Skip to main content
FlyStandby
Legal · Data Protection

GDPR Notice

Last updated · April 2026

Section 01

Introduction

This GDPR Notice explains how FlyStandby.app ("FlyStandby," "we," "us," or "our") collects, processes, stores, and protects your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). FlyStandby is an airline standby travel platform — accessible via the website at flystandby.app and the FlyStandby mobile application (collectively, the "Service") — designed exclusively for airline employees and eligible companions, enabling users to find standby flights with seat availability, manage load requests, and plan non-revenue travel.

Read alongside our Privacy Policy, Terms of Service, and Cookie Policy.

Section 02

Data Controller

FlyStandby is the data controller responsible for your personal data. For any questions about this GDPR Notice or to exercise your data protection rights, contact our Data Protection point of contact:

FlyStandby

Data Protection Contact

Section 03

Categories of Personal Data

We collect and process the following categories of personal data:

Identity & Account

Full name · email · airline affiliation (employer + additional airlines) · employee ID (for verification) · referral code and relationships · account preferences (currency, timezone, time format, notification settings).

Financial & Transaction

SkyCredits balance, transactions, tier · subscription plan, status, billing period, renewal · payment records via Stripe or Apple (we don't store full card numbers) · purchase history · referral payout records · withdrawal-waiver consent records (Stripe checkouts only — see Right of Withdrawal).

Travel & Activity

Flight search queries and cached results · load requests and responses · followed flights · trip plans (multi-leg itineraries, canvas positions, options) · traveler agreements · flight comparison data.

Verification

ID photo uploads (airline ID badge) · verification status and review history · airline name and employee ID associated with verification requests.

Technical & Device

IP address (per connection, fraud prevention) · persistent device identifier cookie · connection metadata (browser, language, approximate geo from IP) · push notification subscriptions (endpoint, keys) · cookies and local storage · standard HTTP headers.
Section 04

Legal Basis for Processing

Under Article 6 of the GDPR we rely on the following legal bases:

Performance of Contract
Art. 6(1)(b)
  • Creating and managing your user account
  • Processing SkyCredits transactions and purchases
  • Facilitating load requests and responses
  • Providing flight search and trip planning services
  • Processing payments through Stripe
  • Delivering notifications about your requests and account activity
Consent
Art. 6(1)(a)
  • Sending marketing and promotional email communications
  • Setting analytical and tracking cookies
  • Push notification delivery
  • Processing optional data (airline affiliation, additional airlines)
Legitimate Interest
Art. 6(1)(f)
  • Maintaining platform security and preventing fraud (persistent device cookies, connection tracking)
  • Employee verification to ensure platform integrity
  • IP address and device identifier logging for abuse prevention and duplicate account detection
  • Enforcing our Terms of Service (e.g. banned email list)
  • Internal analytics to improve service quality
  • Referral fraud detection
Legal Obligation
Art. 6(1)(c)
  • Retaining financial transaction records as required by tax and accounting laws
  • Responding to lawful data access requests from authorities
Section 05

Third-Party Data Processors

We share personal data with the following third-party processors, each bound by data processing agreements and compliant with GDPR requirements.

ProcessorPurposeData SharedLocation
Hetzner Online GmbHDatabase hosting, application server, file storageAll account and platform data, authentication tokens, uploaded filesGermany
Stripe Inc.Payment processingEmail, payment card details, transaction amountsUnited States
AeroDataBox (AvionStack GmbH)Flight search, seat availability, flight status dataFlight search parameters; no personal identity dataGermany
Brevo (Sendinblue SAS)Transactional, notification and marketing emailsEmail address, name, notification contentFrance
Apple Inc.App Store distribution and in-app purchasesApple ID, purchase records, device identifiersUnited States
Cloudflare Inc.CDN and DDoS protectionIP addresses, request metadataUnited States
Google LLCAnalytics (Google Analytics 4)Anonymised page views, usage events (consent-gated)United States
Meta Platforms Inc.Advertising measurement (Meta Pixel & CAPI)Hashed email, event data (consent-gated)United States
We do not sell, rent, or trade your personal data to any third party for their own marketing purposes.
Section 06

International Data Transfers

Some processors are located outside the European Economic Area, primarily in the United States and United Kingdom. When transferring outside the EEA we apply appropriate safeguards:

  • EU-US Data Privacy Framework — for US processors certified under it.
  • Standard Contractual Clauses — EU-approved SCCs where DPF does not apply.
  • UK Adequacy Decision — Commission decision permits UK transfers without additional safeguards.

You may request a copy of the specific safeguards applied to your data transfers by emailing [email protected].

