Accomy UK Ltd, a company incorporated under the laws of England and Wales with company number 16168100, whose registered office is at 86-90 Paul Street, London, Greater London, EC2A 4NE, United Kingdom (“we”, “our” or “us”), together with its subsidiaries, affiliates and/or related companies, operates the Runway business travel platform (“Runway”). Accomy UK Ltd is the controller of the personal data described in this Privacy Policy. We are committed to safeguarding your privacy; the success of our business depends on our ability to maintain the trust of our customers.
This privacy policy (“Privacy Policy”) describes the personal data we collect from users (“Users” or “you”) through our website and web application at runwaytravel.io (marketing) and app.runwaytravel.io (the Runway platform) (or such other web address as may be established, maintained or updated by us from time to time) (the “Site”), and the services we provide through the Site (collectively, the “services”); how that data is used, transferred, disclosed and stored; and the choices available to you.
Runway is currently provided as a web application only. We do not have a mobile application and we do not collect precise location data. If we release a mobile application, or introduce a feature that collects location, this Privacy Policy will apply to it and we will update this section before that collection begins — see sections 1.2(f) and 10.
Any capitalised terms not defined here are defined in our Terms of Use, available on the Site. Please read this Privacy Policy carefully to understand our practices regarding your Personal Data and how we will treat it.
What is personal data? “Personal Data” means any information relating to an identified or identifiable living individual, including your name, postal address, email address and telephone number. Because we are established in the United Kingdom, our processing is governed principally by the UK General Data Protection Regulation and the Data Protection Act 2018 (“UK data protection law”). Where the data protection law of another country also applies to you, we comply with that law in addition.
Why do we need your personal data? We need certain Personal Data for the purposes described below, principally to deliver the services to you and to complete the travel bookings you make.
1. Types of Personal Data we collect
We collect and process Personal Data about you or your devices from the sources described below. Where applicable, we indicate whether and why you must provide us with your Personal Data, and the consequences of failing to do so, at the time the data is collected.
1.1 Personal Data you provide to us
- (a)
- Account information. We collect Personal Data such as your first and last name, work email address, phone number and password when you create an account or are invited to join a Company Account.
- (b)
- Company information. Where you create a Company Account, we collect your company name, your company’s email domain, the settlement currency you select, and the travel policy, approval and role settings you configure.
- (c)
- Booking information. Depending on the booking you make, we collect the name(s) of the traveller(s), email address, phone number, and any travel or accommodation preferences (such as accessibility requirements).
- (d)
- Travel document information. Airlines and other Suppliers require identity details in order to issue tickets and complete reservations. We may therefore collect passport or national identity document number, document type, issuing country, expiry date, nationality, date of birth and gender, for you or for travellers you book on behalf of. This information is collected only where a Supplier requires it, is displayed in masked form in the Site once saved, and is transmitted to the relevant Supplier for the purpose of completing your booking.
- (e)
- Traveller preferences. We collect the preferences you choose to save, such as home airport, cabin class, seat preference, meal preference, preferred hotel brands and airline or hotel loyalty programme membership numbers. Some preferences, in particular meal preferences, may indirectly reveal information about your religion, beliefs or health. You choose whether to provide them; you do not need to save a preference in order to book, and you can remove a saved preference at any time in your profile.
- (f)
- Payments and billing information. To allow you to pay for a booking, we may ask you to provide a postal and billing address, phone number and tax registration number. We do not collect or store your credit or debit card number or other payment credentials. Payments are facilitated by a third-party payment services provider. You provide card details directly to that provider, which operates a secure platform to process payment details, encrypt them and authorise payment. We use payment processors to process all card transactions.
- (g)
- Expense information. Where you use our expense features, we collect the expense records you create and the receipt images or documents you upload, together with any project or cost code, description and amount you enter, and the approval and reimbursement status of each record.
- (h)
- Region and language. We may ask you to select your region and language in order to provide you with the relevant services.
- (i)
- Communications. If you provide us with feedback or contact us by email, we collect your name and email address, and any other content included in your message, in order to reply.
- (j)
- Waitlist and marketing sign-up. If you join a waitlist or sign up to receive emails or information about our services, we collect your email address and any other details you choose to provide. When we send you marketing emails, we may track whether you open them, in order to improve those communications.
- (k)
- Referral participation. If you share a referral link or use one, we collect the referral code used and the details of the account created or booking made through it. See section 1.2(e).
- (l)
- Testimonials, if you give one. If you choose to give us a testimonial or case study about Runway, we may use and publish it. We will obtain your consent before publishing your name, job title, employer or photograph alongside it, and you can withdraw that consent at any time.
