Privacy Policy
Version: 2026-09-23
Last updated: June 4, 2026
Effective date: June 4, 2026
This policy should be presented alongside the Terms of Service at account and Organization creation.
---
Controller / business: Aerial Flight Management System LLC (“Company,” “we,” “us”)
Product: Aerial Flight Management System (the “Service”)
Privacy contact: contact@flyaerial.app
Address: 730 N Milwaukee Ave, Chicago, IL 60642
This Privacy Policy explains how we collect, use, disclose, and retain personal information when you use the Service. Capitalized terms not defined here have the meaning in the Terms of Service.
Depending on the relationship:
- For Organization Data processed on behalf of a flight school, we generally act as a processor / service provider, and the school is the controller / business.
- For account data, website analytics (if any), and our own billing of schools for SaaS subscriptions, we generally act as a controller / business.
---
1. Personal information we collect
1.1 You provide
| Category | Examples |
| --- | --- |
| Account identifiers | Name, email, password (hashed by auth provider), phone |
| Profile / aviation | Certificate numbers, ratings, medical class/expiry, total hours, accident/enforcement history you choose to enter, address, DOB, citizenship/ID documents you upload |
| Organization membership | Roles, locations, employee/student numbers, school notes |
| Training & operations | Schedules, flight requests, enrollments, lesson grades, logbook entries, signatures, aircraft assignments |
| Emergency contacts | Name, relationship, phone, email of people you designate (third-party data) |
| Billing | Subscription plan, invoices, partial payment tokens/IDs from processors, billing address, school payout / Connect account metadata |
| Communications | Support tickets, email contents you send us, in-app notices |
| Documents | Uploaded files (IDs, medicals, syllabi, org documents) |
1.2 Collected automatically
- Device / browser type, IP address, approximate location derived from IP
- Log data (timestamps, pages/API routes accessed, error diagnostics)
- Authentication session metadata
- Cookies or similar technologies as described in Section 8
1.3 From others
- Organization admins who invite you or enter member fields
- Instructors / schools who record training against your profile
- Payment processors (payment success/failure, dispute events)
- Identity verification providers used by payment onboarding (Connect)
1.4 Sensitive / regulated data
The Service may process government ID, medical, and aviation safety related information if you or your school enter it. Provide only what is needed. Do not upload unnecessary sensitive documents.
We do not intentionally collect information from children under 13 without appropriate consent mechanisms. Schools that enroll minors must ensure guardian consent and lawful basis.
---
2. How we use personal information
We use personal information to:
1. Provide, operate, secure, and support the Service
2. Authenticate users and enforce role-based access within Organizations
3. Enable scheduling, training programs, logbooks, fleet, and related workflows
4. Process SaaS subscription billing and (where enabled) facilitate school–student payments via processors
5. Send transactional messages (invitations, booking notices, security alerts, billing receipts)
6. Detect fraud, abuse, and security incidents; audit access
7. Comply with law and enforce Terms
8. Improve the Service using aggregated or de-identified analytics
9. Communicate product changes or marketing where permitted (you may opt out of non-essential marketing)
We do not sell personal information as “sale” is commonly understood (cash for lists). If a privacy law defines “sale” or “share” broadly (e.g., certain advertising technologies), see Section 9 for rights and opt-outs.
---
3. How we share personal information
We share personal information with:
| Recipient | Purpose |
| --- | --- |
| **Your Organization’s Authorized Users** | Per roles/permissions (e.g., instructors see student schedules; billing admins see invoices) |
| **Service providers / subprocessors** | Hosting, database/auth/storage, email, error monitoring, payment processing (e.g., Stripe), analytics if enabled, and tools used to operate support (e.g., issue tracking) |
| **Payment processors** | Charging Fees, student invoices, Connect payouts, disputes |
| **Professional advisors** | Legal, accounting, insurance, under confidentiality |
| **Authorities** | When required by law, court order, or to protect rights, safety, and security |
| **Successors** | In a merger, acquisition, or asset sale, subject to continuing protections |
We do not allow subprocessors to use Customer Data for their own unrelated marketing.
