile photograph (optional)

A photograph you choose to upload to your account. We remove the camera metadata, including any location the camera recorded, before storing it.

We collect this information from you directly when you create an account, make a purchase, top up a wallet, send a gift card, or contact us. We also collect technical data automatically when you use the Services, and we may receive information from third parties (for example, lounge operators confirming an entry, or payment processors confirming a transaction).

We do not knowingly collect personal information from children below the digital age of consent in their country of residence (16 under EU GDPR, 13 under UK GDPR and US COPPA, varying elsewhere). If you believe a child has provided us with personal information, contact us at privacy@loungepair.com.

4. How We Use Your Personal Information

We use your personal information for the purposes listed below. The lawful basis on which we process your personal information depends on the purpose:

Purpose

Lawful basis (GDPR / UK GDPR)

Creating and maintaining your account

Performance of contract (Article 6(1)(b))

Processing your purchases (passes, wallet top-ups, gift cards, LoungePair Plus)

Performance of contract (Article 6(1)(b))

Issuing and confirming lounge passes, including transmitting pass details to lounge operators

Performance of contract (Article 6(1)(b))

Verifying your identity or eligibility where a lounge or partner requires travel document details before admitting you

Performance of contract (Article 6(1)(b))

Investigating denied-access claims and processing refunds (including transmitting necessary details to lounge operators)

Performance of contract (Article 6(1)(b)); Legitimate interests (Article 6(1)(f))

Customer support and responding to your inquiries

Performance of contract (Article 6(1)(b)); Legitimate interests (Article 6(1)(f))

Sending you transactional and service communications (purchase confirmations, refund notices, account changes)

Performance of contract (Article 6(1)(b))

Sending you marketing communications about LoungePair and our services

Consent (Article 6(1)(a)) where required; Legitimate interests (Article 6(1)(f)) where permitted

Personalizing the Services and showing relevant content

Legitimate interests (Article 6(1)(f)); Consent (Article 6(1)(a)) for any non-essential analytics or advertising cookies (none currently used — see section 9)

Anti-fraud, anti-abuse, and identity verification checks

Legitimate interests (Article 6(1)(f)); Legal obligation (Article 6(1)(c))

Maintaining records for tax, accounting, and audit obligations

Legal obligation (Article 6(1)(c))

Defending or asserting legal claims, complying with court orders or regulator requests

Legal obligation (Article 6(1)(c)); Legitimate interests (Article 6(1)(f))

Improving our Services through aggregated and anonymized analytics

Legitimate interests (Article 6(1)(f))

Keeping the Services available and secure, diagnosing faults, and detecting abuse (logging, monitoring, and error reporting)

Legitimate interests (Article 6(1)(f))

We do not use your personal information for automated decision-making that produces legal or similarly significant effects on you without human involvement.

5. How We Share Your Personal Information

We share personal information with the following categories of recipient. We do not sell your personal information for marketing purposes.

Lounges and partners involved in delivering your pass. Some passes you purchase from us are fulfilled directly by the lounge; others are issued or facilitated by industry partners we work with (for example, third-party operators that issue the pass on the lounge’s behalf, or industry partners providing related services such as fast track or food and beverage). Where information about you needs to flow to one of these parties to deliver the pass you bought, we share the minimum necessary — typically your name, the booking reference, (where the booking is for a specific date or time) the time of your visit, and, where a lounge or partner requires them before admitting you, travel document details such as your passport number or flight number. When you raise a denied-access claim, we may share your name, booking reference, and time of attempted entry to verify the claim with the relevant party.

Service providers and sub-processors acting on our behalf:

  • Stripe, Inc. (United States) and Stripe Payments Singapore Pte. Ltd. (Singapore) — payment processing. Stripe is a PCI-DSS Level 1 Service Provider. Cardholder data is captured by Stripe Checkout directly in your browser and sent to Stripe; LoungePair receives only tokenized references, charge identifiers, and the last four digits of your card.

  • Fly.io, Inc. — application hosting and compute (primary data residency: Singapore).

  • Neon (Databricks, Inc.) — managed Postgres database, used as our primary data store (primary data residency: Singapore, hosted on AWS).

  • Cloudflare, Inc. — content delivery network, web application firewall, DDoS protection, and TLS termination (global Anycast edge); bot protection (Turnstile) on our sign-in and sign-up forms, which receives your IP address to verify the challenge; and object storage (R2) for the profile photograph you upload to your account.

