Main Privacy Statement

How we protect your personal information across our family of brands.

Effective: September 18, 2026

  1. Revised Main Privacy Statement

    We have updated our Main Privacy Statement to describe our general privacy practices more clearly, including our use of guest personal information; our use of automated and AI (artificial intelligence)-enabled tools; and how we use information across WestJet, WestJet Rewards, and our related brands to support travel, account, operational, and service experiences. We also have a separate WestJet Rewards Privacy Statement for program-specific information about the WestJet Rewards loyalty program. You may contact our Privacy Office with any questions.

  • Our commitment

    Your trust is our baseline

  • At WestJet, we are committed to respecting and safeguarding your privacy. This Main Privacy Statement (“Privacy Statement”) describes how we collect, use and disclose personal information. This Privacy Statement applies to the websites, apps, products, and services to which it is posted or linked, except as noted below.

    This Privacy Statement explains our privacy practices and applies to all collections, uses, or disclosures of personal information. Where consent is required by applicable law, we obtain it separately or through the notices, choices, and settings presented to you when your personal information is collected or used. If you have questions or concerns about any aspect of this Privacy Statement, please contact our Privacy Office.    

    We reserve the right to update or modify this Privacy Statement at any time as required or permitted by applicable law, including by posting an updated version on this website, at which time we will update the effective date of this Privacy Statement to alert you of a change. Each time you use products or services that link or otherwise refer to this Privacy Statement, the version of this Privacy Statement then posted will apply to that use, so you should check this Privacy Statement each time you use such products or services.

On this page

  1. Who is WestJet?

    Who is covered by this Main Privacy Statement and how WestJet companies work together when providing services and managing personal information. 

    About WestJet and our brands
  2. Exercising Your Rights

    Your privacy rights and the options available to access, correct, delete, or manage your personal information.  

    Learn about your privacy rights

This is the Main Privacy Statement for the WestJet Group brands. It covers WestJet and the WestJet website, together with our related travel brands, including Sunwing and Vacation Express, except where one of those brands publishes its own separate statement. WestJet Rewards has a separate WestJet Rewards Privacy Statement that explains program-specific practices.  

We collect information to book and manage your travel, support you, keep our services secure, meet legal requirements, and, with your consent, personalize offers and run the contests and promotions you enter.


Who is WestJet?

For the purposes of this Main Privacy Statement, “WestJet,” “we,” or “us,” means WestJet, an Alberta partnership, WestJet Group Inc., and their controlled affiliates and subsidiaries, including WestJet Encore Ltd., WestJet Loyalty Holding LP and WestJet Loyalty LP. WestJet Group means the broader group of travel brands under common ownership, including Sunwing and Vacation Express.  

This is our Main Privacy Statement that applies across our business. We have separate privacy statements that set out how we process the personal information of (i) employees, which prospective, current and former employees should refer to; (ii) members of WestJet Rewards, who should refer to the WestJet Rewards Privacy Statement for program-specific details; and (iii)  customers of Sunwing or other related brands, who should refer to any separate privacy statement posted by that brand.


Personal Information

Personal information is information about an identifiable individual, including information that can be used to identify or contact you directly or indirectly. It includes identification, contact, travel and interaction information. Anonymized and aggregated information that cannot identify anyone is not personal information.

Information needing extra care. Health and accessibility, financial, and biometric information are more sensitive; we collect them only where necessary and, where the law requires, with express consent.

If you are in the EEA (European Economic Area) or the United Kingdom (UK). European and United Kingdom law defines special categories (health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data, and data about sex life or sexual orientation) that attract additional conditions, and separately restricts criminal-conviction information.

We collect, use and disclose personal information with your knowledge and consent, express or implied, unless the law permits or requires us to act without it. When we perform services for you, your consent is implied for uses a reasonable person would expect in the context of the transaction; this is based on what is necessary for us to fulfill our contract with you. Anything not required for us to deliver our services to you is based upon one of the following: 

  • requirements under the law to collect, process, retain and share information; 
  • legitimate interests, such as preventing fraud or protecting our networks; or 
  • consent obtained from you. 

We rely on statutory exceptions to consent, and our legitimate interests as a secondary basis, where it is available and applicable, for service continuity, security, fraud prevention, internal analytics and operational improvement. We ask for your express consent for optional and higher-risk uses. Where we rely on legitimate interests under European or United Kingdom law, you can object at any time; where we rely on legitimate interests for direct marketing, your objection is absolute.  

