Privacy Policy
Last updated · July 2026
Introduction
At FlyStandby.app ("FlyStandby"), we take the security and privacy of your data seriously and are fully committed to adhering to the General Data Protection Regulation (GDPR) and all relevant privacy laws. This document outlines exactly what personal information we gather, our protocols for storing and securing it, the reasons we process it, and the third parties with whom it may be shared. It also explains your rights to access, modify or erase your personal data and manage your communication settings.
Application. This Privacy Policy governs your access to and use of flystandby.app (the "Website") and the FlyStandby mobile application (the "App"), including all related products, features, and services (collectively, the "Service").
Your Personal Data
Definition
Your Consent
Legal Bases
Source
Data We Collect
Full Name
Required
Email Address
Required
Current Airline Employer
Optional
Subscription & Payment Data
Withdrawal Waiver Records
Additional Information
Device Fingerprint
Referral & Attribution Data
Session & Connection Data
Push Notification Tokens
How Your Data Is Used
We use the information you provide for the following reasons:
- Communication. We use your email and details to set up your account and send updates. Occasionally we may send news we think you'll like; you can always unsubscribe.
- Verification. If we cannot verify your identity automatically, we may ask for additional proof (e.g. an airline ID). It is deleted immediately after review.
- Fraud Protection. We use security measures including persistent device identifiers stored as cookies, connection metadata (IP, browser), and device fingerprinting (canvas rendering characteristics, graphics adapter info). Fingerprints are generated locally in your browser and stored as a hash — they don't identify you personally but help detect patterns across sessions. If fraud occurs we may share the minimum data required with the victim and will alert you before doing so.
- Storage & Retention. We retain your personal data for the duration of your membership. On account deletion, all personal data is permanently removed immediately, with the following exceptions retained for legitimate purposes: email (to prevent re-registration abuse), IP and device identifiers (fraud prevention), and transaction records (Belgian tax law, 7 years). Verification photos are deleted on review; analytics IPs are anonymised after 90 days; expired load requests are kept 12 months; session data is kept 90 days. Full details in our GDPR Notice.
Sharing of Your Personal Data
Third-Party Service Providers
To provide the service we work with select partners. We only share information with these companies when it is necessary to deliver the features and services you use.
Cloudflare
USA · CDN
Stripe
USA · Payments
USA · Analytics
Meta Platforms
USA · Advertising measurement
We report events such as account creation, flight searches, purchases and subscription starts, together with a hashed email address, our internal user ID, and — where an ad click brought you here — the click identifier Meta attaches to its own ad links. We never send your name, your itineraries or your load data.
If you are in the EEA, the UK or Switzerland: none of this happens until you opt in. On the website that means accepting marketing cookies; in the mobile app it means allowing tracking when the app asks (Apple's App Tracking Transparency prompt). Decline, and nothing is shared.
Elsewhere: measurement is on by default and you can turn it off at any time — from the cookie banner and cookie settings on the website, or under Preferences, in the Privacy section, in the app. Turning it off also deletes the click identifier we stored.
Your device advertising identifier (IDFA) is only ever used if you allowed tracking at the App Tracking Transparency prompt, in every country, with no exception. Declining that prompt does not otherwise change how the app works for you. The app also reports standard device characteristics (model, OS version, language, timezone, screen size).
AeroDataBox
Germany · Flight Data
Brevo (Sendinblue)
France · Email
Apple
USA · Distribution & IAP
Hetzner Online GmbH
Germany · Hosting
All processors adhere to GDPR and are bound by data processing agreements. Transfers to the United States rely on the EU-US Data Privacy Framework (where applicable) and on Standard Contractual Clauses approved by the European Commission. We do not grant data access to any other third parties.
Non-Personal Data
We may share general data trends with our trusted partners. When we do, the information is fully anonymised so it cannot be traced back to you. We also use this general data to spot bugs and resolve technical problems.
Personal Data Protection
Keeping your data safe is a top priority. We take strong measures to prevent unauthorised access, modification, or destruction. Connections are protected with TLS; data is secured behind passwords and digital signatures; internal access is granted on a need-to-know basis. We follow established best practices for handling and storing information.
Cookies
We use cookies to optimise your interaction with our Website. You can configure your browser to reject cookies; doing so may impede certain features.
- Strictly Necessary. Critical for the fundamental performance of the platform — navigation, authentication, fraud prevention.
- Analytical. Anonymous visitor statistics used to refine the product.
- Marketing / Tracking. Conversion tracking and retargeting via Meta Pixel and similar pixels. Only activated when you consent.
For details, see our Cookie Policy.
Third-Party Websites
You may encounter links or ads that take you to other services. We are not responsible for the content or practices of those sites. If you provide personal information on a linked site, you are agreeing directly with that site, which acts as the Merchant of Record and applies its own policies.
Modifications to This Policy
FlyStandby reserves the right to amend this Privacy Policy at any time. For material changes we will publish a prominent notification on the Website with the revised document and may notify you by email. Continued use may require formal acknowledgment of the updated terms.
Your Rights and Data Management
In compliance with the GDPR, you retain full rights regarding your personal data:
- Right to access — Request a copy of your personal data.
- Right to rectification — Request correction of inaccurate data.
- Right to erasure — Request deletion of your personal data.
- Right to restrict processing — Limit how we use your data.
- Right to object — Object to processing based on legitimate interests (Art. 6.1f GDPR).
- Right to data portability — Receive your data in a structured, machine-readable format.
To exercise any of these rights, contact us at [email protected]. If we have not addressed your concern, you have the right to lodge a complaint with a supervisory authority in your country of residence or the place of the alleged infringement.
Contact
Questions, comments, or concerns about how we handle your personal data: [email protected].