  • Inngest, Inc. (United States) — durable background job orchestration for scheduled and event-driven tasks (e.g., booking reminders, post-purchase emails). Job payloads have a short, configurable retention period.

  • Postmark (ActiveCampaign, Inc.) (United States) — transactional email delivery (booking confirmations, reminders, receipts).

  • Freshdesk (Freshworks Inc.) (United States) — customer support helpdesk (support tickets and correspondence).

  • FreeScout — customer support helpdesk, self-hosted on LoungePair-controlled infrastructure in Singapore.

  • Attio Ltd (United Kingdom; platform hosted on Google Cloud in the European Economic Area) — customer relationship management, including synchronization of business email correspondence.

  • Fathom Analytics — website analytics (cookieless and privacy-respecting; collects only aggregate, anonymized usage data).

  • Ahrefs Web Analytics — website analytics (cookieless and privacy-respecting; collects only aggregate, anonymized usage data).

  • Sentry (Functional Software, Inc.) (United States) — application error monitoring, performance tracing, and session replay. Replays are recorded with text and form inputs masked, so what you type is not captured, and are used only to diagnose faults.

  • Better Stack, Inc. (United States company; log data stored in Singapore) — application and infrastructure logging, uptime monitoring, and incident alerting. Email addresses are replaced with an irreversible token before a log line is written.

  • Google Cloud (Google LLC) (BigQuery) — our internal reporting warehouse, which holds copies of account, booking, and billing records for business analysis (stored in the European Union), and storage for the search terms entered on our site and the paths that return "not found", which we use to improve the lounge catalog (stored in Singapore).

  • Airbyte, Inc. (United States) — data pipelines that copy records from our primary systems into the reporting warehouse. Airbyte does not retain the data after each transfer.

  • DigitalOcean, LLC (Singapore) — hosting for the applications we run ourselves: our content management system, helpdesk, log store, and internal reporting.

  • Mapbox, Inc. (United States) — interactive lounge and terminal maps. The map loads directly from Mapbox’s servers in your browser, so when you view a page that shows one, Mapbox receives your IP address, information about your browser, network or device, and data about how the map is used. If you choose to show your location on the map, your browser also shares your device’s location with Mapbox. We do not receive or store that location.

We engage each sub-processor that processes personal information under a written data processing agreement covering confidentiality, security, breach notification, sub-processor onboarding, deletion of data on termination, and (where applicable) rights of audit or inspection. We assess sub-processors against a consistent set of criteria (security posture, data-protection posture, jurisdiction and data residency, availability) before engagement and review them at least annually.

A current list of our material sub-processors is available on request via privacy@loungepair.com.

Within the LoungePair group. Personal information may be shared between LoungePair group entities where necessary to operate the Services, support you, and meet legal obligations. Intra-group transfers are governed by appropriate data sharing arrangements.

Legal and compliance recipients. We may disclose personal information where required by law, court order, regulator request, or to defend or assert legal claims.

Business transfers. If we are involved in a merger, acquisition, financing, restructuring, or sale of all or part of our business or assets, personal information may be shared with the counterparty under appropriate confidentiality and data protection obligations.

6. International Data Transfers

LoungePair operates globally. Your personal information may be transferred to, stored in, and processed in countries other than your country of residence.

As at the Effective date of this Policy, our primary data residency is Singapore (application hosting, primary database, application logging and monitoring, and the applications we host ourselves). Cross-border transfers occur to:

  • the United States — for payment processing (Stripe), durable background job orchestration (Inngest), transactional email delivery (Postmark), customer support (Freshdesk), error monitoring and session replay (Sentry), data pipelines for internal reporting (Airbyte), interactive maps (Mapbox), and embedded video (YouTube);

  • the European Economic Area — for customer relationship management (Attio, hosted on Google Cloud in Ireland) and our internal reporting warehouse (Google Cloud, BigQuery);

  • global Anycast edge locations — for content delivery, web application firewall, DDoS protection, bot protection (Turnstile), and profile photograph storage (R2) (Cloudflare);

  • other countries where a sub-processor operates, as listed in section 5.

