Last updated: August 2026
DutyBoost is committed to protecting your personal information. This Privacy Policy explains how we collect, use, and safeguard the data you provide when using our platform. DutyBoost operates a Performance-based Customer Acquisition Infrastructure for Global Travel โ a shared, performance-based commercial ecosystem connecting Travel Partners, Airport Retailers, POS Partners, and travelers through booking-linked DutyCredits. We process data in accordance with GDPR (EU) 2016/679 and applicable travel industry data standards. DutyBoost does not send emails to travelers; we send emails only to Airport Retailers, Travel Partners, and POS Partners that decide to work with, integrate, or join the ecosystem.
We do not sell your personal data. We may share data in the following circumstances: with participating Airport Retailers (limited to DutyCredit validation data required at the point of sale); with POS Partners (limited to redemption validation and transaction data required to process DutyCredits through their infrastructure); with our infrastructure and payment service providers under data processing agreements; with airport authorities or government agencies where legally required (e.g. in connection with security or customs obligations); and with regulatory authorities where required by law, including in connection with AML obligations.
Some of our sub-processors are based outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission. A full list of sub-processors is available in our Data Processing Agreement.
We retain personal data for as long as your account is active or as needed to provide services. Booking and transaction records are retained for a minimum of 7 years in accordance with financial record-keeping obligations. KYC verification records are retained as required by applicable AML regulations. POS integration logs are retained for the duration of the partnership plus the applicable statutory period.
If you are based in the EU/EEA, you have the right to: access your personal data; request correction of inaccurate data; request deletion of your data (subject to legal retention obligations); object to or restrict processing; and request data portability. To exercise your rights, contact us at privacy@dutyboost.com. You also have the right to lodge a complaint with your national data protection authority.
We use industry-standard encryption (TLS 1.2+ in transit, AES-256 at rest), role-based access control, and multi-factor authentication for internal systems. DutyCredit codes are cryptographically unique and single-use. POS Partner integrations are secured using authenticated API channels. We conduct regular security assessments and maintain a documented incident response procedure.
DutyBoost processes limited traveler data (name, email, booking reference, departure airport, travel date) provided by Travel Partners for the sole purpose of generating and validating DutyCredits. DutyBoost does not send marketing or transactional emails to travelers. Travel Partners are the data controllers for their travelers' data and are responsible for their own privacy obligations toward their customers. Airport Retailers and POS Partners receive only the minimum data needed to validate a DutyCredit at the point of sale.
For privacy-related enquiries: privacy@dutyboost.com ยท DutyBoost B.V., a legal entity registered at the Dutch Chamber of Commerce (Kamer van Koophandel) under number 42053181, Amsterdam, the Netherlands.
We use cookies to improve your experience. You decide which cookies to allow โ essential cookies are always required for the platform to function. Cookie Policy