Where available, you may manage your consent choices and communication preferences through self-service tools, account settings, or other channels we provide. These options may include preferences related to marketing communications, surveys, notifications, recommendations, and other communications or experiences. The choices available to you may change over time as we introduce new services, features, or methods of communicating with you. 

Electronic marketing. We send commercial electronic messages only with the consent that Canada’s Anti-Spam Legislation (CASL) requires - express consent, or implied consent where CASL permits it (for example, where we have an existing business relationship with you) - or as other applicable electronic-communications laws provide, and every message identifies us and lets you unsubscribe. Service messages, such as flight updates or messages that support our services to you, are not commercial electronic messages and do not require consent to send. 

You can withdraw consent at any time, subject to legal and contractual limits, and withdrawing does not affect what we did beforehand. 

Historic information. We use information collected before this Statement took effect in accordance with this Statement, to the extent the uses described here are consistent with the purposes for which the information was originally collected or for which consent was obtained. Where required by applicable law, we will provide notice and obtain consent before using personal information for a materially new purpose. 

What information we collect, and where it comes from

We collect most information directly from you when you book, fly, enrol, contact us, enter a contest or promotion, or use our websites, apps, and digital services. We also receive it from a person booking on your behalf; from travel partners and suppliers; from our group brands; from service providers acting for us; from the financial institution that issues the WestJet-brand credit card where you opt in; and from government authorities. The WestJet Rewards Privacy Statement provides more detail about Rewards-specific collection, partner relationships, points, redemptions, and WestJet-brand credit card participation.

Categories include your name, date of birth, nationality, gender, marital status (where required for certain destinations), contact and payment information; passport, residence and visa information for international travel; health and accessibility information for accommodation; device, usage and, where enabled, location information; contest and promotion entries; and records of your interactions across phone, web and app.

Whether you have to give us this information

  1. Required by law. Identity and travel document information, and advance passenger information for international flights. Without them, we cannot carry you.

  2. Required to make the contract work. Name, contact and payment information. Without them, we cannot complete the booking.

  3. Optional. Marketing preferences, personalization, WestJet Rewards enrolment, contest and promotion entries, and accessibility or dietary requests. You can still fly; we cannot provide the service or offers the information supports. For Rewards-specific enrolment and account-management consequences, see the WestJet Rewards Privacy Statement.

In Canada the basis is knowledge and consent unless a statutory exception applies, and electronic marketing additionally requires the consent that Canada’s Anti-Spam Legislation (CASL) requires, whether express or implied where CASL permits. In the EEA and the UK (United Kingdom) the basis is the one named, and where we rely on legitimate interests the interest is stated.

Purpose

Basis (Canada)

Basis (EEA and UK)

Make and manage your booking

Implied consent for purposes a reasonable person would expect in the context of the transaction

Contract

Contact you about your booking, schedule changes and cancellations; provide consistent service and support across channels and interactions

Consent

Contract

Verify your identity and permit boarding

Statutory exception

Legal obligation

Provide advance passenger and border information to authorities

Statutory exception

Legal obligation

Assess and provide a medical or accessibility accommodation

Express consent

Explicit consent; vital interests in an emergency

Engage service providers for technology, storage and processing

Consent

Legitimate interests: operating and securing the systems that deliver the service

Respond to your inquiries, including through our messaging assistant

Consent

Legitimate interests: answering guest inquiries promptly across channels

Detect, prevent and investigate fraud and unauthorized access; monitor, detect, flag or investigate patterns, risks, issues or unusual activity

Statutory exception: protecting guests and the business against fraud and account takeover

Legitimate interests; legal obligation: protecting guests and the business against fraud and account takeover

Provide connected travel experiences, consistent service, personalized interactions including using AI for personalization, loyalty experiences, account protection, fraud prevention, analytics, and operational improvement using information from our brands, programs, services, and interactions with you

Implied consent for purposes a reasonable person would expect in the context of the transaction; express consent for new uses involving sensitive or biometric information; statutory exception where applicable

Legitimate interests: service continuity, security, fraud prevention, internal analytics and operational improvement; consent where required

Analyze your interactions and generate inferences; personalization, profiling and recommendations: tailor, rank, recommend or offer something based on guest behaviour, preferences or history. For Rewards-specific profiling, personalized offers, points, and redemptions, see the WestJet Rewards Privacy Statement.

