Legal

Privacy Policy

Last updated September 9, 2026

Watching award seats for you needs your email address, the alerts you set up, and a way to bill you. It does not need your program login, your password, or your card number, and we hold none of them. This is the whole list.

1Who we are

MilesZone is the miles.zone website and service, operated by GEREZ TECH LABS, a company registered in the United Arab Emirates. We decide what happens to the data described on this page. Questions about any of it: hello@miles.zone.

2What we never collect

The shortest list first, because it is the one that matters.

  • Your mileage program logins. We never ask for them and we never will. Everything we show comes from award seats that are publicly visible.
  • Passwords. MilesZone has none. There is nothing here to reuse, leak, or steal.
  • Card numbers. Card details are entered with our payment processor. We receive a reference to the payment method plus the brand and the last four digits. The number never crosses our boundary.
  • Traveller details. No frequent-flyer numbers, no passport or identity documents, no date of birth, no postal address. Booking happens on the airline or program site, and what you give them there is between you and them.

3What we collect

  • Your email address. That is the whole of your account: an address, when the account was created, and when you last signed in.
  • Sign-in records. When you request a sign-in link we store a hashed version of the token, the address it was sent to, when it expires, whether it has been used, and the IP address that asked for it, which we use to stop abuse. If you sign in with Google we request the scopes openid email profile and nothing more, and we take your email address from the identity token Google signs. We never see your Google password.
  • Your session. A hashed session token, when it was created, when it expires, when it was last used, and the browser user-agent string and IP address it started from.
  • The alerts you create. The name you gave it, origin and destination, cabins, the programs and airlines you want, your date window, the minimum number of seats, your maximum miles and maximum fees, whether you want non-stop only, how often you want to hear from us, and whether the alert is running or paused.
  • What your alerts find. Every match and near miss we record for you: the program, cabin, airline, flight number, miles, fees, seats left, stops, departure date and time, the booking link, when we saw it, when we re-checked it, and how long it stayed available.
  • The emails we sent you. Subject, which of your finds the message carried, when it went out, whether the provider accepted it, its message identifier, and the error if it failed.
  • The weekly email list. If you sign up we keep your address, when you asked and when you confirmed, the IP address, browser and page you did it from, and the wording of the form you saw, and an address that is never confirmed is deleted after 30 days. You can leave from the one-click link in any issue or from your account page, and we keep a note that you left so you are never added back by mistake.
  • Your subscription. Plan, status, when a trial ends, when the current period ends, whether you have asked to cancel, any discount and how long it runs, and the payment-method reference, card brand, and last four digits described above.
  • Why you cancelled. If you cancel we record the reason you pick and, if you write one, the free-text note you type in, stored as you wrote it. We also record which offer we showed you to keep you, whether you accepted it, and how long you had been subscribed.
  • Searches. Searching needs no account and we do not attach searches to one. Where product analytics are switched on they record that a search happened and the route it was for; see cookies and analytics below.

4Cookies and analytics

MilesZone sets four cookies, and none of them belongs to an advertising network.

  • mz_session keeps you signed in. It is strictly necessary: without it there is no account.
  • mz_google_state protects the Google sign-in round trip against forgery. It lasts ten minutes.
  • mz_attr and mz_attr_first hold the ad click identifier and UTM tags a visit arrived with, so we can tell which advertising brings people who stay. They last 90 and 180 days.

MilesZone is built to support Google Tag Manager, PostHog product analytics, and Google Ads conversion tracking. None of them is configured today, so no analytics or advertising data leaves the site. If we switch one on, this section is where we will say so. When Google Ads conversion tracking is enabled, your email address is passed to the Google tag so that a signup can be matched to the advertisement that led to it. That is the one place where an identifier of yours would reach an advertising platform, and we will name it here before it does.

5How we use your information

  • Sign you in and keep your session alive.
  • Run your alerts: check the routes you asked for, re-check the seat before the email leaves, and send it to you.
  • Rate-limit sign-in requests, and detect and investigate abuse, fraud, and scraping.
  • Take payment, run the trial, and manage your subscription.
  • Answer you when you write to us.
  • Understand what people search for and where signups come from, so we know what to build and what to advertise.
  • Meet our legal and accounting obligations.

We do not sell your personal information, and we do not use your alerts or your searches to target you with third-party advertising.

6Service providers we rely on

We share the minimum each provider needs to do its job:

  • Email: Resend, which sends your sign-in links and your alert emails. It receives the address and the message.
  • Sign-in: Google, if you choose to sign in with Google.
  • Payments: Stripe. You enter your card with Stripe; we keep a reference, the brand, and the last four digits.
  • Hosting and database: our infrastructure providers, who store the data described above on our behalf.
  • Analytics: Google Tag Manager, PostHog, and Google Ads are supported and not currently configured. See cookies and analytics.

These providers act as our processors: they handle your data to operate MilesZone, under their own business terms, and not for their own purposes. We do not sell your data.

7How we share information

Beyond the providers above, we disclose information only to comply with law, regulation, or valid legal process; to enforce our Terms of Service or protect the rights, safety, and security of our users, the public, or MilesZone; and in connection with a merger, acquisition, or sale of assets, in which case we will tell you. Airlines and programs never receive your data from us. When you follow a booking link you leave MilesZone and deal with them directly.

8How long we keep it

Sign-in tokens expire after 15 minutes and are deleted 24 hours after that. Expired and revoked sessions are deleted on the same schedule.

Your account, your alerts, and the finds and emails attached to them are kept while your account is open, because that history is what your alert pages show you. Delete an alert and the events and email records attached to it go with it. Close your account and we delete or de-identify your personal data within 30 days, except records we are required to keep for legal or accounting reasons.

9Security

Sign-in tokens and session tokens are hashed before they reach the database and compared in constant time, so we never hold a copy we could read or replay. Session cookies are HTTP-only, same-site, and secure in production. Sign-in requests are rate-limited per email address and per IP address. Traffic runs over HTTPS. No system is perfectly secure, so we cannot promise absolute safety, but we will notify you and the relevant regulator about an incident where we are required to.

10Your choices and rights

Depending on where you live you may have the right to access, correct, export, or delete your personal data, to object to or restrict some processing, and to withdraw consent. Users in the EU and UK have these rights under the GDPR, California residents under the CCPA and CPRA, and users in the UAE under the Personal Data Protection Law. Write to hello@miles.zone and we will act on it.

You can also act directly, without asking us:

  • Pause or delete any alert, from your account or from the links in any alert email.
  • Unsubscribe from an alert in one click from the email itself.
  • Change how often we email you.
  • Cancel your subscription from your account settings.
  • Close your account, which takes the data with it.

Searching stays free and works without an account, so you can use it and leave nothing.

11International data transfers

We and our providers may process your data in countries other than your own, including in the United States and the European Union. Where the law requires it, we rely on approved safeguards such as Standard Contractual Clauses for those transfers.

12Children

MilesZone is for adults and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has given us data, write to us and we will delete it.

13Changes to this policy

We may update this policy. When a change is material we will update the date at the top of this page and, where it matters, tell you. Continuing to use MilesZone after an update means you accept the revised policy.

14Contact

Questions or requests about your data: hello@miles.zone. GEREZ TECH LABS, United Arab Emirates.

Weekly email

This week's best award seats, in one email.

The business and first class seats that opened this week, and which program books each one for the lowest fees.

One email a week. You confirm it from your inbox first, and every issue unsubscribes in one click.