Privacy policy
How SkyField handles the personal data of pilots, instructors, club admins and magazine readers, under the EU General Data Protection Regulation (GDPR).
Last updated: 6 August 2026
Review before launch. This is a starting draft written for a European SaaS that stores member names, email addresses and booking data in the EU. Fill in the bracketed details, check it against how you actually operate, and have a lawyer review it before you go live. It is not legal advice.
Who is responsible for what
SkyField is operated by [legal entity name], [registered address], company number [number], contact [privacy@yourdomain] (“SkyField”, “we”). If we are required to appoint a data protection officer or an EU representative, their details go here.
There are two distinct roles, and the difference matters for your rights:
- We are the controller for your user account, sign-in and security data, the magazine, the newsletter, contact messages and website operation.
- The club or flight school is the controller for what it records inside its own workspace — membership and roles, aircraft, bookings, instructor assignments, flight logs, meter readings, maintenance items, defect reports and its activity log. For that content we act as a processor on the club's instructions. If you want that data corrected or erased, contact your club admin first; we will help, but we will not silently overwrite a club's operational record.
What we collect and why
- Account data — name, email address, a securely hashed password (we never see the plain password), and the sign-in timestamps kept by our authentication provider. Needed to create your account, sign you in, and show fellow club members who holds a booking.
- Club and membership data — club name and description, optional club and aircraft photos, your role (viewer, member, instructor, club admin), membership status and invitation history. Needed to run the club and to decide what you may see.
- Booking, training and maintenance data — aircraft, start and end time, optional purpose, the pilot, an optional instructor and student, attendance confirmations, maintenance and grounding periods with a reason, maintenance items and their sign-offs.
- Flight logs and meter readings — what was recorded after a flight (for example Hobbs or tacho start and end, landings, fuel or oil added, notes) together with who recorded or edited it. Needed to keep the shared fleet's operational record.
- Defect reports — description, severity, when noticed, and who reported it, so the next pilot sees it before flying.
- Invitation data — invited email address, status and timestamps, so invitation links can be single-use and expire.
- Activity log — who created, changed or cancelled a booking, maintenance period, defect or invitation, and when. Clubs need to account for changes to a shared aircraft.
- Notification data — the emails we queued and sent to you (invitations, booking confirmations and cancellations, reminders), their delivery status and your reminder preference.
- Newsletter data — email address, confirmation status and timestamps. Only if you sign up, and only once you confirm by email (double opt-in), as EU rules require.
- Contact messages — your email address, subject and message, so we can reply.
- Anti-abuse data — a salted, irreversible hash of your IP address and email for newsletter signups and contact messages; we do not keep the raw IP for this purpose. Our hosting provider processes standard server logs, including IP addresses, for a short period to keep the service available and secure.
We do not knowingly collect special-category data. Please do not put medical details, licence scans or other sensitive information into free-text fields such as booking purposes, notes or defect descriptions.
Legal basis (GDPR Article 6)
- Contract (Art. 6(1)(b)) — account, club, booking, training, flight log, maintenance, defect and invitation data. The service cannot work without it.
- Consent (Art. 6(1)(a)) — the newsletter. You may withdraw at any time through the unsubscribe link in every email; withdrawal does not affect processing already carried out.
- Legitimate interests (Art. 6(1)(f)) — security logging, abuse and spam prevention, keeping backups, and defending legal claims. We keep this to the minimum needed and balance it against your interests.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose data, for example accounting records or a lawful order.
Operational emails (invitations, booking confirmations and cancellations, reminders) are part of the service, not marketing, so they are sent under contract rather than consent. Reminders can still be switched off on your account page.
Where your data is stored and international transfers
The database, authentication and file storage are hosted by Supabase in the European Union. The website itself is served by our hosting provider, and email is delivered by Resend. Some providers may process limited data (for example server logs or email delivery metadata) outside the EEA; where they do, transfers rely on the European Commission's Standard Contractual Clauses together with additional technical measures such as encryption in transit and at rest. Confirm the exact regions with your providers and state them here before launch.
Who we share it with
We do not sell personal data and we do not use it to train AI models. Our processors are:
- Supabase — database, authentication and file storage (EU region).
- Resend — sending account, invitation, booking, reminder and newsletter email.
- Our hosting provider — serving the website and running server-side code.
- Google Fonts — web fonts are requested from Google's servers, which exposes your IP address to Google. No cookie is set. See the cookie policy.
We have a data processing agreement with each processor. Within a club you belong to, other members can see your name, your role and your bookings; instructors and club admins additionally see training bookings, flight logs and defect reports for that club. Members of other clubs cannot see any of it — access is enforced in the database, not only in the interface. We may also disclose data where legally required, or to establish or defend legal claims.
How long we keep it
- Account data: while your account exists, then deleted or anonymised within 30 days.
- Club, booking, flight log, maintenance and activity data: kept as the club's operational record for as long as the club uses SkyField, and after that for [e.g. 24 months] unless the club asks for earlier deletion. Clubs may have their own aviation record-keeping duties.
- Invitations: expire automatically after 14 days and are then unusable.
- Defect reports: kept with the aircraft's record; resolved defects keep the resolution note.
- Notification records: [e.g. 90 days], so delivery problems can be traced.
- Newsletter: until you unsubscribe. Unconfirmed signups are removed after a short period.
- Anti-abuse hashes: a rolling window of a few hours.
- Contact messages: as long as needed to handle your enquiry, then [e.g. 12 months].
- Encrypted backups: overwritten on a rolling [e.g. 30-day] cycle.
How we protect it
Access is enforced per row in the database with row-level security, so a request can only ever return data the signed-in user is entitled to. Passwords are hashed by our authentication provider, traffic is encrypted with TLS and strict security headers, uploads are restricted by type and size, exported files are sanitised, and administrative actions are logged. No system is perfectly secure; please report anything suspicious to us privately.
Automated decisions
We do not carry out automated decision-making or profiling with legal or similarly significant effects. Booking clash checks, maintenance-due calculations and reminders are simple deterministic rules, not profiling.
Your rights
You may request access, rectification, erasure, restriction, data portability, and object to processing based on legitimate interests. Where processing relies on consent you may withdraw it at any time.
Email [privacy@yourdomain] from the address on your account, or use the contact form. We reply within one month and may extend by two further months for complex requests, telling you why. We may ask for proof of identity where a request is unclear or the risk of wrongful disclosure is real. If the data sits in a club workspace, we will forward your request to that club as its controller. Deleting your account removes your profile and memberships; bookings and flight logs may be retained in a form that no longer identifies you where the club needs the operational record.
You can also complain to your national data protection authority, or to [your lead supervisory authority] where we are established.
Cookies and browser storage
We use only strictly necessary storage to keep you signed in, and no advertising or analytics cookies. Details in the cookie policy.
Children
Accounts are for people aged 18 or over. If a club records a student pilot who is a minor, the club is responsible for having a lawful basis and any parental consent required in its country. Tell us if you believe a child has created an account and we will delete it.
Changes to this policy
We publish changes here and update the date above. Where a change materially affects how we use your data, we notify account holders by email before it takes effect.