- (m)
- Job applications. If you apply for a role with us, whether directly or through a third-party platform, we collect the contact details, employment history and other information you choose to submit. Recruitment data is handled separately from the account and booking data described above, and is kept only for as long as we need it for the recruitment process and any period afterwards that employment law requires.
- (n)
- Other collections. Please do not send or disclose to us any sensitive Personal Data (for example information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometric or genetic characteristics, criminal background, or trade union membership) on or through the services, except where it forms part of the travel document details or traveller preferences described in paragraphs (d) and (e) above.
1.2 Personal Data we collect when you use our services
- (a)
- IP address and device information. Our servers, which may be hosted by third-party service providers, collect data from you including your browser type, operating system, Internet Protocol (“IP”) address, domain name, and a date and time stamp for your visit. We may associate your IP address with your account and your other Personal Data.
- (b)
- Log files. As is true of most websites, we automatically gather certain data and store it in log files. This data includes IP addresses, browser type, internet service provider, referring and exit pages, operating system, date and time stamps, and clickstream data. We use this data to analyse trends, administer the services, understand how the Site is used, and improve the services.
- (c)
- Product analytics. We record events about how the services are used — for example searches performed, pages viewed, bookings started and completed, and approval decisions — so that we can understand and improve the product. These events are linked to your account.
- (d)
-
Cookies. Like many online services, we use cookies to collect data. A cookie is a small text file that allows us to distinguish your browser or device from another user’s. We use cookies to help operate the Site and to manage your experience. Cookies set on our sites, including third-party cookies, may be session or persistent cookies.
Our services use the following types of cookies:
- (i)
- Essential cookies. These cookies are essential to provide the services and to enable you to use their features. Without them, the services you have asked for cannot be provided, and we use them only to provide those services. Our essential cookies cover: keeping you signed in, so you are not required to log in repeatedly; and remembering your cookie preferences, so the cookie banner does not reappear after you have chosen.
- (ii)
- Functional cookies. These cookies allow the services to remember choices you make, such as your language preference and other settings you customise, so that you do not have to re-enter them on every visit.
- (iii)
- Analytics and performance cookies. These cookies collect aggregated information about traffic to our services and how they are used — the number of visitors, the sites that referred them, the pages visited, the time of visit, and whether they have visited before. We may use third-party analytics providers to help analyse this. We use the information we obtain from these providers only to operate and improve the services.
- (iv)
- Marketing cookies. On our public marketing website, we and our marketing partners may set cookies that record how you arrived at the site and which content you viewed, so that we can measure the effectiveness of our marketing and, where you have consented, show you relevant advertising on third-party sites.
If you would like to opt out of cookies set by our site, you can generally do so on a cookie-by-cookie basis through your browser settings. Doing so may limit site operation or functionality. We do not use cookies to retrieve information that was not originally sent in a cookie, and we do not use information transferred through cookies for direct promotional or marketing purposes without your consent.
- (e)
- Referral measurement. Where a Company Account shares a referral link, we record when that link is opened, when an account is created through it, and when a first booking is completed by the referred company. This measurement is linked to the referring Company Account and to the referred account, and is used to operate and measure the referral programme. See the Referral Programme Terms.
- (f)
- Location, if we introduce it. We do not collect precise location today. If we release a mobile application, it may, with your permission, collect your precise location using GPS or nearby wi-fi or Bluetooth signals — for example to show you properties near you. Any such collection would be optional, would require the permission you grant in your device settings, and can be switched off there at any time. We will update this Privacy Policy, and tell you, before any location collection begins.
1.3 Personal Data collected from other sources
- (a)
- Invitation from an Admin. If you are invited to use the services by an Admin of a Company Account, that Admin may provide us with your name and email address in order to send the invitation.
- (b)
- Your employer’s records. A Company Account’s Admin may provide or update information about you in the Company Account, such as your role, approval responsibilities and cost centre or project codes.
- (c)
- Suppliers. We receive booking status, ticket, reservation, cancellation and refund information from airlines, hotels and our travel distribution partners in connection with your bookings.
- (d)
- Social media. If you post or engage with our content on a third-party platform such as LinkedIn, we and other users of that platform may be able to see the information you make available there. Social media cookies may record that you have shared or engaged with our content.
