8 Total
2 High severity
6 Medium severity
0 Low severity
Summary

This is American Airlines' privacy policy, covering all personal data the airline collects when you book flights, use the AAdvantage loyalty program, visit aa.com, or use its mobile app. The most important thing to know is that American collects sensitive categories of data including biometric identifiers, health information, vaccination status, and geolocation, and shares this data with a wide network of travel, loyalty, credit card, and advertising partners, while using cookies and cross-device tracking to deliver targeted advertising both on its own platforms and on third-party websites. California residents and certain other state residents have specific rights to access, delete, or opt out of certain data uses, which can be exercised through the privacy portal linked in the policy.

Technical / Legal Breakdown

This Privacy Policy governs the collection, use, sharing, and protection of personal information by American Airlines, Inc. across its Travel Services, Program Services, and Interactive Services, including the AAdvantage loyalty program, and applies to all interaction channels regardless of device. The agreement states that American collects a broad range of data including biometric identifiers, health information, geolocation, payment data, and communications content; the terms authorize sharing this data with travel partners, loyalty partners, credit card partners, government and law enforcement agencies, advertising networks, and third-party analytics providers, and permit combining online and offline data for targeted advertising purposes. Notably, the policy asserts broad cross-device tracking and data combination practices for behavioral advertising, collects sensitive categories such as biometric, health, and vaccination data, and conditions certain opt-out rights on state residency rather than applying them universally, though applicable law including GDPR, CCPA, and state biometric statutes may constrain how some of these asserted rights operate in practice. The policy engages GDPR for EU/EEA data subjects, the California Consumer Privacy Act and California Privacy Rights Act for California residents, state biometric privacy laws such as Illinois BIPA where biometric data is collected, and federal aviation security and customs regulations that independently compel collection of certain traveler data; the dual role of American as both a commercial data controller and a regulated air carrier creates layered compliance obligations across multiple frameworks and jurisdictions.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 2 provisions
Medium — 6 provisions

Monitoring

American Airlines has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Biometric Data Collection and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:31 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000633
Version ID CA-V-001287
SHA-256 474ee5633e1a74620002cdd4f9e989cd1f53b4d02591b5c1a46b6d5dab9cbc25
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans