Private document delivery
Authenticated uploads are stored in a private document bucket. The application checks document ownership before issuing time-limited access; it does not publish a permanent storage URL.
Security and privacy
Baggage claims can include receipts, travel records, photos, and identity documents. These are the controls the product currently uses—and the limits we do not hide behind a security badge.
Authenticated uploads are stored in a private document bucket. The application checks document ownership before issuing time-limited access; it does not publish a permanent storage URL.
Claim and document records use account ownership checks and database row-level security. Fulfillment access is a separate server-controlled permission.
Stripe collects card and wallet details on its hosted checkout. My Bag Claim records payment status and identifiers, not complete card numbers.
Product events use an allowlisted context and exclude passenger names, emails, booking references, baggage tags, flight numbers, and uploaded files.
Email support@mybagclaim.com. We use that monitored address for customer support, privacy requests, and responsible security reports.