2. Use of your Personal Data
2.1 To provide the services. We collect Personal Data to provide the services to you, enable your use of them, respond to your requests, and serve you better, including to:
- (a)
- create and secure your account and your Company Account;
- (b)
- complete the bookings you make through the services, including transmitting the traveller and travel document details a Supplier requires;
- (c)
- manage pending and Confirmed Bookings, trips and expense records, and enable the features available to account holders;
- (d)
- apply your company’s travel policies and approval configuration to your bookings, and notify Approvers and Admins as required;
- (e)
- identify you as a User in our system;
- (f)
- provide the services you request, including customer support and troubleshooting;
- (g)
- send you a welcome email to verify ownership of the email address provided when your account was created, and send password reset emails you request;
- (h)
- send you administrative emails, such as booking, approval, expense, security, support and maintenance notices;
- (i)
- keep our services safe and secure, including to protect against and prevent fraud and cyber threats, unauthorised transactions, claims and other liabilities, and to maintain the integrity of the services;
- (j)
- operate and measure promotions, referral programmes and any credit we issue;
- (k)
- send you marketing and promotional material that may be relevant to you, where you have chosen to receive it or where we are otherwise permitted to do so;
- (l)
- understand and analyse how you use our services and develop new products, services and features;
- (m)
- meet legal and compliance obligations, including customer due diligence and ongoing monitoring, internal risk management, audit, financial accounting and management reporting, enforcing our legal rights, or as required by applicable laws and regulations or requested by any judicial process or governmental agency;
- (n)
- respond to and process queries, requests, applications, complaints and feedback from you;
- (o)
- any other purpose for which we give specific notice at the time the Personal Data is collected; and
- (p)
- any other incidental business purpose related to or in connection with the above.
2.2 We do not sell your Personal Data.
3. Our legal bases for processing
We process your Personal Data only where we have a valid legal basis under UK data protection law. The bases we rely on are:
- (a)
- Consent. You have consented to the use of your Personal Data — for example, to send you marketing communications or to use non-essential cookies.
- (b)
- Contractual necessity. We need your Personal Data to provide the services to you — for example, to complete bookings, process payments and respond to your requests.
- (c)
- Compliance with a legal obligation. We have a legal obligation to use your Personal Data — for example, to comply with tax and accounting obligations.
- (d)
- Legitimate interests. We or a third party have a legitimate interest in using your Personal Data. Specifically, we have a legitimate interest in using your Personal Data for product development and internal analytics, and to improve the safety, security and performance of our services.
3.1 Special category data. A small number of optional fields can reveal special category data — most obviously a meal preference that indicates a religious observance or a health requirement, or an accessibility requirement recorded against a booking. Where you choose to provide these, we rely on your explicit consent, and we process them only to pass the requirement to the airline, hotel or other Supplier. You do not have to provide them in order to book, and you can remove them at any time in your profile.
3.2 No automated decision-making. We do not make decisions producing legal or similarly significant effects about you by automated means alone. Travel policy checks and approval routing are automated, but the decision to approve or refuse a booking is made by a person at your own organisation.
4. Disclosure of your Personal Data
We may share, process and disclose Personal Data where (i) disclosure is required to perform obligations in the course of, or in connection with, our provision of the services you request, or (ii) to third-party service providers, agents and other organisations we have engaged to perform any of the functions listed above. For example:
- (a)
- Travel Suppliers and distribution partners. We share traveller details, travel document details where required, and booking details with airlines, hotels, property operators and the travel distribution partners through whom we source Travel Products, in order to complete, change or cancel your booking.
- (b)
- Payment services provider. We share the information necessary to authorise, capture, refund and reconcile payment for your booking with our payment services provider. Card details are provided by you directly to that provider.
- (c)
- Other third-party service providers. We may share your Personal Data with providers of hosting and database infrastructure, transactional email delivery, analytics, customer relationship management, and internal team notification tooling, in order to provide the services, conduct quality assurance testing, facilitate account creation, and provide technical support. We share Personal Data with such third parties only in accordance with this Privacy Policy, on a need-to-know basis, and under a written contract that meets the requirements of UK data protection law for processors. The providers we use are named in the Annex to this Privacy Policy.
- (d)
- Your Corporate Customer. If your account is associated with a Company Account, we share your Personal Data with that Corporate Customer for travel management, billing, approval, expense and administrative purposes. Your travel bookings, trips, expense records and policy exceptions are visible to the Admins, and where relevant the Approvers, of that Company Account. Where you were invited by an Admin, your Personal Data may also be shared with that Admin.
- (e)
- Affiliates. We may share some or all of your Personal Data with our subsidiaries, joint ventures, or other companies under common control, in which case we will require them to honour this Privacy Policy.
