Legal

Atlastic Privacy Policy

⚠️ DRAFT — pending review by the owner’s legal counsel. Not yet in effect; do not publish or rely on it until counsel approves and all [OWNER: …] items are resolved.

This document is a draft prepared for the owner and is pending review and approval by qualified legal counsel before publication. It must not be published or relied upon as a live legal notice until counsel has reviewed it and every [OWNER: …] placeholder has been completed. Nothing in this draft should be read as describing data practices, certifications, or features that Atlastic does not actually have.

Effective date: 28 June 2026

Last updated: 28 June 2026

Who we are

This Privacy Policy explains how Atlastic (“Atlastic”, “we”, “us”, “our”) collects, uses, shares, and protects your personal information when you use the Atlastic mobile app for iOS and Android (the “App”), our website at atlastic.com (the “Site”), and the Atlas in-app AI travel concierge (together, the “Services”).

Atlastic is a consumer travel service. We help you discover curated daily trips and book flights, hotels and stays, activities, airport transfers, and curated multi-component travel packages. We are committed to honest all-in pricing (taxes and fees included — no drip pricing), and we apply the same honesty to how we handle your data.

Atlas is our in-app AI travel concierge. Atlas advises and helps you plan — it never books anything automatically. You always make the final booking decision.

Who is responsible for your data (controller). The entity responsible for your personal information under this Policy is MajeStay Technologies Limited, with registered address DIFC, Dubai, UAE [exact office/unit to be confirmed] (associated with the MajeStay group of brands). For any privacy question, use the details in “Contact us” below.

At a glance

This summary is for convenience only and does not replace the full Policy.

#SectionIn short
1Information we collectAccount, traveler & booking details, search queries (incl. to Atlas), device/crash diagnostics, approximate location (only if you allow it). The Site collects only a waitlist email.
2Where your data comes fromFrom you, from your device, and from Google/Apple if you use social sign-in.
3How and why we use your data + legal basesRun your account, process bookings and payments, power Atlas, keep the Service safe, and meet legal duties.
4CCPA/CPRA categories of personal informationThe statutory categories we collect, our sources, purposes, and who receives them.
5The Atlas AI conciergeYour queries are processed by a third-party cloud LLM. Atlas suggests only and can be wrong — verify before you rely on it. No solely-automated decisions are made about you.
6Who we share data withStripe, travel suppliers (via a B2B distribution partner), Google/Apple, Firebase/Google, AWS/SES, and the LLM provider — all as service providers/processors.
7We do not sell your dataWe do not sell or share your personal data for cross-context behavioral advertising.
8International transfersYour data may be processed outside your country, with safeguards.
9How long we keep dataOnly as long as needed; some booking/payment/tax records are retained by law.
10How we protect your dataEncryption in transit, access controls, a PCI-compliant payment processor.
11Your privacy rightsGDPR/UK and CCPA/CPRA rights and how to use them.
12Deleting your accountIn-app (Settings → Delete Account) or off-app via privacy@atlastic.com.
13Cookies & the websiteEssential/functional only — no analytics or third-party tracking.
14ChildrenNot directed to children; we do not knowingly collect their data.
15Bookings & supplier termsBookings are subject to each supplier’s own terms and policies.
16Changes & contactHow we notify you of updates and how to reach us.

1. Information we collect

We collect only what we need to run Atlastic. What we collect depends on whether you use the App or only the Site.

In the Atlastic App

Account information

  • Email address (required to create an account).
  • Name.
  • Phone number (optional).

Traveler and booking details (needed to make a booking)

  • Date of birth and traveler details (e.g. traveler names and other details a supplier requires to issue a flight ticket, hotel reservation, activity, or transfer). Where a travel supplier requires it to issue a booking (for example, an international flight), we collect passport or government-ID details solely for that booking. We treat such details as sensitive personal information and handle them as described in “Sensitive information” below. (Interim draft default; counsel to confirm.)
  • Your booking and travel history.