Where we transfer personal information out of the European Economic Area (EEA), the United Kingdom, or another jurisdiction with restrictions on cross-border transfers, we use one or more of the following safeguards:

  • the European Commission’s Standard Contractual Clauses (SCCs), supplemented by the UK Information Commissioner’s Office International Data Transfer Addendum (IDTA) or UK Addendum for UK transfers, and equivalent mechanisms for transfers from other restricted jurisdictions;

  • transfers to countries that benefit from a current adequacy decision by the relevant authority;

  • where appropriate, your explicit consent to the transfer, after you have been informed of the risks.

Where required, we conduct transfer impact assessments before relying on SCCs.

7. Data Retention

We keep your personal information only for as long as we need it for the purposes described in this Policy, or for as long as required by law or by contract. The retention period depends on the type of data and the purpose.

Data category

Retention period

Booking records (your name, contact email, and booking metadata)

For as long as necessary to fulfill the booking, then up to 7 years for accounting and tax record-keeping obligations

Travel document details supplied for a booking (passport number, flight number)

For as long as necessary to fulfill the booking, then in line with the booking-records period above

Profile photograph

Until you replace or remove it, or your account is closed

Wallet and Gift Card Wallet transactions

Transaction history retained for 7 years for accounting purposes; live balances retained until fully spent, expired, or refunded

Authentication events (email + one-time password logs)

12 months

Application and infrastructure logs

7 days for application and database logs; 30 days for partner API request logs. Email addresses are replaced with an irreversible token before a log line is written.

Error reports and session replays

Up to 90 days, under the retention our error monitoring provider applies

Site search terms and not-found paths

Up to 90 days

Internal reporting warehouse (copies of booking and billing records)

Refreshed from our primary systems and expire automatically within 90 days; records deleted from our primary systems are removed from the warehouse on the next refresh

Database backups

Point-in-time recovery window provided by our database provider, currently 30 days, plus any additional snapshots we configure

Cardholder data

Not retained by LoungePair. Card details are captured by Stripe directly and retained by Stripe under its own PCI-DSS obligations.

Marketing consent and communication preferences

Retained until you withdraw consent or close your account, plus 24 months for audit purposes

Support correspondence

Up to 3 years after the last contact

Anti-fraud records

Up to 5 years from the relevant transaction

De-identified analytics and aggregated usage data

May be retained indefinitely

Where a statutory retention obligation conflicts with a shorter business-driven period (for example, accounting record-keeping rules under Singapore’s Companies Act or equivalent legislation in your jurisdiction), the statutory period applies.

8. Your Privacy Rights

Depending on the laws that apply to you, you have some or all of the following rights over your personal information:

  • Access — to obtain a copy of the personal information we hold about you.

  • Rectification — to have inaccurate or incomplete information corrected.

  • Erasure (“right to be forgotten”) — to have your personal information deleted, subject to exceptions (for example, where we need to retain it for legal obligations).

  • Restriction — to limit how we use your personal information in certain circumstances.

  • Objection — to object to processing based on our legitimate interests, including direct marketing.

  • Portability — to receive a copy of your personal information in a machine-readable format and have it transmitted to another controller.

  • Withdrawal of consent — where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.

  • Lodging a complaint with your data protection authority (see jurisdiction-specific notices in section 14).

  • Right to non-discrimination for exercising privacy rights (see California notice in section 14).

To exercise any of these rights, contact us at privacy@loungepair.com. We will respond within the timeframe required by the law that applies to you — for example, one month under GDPR and UK GDPR, 45 days under CCPA and CPRA, and “as soon as reasonably possible” under Singapore PDPA — and may need to verify your identity before fulfilling the request.

If we are unable to fulfill your request, we will explain why.

9. Cookies and Tracking Technologies

We do not use cookies for analytics, marketing, advertising, or cross-site tracking.

Our website uses two analytics tools — Fathom Analytics and Ahrefs Web Analytics — both of which are cookieless and privacy-respecting. They do not set cookies on your device, do not collect personal information about you, and do not track you across other websites. They give us aggregate, anonymized information about how the Services are used so we can improve them.

Separately from analytics, we use Sentry to find and fix faults. Sentry records application errors and, for a sample of sessions, a replay of how a page behaved — clicks, navigation, and layout. Text and form inputs are masked, so the content you type is not recorded, and card details are entered in a frame hosted by Stripe that is never captured. This uses your browser’s session storage rather than cookies. We do not use it for advertising, profiling, or tracking you across other websites.