- (f)
- Corporate restructuring. We may share some or all of your Personal Data in connection with, or during negotiation of, any merger, financing, acquisition or dissolution transaction or proceeding involving the sale, transfer, divestiture or disclosure of all or a portion of our business or assets. In the event of insolvency, bankruptcy or receivership, Personal Data may also be transferred as a business asset. If another company acquires our shares, business or assets, that company will hold the Personal Data collected by us and will assume the rights and obligations regarding your Personal Data described in this Privacy Policy.
- (g)
- Professional advisers. We may share some or all of your Personal Data with our legal counsel (for example, to protect or defend our rights or property or those of users of the services), accountants, auditors and other professional advisers, on a need-to-know basis.
- (h)
- Regulatory authorities. We may share some or all of your Personal Data as required by law or by any applicable legal requirement (including for the prevention of fraudulent, illegal or unlawful transactions, claims or liabilities) with governmental, regulatory and law enforcement agencies, and in compliance with any judicial process or assistance rendered for any legal or regulatory investigation.
- (i)
- With your consent. We may also disclose Personal Data from or about you or your devices with your permission.
5. International transfers
Our services, and the third-party providers we use, operate across more than one country. Your Personal Data may therefore be stored and processed outside the United Kingdom, including in [the United States, the European Economic Area, Singapore, Hong Kong and mainland China — to be confirmed against the Annex before publication].
Where we transfer Personal Data out of the United Kingdom — whether to our subsidiaries, group companies, business partners, affiliates, third-party service providers or data storage facilities — we do so only where one of the following applies: the destination is covered by UK adequacy regulations; the transfer is made under the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses; or another safeguard or exception permitted by UK data protection law applies. You may request a copy of the safeguard we rely on for a particular transfer by contacting us.
Bookings inherently involve international transfer: to complete a booking we must send traveller details to the airline, hotel or distribution partner concerned, which may be located in the destination country.
6. Retention
We will cease to retain Personal Data, or remove the means by which the Personal Data can be associated with you, as soon as it is reasonable to assume that the purpose for which that Personal Data was collected is no longer being served by retention and retention is no longer necessary for legal or business purposes.
Booking, invoice, payment and expense records are retained for [six years after the end of the financial year to which they relate, to meet UK company and tax record-keeping requirements — period to be confirmed]. Travel document details are retained only for as long as they are needed to complete and support the bookings for which they were provided, or until you delete them from your profile, whichever is earlier.
7. Your rights
Under UK data protection law you have the following rights, which apply in the circumstances the law provides for:
- (a)
- Access. Obtain confirmation that we process your Personal Data, and a copy of it. Much of it is visible in your account.
- (b)
- Rectification. Have inaccurate Personal Data corrected and incomplete Personal Data completed.
- (c)
- Erasure. Ask us to delete your Personal Data where there is no continuing lawful reason to keep it.
- (d)
- Restriction. Ask us to limit how we use your Personal Data — for example while we investigate a claim that it is inaccurate.
- (e)
- Portability. Receive the Personal Data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller.
- (f)
- Objection. Object to processing carried out on the basis of our legitimate interests. You may object to direct marketing at any time, and we will stop.
- (g)
- Withdraw consent. Where we rely on your consent, withdraw it at any time. We will apply your preference going forward; withdrawal does not affect the lawfulness of processing carried out before it.
- (h)
- Complain. Lodge a complaint with the Information Commissioner’s Office (ico.org.uk, helpline 0303 123 1113), or with the supervisory authority in your country of residence or place of work.
Despite your marketing preferences, we may still send you service-related communications, including booking notices and notices of updates to our Terms of Use or Privacy Policy.
Where your account belongs to a Company Account, some records — bookings made on behalf of your employer, and expense records — are also your employer’s business records, and we may need to keep them even where you ask us to delete your account. Where your employer determines how those records are used, your employer is a controller of them in its own right and you may also exercise your rights against your employer.
To exercise any right, please contact us at legal@accomy.com. In your request, please make clear (i) what Personal Data is concerned and (ii) which right you wish to exercise.
We respond within one month of receiving your request. Where a request is complex, or where you have made several, we may extend that period by up to two further months and will tell you within the first month if we do. Exercising your rights is free of charge. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive, and we will explain our reasons if that happens. For your protection, we may need to verify your identity before acting.
If we fall short of your expectations in processing your Personal Data, or you wish to raise a concern or complaint about our privacy practices, please tell us — it gives us the opportunity to put things right.
8. Security
We are committed to protecting the security of your Personal Data. We use a range of industry-standard security technologies and procedures to help protect your Personal Data from unauthorised access, use or disclosure. Access to Company Account data is restricted to the Users of that Company Account and to authorised personnel who need it to operate and support the services.
