Legal

Terms of Service

Effective date: 15 September 2026

[ 01 ]

Scope, and which part applies to you

Norba is a service operated by NORBA TRAVEL OÜ, a private limited company registered in the Estonian Business Register under registry code 17597060 ("Norba", "we", "us"). Where these terms say "we", they mean that company: it is the party you are contracting with, whichever part below applies to you.

These terms cover everything Norba operates. They are in two parts, because two very different relationships are involved and conflating them would leave both unclear:

  • Part A — clauses 2 to 12 — the agreement between Norba and a business using the API and the dashboard at app.norba.io and api.norba.io.
  • Part B — clauses 13 to 19 — the terms for a traveller searching or reserving a flight on booking.norba.io.

Clauses 20 onward apply to both. By using any of these, you accept the parts that apply to you; if you do not accept them, do not use the service.

A business that takes its keys to production also signs the Norba Production Agreement, and that document governs the production relationship: where it and these terms disagree, it wins, and everything it does not cover stays here.

How we handle personal data is in the Privacy Policy; what we store in your browser is in the Cookie Policy. Both are part of these terms by reference.

[ 02 ]

Part A — What the API does

Norba is an NDC aggregation API. It calls airlines' own distribution interfaces, normalises what comes back into one canonical schema, and lets your software search, price, book and service flights through a single REST contract rather than one integration per carrier.

We are an intermediary, not a carrier. We do not operate aircraft, we do not set fares, and we do not own the inventory: every offer, price, rule and seat comes from an airline and is subject to that airline's own terms. Where an airline's answer is wrong, late or unavailable, that is what our API will report.

We are not the seller either. Where a business sells through us, that business is the one its traveller buys from, and the contract of carriage is between that traveller and the airline. What we operate is the technology between the two — clauses 5 and 6 set out what follows from that, including whose money goes where.

The service is in beta. Endpoints, response shapes and error codes can change; breaking changes are announced in advance where we can, and never silently.

[ 03 ]

Accounts and API keys

An account is for one business, and the person creating it warrants they may bind it.

  • API keys are credentials. Keep them secret, out of client-side code and out of version control; anything done with your key is treated as done by you.
  • Keys belong to the business behind the account, not to the person who created them. Anyone the account lets manage keys can create, rotate, restrict and revoke them, and the business answers for what is done with each of them.
  • There is one kind of key in two environments. A sandbox key reaches the airlines' test systems; a production key reaches live systems. To get one, file a go-live request from the dashboard: your company details, your incorporation and tax documents, and your signature on the production agreement as it currently stands. We review what you filed, and your sandbox keeps working throughout and afterwards.
  • When we materially rewrite the production agreement, the signatures given for the older wording stop being the agreement in force and we ask you to sign the current text. The earlier acceptance is kept, not deleted: it is the record of what was agreed on the day it was agreed.
  • Do not share a key with a party that is not covered by your agreement with us. If you need to give a third party access, ask us and get a key of their own.
  • Rotate a key you suspect has leaked — you can do that yourself in the dashboard, and revocation is immediate.
  • Revoking, rotating, restricting or expiring a key is your decision and takes effect at once for every system still using it. Requests refused for that reason are not a failure of the service; check what depends on a key before you revoke it.
  • We may revoke a key without notice where it is being used in breach of these terms, is implicated in an incident, or is generating traffic that threatens the platform or a carrier's tolerance of it. We tell you as soon as we have.
  • Enable two-factor authentication. We may require it for accounts holding production keys.

[ 04 ]

Acceptable use

You must not:

  • Send abusive, fraudulent or unlawful requests to airlines through us — including speculative bookings, fictitious names, or holds you have no intention of paying for. Airlines police this, and the consequence lands on the platform as a whole.
  • Scrape, mirror or resell airline content in breach of the carrier agreements the offers reach you under, or build a fare-comparison database out of responses obtained for booking.
  • Exceed a rate limit deliberately, run load tests against production without agreeing them with us first, or attempt to circumvent quotas or the look-to-book ratios airlines hold us to.
  • Resell or white-label API access without a written agreement with Norba.
  • Interfere with the availability or integrity of the service, or attempt to reach data belonging to another account.
  • Use the sandbox to serve real customers, or production to run tests.