Consent

Consent

Send you marketing and personalized offers

Consent; for electronic messages, the consent CASL requires (express, or implied where CASL permits)

Consent

Run contests, sweepstakes and promotions you enter: administer your entry, run the draw or judging, select, verify and contact winners, award and deliver prizes, publish winner information where the contest rules say so, and meet contest-law and record-keeping requirements

Consent (you enter under the contest rules); express consent for related electronic messages; statutory exception for record-keeping the law requires

Contract (the contest terms you accept when you enter); legal obligation for contest-law and record-keeping requirements; consent for related marketing

Use cookies and similar technologies for advertising

Consent

Consent

Respond to lawful requests from authorities; legal and regulatory obligations

Statutory exception

Legal obligation

Make automated decisions and support decisions about you, including automated guest authentication and recommending compensation and claims outcomes for a person to decide

Consent; statutory exception for authentication and security

Contract; legal obligation; legitimate interests: verifying identity, protecting accounts, and handling claims efficiently

Develop, test, monitor, maintain, and improve the technologies, tools, analytics, and automated capabilities used to deliver, support, secure, and improve our services, using appropriate safeguards and controls (e.g., synthetic data, de-identified data) where feasible

Consent; de-identified or synthetic data where feasible

Consent; legitimate interests: developing and assuring the tools that deliver and secure the service; de-identified or synthetic data where feasible

Support WestJet-brand credit card participation, including account linkage, payment-related support, fraud detection, and analysis. For details about credit-card issuer and Rewards partner data sharing, points, and redemptions, see the WestJet Rewards Privacy Statement.

Implied consent for purposes a reasonable person would expect in the context of the transaction; consent; legitimate interests secondarily

Contract; consent; legitimate interests secondarily: service continuity, security, fraud prevention, internal analytics and operational improvement

Support services booked or offered by third parties; supporting contractual obligations with third parties (travel agents, airlines, employers, in-flight services, or family members) requesting services on behalf of a traveler for air travel, car or room rental or other services

Implied consent; statutory exception where applicable

Legitimate interests: operating and delivering contracted service

Where we act as a service provider or processor

We handle personal information in two directions. Most of the time we handle it as your airline, for our own purposes, as this Main Privacy Statement governs. Sometimes we handle it for another organization instead, on its behalf and under contract with it.

When you book or travel with one of our partners, such as a partner airline on a codeshare or interline itinerary, and we carry out or support part of your journey, we may handle your information for that partner, as its service provider, and where European or United Kingdom law applies, as its processor. We are not the organization accountable to you for that information.

Where we act for another organization:

  • that organization, not WestJet, is the party responsible to you for the information it entrusts to us, and its own privacy statement governs how that information is handled;
  • we use the information only to provide the service that organization has asked us for, on its instructions and under contract, and not for our own purposes, unless you have provided it to WestJet independently; and
  • if you ask to see, correct or delete that information, or to exercise another right, we direct you to that organization, or pass your request to it, because it is the one that can act on it.

Who we share information with

We share personal information with medical personnel for an accommodation; the person who made your booking, once identified; travel suppliers and partners; an insurance provider you bought from; credit-card issuers and Rewards partners to support WestJet Rewards and WestJet-brand credit card participation, as described in more detail in the WestJet Rewards Privacy Statement; service providers under contract; our group brands, including Sunwing, Vacation Express and WestJet Vacations, as described in this section; contest co-sponsors, prize suppliers and contest administrators, for a contest or promotion you enter and as its rules describe; government and border authorities, including because a flight crosses United States airspace; law enforcement in a lawful investigation; a successor in a corporate transaction; and organizations in the travel, hospitality and financial services sectors whose offers may interest you, only with your consent and with those organizations identified to you at the time we seek your consent.

Processing outside your country

Your personal information may be processed outside the province or country where you gave it to us, including by service providers and partners, where it may be accessible to local courts, law enforcement and authorities under local law. We use contractual, organizational and technical safeguards appropriate to the transfer, and you can ask us for information about the safeguards that apply.

