Skip to main content
FlyStandby
Legal · Privacy

Privacy Policy

Last updated · July 2026

Section 01

Introduction

At FlyStandby.app ("FlyStandby"), we take the security and privacy of your data seriously and are fully committed to adhering to the General Data Protection Regulation (GDPR) and all relevant privacy laws. This document outlines exactly what personal information we gather, our protocols for storing and securing it, the reasons we process it, and the third parties with whom it may be shared. It also explains your rights to access, modify or erase your personal data and manage your communication settings.

Application. This Privacy Policy governs your access to and use of flystandby.app (the "Website") and the FlyStandby mobile application (the "App"), including all related products, features, and services (collectively, the "Service").

Section 02

Your Personal Data

Definition

For the purposes of this Policy, "personal data" refers to any information or combination of data points that can be used to identify you as a specific individual.

Your Consent

We only collect or disclose your data with your prior approval. By creating an account you agree to let us collect and manage your information as outlined here. You may withdraw that agreement at any time.

Legal Bases

We rely on three legal grounds to process your data: your provided consent; the necessity to deliver the services you signed up for (performance of a contract); and our legitimate interest in maintaining system security by identifying you as a user.

Source

FlyStandby gathers personal data when you register a new account or update existing details via our online forms. The categories below are mandatory for secure access, relevant updates, payments, and continued service development.
Section 03

Data We Collect

Full Name

Required

We use your name to identify you, contact you when necessary, and ensure we can fulfil your service requests.

Email Address

Required

Used to create the account, for direct electronic communication, and to verify your identity for secure automated password resets.

Current Airline Employer

Optional

Used to filter and display open requests that match your eligibility. Only stored if you choose to configure it.

Subscription & Payment Data

When you purchase SkyCredits or subscribe to a plan (Pro or Max), we process payment information through Stripe (website) or Apple (App Store in-app purchases). We do not store full credit card numbers. We retain transaction records — purchase amounts, subscription status, billing period, payment method type — for accounting and service delivery.

Withdrawal Waiver Records

For Stripe purchases, we record the express consent and acknowledgment of waiver of the 14-day right of withdrawal collected at checkout, together with the timestamp, IP address and browser. See our Right of Withdrawal policy.

Additional Information

Certain services may require us to request further details. We only process additional information if you choose to submit it.

Device Fingerprint

A hash derived from browser/device characteristics (canvas rendering, graphics adapter). Generated locally and stored as a hash for fraud detection — it doesn't identify you personally.

Referral & Attribution Data

If you arrive via a referral link, advertising campaign, or partner site, we store the associated parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term, and the referrer) so we can measure attribution and credit the correct referrer.

Session & Connection Data

When you sign in, your session record includes the IP address and browser user-agent used to create the session. This is retained for session validity and security.

Push Notification Tokens

If you opt in to push notifications, we store the browser or device push subscription (endpoint plus public keys) so we can deliver alerts you've subscribed to. Deleting the browser subscription or uninstalling the app removes it server-side on next sync.
Section 04

How Your Data Is Used

We use the information you provide for the following reasons:

  • Communication. We use your email and details to set up your account and send updates. Occasionally we may send news we think you'll like; you can always unsubscribe.
  • Verification. If we cannot verify your identity automatically, we may ask for additional proof (e.g. an airline ID). It is deleted immediately after review.
  • Fraud Protection. We use security measures including persistent device identifiers stored as cookies, connection metadata (IP, browser), and device fingerprinting (canvas rendering characteristics, graphics adapter info). Fingerprints are generated locally in your browser and stored as a hash — they don't identify you personally but help detect patterns across sessions. If fraud occurs we may share the minimum data required with the victim and will alert you before doing so.
  • Storage & Retention. We retain your personal data for the duration of your membership. On account deletion, all personal data is permanently removed immediately, with the following exceptions retained for legitimate purposes: email (to prevent re-registration abuse), IP and device identifiers (fraud prevention), and transaction records (Belgian tax law, 7 years). Verification photos are deleted on review; analytics IPs are anonymised after 90 days; expired load requests are kept 12 months; session data is kept 90 days. Full details in our GDPR Notice.
Section 05

Sharing of Your Personal Data

FlyStandby does not engage in the commercialisation of user data. We do not transfer, lease, or exchange personal information with external parties for monetary gain.
Section 06

Third-Party Service Providers

To provide the service we work with select partners. We only share information with these companies when it is necessary to deliver the features and services you use.

