Booking a flight reservation online means handing a stranger some of your most personal details, and it's right to ask what happens to them. This guide does three things. It sets out what a reservation genuinely needs, so you can spot a seller asking for too much. It reports what our own privacy policy says, in its own terms, without adding promises it doesn't make. And it explains the rights that data protection law gives you, using the text of India's Digital Personal Data Protection Act, 2023 and official EU and UK guidance on the GDPR. Nothing here is legal advice; it's a practical guide for travellers.
What a reservation needs, at a glance
| Detail | Needed for a reservation? | Why |
|---|---|---|
| Each traveller's name exactly as in the passport | Yes | The airline record is issued in this name; consulates compare it with your passport. |
| Route and travel dates | Yes | That is what the reservation shows. |
| Email address and phone number | Yes | To deliver the PDF and contact you about the order. |
| Nationality and date of birth | Asked on our form | Our booking form requests both for each passenger. |
| Passport photo | No, optional | Only an aid to fill in names; you can type them instead. |
| Bank statements, visa forms, Aadhaar, PAN, photographs | No | None of these is needed to create a flight reservation. |
| Card number, OTP, UPI PIN | Never to the seller | Card and bank details go into the payment gateway's checkout, not the booking form. |
What personal data does a flight reservation actually need?
Very little. A reservation is a record in an airline's system showing who is booked, on which flights, on which dates. To build it, a seller needs each traveller's name as written in the passport, the route and the dates. To deliver it, they need a way to reach you, usually an email address and a phone number.
Our booking form asks for each passenger's title, first and last name, nationality and date of birth, plus the route, dates, an email address and a phone or WhatsApp number. There is an optional notes field for things like a preferred airline. That's it. It does not ask for your passport number, your address, your bank statements or your visa application.
Anything beyond that list deserves a question. If a seller insists on a full scan of every passport page, your Aadhaar card or a copy of your bank statement "for verification", ask what the reservation needs it for. A clear answer is fine. A vague one is a reason to go elsewhere.
What about uploading a passport photo?
Our booking page offers it as a shortcut to fill in names. In the page's own words, the name, date of birth and nationality are read on your device, and "The image is not uploaded or stored — only the recognised text is checked to fill the form." You don't have to use it. Typing the names yourself gives the same result. Either way, check every letter against the passport, because the reservation is issued exactly as entered.

What does our privacy policy say about your data?
Here is a faithful summary of our privacy policy (last updated 20 November 2025). We have not added anything to it.[1]
- What it collects. Details you give through the booking form or on WhatsApp that are needed to process a flight itinerary: name, email address, phone number, origin and destination cities, and travel dates. It also lists usage data (such as IP address, browser type, pages visited and visit times) and cookies.
- Why. To provide the service you requested, communicate about your booking and support, keep the site secure and working, run internal analytics, and show personalised advertising.
- Cookies and advertising. The policy says the site uses Google Ads for advertising and remarketing and Google Analytics to analyse usage. You can opt out of personalised ads through Google's Ads Settings, or set your browser to refuse cookies.
- Sharing. With service providers that monitor and analyse use of the site, such as Google Analytics; in a business transfer such as a merger or sale; and where disclosure is believed necessary to comply with the law, protect rights or safety, or investigate wrongdoing.
- Security. The policy says commercially acceptable means are used to protect personal data, and is frank that no internet transmission or storage method is completely secure, so absolute security can't be guaranteed.
- Third-party sites. Links such as WhatsApp lead to services with their own privacy policies.
- Contact. Questions go to support@dummyticketprice.com or WhatsApp +91 9986491066.
Just as important is what the policy does not cover. It does not state how long booking details are kept. It does not separately mention the nationality and date of birth fields, or the passport-photo shortcut. If you want an answer on any of those points, or want your details deleted after your trip, email us and ask. That's a reasonable request, and the law described below gives you a basis for making it.
Payments are a separate matter. Card and bank details are entered on the Razorpay checkout, not our form. Razorpay's own security practices, and how to pay safely, are covered in our payment safety guide.