Where it moves

Why

Mechanism

To service providers and contractors abroad, including the United States and India

Technology, storage, analytics, contact-centre and professional services

Contractual terms requiring comparable protection, access controls, confidentiality obligations, security controls, and vendor oversight

From Quebec, outside the province

Any processing or access

A privacy impact assessment completed before the transfer, a written agreement recording the agreed protection, and an assessment that the information will receive protection equivalent to that provided by Quebec law, where Loi 25 applies

From the EEA and the UK

Group processing, technology and analytics

Adequacy where it applies, including Canada adequacy for PIPEDA-covered recipients; otherwise EU standard contractual clauses, and for the UK the international data transfer agreement or addendum, each with a transfer risk assessment

From the United States to Canada

Guest services, loyalty experiences, personalization, fraud prevention, analytics, and operational support

Contractual terms requiring appropriate protection, access controls, confidentiality obligations, and security controls

Children

We do not direct our services to children, and we do not knowingly collect from a child except in connection with travel arranged by an adult. A parent, guardian or legal representative provides the information, consents, and exercises rights for the child. Where age-based consent rules apply, we follow them: in Canada, the age of majority; in Quebec, consent for a minor under 14 is given by the person having parental authority; in the EEA and the UK, the applicable national age of digital consent (between 13 and 16) applies; and in the United States, we follow the Children’s Online Privacy Protection Act for children under 13.


Automated Decisions & AI

This section applies across the WestJet Group, including WestJet Rewards except where the WestJet Rewards Privacy Statement gives more program-specific detail. It tells you when you are dealing with an AI system, what personal information our automated and AI-enabled tools use, what they decide, and what you can do about it.

Personalization with AI

We may use AI to provide personalization, recommendations, analytics, and connected experience capabilities.

When you are dealing with AI

You will know when you are interacting with an AI system; we tell you at the start of the interaction, unless it is obvious, and a person is available where the assistant cannot help.

Content generated by AI

Where our AI tools generate content publicly, we mark that content, so it is detectable as artificially generated. The European transparency obligations apply from 2 August 2026: the duty to tell you that you are interacting with an AI system, and the duty to mark artificially generated content.

Decisions our automated tools make

We use AI and automation in different ways. In some cases, AI and automation provide recommendations or insights that are reviewed and acted upon by a person. We also use AI and automation to make certain decisions without human involvement where appropriate and permitted by law. Not every use of AI or automation involves an automated decision about you. Where we rely on AI or automation to make decisions that affect individuals, we provide information about those uses and any applicable rights in accordance with legal requirements.

The decision

Information it uses

How it decides

What happens to you

Your options

Guest authentication in the contact centre

The identifiers you provide, your booking and account records, and channel signals

Compares what you provide against our records and scores the match against a confidence threshold

Access to your account and booking is allowed, limited, or refused

Ask for a person to verify you another way, and ask us to review the outcome

Interaction routing, information retrieval, responding to questions

The information you provide with your voice

Uses AI to understand your requests and provide the appropriate information

Your voice is interpreted to allow an automated assistant to respond

Ask for a person to support you

Whether you are owed compensation under relevant regulations for a flight delay, cancellation or denied boarding, and how much

Your booking and itinerary, the flight disruption record and its cause and category, your claim and entitlement rules

An automated tool reviews the disruption against entitlement rules and recommends whether compensation is owed and the amount; a WestJet agent conducts a meaningful review of the recommendation, considering any additional information, and makes the final decision

A person decides your claim, taking the recommendation into account. You are paid the compensation owed, or told why it is declined and on what basis

Ask how the amount was worked out, give us more information, ask a person to reconsider, and use your rights under the complaint process

When we tell you

Where a decision about you is made solely by automated means, we tell you. If you ask, we will explain how automation was used to make the decision. We will also correct any personal information relating to you that is inaccurate.

Asking a person to review a decision

Please submit your request through our privacy request webpage.

What our AI tools cannot do

Our AI tools can be wrong or incomplete. If you need help, a person is available on request.


Websites & Apps

This section explains how we handle personal information specifically when you use our WestJet Group websites, mobile apps, and digital services.

What this section covers

This section covers digital channels: what we collect when you visit, browse, sign in, book, or use a feature on our websites, apps, and digital services; what we collect automatically through your device and through cookies and similar technologies; information that reaches us from third-party content built into our sites; and the choices you have online.  

Information we collect online

We collect online information including but not limited to the following ways: 

  1. Information you give us. When you register, sign in, book, subscribe, enter a form, upload a document, enter a contest or promotion, or contact us through the site or app, we collect what you provide, such as your name, contact details, travel information, payment information, and the contents of your request or entry. 
  2. Information we collect through tools and automation. When you use our sites and apps, we collect technical and usage information such as your device type and settings, browser type, operating system, unique device and app identifiers, your IP address, general location derived from your IP address, and, on mobile where you permit it, more precise location; the pages and screens you view, the searches you run, the links you select, the dates and times of your visits, and how you move through the site; and information from cookies, pixels, and similar technologies. 
  3. Information from third-party content. Some pages include content and services provided by other companies, such as maps, embedded video, and analytics and advertising technologies. Those providers may receive information about your visit directly, as set out below. 

