Privacy
What we collect, and why.
Last updated 28 August 2026.
NomadFare is a self-hosted flight-deal finder. It is not an airline, not a ticket seller, and not a GDS. When you tap Book this deal, you leave this site for an online travel agency (Aviasales, Jetradar, Kiwi, Kayak, and similar). That OTA processes the purchase. If you complete a booking through NomadFare’s affiliate codes, the travel site may pay the operator a commission. You are not charged extra for that.
Account data
If you create an account we store email, a password hash, home airports, saved deals, route watches, and alert preferences (including an optional phone number for SMS). Stripe customer and subscription ids live on the user row when billing is configured. Google OAuth and magic links only run when those keys are set.
Search and fare data
Live quotes come from Travelpayouts, and optionally Amadeus, Duffel, Sabre, Kiwi, and SerpAPI. We cache those responses so the feed stays fast. Point-of-sale (POS) cards are market-currency probes: we re-fetch the same city pair in another market’s currency and convert with public FX. That is not a GDS country-of-sale scrape and it is not a VPN log.
Alerts
Email (Resend), Telegram, Discord, web push, and SMS (Twilio) only send when you turn the channel on and the matching secret exists. Quiet hours apply to immediate pings. We do not sell your phone number or email.
Cookies and device storage
Sign-in uses an Auth.js session cookie. Search filters, hidden deals, and unsynced pins live in your browser (localStorage) until you sign in. A service worker powers the installable PWA.
Deletion
Signed-in users can delete the account from the dashboard. That removes the user row and cascaded sessions, saved deals, webhooks, push subscriptions, and notification logs. Affiliate OTAs keep their own booking records.
Questions: the operator who runs this instance. See also Terms.