Cloudflare

USA · CDN

Content delivery, edge security, DDoS mitigation.

Stripe

USA · Payments

Payment processing for web purchases, subscriptions, and refunds.

Google

USA · Analytics

Anonymised website analytics.

Meta Platforms

USA · Advertising measurement

Measures which of our own advertising campaigns bring people to FlyStandby.

We report events such as account creation, flight searches, purchases and subscription starts, together with a hashed email address, our internal user ID, and — where an ad click brought you here — the click identifier Meta attaches to its own ad links. We never send your name, your itineraries or your load data.

If you are in the EEA, the UK or Switzerland: none of this happens until you opt in. On the website that means accepting marketing cookies; in the mobile app it means allowing tracking when the app asks (Apple's App Tracking Transparency prompt). Decline, and nothing is shared.

Elsewhere: measurement is on by default and you can turn it off at any time — from the cookie banner and cookie settings on the website, or under Preferences, in the Privacy section, in the app. Turning it off also deletes the click identifier we stored.

Your device advertising identifier (IDFA) is only ever used if you allowed tracking at the App Tracking Transparency prompt, in every country, with no exception. Declining that prompt does not otherwise change how the app works for you. The app also reports standard device characteristics (model, OS version, language, timezone, screen size).

AeroDataBox

Germany · Flight Data

Flight schedules, route data, status data.

Brevo (Sendinblue)

France · Email

Transactional and marketing email delivery.

Apple

USA · Distribution & IAP

iOS app distribution and in-app purchases.

Hetzner Online GmbH

Germany · Hosting

Primary database hosting and file storage for the Service. Data is processed within the European Union.

All processors adhere to GDPR and are bound by data processing agreements. Transfers to the United States rely on the EU-US Data Privacy Framework (where applicable) and on Standard Contractual Clauses approved by the European Commission. We do not grant data access to any other third parties.

Section 07

Non-Personal Data

We may share general data trends with our trusted partners. When we do, the information is fully anonymised so it cannot be traced back to you. We also use this general data to spot bugs and resolve technical problems.

Section 08

Personal Data Protection

Keeping your data safe is a top priority. We take strong measures to prevent unauthorised access, modification, or destruction. Connections are protected with TLS; data is secured behind passwords and digital signatures; internal access is granted on a need-to-know basis. We follow established best practices for handling and storing information.

Section 09

Cookies

We use cookies to optimise your interaction with our Website. You can configure your browser to reject cookies; doing so may impede certain features.

  • Strictly Necessary. Critical for the fundamental performance of the platform — navigation, authentication, fraud prevention.
  • Analytical. Anonymous visitor statistics used to refine the product.
  • Marketing / Tracking. Conversion tracking and retargeting via Meta Pixel and similar pixels. Only activated when you consent.

For details, see our Cookie Policy.

Section 10

Third-Party Websites

You may encounter links or ads that take you to other services. We are not responsible for the content or practices of those sites. If you provide personal information on a linked site, you are agreeing directly with that site, which acts as the Merchant of Record and applies its own policies.

Section 11

Modifications to This Policy

FlyStandby reserves the right to amend this Privacy Policy at any time. For material changes we will publish a prominent notification on the Website with the revised document and may notify you by email. Continued use may require formal acknowledgment of the updated terms.

Section 12

Your Rights and Data Management

In compliance with the GDPR, you retain full rights regarding your personal data:

  • Right to access — Request a copy of your personal data.
  • Right to rectification — Request correction of inaccurate data.
  • Right to erasure — Request deletion of your personal data.
  • Right to restrict processing — Limit how we use your data.
  • Right to object — Object to processing based on legitimate interests (Art. 6.1f GDPR).
  • Right to data portability — Receive your data in a structured, machine-readable format.

To exercise any of these rights, contact us at [email protected]. If we have not addressed your concern, you have the right to lodge a complaint with a supervisory authority in your country of residence or the place of the alleged infringement.

Section 13

Contact

Questions, comments, or concerns about how we handle your personal data: [email protected].