Search and concierge data

  • Your search queries, including the travel questions and prompts you send to the Atlas AI concierge.

Social sign-in data (only if you choose it)

  • If you sign in with Google or Apple, we receive your name, email address, and avatar/profile image from that provider, as permitted by your settings. With Sign in with Apple, you may choose to hide your email and use Apple’s private relay address.

Device and diagnostics data

  • Device and app diagnostics, including crash reports and usage diagnostics, collected via Firebase Crashlytics to keep the App stable and fix bugs. We use Firebase for diagnostics only — not for account sign-in. Where consent is required for diagnostics (for example for EU/UK users), the App will obtain it on first run and offer an opt-out, and the App’s first-run experience will match this Policy. (Interim draft default; counsel to confirm.)

Approximate location (only if you allow it)

  • If you grant location permission, we use your approximate location to improve search results (e.g. trips and stays near you). You can turn this off at any time in your device settings. We do not need precise/GPS-level location to operate the Service.

Payment information

  • When you pay, your card details are captured directly by Stripe’s payment fields within the App and are processed by Stripe, our payment processor. Your full card number is never stored on, and does not pass through, Atlastic’s systems. We may receive limited payment metadata from Stripe — for example the last four digits, card brand, an authorization result, and a transaction/booking reference — to manage your booking, receipts, refunds, and fraud prevention. We receive and store only limited payment metadata from Stripe — typically the last four digits of the card, the card brand, the authorization result, and a transaction/booking reference. (Interim draft default; counsel to confirm.)

On the Atlastic website (atlastic.com)

The Site is intentionally minimal. It does not run analytics or third-party tracking, and uses near-zero JavaScript.

  • The only personal data the Site itself collects is the email address you submit to our waitlist form, which we use to contact you about Atlastic’s launch and updates.
  • The Site uses only the essential/functional storage needed for it to work and be secure (see “Cookies and the website”). The Site uses only the minimal essential/functional storage strictly needed for it to work and be secure, and sets no analytics, advertising, or tracking cookies. (Interim draft default; counsel to confirm exact cookie inventory.)

Sensitive information

We do not seek special-category data (such as health, religion, or biometric data). Date of birth, and any accessibility or dietary requests or government-ID details a supplier requires, may be treated as sensitive personal information under the CPRA and as special-category-adjacent data under the GDPR. We collect and use such data only to fulfill a booking you request and only as the law allows. Where a supplier requires passport or government-ID details to issue a booking, we collect them solely for that booking and treat them as sensitive personal information, using them only to fulfill the booking you request. (Interim draft default; counsel to confirm.) Please do not enter sensitive information into Atlas unless it is needed for travel planning.

2. Where your data comes from

We collect personal information:

  • Directly from you — when you create an account, set up your profile, enter traveler details, make a booking, contact us, chat with Atlas, or join the waitlist.
  • From your device — diagnostics, crash data, and (if permitted) approximate location.
  • From Google or Apple — if you choose social sign-in, we receive basic profile data (name, email, avatar) from that provider.
  • From our payment processor and travel partners — limited status data needed to complete and manage your bookings and payments (for example, booking confirmations, ticket references, and payment results).

We use your personal information for the purposes below. For users in the EU, UK, and other regions where the GDPR or equivalent law applies, the corresponding legal basis is shown.

What we doWhyLegal basis (GDPR)
Create and manage your account; authenticate you (incl. Google/Apple sign-in)To give you access to the ServicePerformance of a contract
Process your bookings and share required traveler details with suppliersTo deliver the travel service you requestPerformance of a contract
Process payments via Stripe; manage receipts, refunds, and Freeze-your-deal feesTo take payment and fulfill your bookingPerformance of a contract
Power the Atlas AI concierge and respond to your search/travel queriesTo provide the concierge feature you usePerformance of a contract
Provide customer support and respond to your requestsTo help youPerformance of a contract; legitimate interests
Maintain stability, fix bugs, and prevent crashes (Firebase Crashlytics)To keep the App working and reliableLegitimate interests where consent is required for EU/UK diagnostics, the basis is Consent
Detect, prevent, and investigate fraud, abuse, and security incidentsTo protect users and AtlasticLegitimate interests; legal obligation
Use approximate location to improve searchTo show relevant nearby resultsConsent (device permission you grant)
Send waitlist, launch, and service communicationsTo keep you informedConsent (waitlist sign-up); or legitimate interest for essential service messages
Keep booking, payment, tax, and anti-fraud recordsTo meet accounting, tax, and legal dutiesLegal obligation

