Legal
Privacy policy
Effective 2 October 2026
This policy explains what Cruise Itinerary (cruise-itinerary.com) collects about you, why, who else sees it, and what you can ask us to do about it. The controller is Agile Travel Group, Inc., doing business as Cruiseable. We keep it short because there is not much to say: we run a data API, not an advertising business. We do not sell personal data and we do not use it for advertising.
What we collect
If you only read the site or use the API without a key
Our web server and Cloudflare log each request: IP address, time, URL, status, user agent and referrer. For rate limiting we also keep a counter per hashed IP address and per minute, which is deleted within an hour. Open API calls are not tied to a person.
If you create an account
- Your email address, and a company name if you give one.
- Sign-in links: a hash of each one-time token, the email it was sent to, a hash of your IP address, and the times it was created and used.
- Sessions: a hash of the session token and its expiry. The cookie itself is
ci_session. - API keys: a SHA-256 hash of each key (we cannot read it back), its first twelve characters so you can recognise it, the name you gave it, and when it was created, last used and revoked.
- Usage: the number of successful calls per month for your account.
- Webhook settings, if you use them: the URL, the signing secret, your filters, and a log of each delivery with its status, attempt count and any error text.
If you pay
Stripe handles payment. Card details go to Stripe and never reach our servers. We store your Stripe customer and subscription identifiers, your plan, billing interval, subscription status and the end of the current period, and the Stripe event records we need to apply payments exactly once.
If you subscribe to the Price Index email
Your email address, a hash of your confirmation token, and the times you confirmed and unsubscribed. Nothing is sent until you confirm.
We send sign-in links, billing notices, security and service messages, and the Price Index email if you asked for it. Mail goes out from our own server. We keep ordinary mail server logs.
Cookies and analytics
We set three cookies for the site to work: ci_session (signed-in state, up to 30 days, HttpOnly), ci_csrf (form protection) and ci_flash (a message shown once after an action, two minutes). They are not used for tracking.
For understanding use of the site we run Google Analytics 4 (measurement ID G-TT63XX31ST), which sets its own cookies and sends page-view data to Google. We also run a small first-party analytics script from bigballi.com, another site we operate. It records page views, scroll depth and whether the page was visible, with a random visitor identifier (kept for up to two years) and a session identifier (30 minutes). Block them with a browser setting or extension and the site still works.
Why we use it
- To provide the Service you asked for: accounts, keys, usage limits, billing, webhooks. (Contract.)
- To keep it secure and fair: rate limiting, abuse prevention, logs. (Legitimate interests.)
- To understand and improve the site: analytics. (Legitimate interests, or consent where the law requires it.)
- To send the Price Index email. (Consent, which you can withdraw at any time.)
- To keep records the law requires, such as payment records. (Legal obligation.)
Who else handles it
- Stripe, for payments and billing records.
- Cloudflare, which sits in front of the site and API, sees and caches traffic, and applies security rules.
- Google, for Google Analytics, and for Google Cloud Storage, where encrypted-in-transit nightly backups of our database are kept.
- IONOS, the hosting provider whose servers run the Service.
These providers act on our behalf or as independent controllers under their own terms. We disclose personal data to others only to run the Service, to comply with the law, or to protect our rights. Your data may be processed in the United States and other countries where these providers operate.
How long we keep it
Account, key, usage and webhook records are kept while your account exists. Server and CDN logs are kept for the period those systems retain them. Payment and tax records are kept as long as the law requires. Database backups run nightly; daily copies are kept for 35 days and a monthly copy is kept longer, so a deleted record may remain in a monthly backup until that backup is retired.
Your choices and rights
Write to [email protected] from the address on your account to ask for a copy of your data, to correct it, or to delete the account. We will reply within 30 days. Depending on where you live (for example under the GDPR or the California Consumer Privacy Act) you may also have the right to object to or restrict processing, to data portability, and to complain to your data protection authority. We will not treat you differently for using these rights. Unsubscribe from the Price Index email with the link in any message. Revoke a key or delete a webhook from your dashboard at any time.
Security
Keys, sign-in tokens and session tokens are stored only as hashes. Traffic is encrypted in transit. No system is perfectly secure; if a breach affects you we will tell you as the law requires.
Children
The Service is for businesses and developers, and is not directed to anyone under 16. We do not knowingly collect their data.
Changes
If we change this policy we will update the date above, and tell account holders by email when the change is material.
Contact
Agile Travel Group, Inc., d.b.a. Cruiseable. [email protected], or [email protected]. See also our terms of service.