Privacy Notice
Version 1.1 — Effective 1 October 2026
DocumentJet is operated by FLYTRIX Americas LLC.
This Privacy Notice explains how we collect, use, disclose, retain and protect personal information when you request a quote, make a Booking, act as a Sender or Recipient, use the DocumentJet website, communicate with us or otherwise interact with the service.
1. Controller
Unless otherwise stated, the controller responsible for DocumentJet personal data is:
FLYTRIX Americas LLC
222 N Pacific Coast Hwy, PCT Tower, Floor 10, El Segundo, CA 90245, United States
Email: help@documentjet.com
FLYTRIX EMEA GmbH and other FLYTRIX affiliates may provide operational support and may process personal information on our behalf or, where required by applicable law, for their own lawful operational obligations.
EU representative (Art. 27 GDPR):
FLYTRIX EMEA GmbH
Adlzreiterstraße 11, 83022 Rosenheim, Germany
Contact: Fabian Angeloni
Telephone: +49 89 24414368-4
Email: office@flytrix.com
2. Information We Collect
Quote information
Origin and destination city or postal area, geographic coordinates, country, selected airport and quote details.
Customer information
Name, company name, postal address, email address, telephone number, VAT identification number where applicable and Customer type.
Sender information
Name, company, address, email where provided, phone number, pickup instructions and contact information.
Recipient information
Name, company, delivery address or airport, email where provided, telephone number, handover instructions and relevant Airport Delivery information.
Shipment information
Document category, urgency reason where voluntarily provided, routing, airports, courier information, status, pickup and delivery times and operational notes.
Payment information
Payment status, amount, currency, Stripe identifiers and fraud/security information supplied by our payment provider.
DocumentJet does not receive or store full card numbers or card security codes when Stripe's secure payment components are used.
Verification information
Email-verification status, verification time and method.
We do not retain plaintext email one-time passwords after they are no longer needed.
Technical and security information
IP address, browser/user-agent information, security events, session information, rate-limit events, request metadata, timestamps, advertising click identifiers (see Section 12) and information used to detect abuse or fraud.
Communications
Emails, calls, messages, customer-service correspondence and information you choose to provide to our operations team.
3. Information We Intentionally Do Not Routinely Collect
We do not routinely request or store:
- passport numbers;
- national identity numbers;
- passport scans;
- full document copies;
- dates of birth; or
- substantive contents of documents being transported.
Please do not enter such information into free-text fields unless specifically requested and necessary.
A flight courier may physically inspect a document to confirm compliance. Physical inspection does not mean DocumentJet routinely digitizes or records the contents.
4. Information About Other People
A Customer may provide information about another person, such as a Sender, Recipient, traveler or passport holder.
Where you provide another person's information, you must be authorized to provide it and should make this Privacy Notice available to that person.
Where EEA or UK data-protection law requires us to provide privacy information directly to a person whose information was supplied by someone else, we will make this Notice available within the required period and, where applicable, no later than our first direct communication with that person.
5. Why We Use Personal Information
We may use personal information to:
- generate/administer quotes;
- prepare/process Bookings;
- verify Customer email;
- arrange pickup/delivery;
- arrange flight-courier transportation;
- contact Senders/Recipients;
- coordinate airport/authority handovers;
- process payment authorization/capture;
- prevent payment fraud;
- verify VAT status;
- perform sanctions/restricted-party screening;
- comply with export-control/customs/aviation/legal obligations;
- provide support;
- send transactional communications;
- maintain chain-of-custody/contract records;
- investigate complaints/disputes;
- secure systems;
- prevent scraping/abuse;
- measure aggregate website performance;
- analyze conversion/operations; and
- establish/exercise/defend legal claims.
6. Legal Bases Under EEA/UK Law
Contract / pre-contract
Customer information used to quote, book, pay and perform service.
Legitimate interests
Sender/Recipient information supplied by Customer, delivery coordination, security, fraud prevention, performance analysis and efficient operation.
Legal obligations
Tax, accounting, sanctions, export controls, customs, aviation security, law-enforcement and similar requirements.
Consent
Where specifically required. Marketing consent, if later introduced, will be separate and optional.
Acceptance of this Privacy Notice is not treated as consent to processing necessary for the service.
7. Automated Rules and Quoting
DocumentJet uses automated rules to calculate price, pickup and delivery estimates and may use security rules to detect suspicious quote activity, payment risk and scraping.
We do not use sensitive personal characteristics to personalize pricing.
8. Payment Processing
Payments are processed through Stripe.
Card data entered into Stripe secure payment interfaces is transmitted to Stripe rather than DocumentJet.
DocumentJet retains only information reasonably required to administer the Booking, such as PaymentIntent identifiers, payment status and amount.
9. Address Services
DocumentJet uses Google Maps Platform to suggest and validate addresses. The text you type and the place you select are sent from our servers to Google; your browser does not connect to Google for this.
10. Cloudflare / Website Security and Analytics
DocumentJet uses Cloudflare for website delivery, security and bot protection. Security systems may process network information such as IP address where necessary.
On the contact form and before the payment page, DocumentJet uses Cloudflare Turnstile to check that a request comes from a person. Turnstile evaluates browser and device signals for this purpose only and does not set advertising cookies.
DocumentJet may use Cloudflare Web Analytics to measure aggregate page views and page performance. It does not use cookies or local storage, does not fingerprint visitors and does not track individuals across websites. The legal basis is our legitimate interest in operating and improving the website.
DocumentJet does not use advertising cookies or cross-site behavioral analytics.
11. Cookies and Similar Technologies
DocumentJet uses only technologies that are strictly necessary to provide the website and the service you request. For that reason we do not show a cookie consent banner.
