Odynn Connect & TravelerDNA

Privacy policy

This policy covers Odynn Connect — the service a business uses to connect your travel loyalty accounts — and the TravelerDNA app you may have used to sign in. It is written to be read rather than filed: plain language, in the order things actually happen.

Last updated September 20, 2026

How a connection starts

Every connection begins the same way. A business you already deal with — your bank, a travel app, a rewards partner — hands you a link. You open it on your own phone, and your loyalty program's own sign-in page opens. You sign in there, to the airline or hotel directly.

Nothing starts on its own. If you never open the link, nothing happens. What happens after that first sign-in depends on whether you installed the TravelerDNA app, which is covered further down.

Your loyalty sign-in never reaches us

Your loyalty program username and password are typed into that program's own page, on your device, and they go to that program.

Odynn never receives them, never stores them, never logs them, and never transmits them anywhere. There is nothing for us to lose, leak, or be compelled to hand over, because we never hold them at any point. The same is true of any one-time code or security question the program asks you for.

What a completed sync hands over

Once you are signed in, we read the account information the program shows you and pass it on in a consistent shape. That is:

Your membership number
The number that identifies you to the loyalty program.
The identifier for the sync itself
A session identifier we generate for this one connection, so the business that asked for it can match the result to you.
Your name
As the loyalty program has it on file.
Your email address, phone number and mailing address
Where the program returns them — some do, some do not. Nothing beyond these four contact details is read from your profile.
Your point and mile balances
Every balance the program shows you: redeemable points, qualifying counters, lifetime totals.
Your tier standing
The status level you hold and when it expires.
Your account activity
Flights flown, stays completed, points earned and redeemed — the history the program lists on your account.
Your awards and certificates
Upgrade certificates, free-night awards, and similar credits.
Your upcoming reservations
Flights and stays the program has booked under your account.
Promotions the program is running for you
Offers and bonus campaigns shown on your account.

Not every program returns every one of these. You get what your program publishes about your own account, and nothing that is not on it.

What the app registers, and what it does on its own

If you install the TravelerDNA app and allow notifications, the app registers two things with us: a push token and a device identifier. Both are created for this app alone, kept on your device, and exist for one purpose — routing a refresh back to the right device. Neither is an advertising identifier, and neither follows you across other apps or websites.

That push token is what makes background refresh possible. With it, the app can refresh the accounts you already connected in the background, so you are not asked to sign in again every time the business needs current information. Three things bound it: it happens only because you installed the app and allowed notifications, it covers only accounts you already connected yourself, and it collects nothing that your first sync did not already collect.

If you used the App Clip instead — the lightweight version that opens without installing anything — none of the above applies. The App Clip registers no push token and no device identifier, and has no background activity at all.

Staying signed in between syncs

Signing in leaves behind cookies and session tokens — the loyalty session artifacts your browser would normally keep for you. We keep them encrypted so a later refresh does not have to interrupt you for another sign-in. They are not your password, and they cannot be used to work it out.

Who the data is for

We collect it on behalf of the business whose link you opened, deliver it to that business, and store it scoped to them — no other business on the platform can reach it. It is encrypted at rest. What that business then does with the data is governed by their own privacy policy, not by this one.

What we do not collect

Location
No location data of any kind. Neither the app nor the App Clip asks your device where you are.
Contacts
Your address book is never read.
Browsing history
The web view loads only your loyalty program's own pages — during a sync you started, and during a background refresh of an account you already connected. Nothing else you browse is visible to it, and no record of your browsing is collected.
Payment and credit data
Point balances are not payment data. The app never sees a card number, a bank account, or any other payment credential.
Analytics and crash reporting
No analytics SDK and no crash reporting SDK is built into the app. We do not measure how you use it.
Advertising identifiers
None are read, no advertising is served, and you are never asked to allow tracking.
Data brokers
Nothing is shared with data brokers, and nothing is sold.

Every purpose described on this page is app functionality. Nothing we collect is used for tracking.

Questions, and removing your data

If you want to know what we hold for you, or you want it removed, write to us and we will act on it. Tell us which business you opened the connection from — they hold their own copy of what we delivered, so a complete removal usually means asking them too, and we will point you to the right place. Start at our support page.