Security research is welcome and is not a breach of this clause when it is confined to your own account and reported to hello@norba.io before disclosure. Please do not test against carrier production systems.

[ 05 ]

Your obligations to the travellers you serve

When you use our API to serve your own users, you are the one facing them, and you take on what that means:

  • You are the seller of record. The traveller buys from you, on your terms, at a total you set, and the flight itself is flown by the airline under its own conditions of carriage. We are not a party to that sale and we are not your traveller's travel agency.
  • You collect the traveller's money yourself, on your own checkout and through your own payment provider, and you keep it. It does not reach us — clause 6 says which money does.
  • Show the traveller what each part of the price is: the airline's fare and the taxes and charges as the airline stated them, your own service fee as yours, and our fee, where you choose to pass it on, labelled as ours. Never as a tax, a surcharge or part of the fare.
  • You are the controller of your users' personal data and need your own lawful basis and privacy notice; we act as your processor for it, on the terms of the Privacy Policy and any data-processing agreement we sign.
  • You must show your users the airline's fare rules, baggage terms and conditions of carriage that our responses carry — not a summary of your own that contradicts them.
  • You must not present a held, unpaid reservation as a confirmed ticket. See clause 14; the distinction matters as much in your product as in ours.
  • You are responsible for your own consumer, tax and travel-agency obligations in the markets you sell in, including any IATA accreditation or licence your model requires.

[ 06 ]

Billing, and whose money is whose

What we invoice you is our own service fees, and nothing else. They are the fees set out on the Pricing page or in your written agreement; we do not restate a rate in these terms, because rates change and a figure written into a contract outlives the price it described. What is fixed here is the mechanism: usage is metered from the request log described in the Privacy Policy, together with the bookings, extras and servicing operations you made, calculated monthly and invoiced in arrears. Our own invoices are paid by card through Stripe; we never receive that card number.

The money that pays for the flight never passes through us. The traveller pays you the whole price you quoted, on your own checkout. You then pay the carrier: the payment method you submit with a booking — normally a card of your own — is transmitted to that carrier for that one transaction, and the carrier authorises it, captures it and issues the ticket. We do not receive, hold, settle or forward either amount. We are not the merchant of record for anything a traveller pays, we hold no traveller funds and no funds of yours, and nothing in these terms makes us a payment service.

Payment credentials reach us only inside a booking request, and only to be passed to the carrier. We do not store the card number, and we ask for the fewest fields that will complete the transaction: the security code is optional and should be sent only where the carrier you are booking requires one, and the result of an authentication you carried out yourself may travel with it where the carrier accepts one. We will not take card details by email, chat, a support ticket or the telephone.

One charge depends on how you search rather than on what you sell, so it is described here even though rates are not. Every airline caps, in its own contract with us, how many searches it will serve for each booking made — its look-to-book ratio. While your ratio with a given airline is above what that airline allows, each request you send to THAT airline carries an excess look-to-book charge on top of the call, at the rate on the Pricing page. It applies only to the airline you are over with and never to the others; it is not applied until you have made enough searches with that airline for the ratio to mean anything, so a new integration is not charged while it is being built; and it stops by itself as soon as the ratio returns inside the limit — a booking on that airline recalculates it immediately. We do not refuse or throttle your searches for being over a ratio. You can see your ratio, the limit and what has been charged, per airline, in your dashboard.

Invoices are due within 30 days. We may suspend keys on an invoice more than 30 days overdue, after telling you first. Raise a disputed charge within 30 days of the invoice date at hello@norba.io and we will not suspend anything that is genuinely in dispute while we look at it.