We may use a small number of strictly necessary cookies for the technical operation of the Services — for example, to maintain your login session, prevent cross-site request forgery, provide security and bot protection (Cloudflare), or to support our payment processor (Stripe) when you are completing a purchase. These cookies are essential to provide the Services you have requested. Under the EU and UK e-Privacy regulations, the Singapore PDPA, and equivalent regimes, strictly necessary cookies do not require your consent.

We do not display a cookie consent banner because we do not set non-essential cookies. We do not respond to Global Privacy Control (GPC) signals because we do not engage in the kinds of tracking or “sale” / “sharing” that GPC is designed to opt out of.

If our cookie or tracking practices change in the future, we will update this section and (where required) implement an appropriate consent mechanism before doing so.

10. Marketing Communications

We may send you marketing communications about LoungePair where you have opted in, or where another lawful basis applies. Marketing communications are sent by email only; we do not currently collect telephone numbers for marketing purposes.

You can opt out of marketing communications at any time by:

  • clicking the “unsubscribe” link in any marketing email;

  • adjusting your communication preferences in your LoungePair account; or

  • contacting us at privacy@loungepair.com.

We will continue to send you transactional and service communications (purchase confirmations, refund notices, security alerts) regardless of your marketing preferences, as these are necessary to operate your account.

11. Security

We use technical and organizational measures appropriate to the nature, scope, and risk of our processing to protect your personal information. These include:

  • TLS encryption for data in transit;

  • encryption at rest for sensitive data, where appropriate;

  • access controls, authentication, and audit logging for our systems;

  • replacement of email addresses with an irreversible token in our application logs, which are kept for days rather than months;

  • removal of camera metadata, including any location recorded by the camera, from profile photographs before they are stored;

  • payment data handled by Stripe under PCI-DSS standards (we do not store full card numbers);

  • regular review of security policies and practices.

No system is perfectly secure. You are responsible for protecting your account credentials and the devices you use to access the Services.

12. Data Breach Response

If we become aware of a personal data breach that affects your personal information, we will:

  • investigate the breach and take appropriate action to contain and mitigate it;

  • notify the relevant supervisory authority within the timeframe required by the law that applies — for example, within 72 hours under GDPR and UK GDPR where the breach is likely to result in a risk to individuals, and within 3 calendar days to the Singapore PDPC where the breach is of significant scale or likely to result in significant harm;

  • notify affected individuals where the breach is likely to result in a high risk to your rights and freedoms, or where otherwise required by law.

If you believe your personal information has been compromised, contact us at privacy@loungepair.com.

13. LoungePair Plus, Wallet, and Gift Card Data Flows

This section describes data processing specific to certain Services.

LoungePair Plus. When you join LoungePair Plus, we process your subscription billing data, membership status, and any membership-related entitlements (for example, complimentary passes, FlexiPass benefits, companion passes). We retain this information for the duration of your membership and for the periods set out in section 7. Refer to the LoungePair Plus Specific Terms of Use for the contractual terms.

LoungePair Plus as a gift. A LoungePair Plus membership can be purchased as a gift. In that case, we process the purchaser’s payment and account information at the point of purchase and issue the purchaser a coupon code, which the purchaser forwards to the recipient outside our Services (typically by email). We do not collect or process the recipient’s personal information until the recipient claims the membership by creating or signing in to a LoungePair account.

Wallet and Gift Card Wallets. We process information about your wallet balances (Primary Wallet and any Gift Card Wallets), top-ups, bonus credit grants, transaction history, and refund destinations. Wallet balances are personal to your account and are not shared with third parties except where required to process a transaction or comply with legal obligations.

Gift Card recipients. When you purchase a Gift Card and provide a recipient’s name and email address, we use that information to deliver the Gift Card to the recipient. The recipient’s information is processed under our legitimate interests in completing the gift card transfer the purchaser has initiated. Recipients can contact us at privacy@loungepair.com at any time to exercise their rights.

14. Jurisdiction-Specific Notices

14.1 European Economic Area (EEA) and United Kingdom

For users in the EEA and UK:

  • The LoungePair group entity that contracts with you is the controller of your personal information, as described in section 1.

  • You may lodge a complaint with the data protection authority in your country of residence. For UK users, this is the Information Commissioner’s Office (ICO, ico.org.uk). EEA users may complain to the supervisory authority in their country of residence.