How we use online information

We use online information in several ways to run our sites and apps and keep them secure; to remember your settings and choices; to complete and manage your booking; to understand how our digital services are used so we can improve them; to detect and prevent fraud, unauthorized access, and misuse; to associate your activity so we can support connected travel experiences and consistent service across our brands; and, where you have consented, to personalize content and advertising.

IP address, security, and fraud prevention

We collect and retain your IP address and related device information to identify visitors, to keep our sites and accounts secure, to investigate and prevent unauthorized use, misuse, and payment-card fraud connected with an online booking, and to meet legal and regulatory requirements. We may use and disclose this information for those purposes, including to law enforcement in a lawfully authorized investigation.

Cookies and similar technologies

We use cookies, pixels, and similar technologies to run our digital services, remember your choices, understand how these technologies are used, and, where you consent, to advertise.

What we use and why

Category

What it does

Consent

Strictly necessary

Runs the site, keeps your session, keeps the site secure, and remembers your privacy choices

Not required

Functional

Remembers your preferences, such as language and recent searches

Required outside strictly necessary use

Analytics

Tells us how the site is used so we can improve it

Required

Advertising

Builds a profile of your interests and shows you our advertising on our site and elsewhere, including across devices

Required

What happens if you refuse

Refusing functional cookies means the site will not remember your choices between visits. Refusing analytics does not affect how the site works. Refusing advertising cookies does not reduce the advertising you see; it means the advertising is not based on your interests. Strictly necessary cookies cannot be refused, because without them the site does not work.

Your choices

The banner appears the first time you visit and lets you accept all, reject all non-essential cookies, or choose by category. You can change your choice at any time through the cookie preferences link in the site footer. We honour the Global Privacy Control (a browser-based privacy preference signal) where required by applicable law or where WestJet honours that signal. 

When you sign in

When you sign in or authenticate, information about how you use our websites, apps, and digital services may be associated with records we maintain about you for service continuity, security and fraud prevention, analytics, and, where you consent or the law permits, personalization. See the Personal Information section of this Main Privacy Statement and, for Rewards-specific personalization, the WestJet Rewards Privacy Statement.

Where you are

In the EEA and the United Kingdom, we set cookies that are not strictly necessary only with your consent. In Quebec, technologies that identify, locate or profile you are activated only with your consent, and we tell you how to disable them. In the United States, you can opt out of the sharing of information collected by advertising cookies, and we honour the Global Privacy Control where required by applicable law or where WestJet honours that signal.  

Third-party content and links on our sites

Some features on our sites and apps are provided by other companies. For example, mapping features use third-party map services, some pages embed media or social features, and we use third-party analytics and advertising technologies. The provider may collect information directly from your device under its own privacy terms, which we do not control. Our sites also link to sites we do not operate. We are not responsible for the content or the privacy practices of sites and services we do not control, and we encourage you to read their privacy statements.

Your online account and security

When you create an account, you choose credentials that let you sign in and manage your travel, documents, and preferences. Keep your password unique and confidential and tell us if you think your account has been accessed without your permission. We will not ask for your password or multi-factor authentication code. We protect account and site information with technical and organizational measures including access controls, encryption, firewalls, employee awareness, but no system is completely secure and no transmission over the internet can be guaranteed.

Booking or entering information for someone else

You can use our sites to book or manage travel for other people. If you enter another person’s information, you confirm that you have their authority to do so and to share their information with us, and, for a child or a person who cannot consent, that you are their parent, guardian, or legal representative. We handle information you provide about another person in the same way as your own, under this Main Privacy Statement.

Online forms and special requests

When you enter information into an online form, we use it for the purpose of the form. Some forms ask for information that needs extra care, such as a health, accessibility, or dietary request. 

We collect that information a) where it is necessary for the request you are making, b) where the law requires, or c) with your consent.

Online forms and special requests

When you enter information into an online form, we use it for the purpose of the form. Some forms ask for information that needs extra care, such as a health, accessibility, or dietary request. 

We collect that information a) where it is necessary for the request you are making, b) where the law requires, or c) with your consent.


Contact Centre Recording

This section applies to the contact centres of the WestJet Group. A notice may be delivered at the start of an interaction. 

We record interactions and may create transcripts and summaries of interactions. We analyze interactions, including with automated and AI-enabled tools, to check and improve our service quality, to train our people, and to resolve your request to the best of our ability. We may analyze the tone or sentiment of an interaction based on the words and content of the interaction. The recording, transcript and summary may be maintained in systems we use for contact-centre operations, analytics, quality assurance, and service management. 