Book with only the details a reservation needs
Names, route, dates and contact details. Live PNR, emailed in about 10 minutes.
What rights does India's DPDP Act give you?
The Digital Personal Data Protection Act, 2023 calls you the "Data Principal" and the business deciding how your data is used the "Data Fiduciary".[2] The parts that matter most to a traveller are these:
| Right or duty | What the Act says | Section |
|---|---|---|
| Notice | A request for consent must come with a notice describing the personal data, the purpose, and how to exercise your rights and complain. | 5[2] |
| Limited consent | Consent must be free, specific, informed, unconditional and unambiguous, and limited to the data necessary for the stated purpose. | 6(1)[2] |
| Withdrawal | You may withdraw consent at any time, as easily as you gave it. | 6(4)[2] |
| Security and breach notice | The fiduciary must take reasonable security safeguards and tell the Board and each affected person about a breach. | 8(5), 8(6)[2] |
| Erasure when finished | Data must be erased when consent is withdrawn or the purpose is no longer served, unless a law requires keeping it. | 8(7)[2] |
| Access | You can ask for a summary of your data being processed and who it has been shared with. | 11[2] |
| Correction and erasure | You can ask for correction, completion, updating and erasure. | 12[2] |
| Grievance redressal | The fiduciary must offer a readily available way to resolve complaints; you must use it before going to the Data Protection Board. | 13[2] |
| Your duties | Don't impersonate another person, and give only verifiably authentic information when asking for corrections. | 15[2] |
Section 6 is the one to remember when a seller asks for too much. The Act's own example is a telemedicine app that asks for access to a user's phone contacts; because the contacts aren't needed for the service, the consent is treated as limited to what the service needs.[2] The same logic applies to a flight reservation and your bank statement.
Notice also section 15. The Act puts duties on you as well. Giving someone else's details, or false ones, isn't just a visa problem; the Act expressly says a Data Principal must not impersonate another person.[2]
Booking for children
Family reservations include children's names and dates of birth. The Act treats anyone under 18 as a child and gives a parent or lawful guardian the role of Data Principal for them.[2] Section 9 requires a fiduciary to obtain verifiable consent from the parent before processing a child's personal data, and bars tracking, behavioural monitoring and targeted advertising directed at children.[2] In practice, a parent fills in the family booking, and that parent is the person to make any access or deletion request for the children's details afterwards.
If you're in the EU or UK: what does the GDPR give you?
The European Commission's guide for individuals lists the GDPR rights: to be informed, to access your data, to have it corrected, to have it erased when it is no longer needed or is processed unlawfully, to restrict processing, and to data portability, among others.[3] It says organisations should respond to requests without undue delay and at the latest within one month, and that if you think your rights have been breached you can complain to your national data protection authority, which should tell you about progress or the outcome within three months.[3] The Commission also notes these rights apply when you buy from non-EU companies operating in the EU.[3]
In the UK, the Information Commissioner's Office explains that anyone can make a subject access request, that you don't need a solicitor, and that organisations usually have one month to respond.[4]
Whether a particular law applies to a particular business depends on where it operates and whom it serves, and we won't pretend to settle that here. In practice, a clear, polite written request is the place to start under any of these laws.
How to protect your passport details when booking
Most of the risk sits in how you share documents, not in the reservation itself. The comparison below reflects our practical view.
| How you share details | What travels | Risk | Our advice |
|---|---|---|---|
| Typing names into a seller's HTTPS booking form | Only the fields you fill in | Lowest | Best option. Check the address and the published privacy policy first. |
| Sending passport scans by chat | The full page: number, photo, signature, dates | Higher; copies sit in chat histories and backups | Avoid unless genuinely needed, and delete the chat afterwards. |
| Emailing scans to an unknown address | Same, plus whatever else is attached | Higher; hard to recall | Don't. Use the seller's form instead. |
| Uploading full visa packs "for checking" | Bank statements, payslips, employer letters | Highest | Never needed for a reservation. Refuse. |
- Share the minimum. Names, route, dates and contact details are enough.
- Type, don't scan, wherever a form allows it.