Where we rely on consent (for example, approximate location, diagnostics where required, or waitlist marketing), you can withdraw it at any time without affecting processing already carried out. Where we rely on legitimate interests, you have the right to object — see “Your privacy rights.”

We rely on consent for waitlist and marketing communications, and we treat diagnostics as requiring consent where applicable law (including for EU/UK users) so requires. (Interim draft default; counsel to confirm the final legal-basis mapping.)

4. CCPA/CPRA categories of personal information

For California residents, the table below maps what we collect to the statutory categories under the CCPA (as amended by the CPRA), with our sources, business purposes, and the categories of recipients. We have not sold or shared any of this for cross-context behavioral advertising in the preceding 12 months.

CCPA categoryExamples we collectSourceBusiness purposeDisclosed to (service providers/contractors)
IdentifiersName, email, phone, account ID, device identifiersYou; your device; Google/AppleAccount, support, securityStripe, suppliers, Google/Apple, Firebase, AWS/SES
Customer recordsTraveler details, date of birth, booking/contact detailsYouProcess and service bookingsTravel suppliers (via distribution partner), Stripe
Commercial informationBooking/travel history, transactions, Freeze-your-deal useYou; suppliers; StripeFulfill and manage bookingsSuppliers, Stripe
Internet/electronic activitySearch queries, Atlas prompts, app usageYou; your deviceProvide search and the Atlas conciergeLLM provider, AWS
Geolocation (approximate)Approximate location, only if permittedYour deviceImprove nearby searchAWS
Sensitive personal informationDate of birth; any accessibility/ID details a supplier requiresYouOnly to fulfill a bookingRelevant supplier
DiagnosticsCrash and usage diagnosticsYour deviceApp stability and bug-fixingFirebase/Google

We do not use sensitive personal information for any purpose that would trigger the CPRA right to limit its use (we use it only to perform the service you request). This categories table is intended to match the Apple App Privacy label and the Google Play Data Safety form, including data shared with third parties. (Interim draft default; counsel and the app team to confirm exact alignment before publication.)

5. The Atlas AI concierge — how it uses your data

Atlas is an AI travel concierge built into the App.

How your data is processed. When you ask Atlas a question, your query (and relevant trip context) is sent to a third-party large-language-model (LLM) provider operating in the cloud, which processes the text and returns suggestions. We send Atlas only what is needed to answer your travel question. Please avoid entering sensitive personal information into Atlas that is not needed for travel planning.

We use the LLM provider on a no-training, short-retention configuration: your prompts are not used to train the provider’s models, and the provider retains prompt data only briefly before deletion in line with that configuration. We do not use your Atlas data to “improve the Service” beyond answering your query. (Interim draft default; counsel to confirm the provider’s name and data terms.)

Atlas advises — it does not book. Atlas provides AI-generated suggestions and itineraries. It never finalizes a booking on your behalf. You always review and confirm every booking yourself.

No solely-automated decisions. Because you always make the final booking decision, Atlas does not make decisions about you that produce legal or similarly significant effects without human involvement (GDPR Article 22). Atlas only suggests; you decide.

AI accuracy disclaimer. Atlas’s suggestions may contain errors, omissions, or out-of-date information. Atlas does not provide professional travel, financial, legal, medical, or visa/immigration advice. You are responsible for verifying important details — including prices, availability, fare and cancellation rules, and entry/visa/health requirements — directly with the supplier or relevant authority before you rely on them or travel.