We keep the recording, transcript, summary, the reason for your interaction, the outcome, and our service notes, so we can support your service, handle claims and compensation, prevent fraud and protect security, and provide consistent support across our brands. 

We may use service providers to run and support our contact centres. They act as our processors and handle this information only for us and under contract. 

If your interaction involves sensitive information, such as health, accessibility or a claim, tell us. We treat it with additional protection, ask for your express consent where the law requires and offer you a way to give sensitive information that does not involve recording or automated analysis. Sensitive and consent-only categories captured on an interaction are not used for profiling, personalization or AI model development unless the required legal basis, notices, controls and safeguards are in place. 

If you do not want to be recorded, tell the agent. We will handle the recording in accordance with applicable law, retention, security, workplace, and guest protection policies


Data Retention

This section explains how the WestJet Group decides how long to keep personal information, across every channel and section of this Main Privacy Statement.

We do not keep personal information forever. As a general rule, we keep personal information for three years after your last interaction with us, and that period starts again each time you interact with us. Some categories of records are kept for longer where the law or our operations require it, and some information is removed sooner. When a period ends, we review the records and then securely destroy the information or anonymize it.

How our retention schedule works

We use a records retention schedule that assigns retention periods by record category and business purpose. Each category is tied to a standard timeline. Depending on the type of information, a period runs either from a fixed point or from a later event: 

  • a fixed period measured from the date the record is created or captured; or 
  • a fixed period measured from a specific event, such as the end of a program, the closure of an account, the decommissioning of a system, the resolution of a claim or dispute, or the expiry of a contract. 

Our standard timelines are measured in years. Most guest records fall into a shorter timeline of about three years or a longer timeline of about ten years, according to the category the record belongs to. Some records are removed sooner where privacy law, security standards, or technical design require it. We keep payment-card details only for the limited period needed to process and confirm payment. 

General retention principles

We apply the following principles: 

  • We keep personal information only as long as needed for the purposes described in this Main Privacy Statement. 
  • We apply different retention periods to different categories of records. 
  • We may keep information longer where required for law, regulation, safety, security, tax, accounting, fraud prevention, dispute resolution, claims handling, or legal proceedings. 
  • We may delete, de-identify, anonymize, or restrict information sooner where it is no longer needed, or where privacy law, security standards, or consent withdrawal requires it. 
  • We allow for automated destruction of records. At times, records go through a disposition review to confirm whether continued retention is still required. 

Retention of Information

We generally keep your data for three years after your last interaction. The table below summarizes categories of records that may be kept longer outlining the general retention period and supporting criteria. A record, payment card, and other sensitive information may be kept for a shorter time where it is no longer needed.

Type of information

General retention approach

Main criteria we use

Guest booking and service-delivery records

About three years, unless a longer or shorter period applies

The purpose of the booking or service record; legal or operational needs; whether the record is also needed for refunds, disputes, fraud review, legal claims, safety matters, or regulatory requirements

Financial, payment, refund, tax, accounting, and billing records

Kept longer than ordinary guest service records, up to about ten years. Payment-card details are kept only for the limited period needed to process and confirm payment

Tax, accounting, audit, chargeback, refund, reconciliation, financial-reporting, and other legal or financial compliance requirements

Claims, complaints, disputes, investigations, and litigation records

Kept until the matter and any appeals are resolved, and then reviewed for disposition, which may extend retention for a further period

The time needed to resolve the matter, respond to regulators, establish or defend legal rights, comply with limitation periods, or follow a legal hold

Safety, security, fraud, incident, and regulatory records

Kept until the safety, security, fraud, incident, or regulatory matter is resolved, and generally kept for up to ten years before being reviewed for disposition

Aviation, safety, security, fraud prevention, investigation, regulator response, legal compliance, and risk-management requirements

Marketing analysis, advertising, promotional, contest, and program-development records

Kept for the period required by the specific use: contest-administration and contest-law records are kept for the period applicable law requires (which may be up to ten years); campaign-delivery, advertising, and analytics records are generally kept for up to three years. Where these records are aggregated, de-identified, or anonymized, they may be kept in that form for longer.