- Read the privacy policy before paying. Look for what is collected, who it's shared with and how to contact the business.
- Keep your own copy of what you sent and the order reference, so you can ask for it to be deleted later.
- Be wary of "verification" calls. Nobody needs an OTP or PIN to issue a reservation.
- Check the result. Open the booking reference on the airline's site to confirm it's real; see how to verify a reservation.
How to ask a seller what they hold, or to delete it
- Write to the contact in the privacy policy. For us, that's support@dummyticketprice.com.
- Identify the order with your order reference and the email you used. Don't send a fresh passport scan to prove who you are unless asked for something specific.
- Say what you want: a summary of the data held, a correction, or erasure once your trip is over.
- Name the law if it helps, for example sections 11 and 12 of the DPDP Act, or your GDPR rights of access and erasure.
- Keep the reply. If you aren't satisfied, the DPDP Act expects you to use the business's grievance process first; EU residents can go to their data protection authority.[2][3]
Related reading and pricing
We issue reservations with a live booking reference in the names you enter, emailed in about 10 minutes, at ₹699 in India or $9 worldwide per passenger (see the price page for all currencies). A reservation stays valid for up to two weeks, and the airline decides the exact period. It's a reservation, not a paid ticket.
For context on the documents themselves, read flight reservation for visa, requirements by country, the Schengen guide and onward tickets. Hotel reservations follow the same data principles; see hotel bookings. If you're comparing sellers, the provider checklist and our guide to avoiding scams help. Start from the home page for an overview.
Privacy questions travellers ask
Do I need to send my passport copy to get a dummy ticket?
No. A reservation needs each traveller's name exactly as in the passport, plus the route, dates and your contact details. Our form also asks for nationality and date of birth. A passport photo is optional on our booking page and only helps fill in names; you can type everything instead.
Does a reservation need my passport number?
Our booking form doesn't ask for it. The fields are title, first and last name, nationality and date of birth for each passenger, plus route, dates, email and phone. If another seller insists on a passport number for a reservation, it's fair to ask why before you share it.
What does DummyTicketPrice do with my details?
Our privacy policy says booking details are used to provide the itinerary service, to communicate about your booking, to keep the site secure, for internal analytics and for personalised advertising through Google tools. It lists sharing with service providers such as Google Analytics, in business transfers, and where the law requires it.
How long do you keep my booking details?
Our current privacy policy does not state a retention period, and we won't invent one here. If you want your details deleted after your trip, email support@dummyticketprice.com with your order reference and ask. Under India's DPDP Act, a business must erase data once its purpose is served, unless a law requires keeping it.
What rights do I have over my data in India?
The DPDP Act, 2023 gives you rights to a notice, to withdraw consent, to a summary of your data and who it was shared with, to correction and erasure, to grievance redressal, and to nominate someone to act if you die or become incapacitated. You must use the business's grievance process before approaching the Data Protection Board.
I'm in Europe. Can I ask a seller for my data?
The European Commission explains that GDPR rights include access, correction and erasure, and that organisations should respond within one month at the latest. Its guidance says the rights also apply when you buy from non-EU companies operating in the EU. In the UK, the ICO gives organisations one month to answer a subject access request.
Is it safe to send documents on WhatsApp?
Chats are convenient, but copies of what you send stay in histories and backups on both sides. For a reservation, typing names into a booking form is enough. Send scans only when there's a clear need, and delete the conversation afterwards. Never send OTPs, PINs or card details by chat.
Plain truth: a reservation is not a paid ticket, and no seller can promise that a visa will be granted. Share only what the booking needs.
Sources
All sources last checked: October 2026.
- DummyTicketPrice, Privacy Policy. Last updated 20 November 2025
- Ministry of Electronics and Information Technology, Government of India, The Digital Personal Data Protection Act, 2023 (Gazette text, PDF). Sections 2, 5, 6, 8, 11 to 15
- European Commission, Data protection: information for individuals.
- Information Commissioner's Office (UK), Getting copies of your information (subject access request).
Related: flight reservation for visa · dummy ticket price · requirements by country · how to verify a PNR.