Privacy Policy
Your travel data is yours. This explains what we collect, why, and the control you keep over it.
Last updated 4 July 2026.
This Privacy Policy explains how Carryon (“Carryon”, “we”, “us”) handles personal data when you visit https://carryon.world, create an account, use the free FlightIQ tools, or use the CarryOn application. We have written it to be read, not just filed.
Who we are
Carryon is operated by MVSK Pty Ltd (ABN 65 657 009 768), registered at 55 Clarence Street, Sydney, NSW 2000, Australia. For any privacy matter, the data controller can be reached at contact@carryon.world.
What we collect
- Account details — your name, email and the password you set when you register.
- Free-tool usage — when you use the free visa, lounge and airport tools we count your lookups so we can apply the free allowance. We store a first-party identifier in a cookie and a salted, one-way hash of your IP address — never the address itself, and the hash cannot be reversed back to it. If you enter an email to unlock extra lookups, we store that address and a one-way hash of the six-digit code we send you. Usage records are deleted after 90 days.
- How you found us — when you create an account we record the campaign, referrer and landing page that brought you, which free tool you used, your browser language, time zone, approximate screen size and device family, and how long the journey took. This tells us which of our efforts actually help people; it is never used to build an advertising profile of you. We only collect it if you have accepted analytics cookies.
- Phone number — if you choose to sign in by phone or turn on extra security, so we can send one-time verification codes by SMS or WhatsApp. We store it encrypted and never share it for marketing.
- Travel data — loyalty programs, balances, itineraries and preferences you choose to connect, used solely to provide the service to you.
- Usage data — how you interact with the site and app, collected in aggregate to improve the product.
- Device & technical data — IP address, browser and device type, for security and performance.
How we use your data
- To provide, personalise and improve Carryon.
- To communicate with you about your membership and request.
- To verify your identity and secure your account — including sending one-time passcodes by SMS or WhatsApp for phone sign-in and two-factor authentication. Standard message and data rates from your carrier may apply.
- To secure the service and prevent abuse.
- To meet legal and regulatory obligations.
We do not sell your personal data for money. Carryon is funded by membership. We do use privacy-respecting analytics and marketing-measurement tools (see “Sharing & processors” below); where the law requires it, these run only after you consent.
Legal bases
Where the UK GDPR or EU GDPR applies, we rely on: performance of a contract (to provide the service), legitimate interests (to secure and improve it), consent (for optional analytics and marketing), and legal obligation where required.
Sharing & processors
We share data only with service providers who help us operate Carryon — for example hosting, email, SMS and WhatsApp message delivery (Twilio, which for WhatsApp uses Meta), analytics (PostHog and Google Analytics 4), advertising measurement (the Meta Pixel) and email/CRM & waitlist management (Klaviyo and HubSpot) — under contracts that require them to protect it. A current list of sub-processors is available on request at contact@carryon.world.
Retention
We keep personal data only as long as needed to provide the service or meet legal obligations. When you close your account, we delete or anonymise your data within 24 months, unless we are required to keep it longer for legal, tax or accounting reasons.
Your rights
- Access a copy of your data.
- Correct or update it.
- Export it in a portable format.
- Delete it, in one request.
- Object to or restrict certain processing.
- Withdraw consent at any time.
To exercise any right, email contact@carryon.world. You may also lodge a complaint with your local supervisory authority (in the UK, the ICO).
Security
We encrypt data in transit and at rest, restrict access on a need-to-know basis, and review our practices regularly. No system is perfectly secure, but protecting your data is fundamental to what Carryon is.
International transfers
Where data is processed outside your region, we use appropriate safeguards such as Standard Contractual Clauses.
Cookies & analytics
We use a small number of cookies for essential functionality and, with your consent, analytics and marketing-measurement tools. You can accept or decline non-essential cookies via our consent banner and change your choice at any time.
Children
Carryon is intended for adults. We do not knowingly collect data from anyone under 18.
Changes
We will post any changes here and, where significant, notify you directly. The date above reflects the latest revision.
Contact
Questions about this policy? Write to contact@carryon.world.