Whether the record relates to campaign delivery, contest administration and contest-law record-keeping, market research, website analysis, statistical reporting, product or program design, compliance, or business reporting

Profile, preference, inference, and derived information used to support personalization, loyalty experiences, service delivery, analytics, fraud prevention, and operational improvement

Kept only as long as needed for the purposes described in this Main Privacy Statement and reviewed against the source records from which the information is derived

Whether the profile or inference is still needed for the purpose it supports; whether the underlying records have reached disposition; and your consent and available data-use choices.

Website, app, and digital-service interaction information

Kept for the period needed for site operation, security, fraud prevention, analytics, and service continuity. Interaction data held in our analytics tool is kept for up to 25 months

Whether the information is session-based, account-linked, security-related, analytics-related, or used to support a current request or booking

Call recordings, transcripts, summaries, and contact-centre service notes

Ordinary service records, records tied to a claim, dispute, quality review, or investigation are kept longer.

The reason for the interaction; whether the record is needed for service continuity, complaint handling, claims, fraud review, legal obligations, or dispute resolution

Biometric and voice-authentication information, if introduced

Kept only as long as needed for the authentication purpose and as permitted by law, unless you withdraw consent and no exception applies

Whether the information is still needed to authenticate you, whether you withdraw consent, whether another legal basis permits continued retention, and any security or legal obligations that apply

Video-viewing activity

Kept for two years, or until you withdraw permission

The scope of your consent, whether the activity is linked to third-party disclosure, and any legal or contractual requirements that apply

Cookies and similar technologies

Kept according to the duration shown in the applicable cookie preferences and notices, where applicable

Cookie type, whether it is session-based or persistent, browser or device settings, your consent choices, and the operational purpose of the technology

Marketing suppression and opt-out records

Kept for as long as we operate the relevant list, so that we continue to honour your choice not to be contacted, or not to have your information sold, shared, or used for targeted advertising

Whether the record is needed to keep honouring your choice, unless a shorter period is required by law

De-identified or anonymized information

May be kept longer where it no longer identifies you and is used only in a permitted way

Whether the information has been processed so that it no longer identifies you, the safeguards applied, and the purpose for continued use

Connected travel experiences

We may use information from our brands, programs, services, and interactions with you to provide connected travel experiences and more consistent service, personalize communications and offers where permitted, administer loyalty benefits, protect accounts, detect fraud or misuse, and improve our services and operations. For Rewards-specific points, redemptions, personalized offers, account-management consequences, and profiling, see the WestJet Rewards Privacy Statement.  

To support these purposes, we may use information from different interactions, services, programs, or brands where permitted by law and subject to appropriate safeguards. 

Information used for these purposes is retained according to the retention period that applies to the underlying record category. Profile, preference, and identity-related information is kept only as long as needed for the purposes described in this Main Privacy Statement and subject to legal, regulatory, tax, accounting, claims, dispute, security, fraud-prevention, and legal-hold requirements.

When we keep information longer

We may keep information longer than the general period for a category where needed to: 

  • comply with law, regulation, court process, or regulator expectations; 
  • meet aviation, safety, security, tax, accounting, audit, or reporting obligations; 
  • investigate fraud, misuse, security events, or other incidents; 
  • resolve claims, complaints, disputes, chargebacks, or refunds; 
  • establish, exercise, or defend legal rights; 
  • preserve records under a legal hold; or 
  • complete an ongoing operational process that reasonably requires continued retention. 

When we remove information sooner

We may delete, de-identify, anonymize, or restrict information sooner where:

  • the information is no longer needed for the purpose for which it was collected;
  • privacy law or security standards require shorter retention;
  • payment-card or other sensitive information should not be retained beyond a limited period; 
  • you withdraw consent, and no other legal basis supports continued retention;
  • the information can be kept in a less identifiable form for analytics, reporting, or system-integrity purposes; or
  • technical or operational controls are designed to shorten the life of certain data elements.

Deleting or restricting one data set does not always mean that every related record can be deleted at the same time. Some related records may need to be kept longer because they fall into a different retention category. 

Legal holds and disposition review

We do not delete records automatically as soon as a retention period ends. Before records are finally deleted, destroyed, de-identified, anonymized, or otherwise disposed of, they go through a disposition review to confirm whether they are still needed for: 

  • a legal hold; 
  • an investigation; 
  • a claim, dispute, complaint, or regulator inquiry; 
  • safety, security, fraud-prevention, tax, accounting, or audit purposes; or 
  • another applicable legal or operational reason. 

If a legal hold or similar preservation requirement applies, we keep the affected records until that requirement ends. 

