Security and privacy

What happens to your claim documents

Baggage claims can include receipts, travel records, photos, and identity documents. These are the controls the product currently uses—and the limits we do not hide behind a security badge.

Controls in the product

Private document delivery

Authenticated uploads are stored in a private document bucket. The application checks document ownership before issuing time-limited access; it does not publish a permanent storage URL.

Account-scoped claim records

Claim and document records use account ownership checks and database row-level security. Fulfillment access is a separate server-controlled permission.

Payments stay with Stripe

Stripe collects card and wallet details on its hosted checkout. My Bag Claim records payment status and identifiers, not complete card numbers.

Restricted analytics

Product events use an allowlisted context and exclude passenger names, emails, booking references, baggage tags, flight numbers, and uploaded files.

Important boundaries

  • No online service can promise that a breach will never occur.
  • My Bag Claim does not claim an independent SOC 2 or ISO 27001 certification.
  • A photo selected for automatic field extraction is sent to Google's Gemini service for that request.
  • Airlines and other service providers apply their own privacy and retention practices after data is sent to them.

Questions, deletion, or a security report

Email support@mybagclaim.com. We use that monitored address for customer support, privacy requests, and responsible security reports.