A current subprocessors list is available upon request to contact@flyaerial.app.
---
4. Organization admin access and your choices inside a school
If you join a flight school Organization, school administrators and other roles you are granted under may access information about you according to that school’s configuration and our permission model. That may include contact details, schedule, training progress, and certain profile fields.
Questions about what your school accesses, correction of school-managed notes, or school-level retention should go first to your school. We can assist as processor where appropriate.
You may leave an Organization (or be removed). Leaving may not delete training records the school or we must retain.
---
5. Retention
We retain personal information only as long as needed for the purposes above, including:
| Data type | Typical retention approach |
| --- | --- |
| Account credentials & profile | For life of account + short wind-down |
| Organization membership metadata | For life of membership + audit period |
| **Signed / locked logbook & graded training records** | Retained for integrity and aviation recordkeeping; **may not be fully erasable** on request where retention is necessary |
| Schedules / operational logs | Subscription period + reasonable backup/audit window |
| Billing & tax records | As required by law (often 7+ years) |
| Support tickets | As needed for support history, then delete/de-identify |
| Security logs | Limited period unless investigating an incident |
| Emergency contacts | Until you/school remove them or account winds down |
Exact numeric periods vary by data class and legal requirements. A current retention schedule is available upon request to contact@flyaerial.app. You should not rely on the Service as the only copy of records required by the FAA or your insurer.
---
6. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit, access controls, organization isolation patterns, and least-privilege permissions. No system is perfectly secure. Notify contact@flyaerial.app of suspected vulnerabilities or breaches affecting you.
In a breach requiring notice under applicable law, we will notify you and/or Organization admins as required.
---
7. International transfers
We may process data in the United States and other countries where we or our subprocessors operate. Where required, we use appropriate transfer mechanisms (e.g., Standard Contractual Clauses). Details: contact@flyaerial.app.
---
8. Cookies and similar technologies
We use:
- Essential cookies/storage for login and security
- Preferences cookies for display settings
- Analytics cookies or similar technologies, which we may enable to understand product usage. Details about current analytics vendors are available upon request to contact@flyaerial.app.
You can control cookies via browser settings; blocking essential cookies may break login.
---
9. Your privacy rights
Depending on where you live (e.g., EEA/UK, California, other U.S. states), you may have rights to:
- Access / know what we hold
- Correct inaccuracies
- Delete (subject to legal and recordkeeping exceptions, including signed training records)
- Export / portability
- Restrict or object to certain processing
- Withdraw consent where processing is consent-based
- Opt out of “sale” / “sharing” / targeted advertising if applicable
- Appeal a denied request where required by law
- Lodge a complaint with a supervisory authority
How to exercise: email contact@flyaerial.app with the subject “Privacy Request,” and enough information to verify your identity and locate your data. Organization-managed data may require the school’s involvement.
We will not discriminate against you for exercising privacy rights.
Authorized agents (CA and similar): may submit requests as permitted by law with proof of authorization.
---
10. Do Not Track
The Service does not currently respond to “Do Not Track” browser signals. We will update this section if that changes.
---
11. Automated decisions
We do not use Customer Data for solely automated decisions that produce legal or similarly significant effects about individuals without human involvement, except fraud/security controls. Training progress percentages and scheduling suggestions are operational tools, not credit or employment automated decisions by us.
---
12. Children
The Service is not directed to children under 13. Schools enrolling minors must ensure appropriate parental/guardian consent and school policies. Contact us to flag an account that should be removed.
---
13. Changes
We may update this Privacy Policy. We will revise the “Last updated” date and provide additional notice for material changes where required.
---
14. Contact
| Topic | Contact |
| --- | --- |
| Privacy requests | contact@flyaerial.app |
| Security | contact@flyaerial.app |
| Postal | 730 N Milwaukee Ave, Chicago, IL 60642 |
EEA/UK representative: Not appointed.
Data Protection Officer: Not appointed.