Privacy Policy
Version 2.0 — In force as of 1 September 2026
This policy describes how your personal data is collected, used and protected when you use the HeliShift booking services - whether you book directly, through your concierge or with our team, on the website or in the HeliShift mobile app.
Data controller
The data controller is Priv'Air SARL (SIREN 498 533 546), operating the HeliShift brand, whose registered office is located at Aéroport Annecy Mont-Blanc - Hangar FL250 - 8, route de Côte Merle - 74370 Épagny Metz-Tessy, France. Contact: privacy@helishift.com.
Flights are operated by France Copter, as Operator and actual carrier within the meaning of the HeliShift General Terms and Conditions of Sale, which receives only the information strictly required to perform the flight: passenger manifest, schedules and weight-and-balance elements, together with, where applicable, the special information strictly necessary to the acceptance or the safety of the carriage.
Data we collect
We only collect the data required for your booking and for flight safety, in accordance with the data minimisation principle.
Booking
Name, e-mail address and phone number of the booking holder, inbound flight number where applicable, and any special requests you choose to share. We invite you not to include in free-text fields any sensitive information that is not strictly necessary to your request or your carriage.
Quote request (off-catalogue destinations)
If you request a quote for a destination outside our catalogue: name, e-mail, phone, requested destination (free text), date and number of passengers.
Passenger manifest
For each passenger: identity, date of birth, nationality, passport number and expiry date. This information constitutes the flight manifest required for the operation.
Weight may be provided: it is used exclusively for the aircraft weight-and-balance calculation, an aviation safety requirement. It is never used for pricing.
We never request or store a copy or photo of your passport - only the details you type in.
Special situations and health data
Where a passenger reports a mobility limitation, required assistance, an advanced pregnancy or a medical condition liable to affect fitness to fly or the conditions of acceptance, only the information strictly necessary for the Operator's assessment of the situation is processed. Such information should only be provided where it is necessary to the organisation or the safety of the carriage.
Where information provided in this way constitutes health data or another special category of data within the meaning of Article 9 of the GDPR, its processing is based on the explicit consent of the person concerned where that is the appropriate basis, or on any other exception provided for by Article 9 of the GDPR applicable to the situation. This data is never used for commercial or advertising purposes.
Traveller book
If you choose to save travellers for future bookings, their details are stored with your explicit consent, which you can withdraw at any time by deleting the entry.
Concierge address book
Partner concierges may save their clients' contact details (name, e-mail, phone) where they have a legal basis allowing them to share those details with us and after having duly informed their clients, to prepare their bookings.
Customer account
A customer area is created automatically upon your first confirmed booking, from your booking contact details, to give you access to your tickets and online management. You can delete it at any time, including from the HeliShift mobile app. Deleting the account entails the deletion or anonymisation of the data attached to it, subject to the information Priv'Air is legally required to keep or must keep for the establishment, exercise or defence of legal claims.
Technical data
IP address (short-lived anti-abuse protection), notification delivery traces (e-mail, SMS) and technical error reports, together with, depending on the medium used, the technical identifiers strictly necessary to operation, security and, where you have consented, audience measurement.
Payment
Your card details are entered directly with our payment provider Revolut, in its secure interface. HeliShift never has access to them and stores none of them.
Why we use it
- To perform your booking: confirmation, tickets, flight-related notifications, changes and refunds (performance of the contract).
- To build the passenger manifest and meet aviation safety requirements, including the weight-and-balance calculation (legal and safety obligations).
- To process, where strictly necessary, information relating to a special situation affecting the conditions of acceptance or the safety of the carriage, under the conditions described above.
- To protect the service against fraud and abuse, keep an operational audit trail and fix technical incidents (legitimate interest).
- To remember your travellers, or your concierge clients, for future bookings (consent withdrawable at any time).
Recipients and processors
Your data is never sold. It is shared only with the flight operator - France Copter, as Operator and actual carrier - and the following technical providers:
- Google Cloud / Firebase - data hosting and application logic in the European Union (europe-west1); the account authentication service is a global Google service.
- Vercel - website hosting - United States (global delivery).
- Revolut - payment and refund processing - United Kingdom / EU.
- Twilio SendGrid - transactional e-mails - United States.
- Twilio - SMS delivery - United States.
- Sentry - technical error monitoring - European Union (Frankfurt).
- OpenFreeMap - route map background (data © OpenStreetMap contributors); your IP address is visible to this service when the map loads.
- Google reCAPTCHA - anti-bot protection of the booking steps; Google collects technical browser signals in the process.