Section 07

Data Retention Periods

We retain personal data only as long as necessary for the purposes for which it was collected.

Data CategoryRetention Period
Account data (name, email, preferences)Membership duration + up to 30 days post-deletion
Financial transaction records7 years (legal/tax obligation)
SkyCredits balance and historyMembership duration + up to 30 days post-deletion
Subscription recordsMembership duration + up to 30 days; financial records 7 years
Withdrawal-waiver consent recordsLinked to the related transaction record (7 years)
Flight searches and cached resultsUntil departure time, then auto-purged
Load requests and responsesAuto-expire at departure; retained 12 months for QA
Trip plansMembership duration; deleted on account deletion
Verification ID photosDeleted promptly after review
Push notification subscriptionsUntil unsubscribe or account deletion
Connection records (IP, device IDs, metadata)Membership duration (fraud prevention)
Analytics sessions and eventsIPs anonymised after 90 days; events up to 2 years
Re-engagement email records12 months after sending
Device fingerprintsMembership duration (fraud prevention)
Banned email recordsIndefinite (prevent re-registration of abusive accounts)
Section 08

Your Rights Under the GDPR

You may exercise any of the following rights at any time by emailing [email protected].

Access

Art. 15

Request confirmation of processing and a copy of your personal data, free of charge. We respond within 30 days.

Rectification

Art. 16

Request correction of inaccurate data and completion of incomplete data. Most profile data can be edited directly in account settings.

Erasure

Art. 17

Request deletion of your personal data. Account deletion removes data within 30 days; certain data may be retained where we have a legal obligation.

Restriction

Art. 18

Request restriction of processing in certain circumstances (e.g. you contest accuracy or have objected pending verification).

Data Portability

Art. 20

Receive the personal data you provided in a structured, commonly used, machine-readable format (e.g. JSON or CSV) and transmit it to another controller.

Object

Art. 21

Object to processing based on legitimate interests. We will cease unless we demonstrate compelling legitimate grounds overriding your interests.

Withdraw Consent

Art. 7(3)

Withdraw consent at any time without affecting prior lawful processing. Manage notifications, cookies, and push subscriptions in account settings.

Automated Decisions

Art. 22

You have the right not to be subject to a decision based solely on automated processing producing legal effects. FlyStandby does not engage in such decision-making. Our dynamic pricing algorithm does not constitute automated individual decision-making under Article 22.
Section 09

Data Security Measures

We implement appropriate technical and organisational measures appropriate to the risk, in accordance with Article 32 of the GDPR.

  • Encryption in transit — all data transmitted over HTTPS/TLS.
  • Encryption at rest — database data encrypted at rest via Hetzner.
  • Access control — application-level authorisation; users only access their own data.
  • Authentication — Better Auth with secure session token management.
  • Internal access — restricted to authorised personnel on a need-to-know basis.
  • Payment security — card data handled exclusively by Stripe (PCI DSS Level 1).
  • Content Security Policy — CSP headers enforced to mitigate XSS/data injection.
Section 10

Cookies and Local Storage

We use strictly necessary cookies for authentication, session management, and security (including a persistent device identifier cookie used for fraud prevention and duplicate account detection). Analytical and tracking cookies are only placed with your explicit consent, manageable via the cookie consent banner. Full details in the Cookie Policy.

We also use browser local storage to persist non-sensitive user preferences such as flight comparison selections (24-hour expiry) and authentication session tokens.

Section 11

Children’s Data

FlyStandby is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that a child under 16 has provided personal data, we will take steps to delete it promptly. Contact [email protected] if you believe a child under 16 has provided us with personal data.

Section 12

Data Breach Notification

In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (Article 33). If the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay (Article 34).

Section 13

Right to Lodge a Complaint

If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority — in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement (Article 77 GDPR). FlyStandby is operated from Belgium; the lead supervisory authority is the Belgian Data Protection Authority.

Belgian DPA

Lead Supervisory Authority

Autorité de protection des données / Gegevensbeschermingsautoriteit · Rue de la Presse 35 / Drukpersstraat 35 · 1000 Brussels, Belgium · www.dataprotectionauthority.be · [email protected]

We encourage you to contact us first at [email protected] so we can try to resolve your concern directly.

Section 14

Changes to This Notice

We may update this GDPR Notice from time to time to reflect changes in our data processing practices or applicable law. For material changes we publish a prominent notification on the website and update the "Last updated" date. We may also notify you by email.

Section 15

Contact

For any questions, concerns, or requests related to this GDPR Notice or your personal data: [email protected].