  • We value your privacy and your rights as a data subject and have therefore appointed Prighter Group, with its local partners, as our privacy representative and your point of contact for the European Union (EU) (under Article 27 GDPR) and the United Kingdom (UK) (under Article 27 UK GDPR):

    • EU representative: iuro Rechtsanwälte GmbH t/a Prighter, Schellinggasse 3, 1010 Vienna, Austria.

    • UK representative: Prighter Ltd, United Kingdom.

  • Prighter gives you an easy way to exercise your privacy-related rights (for example, requests to access or erase personal data). If you want to contact us via our representative, Prighter, or make use of your data subject rights, please visit: app.prighter.com/portal/loungepair

14.2 California (USA)

This section provides additional notice for California residents under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

Categories of personal information we collect, use, and disclose are described in sections 3 and 4. We disclose categories of personal information for business purposes (described in section 5) but do not sell your personal information for monetary consideration.

Sharing for cross-context behavioral advertising: we do not “share” personal information with marketing platforms for the purpose of cross-context behavioral advertising as that term is defined under CPRA. We do not display a “Do Not Sell or Share My Personal Information” link because we do not engage in this conduct. If our practices change in the future, we will provide an appropriate opt-out mechanism. In the meantime, you can contact us at privacy@loungepair.com at any time to confirm or update your preferences.

Sensitive personal information: we collect financial data (payment method information) which qualifies as sensitive personal information under CPRA. We use this information only for the purposes set out in section 4 and do not use it for the purpose of inferring characteristics about you. You have a right to limit the use of sensitive personal information, although the limit may not apply where the use is necessary to provide the Services you have requested.

Right to non-discrimination: we do not discriminate against you for exercising your privacy rights.

Authorized agents: you may use an authorized agent to make a request on your behalf. We will require verification of the agent’s authority and your identity.

14.3 Singapore

For users in Singapore, we comply with the Personal Data Protection Act 2012 (PDPA).

  • Our Data Protection Officer (DPO) is Todd Heslin, Director and CTO, and can be contacted at dpo@loungepair.com.

  • We rely on consent, deemed consent (including consent by notification), and the legitimate interests exception (with appropriate impact assessments) as the bases for processing personal data.

  • You may withdraw consent at any time by contacting our DPO. We will inform you of the likely consequences of withdrawal before giving effect to it.

  • You may lodge a complaint with the Personal Data Protection Commission (PDPC, pdpc.gov.sg).

14.4 Other Jurisdictions

This Policy is intended to comply with applicable data protection laws in the jurisdictions where LoungePair operates. Where the law of your country of residence gives you broader rights than those described above, we will honor those rights on request.

15. Third-Party Links and Integrations

The Services may contain:

  • Links to third-party lounge access offers and other travel-related services that are bookable on third-party websites. When you click through to such an offer, you leave the LoungePair Services and any booking, payment, support, and data handling is governed by that third party’s own terms and privacy policy. LoungePair is not party to your transaction with that third party. We may earn affiliate commission on completed bookings, at no additional cost to you.

  • Links to other third-party websites that we reference for information or convenience.

  • Embedded third-party content: interactive maps served by Mapbox, and videos embedded from YouTube in privacy-enhanced (no-cookie) mode. When a map or a video loads, your IP address and browser information reach that provider.

  • Scripts and widgets necessary to operate the Services, such as the payment widget served by Stripe and the bot-protection widget served by Cloudflare. Our fonts are hosted by us, not by a third-party font service.

When you follow such a link or use such a service, you may be subject to that third party’s terms and privacy policy. LoungePair is not responsible for the privacy practices of third parties.

16. Changes to This Policy

We may update this Policy from time to time. The “Effective” date at the top of this document indicates when the current version took effect.

Where we make a material change to this Policy, we will provide notice in advance by:

  • prominently displaying notice of the change on our website; and

  • where you have an ongoing service or relationship with us (for example, an active LoungePair Plus membership, an active wallet balance, or an open booking), sending you direct notice by email to your registered address.

We will provide at least 30 days’ notice before material changes take effect, where reasonably possible. Your continued use of the Services after the Effective date of the updated Policy constitutes acceptance of those updates.

17. Contact

For any questions about this Policy, to exercise your rights, or to lodge a complaint, contact us at:

  • General privacy inquiries: privacy@loungepair.com

  • Data Protection Officer (Singapore PDPA): Todd Heslin, Director and CTO — dpo@loungepair.com

  • Postal address: LoungePair Pte. Ltd. (UEN 202610640G), 20 Peck Seah Street, #05-00, Singapore 079312