Privacy Policy
Abobaker Mohammadi, trading as abobakerbuilds (“Faro”, “we”) runs the Faro iPhone app and website. Faro helps you find flights and asks our staff to buy the ticket for you. To do that we handle personal data, including passport photos. This page says what we collect, why, who else sees it, how long we keep it and what you can do.
What we collect
- Account: your phone number or email, your name, and your sign-in history.
- Travellers you save: name, date of birth, gender, nationality, passport or ID number and expiry date. Document numbers are encrypted before storage.
- Passport photos: a full photo of the passport page for each traveller on a booking request. Photos are encrypted before storage and opened only by the staff member handling your booking.
- Bookings and tickets: the flights you request, contact details, quotes, ticket PDFs and messages about your booking.
- Wallet: deposits, payments, refunds and withdrawals, and the payout details you give us. We keep a permanent record of money movements.
- Identity checks: for larger amounts, or if you forget your wallet PIN, we may ask for a photo of your ID and a new selfie. Our staff compare them with your account. We do not run automated face matching and we do not build a biometric template.
- Device: a push-notification token so we can alert you, a random identifier made when you install the app (used only to limit abuse; stored as a hash and cleared within a day), and basic request logs (IP address, time) kept by our hosting provider.
- Searches: the airports, dates, number of travellers and cabin you search. Searches are not linked to your identity at the search provider.
What stays on your phone
Your four-digit wallet PIN is stored only on your phone, as a salted hash in the iOS Keychain. Face ID is handled by iOS: Faro never receives your face data. We read nothing from your photo library except the images you choose.
Why we use it, and our legal basis
- To search flights, price and buy your tickets, run your wallet and give you support: this is needed to provide the service you ask for.
- To prevent fraud and money laundering and to check that the person using a wallet is its owner: our legitimate interest and legal duties.
- To keep financial and accounting records: legal duty.
- To send sign-in codes, booking updates and tickets: part of the service. We do not send marketing.
Where the law of your country requires your consent, for example for passport and ID images, we ask for it in the app before you upload, and you can withdraw it by deleting your account.
Who else receives data
- Cloudflare hosts our servers, database and logs. Our database is in Western Europe.
- Resend delivers our emails (sign-in codes and tickets).
- Apple delivers push notifications and distributes the app.
- SerpApi supplies flight prices. We send only airports, dates, traveller counts and cabin, never your name or documents.
- Ticket sellers and airlines. To buy your ticket our staff give the seller or airline the traveller names, dates of birth, passport details and contact details that the booking needs. They then handle that data under their own policies.
- Authorities where the law requires it.
We do not sell your data, show ads or use analytics or tracking tools. Staff accounts are individual, restricted by role and recorded in an audit log.
International transfers
Faro is operated from Türkiye. Your data is processed on servers in Europe and may be sent to ticket sellers and airlines in other countries. By using Faro for a booking you accept that this transfer is necessary to buy your ticket.
How long we keep it
- Passport photos, and ID and selfie images used for PIN recovery, are deleted automatically 90 days after the booking is closed (or 90 days after upload if never used), and immediately when you delete your account.
- Money records, bookings and the audit log are kept for as long as accounting, tax, fraud-prevention and legal rules require, even after your account is deleted. After deletion they no longer show your name or contact details.
- Identity-check records for deposits and withdrawals are kept while your account is open and as long as those rules require afterwards.
- Sign-in codes, search results and sessions expire within days.
Your rights
You can ask to see, correct or delete your data, to restrict or object to how we use it, and to withdraw consent. You can delete your account in the app (Account, then Delete account) once your wallet is empty and no booking is open. Otherwise write to faro@abobakerbuilds.com and we will reply within 30 days. You may also complain to the data-protection authority in your country.
Security
Connections are encrypted. Passport images and document numbers are encrypted at rest. Access is limited by role and logged. No system is perfectly secure. If a breach puts your rights at risk we will tell you and the authorities as the law requires.
Children
Faro accounts are for adults aged 18 or over. A parent or guardian may add a child as a traveller to a booking.
Changes
If we make a material change we will update this page and its date, and tell you in the app before it takes effect.
Contact
Abobaker Mohammadi, trading as abobakerbuilds
faro@abobakerbuilds.com