We require you to enter a password to access your account. Please do not disclose your password to anyone. No method of transmission over the internet, or method of electronic storage, is completely secure; while we use reasonable efforts to protect your Personal Data, we cannot guarantee its security.
If we become aware of a data breach affecting your Personal Data, we will notify you and the relevant authorities where required by applicable law.
9. Children
Our services are intended for business users aged 18 and over. We do not knowingly collect Personal Data directly from children. Where you book travel for a child as a traveller, you must be authorised to provide that child’s details, and we process them only to complete the booking.
10. Effect of, and updates to, this Privacy Policy
This Privacy Policy applies in conjunction with any other notice or contractual clause that applies to our collection, use and disclosure of your Personal Data. We amend it from time to time, and changes apply from the time they are posted on the Site. This Privacy Policy is written to cover the services as they are today and as they develop: where we add a feature, a channel or a category of travel that involves personal data we do not already describe here, we will update this Privacy Policy before that processing starts. Where a change is material, we will tell you before it takes effect, and where we wish to use your Personal Data for a new purpose that is not compatible with the purpose it was collected for, we will give you notice of that purpose and, where the law requires it, obtain your consent.
11. Governing law
This Privacy Policy is drafted in accordance with UK data protection law and is governed by the law of England and Wales. Where the data protection law of another country also applies to our processing of your Personal Data, nothing in this Privacy Policy limits the rights you have under that law.
12. Contact
If you have any question or concern about this Privacy Policy or our data collection or processing practices, if you wish to exercise a right, or if you want to report a security concern, please contact us at legal@accomy.com.
- Controller
- Accomy UK Ltd
- Registered in
- England and Wales
- Company number
- 16168100
- Registered office
- 86-90 Paul Street, London, Greater London, EC2A 4NE, United Kingdom
- Email
- legal@accomy.com
- Data protection enquiries
- legal@accomy.com
You can also complain to the Information Commissioner’s Office at ico.org.uk, though we would like the chance to address your concern first.
13. Third-party websites
Our Site, and our communications with you, may contain links to other websites. This Privacy Policy does not cover any external third-party website that may be reached through those links. We are not responsible for the privacy practices of those websites, and we advise you to read the privacy statement of each website you visit that collects Personal Data.
Annex — Service providers we use
Current as at the effective date of this Privacy Policy. We update this list when a provider changes.
To be completed before publication. Processing locations marked for confirmation are a factual question, not a legal one: each is visible in that provider’s own console or contract. The two that matter most are Fusion Connect Group and Lark, because neither mainland China nor Hong Kong is covered by a UK adequacy decision — those transfers need an International Data Transfer Agreement and a transfer risk assessment before the policy is published.
ProviderWhat it does for usData involvedWhere it processes
- Fusion Connect Group
- What it does for us: Flight and hotel distribution — the partner through whom we source and book Travel Products. Data involved: Traveller names, travel document details where the airline requires them, itinerary and booking details. Where it processes: [Hong Kong / mainland China — confirm]
- Airwallex
- What it does for us: Payment processing. Data involved: Billing details and payment status. Card numbers go directly to Airwallex and are never held by us. Where it processes: [confirm which Airwallex entity contracts: UK, Hong Kong or Singapore]
- Supabase
- What it does for us: Application database, file storage and authentication. Data involved: Account details, bookings, trips, expense records, uploaded receipts, travel document details. Where it processes: [confirm project region in the Supabase dashboard]
- Vercel
- What it does for us: Website and application hosting. Data involved: Request logs, including IP address. Where it processes: [United States (iad1) unless a region is configured — confirm]
- Resend
- What it does for us: Transactional email delivery — confirmations, approvals, password resets. Data involved: Recipient email address and message content. Passport numbers are never included in any email. Where it processes: United States (us-east-1)
- Upstash (QStash)
- What it does for us: Queued and retried delivery of transactional email. Data involved: The same message payloads, held briefly in transit. Where it processes: [confirm region in the Upstash console]
- HubSpot
- What it does for us: Marketing and waitlist contact management. Data involved: Email address and marketing contact details. Where it processes: [United States or EU, depending on the account — confirm]
- Lark
- What it does for us: Internal team notifications about waitlist sign-ups and operational events. Data involved: Limited operational details. Where it processes: [Singapore or mainland China, depending on the tenant — confirm]
- Contentful
- What it does for us: Content management for the public blog. Data involved: No account data. Where it processes: [United States or EU — confirm]
- OpenStreetMap
- What it does for us: Map tiles on the stays map. Data involved: Map tile requests are made by your browser directly to OpenStreetMap, which receives your IP address. Where it processes: United Kingdom / EU