- Session and security cookies (DocumentJet): keep your quote and booking session, protect forms against cross-site request forgery and enforce rate limits. They expire when the session ends or shortly after.
- Language cookie (DocumentJet): remembers the language you chose, for up to one year.
- Payment cookies (Stripe): on the payment pages only, Stripe may set cookies to process the payment securely and prevent fraud.
- Security cookies (Cloudflare): Cloudflare may set cookies to distinguish people from bots and to protect the website against attacks.
Address suggestions are requested by our servers; your browser does not connect to Google for them.
These technologies are used on the basis of our contract with you and our legitimate interest in a secure website (Art. 6(1)(b) and (f) GDPR) and, where EEA law on device storage applies, because they are strictly necessary for a service you explicitly requested.
If optional analytics or marketing technologies are introduced in the future, this Notice will be updated and they will only be loaded after you have given any consent required by law.
12. Internal Conversion Analytics
DocumentJet may record server-side events such as quote requested, booking started, email verified, payment authorized, shipment confirmed, revision requested, payment captured, pickup completed and delivery completed.
These events do not contain names, email addresses, phone numbers, passport data, exact street addresses or free-text handover instructions.
How visitors find us. On the first page you open in a browsing session, our servers note where the visit came from: the domain of the referring website (for example a search engine), the page you arrived on, any campaign tags in the link (such as utm_source), the language of the page, your country as reported by Cloudflare and whether you use a phone, tablet or computer. This is kept in your session, which ends when you close the browser, attached to the events above and, if you book, stored with your booking request. We do not store your IP address, a visitor identifier or any cookie of our own for this. The events themselves contain no booking number, name or contact details and cannot be linked back to you; we use them only in aggregate, to understand which countries, languages, pages and channels bring customers to DocumentJet. The legal basis is our legitimate interest in understanding and improving our service (Art. 6(1)(f) GDPR).
Google Ads measurement. If you reach DocumentJet by clicking one of our Google ads, Google adds a click identifier (gclid) to the address of our page. We store it with your booking request. When a Booking is paid for, our servers send Google Ads this identifier together with the booking value, currency, time and our booking number, so that we can see which ads lead to bookings. We do not send your name, email address, phone number or address, and our website loads no Google advertising script and sets no advertising cookie for this. The legal basis is our legitimate interest in measuring the effectiveness of our advertising (Art. 6(1)(f) GDPR). You can object at any time by contacting us.
13. Google Workspace Communications
Transactional emails are sent through FLYTRIX Google Workspace infrastructure.
14. Recipients of Personal Information
We may disclose data where reasonably necessary to:
- FLYTRIX Americas LLC personnel;
- FLYTRIX EMEA GmbH/affiliates;
- authorized flight couriers;
- pickup/delivery drivers;
- airlines;
- airports;
- transit hotels where relevant;
- customs/immigration/police/border/security authorities;
- Stripe;
- Google Workspace;
- Google Ads (advertising measurement only, see Section 12);
- address/location providers;
- Cloudflare;
- hosting/IT providers;
- compliance providers;
- accountants/attorneys/advisers;
- insurers; and
- government authorities where required.
15. International Transfers
DocumentJet is international. Personal information may be processed in the U.S., EEA and other countries involved in the Booking or FLYTRIX operations.
Where personal information is transferred from the EEA to the United States or another country without an adequacy decision, we use the Standard Contractual Clauses approved by the European Commission.
16. Sanctions and Compliance Screening
FLYTRIX Americas LLC may screen Customer, payer, Sender, Recipient and relevant organizations against sanctions/restricted-party lists and may retain evidence of screening where reasonably necessary.
17. Retention
- Email verification codes: stored only as a hash, and only until they expire.
- Quotes that do not lead to a Booking, and booking requests that are never paid for: deleted after 90 days.
- Booking, contract and payment records: seven years, or longer where the law requires.
- Legal acceptance records: as long as the Booking record.
- Security and access logs: about 90 days, unless needed to investigate an incident.
- Compliance records: as long as the law requires or is reasonably necessary.
- Anonymous analytics events (Section 12): without time limit, as they contain no personal information.
De-identified aggregate data may be retained longer.
18. Security
We use appropriate technical and organizational measures such as access controls, role permissions, encrypted connections, secure payment components and audit logs. No system can guarantee absolute security.
19. Individual Rights
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, object, receive portable data, withdraw consent where applicable and complain to a regulator.
Requests: help@documentjet.com
Identity verification may be required.
20. California Privacy
Where California law applies, residents may have applicable rights to know/access/correct/delete and related statutory rights.
DocumentJet does not sell personal information.
DocumentJet does not share personal information for cross-context behavioral advertising.
If this changes, we will update this Notice and honor the opt-out signals required by law.
21. No Advertising Profiling
DocumentJet does not use:
- Meta Pixel
- TikTok Pixel
- LinkedIn Insight Tag
- advertising retargeting cookies
- cross-site behavioral advertising cookies
If this changes, we will update this Notice and ask for any consent required by law.
22. Marketing
Transactional Booking communications are not marketing.
If we send marketing in the future, it will be optional, separate from the Booking, and every message will let you unsubscribe.
23. Children
DocumentJet is not intended to be directly booked by persons under 18. Authorized adults may arrange transportation of a minor's documents.
24. Authorities / Legal Requests
Information may be disclosed where required by law/court/government or reasonably necessary to protect safety/security/rights.
25. Changes
The current Privacy version is published with effective date. The version associated with each Booking is recorded in the contract audit trail.
26. Contact
FLYTRIX Americas LLC / DocumentJet
222 N Pacific Coast Hwy, PCT Tower, Floor 10, El Segundo, CA 90245, United States
Email: help@documentjet.com
Telephone: +1 (424) 220-8574