6. Who we share your data with

We share personal data only to operate the Service. The recipients below act as our service providers / contractors (CCPA) and processors (GDPR) under contracts that require them to protect your data and to use it only for the purposes we specify. We do not sell your data (see next section).

RecipientWhat they doWhat they receive
StripePayment processing (PCI-compliant)Card and payment details, captured directly by Stripe to complete a purchase. Atlastic does not store full card numbers.
Travel suppliers / aggregators (flights, hotels/stays, activities, transfers), accessed via a B2B travel distribution partnerTo fulfill and manage your bookingsThe traveler and booking details required to issue and service your booking (e.g. names, dates of birth, contact details, booking references).
Google and AppleSocial sign-in (authentication)Sign-in/authentication data; we receive your name, email, and avatar if you use their sign-in.
Firebase / GoogleCrash and usage diagnostics onlyDevice identifiers and diagnostic/crash data.
Amazon Web Services (AWS)Cloud hosting and infrastructure; transactional email via Amazon SESData stored and processed to run the Service; your email address for service emails.
Third-party LLM providerPowers the Atlas conciergeYour Atlas queries and relevant trip context (see “The Atlas AI concierge”).

We may also disclose personal data: (a) to comply with law, legal process, or a lawful government request; (b) to enforce our terms or protect the rights, safety, and property of users, the public, or Atlastic (including fraud prevention); and (c) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this Policy and will notify you where required.

We will name the B2B travel distribution partner and the LLM provider here once confirmed, and we maintain Data Processing Agreements / service-provider contracts with each recipient so that the no-sale / no-share claim holds. (Interim draft default; counsel and the owner to confirm partner names and the final processor list.)

7. We do not sell or share your data for advertising

Atlastic does not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA (as amended by the CPRA). We have not sold or shared personal information for these purposes in the preceding 12 months. All recipients listed above act as our service providers/contractors and are contractually bound to use your data only to provide the Service.

Because we do not sell or share your data for advertising, there is no advertising opt-out to exercise — but you can still exercise all your other rights (see “Your privacy rights”).

8. International data transfers

Atlastic operates with cloud infrastructure and partners that may be located in different countries. As a result, your personal information may be processed in, or transferred to, countries outside the one where you live — including by Stripe, AWS, Google/Apple/Firebase, our travel distribution partner, and the LLM provider.

Where we transfer personal data across borders, we put appropriate safeguards in place — for example transfers to countries recognized as providing an adequate level of protection, or contractual safeguards such as the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable) for EU/UK-origin data.

Atlastic is operated by MajeStay Technologies Limited, established in the DIFC, Dubai, UAE. For cross-border transfers, our primary mechanism is transfer to jurisdictions recognized as adequate under the DIFC Data Protection Law (DIFC Law No. 5 of 2020) or appropriate safeguards approved by the DIFC Commissioner of Data Protection, such as the DIFC Standard Contractual Clauses; the EU/UK Standard Contractual Clauses apply only to EU/UK-origin personal data. (Interim draft default; counsel to confirm the primary data-hosting region and final transfer mechanisms.)

9. How long we keep your data (retention)

We keep personal data only as long as we need it for the purposes in this Policy, and then delete or anonymize it.

  • Account and profile data — kept while your account is active. When you delete your account, profile data is deleted or anonymized (see “Deleting your account”).
  • Booking, payment, tax, and anti-fraud records — retained after account deletion where we are legally required to keep them (for example, accounting and tax law) and to meet our obligations to travel suppliers, for a period of the minimum period required by applicable UAE/DIFC law (at least 5 years for financial and tax records). Traveler details (such as name and date of birth) that are embedded within these retained records are kept, minimized where feasible, for the same period.
  • Atlas concierge queries — retained only as long as needed to provide the concierge and keep the Service secure. We retain Atlas queries only for as long as needed to provide the concierge and keep the Service secure, and then delete or anonymize them; this is separate from the LLM provider’s own short prompt-retention terms. (Interim draft default; counsel to confirm.)
  • Diagnostics / crash data (Crashlytics) — retained per the provider’s standard retention window and our debugging needs; the provider retains some diagnostic data independently under its own terms.
  • Waitlist email — kept until you unsubscribe or ask us to delete it, or until launch communications are complete.

