This policy explains what data LSP Voyage collects when you use voyage.lspenterprise.com, why we collect it, how long we keep it, who we share it with, and what your rights are. We comply with the GDPR (European Union), Law 25 (Quebec), and the CCPA (California).
1. Who we are
LSP Voyage is a service published by LSP Web Agency, whose head office is in Quebec (Canada). For any question about your personal data, contact us at voyage@lspenterprise.com.
2. Data we collect
2.1 Data you actively give us
- Email address: when you sign up for our price alerts or our newsletter.
- Search criteria: departure and arrival airports, dates, number of travellers, budget. This information is needed to run the search engine.
- Payment information: when you take out a paid subscription, payments are processed by Stripe. We never store your card number; only a Stripe customer identifier is kept.
- Preferences: displayed currency, language, types of trip that interest you (if you tell us).
2.2 Data collected automatically
- Technical data: IP address (anonymised), browser, operating system, screen size, pages visited, visit duration, traffic source.
- Cookies and similar identifiers: see the dedicated section below.
- Server logs: for security and debugging. Kept 30 days then deleted.
2.3 What we do NOT collect
- No health data.
- No banking data (Stripe handles it for us).
- No precise geolocation — only the country/region inferred from the IP address.
- No cross-site advertising profiling without your explicit consent.
3. Why we collect this data (legal bases)
- Performance of the contract (GDPR art. 6.1.b): to provide the service you asked for (search, alerts, subscription).
- Legitimate interest (GDPR art. 6.1.f): aggregated usage statistics, fraud prevention, site improvement.
- Consent (GDPR art. 6.1.a): marketing newsletter, non-essential cookies.
- Legal obligation (GDPR art. 6.1.c): invoicing and accounting retention.
4. Who we share your data with
We never sell your data. We share it only with technical providers strictly necessary to run the service:
- Vercel (United States) — site hosting.
- Supabase (United States / European Union) — database and authentication.
- Stripe (United States / Canada) — payment processing.
- Resend (United States) — sending transactional emails and newsletters.
- Travelpayouts (Cyprus / European Union) — affiliate network for links to Booking.com, Aviasales and other partners.
- Travelpayouts Drive / analytics partners — measuring affiliate conversion attribution, only after consent to non-essential cookies.
When data is transferred outside the European Union, it is covered by the European Commission's standard contractual clauses and, where applicable, by existing adequacy decisions (for example the EU-US Data Privacy Framework).
5. Cookies and similar technologies
We use three categories of cookies:
- Essential cookies (always on) — sign-in session, cart, currency preference, CSRF security. Without them the site cannot work properly.
- Audience measurement cookies (with consent) — aggregated statistics on the most visited pages, time spent, traffic sources. Anonymised.
- Affiliate cookies (with consent) — placed by our partners (Booking.com, Travelpayouts, etc.) so they can correctly attribute a booking to our site. These are session cookies that expire at the end of your visit to the partner.
You can change your choices at any time by deleting the lsp_voyage_consent cookie from your browser or by using the « Cookie preferences » link in the footer.
6. Retention periods
- Active user account: as long as your account is active, plus 3 years after the last sign-in.
- Billing data: 10 years (accounting obligation, Taxation Act).
- Technical logs: 30 days.
- Newsletter: as long as you are subscribed, plus 1 month after unsubscribing.
- Affiliate cookies: period set by the partner (Booking.com: 1 session; usually 24 h to 30 days for the others).
7. Your rights
Whatever your nationality or place of residence, you can at any time:
- Access the data we hold about you.
- Correct inaccurate data.
- Delete your account and all associated data (« right to be forgotten »).
- Restrict certain processing.
- Port your data to another service (JSON format).
- Object to processing based on legitimate interest.
- Withdraw your consent at any time for the processing that depends on it.
To exercise these rights, write to voyage@lspenterprise.com. We answer within 30 days. If the answer does not satisfy you, you can refer the matter to the competent supervisory authority:
- Quebec: Commission d'accès à l'information du Québec (cai.gouv.qc.ca).
- France: CNIL (cnil.fr).
- Canada (outside Quebec): Office of the Privacy Commissioner (priv.gc.ca).
8. Security
Your data is protected by: mandatory TLS 1.3 encrypted connection (HTTPS everywhere), passwords stored with bcrypt (never in clear text), database access limited by Supabase row-level security, access logs, daily encrypted backups.
In case of a data breach likely to create a risk to your rights, we will notify you within 72 hours, in line with the GDPR and Law 25.
9. Children
LSP Voyage is not intended for people under 16. If we find we have accidentally collected a minor's data, we delete it immediately.
10. Changes to this policy
We may update this policy to reflect legal or technical changes. The date of the last update appears at the top of the page. In case of a significant change, we will inform you by email at least 30 days before it takes effect.