Fees are exclusive of VAT and any other applicable tax, which is added where due.

We may change prices with at least 30 days' notice by email. A price change never applies to a period already invoiced.

[ 07 ]

Availability, and what we do not promise

We aim high, but during beta there is no contractual uptime commitment and no service-credit scheme, and we do not yet publish a status page. Planned maintenance is announced in advance where possible.

A significant part of what can go wrong is not ours: an airline's endpoint can be down, slow, or return a fare it then refuses to honour. We report what the carrier tells us. We are not liable for losses arising from a carrier's failure, from a fare an airline withdraws, or from downtime of the airline systems we depend on.

[ 08 ]

Intellectual property

The API, its documentation and the canonical schema are ours. You get a non-exclusive, revocable right to call the API and to use the schema in your own integration for as long as your account is in good standing — nothing more, and nothing exclusive.

Your application code, your data and your users remain yours. We claim no rights in them, and nothing here licenses us to use your data beyond providing the service.

Airline content — fares, schedules, marketing text, logos — belongs to the airlines. Your right to use it comes from them, through the distribution agreements the offers arrive under, not from us.

[ 09 ]

Confidentiality

Each side will keep the other's non-public technical and commercial information confidential and use it only to perform these terms. This does not cover information that is already public, independently developed, or that the law compels one of us to disclose.

[ 10 ]

Disclaimer of warranties

To the extent the law allows, the service is provided without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, non-infringement, and any warranty that it will be uninterrupted, error-free, or that any particular airline will remain reachable through it.

[ 11 ]

Limitation of liability

Neither side is liable for indirect or consequential loss, lost profit, lost revenue or lost data. To the maximum extent permitted by law, our total liability for all claims arising in any twelve-month period is limited to the fees you paid us in the three months before the event giving rise to the first of those claims.

Nothing here excludes liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot lawfully be excluded — including a consumer's non-waivable rights under Part B.

[ 12 ]

Suspension and termination

You may close your account at any time; fees already accrued remain due. We may suspend or terminate access for a material breach of these terms, for non-payment after notice, or where continuing would put the platform or a carrier relationship at risk. Where the breach can be fixed, we tell you what it is and give you a reasonable chance to fix it first — unless the risk is immediate.

On termination your keys stop working, outstanding fees fall due, and your data is handled as the Privacy Policy describes. Reservations already made with an airline are unaffected by the end of your Norba account: they are between the traveller and the carrier.

[ 13 ]

Part B — Using booking.norba.io

booking.norba.io lets you search flights from the airlines connected to the Norba platform and place a reservation with one of them. The site is operated by NORBA TRAVEL OÜ, registry code 17597060, and that company is the one you deal with here. Norba is an intermediary: the flight is performed by the airline, under that airline's conditions of carriage and fare rules, and the airline — not Norba — is your carrier.

You may use the site to make a genuine reservation for yourself or for someone whose details you are entitled to provide. Speculative or fictitious reservations are not permitted; airlines treat them as abuse and they can lead to the booking being cancelled.

[ 14 ]

What a booking here is — and is not

Read this clause before you rely on a reservation. A booking made on booking.norba.io is an UNPAID HOLD.

  • We send the airline your itinerary and passenger details and the airline holds the seats. We do not send a payment, and this site does not ask for a card.
  • The hold lasts only until the airline's own payment time limit, which the confirmation page shows. If the fare is not paid by then, the airline releases the seats and the reservation simply ceases to exist.
  • A hold is not a ticket and does not entitle you to travel. You are not carried until the airline has been paid and has issued a ticket, through whatever process that carrier requires.
  • The price shown is the airline's quote at that moment. Until a ticket is issued, an airline may reprice or withdraw the fare, and a hold gives no protection against that.

We will not describe a hold as a confirmed purchase, and neither should anyone reselling this flow. If any page here has left you thinking you have bought a ticket, tell us at hello@norba.io — that is a defect and we want to know.

