GDPR Notice
Last updated · April 2026
Introduction
This GDPR Notice explains how FlyStandby.app ("FlyStandby," "we," "us," or "our") collects, processes, stores, and protects your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). FlyStandby is an airline standby travel platform — accessible via the website at flystandby.app and the FlyStandby mobile application (collectively, the "Service") — designed exclusively for airline employees and eligible companions, enabling users to find standby flights with seat availability, manage load requests, and plan non-revenue travel.
Read alongside our Privacy Policy, Terms of Service, and Cookie Policy.
Data Controller
FlyStandby is the data controller responsible for your personal data. For any questions about this GDPR Notice or to exercise your data protection rights, contact our Data Protection point of contact:
FlyStandby
Data Protection Contact
Categories of Personal Data
We collect and process the following categories of personal data:
Identity & Account
Financial & Transaction
Travel & Activity
Verification
Technical & Device
Legal Basis for Processing
Under Article 6 of the GDPR we rely on the following legal bases:
- — Creating and managing your user account
- — Processing SkyCredits transactions and purchases
- — Facilitating load requests and responses
- — Providing flight search and trip planning services
- — Processing payments through Stripe
- — Delivering notifications about your requests and account activity
- — Sending marketing and promotional email communications
- — Setting analytical and tracking cookies
- — Push notification delivery
- — Processing optional data (airline affiliation, additional airlines)
- — Maintaining platform security and preventing fraud (persistent device cookies, connection tracking)
- — Employee verification to ensure platform integrity
- — IP address and device identifier logging for abuse prevention and duplicate account detection
- — Enforcing our Terms of Service (e.g. banned email list)
- — Internal analytics to improve service quality
- — Referral fraud detection
- — Retaining financial transaction records as required by tax and accounting laws
- — Responding to lawful data access requests from authorities
Third-Party Data Processors
We share personal data with the following third-party processors, each bound by data processing agreements and compliant with GDPR requirements.
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Hetzner Online GmbH | Database hosting, application server, file storage | All account and platform data, authentication tokens, uploaded files | Germany |
| Stripe Inc. | Payment processing | Email, payment card details, transaction amounts | United States |
| AeroDataBox (AvionStack GmbH) | Flight search, seat availability, flight status data | Flight search parameters; no personal identity data | Germany |
| Brevo (Sendinblue SAS) | Transactional, notification and marketing emails | Email address, name, notification content | France |
| Apple Inc. | App Store distribution and in-app purchases | Apple ID, purchase records, device identifiers | United States |
| Cloudflare Inc. | CDN and DDoS protection | IP addresses, request metadata | United States |
| Google LLC | Analytics (Google Analytics 4) | Anonymised page views, usage events (consent-gated) | United States |
| Meta Platforms Inc. | Advertising measurement (Meta Pixel & CAPI) | Hashed email, event data (consent-gated) | United States |
International Data Transfers
Some processors are located outside the European Economic Area, primarily in the United States and United Kingdom. When transferring outside the EEA we apply appropriate safeguards:
- EU-US Data Privacy Framework — for US processors certified under it.
- Standard Contractual Clauses — EU-approved SCCs where DPF does not apply.
- UK Adequacy Decision — Commission decision permits UK transfers without additional safeguards.
You may request a copy of the specific safeguards applied to your data transfers by emailing [email protected].
Data Retention Periods
We retain personal data only as long as necessary for the purposes for which it was collected.
| Data Category | Retention Period |
|---|---|
| Account data (name, email, preferences) | Membership duration + up to 30 days post-deletion |
| Financial transaction records | 7 years (legal/tax obligation) |
| SkyCredits balance and history | Membership duration + up to 30 days post-deletion |
| Subscription records | Membership duration + up to 30 days; financial records 7 years |
| Withdrawal-waiver consent records | Linked to the related transaction record (7 years) |
| Flight searches and cached results | Until departure time, then auto-purged |
| Load requests and responses | Auto-expire at departure; retained 12 months for QA |
| Trip plans | Membership duration; deleted on account deletion |
| Verification ID photos | Deleted promptly after review |
| Push notification subscriptions | Until unsubscribe or account deletion |
| Connection records (IP, device IDs, metadata) | Membership duration (fraud prevention) |
| Analytics sessions and events | IPs anonymised after 90 days; events up to 2 years |
| Re-engagement email records | 12 months after sending |
| Device fingerprints | Membership duration (fraud prevention) |
| Banned email records | Indefinite (prevent re-registration of abusive accounts) |
Your Rights Under the GDPR
You may exercise any of the following rights at any time by emailing [email protected].
Access
Art. 15
Rectification
Art. 16
Erasure
Art. 17
Restriction
Art. 18
Data Portability
Art. 20
Object
Art. 21
Withdraw Consent
Art. 7(3)
Automated Decisions
Art. 22
Data Security Measures
We implement appropriate technical and organisational measures appropriate to the risk, in accordance with Article 32 of the GDPR.
- Encryption in transit — all data transmitted over HTTPS/TLS.
- Encryption at rest — database data encrypted at rest via Hetzner.
- Access control — application-level authorisation; users only access their own data.
- Authentication — Better Auth with secure session token management.
- Internal access — restricted to authorised personnel on a need-to-know basis.
- Payment security — card data handled exclusively by Stripe (PCI DSS Level 1).
- Content Security Policy — CSP headers enforced to mitigate XSS/data injection.
Cookies and Local Storage
We use strictly necessary cookies for authentication, session management, and security (including a persistent device identifier cookie used for fraud prevention and duplicate account detection). Analytical and tracking cookies are only placed with your explicit consent, manageable via the cookie consent banner. Full details in the Cookie Policy.
We also use browser local storage to persist non-sensitive user preferences such as flight comparison selections (24-hour expiry) and authentication session tokens.
Children’s Data
FlyStandby is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that a child under 16 has provided personal data, we will take steps to delete it promptly. Contact [email protected] if you believe a child under 16 has provided us with personal data.
Data Breach Notification
In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (Article 33). If the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay (Article 34).
Right to Lodge a Complaint
If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority — in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement (Article 77 GDPR). FlyStandby is operated from Belgium; the lead supervisory authority is the Belgian Data Protection Authority.
Belgian DPA
Lead Supervisory Authority
We encourage you to contact us first at [email protected] so we can try to resolve your concern directly.
Changes to This Notice
We may update this GDPR Notice from time to time to reflect changes in our data processing practices or applicable law. For material changes we publish a prominent notification on the website and update the "Last updated" date. We may also notify you by email.
Contact
For any questions, concerns, or requests related to this GDPR Notice or your personal data: [email protected].
