Back to homepage

Privacy policy

Introduction

Welcome to FlightShield (“the Platform”). This privacy policy (“the Policy”) explains how FlightShield Ltd (“we”, “us”, or “our”) collects, uses, shares, and protects your personal data when you visit our website and use our application. We respect your privacy and are committed to protecting your personal data.

The data we collect

We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped together as follows:

  • Identity data: Includes your first name, last name, and username or similar identifier.
  • Contact data: Includes your email address.
  • Aviation data: Includes your flight hours, personal minimums, aircraft type, and route history inputted into the Platform to generate risk briefings.
  • Financial data: Includes details about your subscription status. Please note that all payment processing is handled securely by our third-party payment processor (“Stripe”), and we do not store your full credit card details on our servers.
  • Technical and usage data: Includes your internet protocol address, browser type and version, time zone setting, operating system, and detailed information about how you use and interact with the Platform.

How we use your data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • To register you as a new user and manage your account.
  • To provide the core services of the Platform, including generating tailored Threat and Error Management briefings based on your aviation data.
  • To process your subscription payments and manage billing via Stripe.
  • To improve our website, products, services, marketing, and customer relationships.

We will never sell your personal data to any third party under any circumstances.

Session replay and marketing analytics

To help us understand how users navigate the Platform and to improve the overall user experience, we use analytics and session replay tools, such as Microsoft Clarity. These tools capture website usage data, including mouse movements, clicks, scroll depth, and basic navigation patterns. This data is used solely for our internal marketing, troubleshooting, and product development purposes. The session replay tools mask sensitive keystrokes (such as passwords and payment details) to ensure your privacy is maintained.

Our lawful basis for processing

Under the UK GDPR, we rely on the following lawful bases to process your personal data:

  • Performance of a contract: Where we need to perform the contract we are about to enter into or have entered into with you (e.g. providing your flight briefings).
  • Legitimate interests: Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests (e.g. using session replay to improve the Platform).
  • Consent: Where you have provided specific consent, such as for direct email marketing. You have the right to withdraw consent at any time.

Who we share your data with

We do not sell your data. We may share your personal data with trusted third parties who act as data processors to facilitate our services. These include our database and authentication providers (such as Supabase), our payment processor (Stripe), and our analytics providers (such as Microsoft Clarity). We require all third parties to respect the security of your personal data and to treat it in accordance with the law of England and Wales.

Data security and retention

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.

Your legal rights

Under certain circumstances, you have rights under UK data protection laws in relation to your personal data, including the right to:

  • Request access to your personal data.
  • Request correction of the personal data that we hold about you.
  • Request erasure of your personal data.
  • Object to processing of your personal data.
  • Request restriction of processing of your personal data.
  • Request the transfer of your personal data to you or to a third party.

If you wish to exercise any of the rights set out above, please contact us using the details below. You also have the right to make a complaint at any time to the Information Commissioner's Office (“the ICO”), the UK supervisory authority for data protection issues.

Contact us

If you have any questions about the Policy or our privacy practices, please contact us at our email address