Where we keep data for legal reasons, we restrict its use to those purposes only.

10. How we protect your data (security)

We use technical and organizational measures designed to protect your personal information, including:

  • Encryption in transit (HTTPS/TLS) for data moving between your device and our services.
  • A PCI-compliant payment processor (Stripe) that captures card details directly, so Atlastic does not handle or store full card numbers.
  • Access controls that limit who can access personal data, on a need-to-know basis.
  • Reputable cloud infrastructure (AWS) and vendor security practices.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal-data breach that affects you, we will notify you and the relevant authorities where, and within the timeframes, the law requires. Under the DIFC Data Protection Law (DIFC Law No. 5 of 2020, Article 41), we will notify the DIFC Commissioner of Data Protection as soon as practicable, and in any event without undue delay and within 72 hours where feasible, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to them. (Interim draft default; counsel to confirm.)

This Policy does not claim any security certification. Atlastic does not currently hold any security certification of its own. For card payments, we rely on Stripe’s PCI DSS compliance as our payment processor. (Interim draft default; counsel to confirm before listing any certification.)

11. Your privacy rights

Depending on where you live, you have rights over your personal data. We honor these rights for all users where we can.

If you are in the EU, UK, or EEA (GDPR / UK GDPR)

You have the right to:

  • Access your personal data and get a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data (“right to be forgotten”), subject to legal retention.
  • Restrict processing in certain cases.
  • Object to processing based on our legitimate interests, and to direct marketing at any time.
  • Data portability — receive certain data in a structured, machine-readable format.
  • Withdraw consent at any time where we rely on consent (e.g. location, diagnostics, marketing).
  • Lodge a complaint with your data protection authority.

If you are in California (CCPA/CPRA)

You have the right to:

  • Know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients (see the table in Section 4).
  • Delete your personal information, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information — note that Atlastic does not sell or share your personal information, so this right does not apply; you may still contact us to confirm.
  • Limit the use of sensitive personal information — we use sensitive information only to perform the service you request, which does not trigger this option.
  • Non-discrimination — we will not treat you differently for exercising your rights.

How to exercise your rights

Email privacy@atlastic.com with your request. You can also manage and delete your account in the App (see “Deleting your account”). We will verify your identity before acting on a request, and we will respond within the timeframe required by law (generally one month under GDPR and 45 days under CCPA/CPRA, each extendable where permitted). You may use an authorized agent where the law allows. You may use an authorized agent where the law allows; we will ask the agent for written authorization and may still verify your identity directly before acting on a request. (Interim draft default; counsel to confirm the authorized-agent process and verification standard.)

12. Deleting your account

You can delete your Atlastic account in two ways:

  1. In the App: go to Settings → Delete Account.
  2. Without the App: email privacy@atlastic.com (or use the request form at atlastic.com/data-deletion) to ask us to delete your account. This off-app method exists so you can request deletion even if you no longer have the App installed.

What happens when you delete your account. We process deletion requests within up to 30 days. When we process your request:

  • Deleted or anonymized: your personal profile data — name, email, phone, date of birth, traveler profile, approximate-location data, saved searches, app preferences, social sign-in identifiers, and your Atlas concierge history — is deleted or irreversibly anonymized so it no longer identifies you. Diagnostic identifiers are deleted or anonymized on our systems; the diagnostics provider retains some data independently under its own terms.
  • Retained: certain records connected to completed bookings, payments, tax, and anti-fraud/abuse prevention are retained where we are legally required to keep them and to meet our obligations to travel suppliers. Traveler details embedded in those records are retained, minimized where feasible. These are kept for the period stated in “How long we keep your data” and used only for those legal and compliance purposes.