Retention and your rights

If you ask us to delete information, we assess the request against the retention rules and legal obligations that apply to the record category involved. Where we cannot delete information immediately, we may instead restrict its use, keep only what is required, or de-identify or anonymize it where appropriate. To learn more or make a request, reference Exercising Your Rights section.


Exercising Your Rights

You may have the right to access, manage and correct your personal information; opt in or out of features like electronic communications; or request deletion of your information, subject to applicable law and retention requirements.  

Privacy Requests

Use the self-serve tools below to manage your privacy requests and preferences.

What you can ask for

  1. A copy of your information. Request a guest information report, and we tell you how we have used and shared it.
  2. A correction. Update your details in your account or ask us to correct information.
  3. Deletion. Ask us to delete your information; what we can delete depends on where you live and what we must keep by law. To delete a WestJet Rewards account, use the Rewards account deletion request and review the WestJet Rewards Privacy Statement for Rewards-specific consequences.
  4. Withdrawal of consent. Withdraw a consent; we tell you what it affects, and withdrawal does not undo what we lawfully did beforehand.
  5. Your communications. Update preferences, unsubscribe from any marketing message, or ask for our do-not-contact list. You will still receive booking and program messages.
  6. Your account. Manage your details by signing in; for a name correction, account consolidation or deactivation, contact the Rewards support team and review the WestJet Rewards Privacy Statement for Rewards-specific account-management consequences.
  7. A person to review an automated decision. Ask for information about a decision made solely by automated means and for a human review.
  8. To report a concern. Tell us about an unknown charge, suspected unauthorized access, or another person’s information reaching you.

How to make a privacy request now

If you have any questions or concerns regarding your personal information, or if you want to exercise any of your rights in relation to your personal information, you can find more information on our privacy request webpage.

What applies where you live

Right

Canada, outside Quebec

Quebec

EEA and UK

United States

See your information

Yes

Yes

Yes

Yes

Correct it

Yes

Yes

Yes

Yes

Withdraw consent

Yes

Yes

Yes, where we rely on consent

Not applicable in this form

Deletion

No general right; we delete when the purpose ends or you withdraw and we no longer need it

Yes, where the conditions are met

Yes, subject to exceptions

Yes, subject to exceptions

Portable copy

No

Yes, structured technological format

Yes

In several states

Stop dissemination or de-index

No

Yes, where conditions are met

Through erasure

No

Restrict during a complaint

No

No

Yes

No

Object to legitimate-interests processing

No

No

Yes

No

Object to direct marketing

Through withdrawal of consent

Through withdrawal of consent

Yes, absolute

Through the opt-out

Opt out of sale or sharing for advertising

Through withdrawal of consent

Through withdrawal of consent

Through consent withdrawal

Yes, including by Global Privacy Control

Limit use of sensitive information

Through withdrawal of consent

Through withdrawal of consent

Through consent withdrawal

Yes, in California

Human review of an automated decision

Yes, a voluntary service for automated decisions that significantly affect you

Yes, with the reasons and principal factors

Yes, for decisions with significant effect

In several states, through the profiling opt-out

Appeal a refusal

To the Privacy Commissioner of Canada

To the Commission d’acces a l’information du Quebec

To your supervisory authority

To us, then the state Attorney General

How we handle your request

We confirm who you are before we act, using the least intrusive method that works: matching information we already hold, confirming through your signed-in account, or, for a request with significant consequences, a telephone call. If a call does not suit you, tell us and we will agree another method.

We respond within 30 days in Canada, extendable where the law allows with notice; within one month in the EEA and the UK, extendable by two further months for complex requests; and within 45 days in the United States, extendable once by a further 45 days. We may refuse or limit a request where the law permits, and we will tell you why and how to challenge that. Making a request costs nothing, and we will not treat you differently for making one.


Complaints, Changes & Contact

Complaints

Reach out to WestJet’s Privacy Officer first, and we will investigate and respond. If you are not satisfied, you can contact the Office of the Privacy Commissioner of Canada; in Quebec, the Commission d’acces a l’information du Quebec; in the EEA, your supervisory authority; in the United Kingdom, the Information Commissioner’s Office. 

Changes to this Statement

This Statement takes effect on the date first posted. We may update it as required or permitted by applicable law. When we make a material change, we post a dated explanation on this page of what changed and why, and the change takes effect one week after posting. We also communicate material changes through our regular channels. Where the law requires consent to a change, we ask for it before the change takes effect.

Contact

WestJet Privacy Officer: privacy_guestsupport@westjet.com, or 22 Aerial Place NE, Calgary, Alberta, Canada T2E 3J1.