Effective September 17, 2026

Privacy policy

This policy explains what FAA Ready, operated by [[FILL: legal entity name]], collects about the people who visit this site and use the service, why, who processes it, how long we keep it and what rights you have. We collect what the service needs to work and nothing for advertising.

1. Who we are and what this covers

FAA Ready is a compliance record-keeping service for aviation organizations. This policy covers this marketing site, the application at the same domain and the API. It applies to visitors, to the people your organization invites into the service (“users”) and to people who contact us.

For customer data, the records your organization puts into the service, your organization decides what is stored and why; we process it on your organization’s behalf under the terms of service.

2. What we collect

Account information: name, work email, password (stored hashed), locale and theme preferences, role and the organization you belong to. If you sign in with Google or Microsoft we receive your name, email and a provider id from them.

Customer data: the records your organization enters or uploads: people, training, tooling, materials, vendors, safety reports, aircraft, manuals and attached files. This can include names, job titles, certificate numbers and signatures of your personnel.

Usage and security data: IP address, browser type, pages requested, timestamps and the actions you take in the application, written to server logs and to the audit log that is part of the product.

Billing: when your organization adds a card, Stripe collects the card details directly; we receive a customer id, the card brand and last four digits, and payment status.

Contact requests: what you type into the contact form (name, email, company, certificate type, message) plus your IP address and browser, used to answer you and to filter abuse.

3. How we use it

To provide the service, authenticate users, send the notifications and reminders the service is for, bill your organization, answer your requests, keep the service secure, meet legal obligations and improve the product using aggregated statistics. We do not sell personal data, do not show advertising and do not train language models on customer data.

4. Cookies

We set only cookies the service needs: a session cookie that keeps you signed in (HTTP-only and secure), a fl_theme cookie that remembers light or dark mode and a fl_locale cookie that remembers English or Spanish. There are no advertising or cross-site tracking cookies and no third-party analytics scripts on this site.

5. Processors we use

Vercel, Inc. hosts the application and this site. Neon, Inc. hosts the PostgreSQL database that stores account and customer data. Vercel Blob stores uploaded files. Stripe, Inc. processes payments and stores card details. Resend, Inc. delivers the emails the service sends. Google and Microsoft handle sign-in if your organization uses it.

Each processor acts on our instructions under a written agreement and its own privacy terms. Data is stored in the United States.

6. When we share data

With the processors above, to run the service. Within your organization, according to the roles your administrators assign, and with inspectors your organization chooses to share a read-only binder with. When the law requires it, or to protect the rights and safety of users and the public. If the business is sold or merged, with the successor under the same commitments. Never for sale or advertising.

7. How long we keep it

Account and customer data are kept for as long as your organization has an active or paused subscription. After cancellation we keep records available for export for [[FILL: retention period after cancellation, e.g. 60 days]], then delete them from the live database; backups expire on their normal schedule within [[FILL: backup retention, e.g. 30 days]] after that. Server logs are kept for [[FILL: log retention, e.g. 90 days]]. Contact requests are kept for two years unless you ask us to delete them sooner. Billing records are kept as long as tax law requires.

8. Security

We describe our controls on the security page: tenant isolation, encryption in transit, database backups, signed records with an audit log, role-based access, scoped API keys and signed webhooks. No system is perfectly secure; if we learn of a breach affecting your data we will notify your organization’s owners without undue delay.

9. Your rights

You can see and correct your own account information in the application, and export your organization’s records at any time. You may ask us to access, correct, export or delete personal data we hold about you, or to object to a use of it, by writing to hello@flightline.example; we reply within thirty days. Where you are a user of a customer organization, we may refer your request to that organization, which controls the records. Depending on where you live you may have additional rights under state or national law, including the right to complain to a supervisory authority.

10. Children

The service is for aviation organizations and their personnel. It is not directed at children under sixteen and we do not knowingly collect their data.

11. Users outside the United States

The service is operated from and hosted in the United States. If you use it from elsewhere, your data is transferred to and processed in the United States, where privacy law may differ from your country’s.

12. Changes to this policy

We may update this policy. For material changes we will notify organization owners by email and post a notice in the application at least thirty days before the change takes effect. The effective date at the top always shows the current revision.

13. Contact

Privacy questions and requests: hello@flightline.example

[[FILL: legal entity name]]

[[FILL: mailing address]]