After deletion you will no longer be able to sign in, and active or upcoming bookings may be subject to the relevant supplier’s cancellation and refund rules. Full details are on our Account & Data Deletion page. We process deletion requests within up to 30 days. Records we are legally required to retain are kept for the minimum period required by applicable UAE/DIFC law (at least 5 years for financial and tax records). A short reversible grace window may apply before deletion is finalized. (Interim draft default; counsel to confirm.)

13. Cookies and the website

The Atlastic website (atlastic.com) is deliberately lightweight.

  • The Site does not use analytics or third-party tracking cookies. It runs near-zero JavaScript and does not embed advertising or behavioral-tracking tools.
  • The Site uses only the essential/functional storage needed for it to work and be secure. The Site uses only the minimal essential/functional storage strictly needed for it to work and be secure, and sets no analytics, advertising, or tracking cookies. (Interim draft default; counsel to confirm exact cookie inventory.)
  • The only personal data the Site collects is the email you submit to our waitlist form.

Inside the App, we use the services described in this Policy (such as Firebase for diagnostics and Stripe for payments) rather than website cookies, and we do not use advertising SDKs. [OWNER: if you later add any analytics or marketing tags to the Site or App, update this section and the data inventory and add a consent banner where required.]

14. Children

Atlastic is not directed to children. We do not knowingly collect personal information from children under the applicable age threshold of 16 years (and, in any event, you must be 18 or older to enter into a payment contract and make a booking). If you believe a child has provided us with personal information, contact privacy@atlastic.com and we will take steps to delete it. Bookings must be made by an adult, who is responsible for any travelers (including minors) included in a booking.

15. Bookings, supplier terms, and Freeze-your-deal

Atlastic facilitates your travel bookings, which are fulfilled by third-party travel suppliers (airlines, hotels and stays, activity and transfer providers) accessed through our distribution partner.

  • Each booking is subject to the relevant supplier’s own terms, fare rules, and cancellation/refund policies, surfaced to you at the time of booking. Please review them before you confirm.
  • Payments for travel are charged directly to your card via Stripe. Atlastic does not use Apple In-App Purchase or Google Play Billing for travel bookings, because travel is a real-world service.
  • Freeze-your-deal: where you choose to lock a price for a window for a fee, the specific Freeze-your-deal terms (including how the fee is applied toward your booking if you complete it) apply and are shown to you at the time. See our Terms of Service for full details. Freeze-your-deal fee and refund terms are shown to you at the time you use the feature and are set out in our Terms of Service. (Interim draft default; counsel to confirm and align with the Terms of Service.)

16. Changes to this Policy, and contact us

We may update this Privacy Policy from time to time. When we do, we will change the “Last updated” date above and post the new version at atlastic.com/privacy and in the App. If the changes are material, we will provide additional notice where required (for example, by email or an in-app notice). Your continued use of the Services after an update means you accept the revised Policy, to the extent permitted by law.

This Policy works alongside our Terms of Service (atlastic.com/terms) and Account & Data Deletion page (atlastic.com/data-deletion).

Contact us:

Data Protection Officer / EU-UK representative: You can reach our privacy team at privacy@atlastic.com. The appointment of a Data Protection Officer under the DIFC Data Protection Law is under review by our counsel; no DPO or EU/UK representative is currently appointed. (Interim draft default; counsel to confirm whether a DPO appointment is required.)

Governing law and jurisdiction: This Policy and any dispute relating to it are governed by the laws of the Dubai International Financial Centre (DIFC), Dubai, UAE, and are subject to the exclusive jurisdiction of the DIFC Courts. (Interim draft default; counsel to confirm.)

If you are in the EU or UK and believe we have not resolved your concern, you may complain to your local data protection authority. If you are in the DIFC, you may also lodge a complaint with the DIFC Commissioner of Data Protection. If you are in the EU or UK, you may complain to your local data protection authority. (Interim draft default; counsel to confirm and add the Commissioner’s contact details.)