[ 15 ]

Passenger details, documents and travel requirements

Names must match the traveller's passport or ID exactly. Airlines charge for corrections and some refuse them outright, in which case the fare is lost; that is the carrier's rule, not ours.

You are responsible for holding the passport, visa, transit permission, and any health or entry documentation your itinerary requires, for every passenger, including infants. Requirements change without notice, depend on nationality and can differ for a connection you never leave the airport on. Check with the airline and the authorities of every country on your route. We do not verify them and cannot be liable for a refusal to board or to enter.

Give a contact email and phone you will actually read. Airlines send schedule changes, cancellations and check-in information to them directly.

[ 16 ]

Changes, cancellations and refunds

What can be changed or refunded, and at what cost, is fixed by the fare rules of the ticket the airline issues — not by us. Where the site shows those rules, they come from the airline's own response.

An unpaid hold needs no cancellation: leave it unpaid and it lapses. Once a ticket has been issued by the airline, changes and refunds go through that airline, or through whoever sold and issued the ticket to you.

Where an airline cancels or significantly delays a flight departing from the EU, or arriving in the EU on an EU carrier, Regulation (EC) 261/2004 may give you a right to rerouting, reimbursement and compensation. That claim lies against the operating carrier. We will give you the booking records you need to make it — ask at hello@norba.io.

[ 17 ]

Right of withdrawal

Consumer law in the EU gives no 14-day right of withdrawal for passenger transport services: Article 16(l) of Directive 2011/83/EU excludes them, along with services tied to a specific date. So a flight reservation is not cancellable simply because you changed your mind — only on the terms of the fare rules.

This does not affect the rights you have when something goes wrong: a cancelled flight, a service not provided as described, or a fault on our side.

[ 18 ]

The demo

Parts of this site can be used without an account as a demonstration. Demo bookings are fictitious: no airline is contacted, no seat is held, and nothing can be flown. They are stored separately from real bookings, never keep a full travel-document number or a full date of birth, and are deleted after 30 days. Do not enter real passport numbers into the demo — it does not need them.

[ 19 ]

Complaints

Write to hello@norba.io and we will answer. If your complaint is about the flight itself — a delay, a cancellation, baggage — it must be made to the operating airline, which is the party with the obligation; we will help you reach them and provide your booking records.

As a consumer in the EU you can also use the European Commission's online dispute resolution platform, and you keep every right your national consumer law gives you, whatever else these terms say.

[ 20 ]

Data protection

The Privacy Policy explains what we collect, why, who else sees it, how long it is kept, and how to exercise your rights. On the booking site we are the controller of your booking data. Where you reach a Norba-powered booking flow inside somebody else's product, that business is the controller and we are its processor.

Airlines receive passenger data because a ticket cannot be issued without it, and become controllers of that data themselves. That is inherent to buying a flight from anyone.

[ 21 ]

Changes to these terms

We may update these terms. Material changes are emailed to account holders and posted here at least 14 days before they take effect. For a traveller, the version in force is the one shown when the reservation was made. Continuing to use the service after a change takes effect is acceptance of it; if you would rather not accept, stop using the service and, for an API account, close it — clause 12 says what happens then.

[ 22 ]

Governing law and jurisdiction

These terms are governed by Spanish law, without regard to conflict-of-law rules, and the courts of Spain have jurisdiction. If you are a consumer, this does not deprive you of the protection of the mandatory law of your country of residence, nor of the right to bring proceedings there.

If any clause turns out to be unenforceable, the rest stands.

[ 23 ]

Who we are, and how to reach us

The company behind Norba:

  • Legal name: NORBA TRAVEL OÜ
  • Registry code: 17597060 (Estonian Business Register)
  • Legal form: osaühing — private limited company, incorporated in Estonia
  • Websites: norba.io, booking.norba.io, api.norba.io

One address for everything — commercial questions, privacy and data rights, security reports: hello@norba.io.

Terms of Service — Norba API & Platform