- Google (Tag Manager, Analytics 4, Ads) - audience and advertising campaign measurement, only if you have consented; no passenger data and no named amount is sent to them.
- AeroDataBox - tracking of your inbound flight; only the flight number and date are transmitted, never your identity.
Priv'Air selects providers offering appropriate confidentiality and security guarantees and ensures, through the applicable contractual commitments and legal mechanisms, that the third parties to which personal data is communicated afford that data a level of protection at least equivalent to the one described in this policy and compliant with the applicable requirements.
Transfers outside the European Economic Area
Some providers are established, or may process data, outside the European Economic Area. Where data is transferred to a third country, Priv'Air ensures that the transfer relies on a mechanism provided for by the GDPR, notably an applicable adequacy decision - including, where relevant, the EU-US Data Privacy Framework for organisations that participate in it - or the standard contractual clauses adopted by the European Commission, supplemented where necessary by additional safeguards. Data processing agreements are entered into with the providers concerned.
Retention periods
Data is deleted automatically on the following schedule, save where longer retention is imposed by a legal, accounting, tax or aviation obligation, or is necessary for the establishment, exercise or defence of legal claims:
- Detailed passenger manifest (passport, date of birth, nationality, weight): automatically deleted 30 days after the flight (90 days at most under operational constraints); immediately for a cancelled or expired booking. Active data attached to the account is deleted or anonymised upon account deletion, subject to the items that must be temporarily kept under the rules above.
- Archived flight tickets (PDF listing passenger names): automatically deleted after 90 days, including where the account was deleted before that deadline if their temporary retention remains necessary for the management or the proof of the carriage.
- Traveller book: deleted after 36 months without use, or as soon as you remove the entry or delete your account.
- Concierge address book: deleted after 36 months without use.
- Booking record (holder contact details, amounts): kept for the duration of the commercial relationship, then under accounting and tax obligations; the holder's contact details are anonymised if you delete your account, to the extent compatible with the legal retention obligations.
- Quote request: a sent offer expires at its stated deadline if you do not book, or after 90 days without a reply if it was never processed; either way, the request is deleted 90 days later. Your contact details and the requested destination are anonymised as soon as you delete your account. A request that led to a booking follows the booking record's retention.
- Notification delivery traces (e-mail, SMS): automatically deleted after 12 months.
- Session cookie: 14 days.
- IP address (anti-abuse): a few minutes.
- Technical error reports: 90 days with our monitoring provider.
Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability over your data, under the conditions and within the limits provided for by the applicable regulations.
From your customer area you can directly correct your details, delete your saved travellers and delete your account. The account deletion function is also accessible from the HeliShift mobile app.
For any other request: privacy@helishift.com. We reply within one month.
You may also lodge a complaint with the French supervisory authority, the CNIL (cnil.fr).
Cookies, trackers and local storage - website and app
The service sets cookies that are strictly necessary to operate, plus audience measurement and advertising cookies that are only set once you have consented. You can accept, refuse, then change or withdraw your choice at any time via the "Manage cookies" link at the bottom of the page. In the mobile app, equivalent technologies or technical identifiers may be used; where consent is required by the regulations, they are only activated once that consent has been collected, and it can be withdrawn as offered in the app.
- __session - authentication cookie (14 days), strictly necessary for your sign-in.
- NEXT_LOCALE - remembers your language choice (for the duration of the visit).
- hs_consent - remembers your cookie choice (6 months), strictly necessary to honour that choice.
- A few technical preferences are kept locally in your browser and are never transmitted.
- Google reCAPTCHA, our anti-bot protection, may set technical identifiers; Google then also acts on its own behalf (see its privacy policy). Where the operations associated with this service pursue purposes subject to consent under the trackers regulations, that consent is collected beforehand; Priv'Air keeps the data transmitted to the strict minimum needed for abuse protection.
- The Revolut payment interface may set its own security cookies, at payment time only.
- Google Tag Manager - loaded only after you consent; it triggers the measurements below and nothing else.
- _ga, _gid - Google Analytics 4, audience measurement and performance of our Google Ads campaigns (13 months maximum). Set only with your consent.
Minor passengers
Information about minor passengers is provided by the adult booking holder and benefits from the same protections and the same retention periods. The adult providing this information warrants being entitled to do so in the context of the booking concerned.
Changes to this policy
This policy may evolve with the service. The update date appears at the top of the page; any substantial change will be flagged in the application and, where relevant, on the website.
Contact
For any question about your data: privacy@helishift.com - Priv'Air SARL - Aéroport Annecy Mont-Blanc - Hangar FL250 - 8, route de Côte Merle - 74370 Épagny Metz-Tessy, France.