FlightHours
PilotsOrganisations
PricingSign inStart free

PRIVACY NOTICE · V0.1.0

Your information and FlightHours.

This notice explains what personal information we use, why we use it, who receives it, how long we keep it and the choices available to you.

Effective
10 August 2026
Applies to
Pilots and organisation users
Jurisdiction
United Kingdom
Contents
1. Who we are2. Scope and roles3. Information we collect4. Uses and lawful bases5. Health information6. Sharing7. International transfers8. Retention9. Security10. Cookies and local storage11. Your rights12. Complaints13. Changes
Production configuration required

Set the missing operator details before launch: legal entity name, entity type and jurisdiction, registered or trading address, legal contact email, privacy contact email.

We collect

Account, pilot, organisation, logbook, training, document, billing and security information.

We do not do

No advertising profiles, sale of personal information or solely automated legal or regulatory decisions.

Your controls

Correct records, export your account, manage sessions and request deletion from Settings.

1Who we are and how to contact us

FlightHours operator, operator details to be configured before production, operates FlightHours and is the controller for personal information used to provide accounts, billing, product security and personal pilot workspaces.

Registered or trading address
Address to be configured before production
General and legal enquiries
Legal contact to be configured before production
Privacy requests and complaints
Privacy contact to be configured before production

2Scope and controller roles

This notice covers the FlightHours website, pilot application, organisation workspaces, branded organisation portals and related support and billing communications.

For a personal pilot workspace, FlightHours normally decides why and how personal information is used. For an organisation workspace, the club, ATO or DTO may be the controller for member, student, staff and organisation records it chooses to enter. FlightHours remains an independent controller for account identity, security, fraud prevention, billing and service administration. Where FlightHours processes organisation data only on the organisation’s instructions, the parties must put an appropriate data-processing agreement in place.

Private pilot records

Joining an organisation does not, by itself, give that organisation access to a pilot’s private logbook, medical, documents or other personal workspace records. Access requires a specific product feature and an explicit authorised grant.

3Personal information we collect

Account and profile

  • Name, email address and authentication identifiers
  • Password hash, verification state, MFA state and recovery data
  • Country, timezone, preferences, home airport and onboarding answers
  • Terms, privacy and health-data consent records

Pilot records

  • Flights, aircraft, routes, crew, approaches, landings, remarks and revisions
  • Opening balances, qualifications, ratings and theory attempts
  • Training records, goals, evidence, recommendations and progress snapshots
  • Costs, budgets, uploaded documents and file metadata
  • Medical class, issue/expiry dates and evidence status; we do not ask for diagnoses or medical history

Organisation information

  • Organisation identity, type, CAA approval reference and locations
  • Membership, role, invitation, training, aircraft-register, document and compliance records
  • Branding, portal configuration and organisation billing information

Technical and service information

  • Session, device, browser, IP-derived security and request information
  • Audit events, error codes, rate-limit and security events
  • Subscription, entitlement, invoice and payment-status information
  • Support correspondence and privacy or deletion requests

Sources

Most information comes directly from you. We also receive information from an organisation owner or administrator, records you import, payment and subscription events from Stripe when enabled, and technical events generated when the service is used. We do not obtain official licensing or medical decisions from a regulator unless a future integration is clearly disclosed.

4How we use information and our lawful bases

PurposeInformationUK GDPR basis
Create accounts, authenticate users and deliver requested workspacesAccount, profile, pilot and organisation recordsContract; steps at your request before contract
Store records, calculate totals, build journey snapshots and provide requested exportsLogbook, training, documents, goals and preferencesContract
Process plans, trials and billingIdentity, plan, subscription and payment statusContract; legal obligation for tax and accounting records
Protect accounts, investigate abuse, prevent fraud and preserve audit historySessions, security events, limited account and audit dataLegitimate interests in operating a secure and accountable service; legal obligation where applicable
Send verification, security, expiry and service messagesEmail, preferences, account and relevant expiry stateContract; legitimate interests for important service and security notices; consent where required for marketing
Respond to rights requests, disputes and authoritiesAccount, request, audit and correspondence dataLegal obligation; establishment, exercise or defence of legal claims
Improve reliability and understand feature performanceMinimised technical and aggregated usage informationLegitimate interests, after balancing necessity against your rights

Where we rely on legitimate interests, you may ask for information about the balancing assessment. We do not use consent where the processing is necessary to provide the service or comply with law.

5Medical and other special-category information

Medical class and medical certificate dates may reveal health information and are treated as special-category data. We process these fields only when you choose to add them and give explicit consent for the stated record-keeping and expiry-tracking purposes (UK GDPR Article 9(2)(a)), alongside the Article 6 basis described above.

  • Entry is optional and the product asks you not to enter diagnoses, treatment or medical history.
  • Sensitive revision payloads are encrypted and are not returned through ordinary list APIs.
  • You may withdraw consent by contacting us and may archive or request deletion of the record. Withdrawal does not make earlier lawful processing unlawful and some limited data may be retained where law permits or requires.
  • FlightHours does not provide medical advice or determine medical fitness.

5AAutomated analysis and recommendations

FlightHours uses deterministic software rules to calculate totals, compare records with a selected rule-pack fixture, classify possible evidence and rank suggested next actions. The system can show the contributing records, exclusions, rule version and confidence state. These outputs are advisory planning information only. They do not produce a legal, licensing, employment or medical decision and are not a substitute for an instructor, ATO or DTO, examiner, medical professional or regulator.

6Who receives personal information

We disclose only what is reasonably necessary to:

  • Infrastructure and service providers: hosting, database, private-file storage, email delivery, security monitoring, malware scanning and customer support providers configured for the production service.
  • Stripe: payment and subscription processing. FlightHours does not receive or store complete payment-card numbers.
  • Your organisation: information in an organisation workspace, or pilot information covered by a specific authorised access grant. Private pilot data is not shared merely because you are a member.
  • Professional advisers and authorities: where necessary for legal advice, audit, insurance, a legal claim, regulatory obligation, court order or the prevention or investigation of unlawful activity.
  • Corporate transactions: to a prospective buyer, investor or successor subject to confidentiality and continued protection.

We do not sell personal information, share it with data brokers, or use it for third-party behavioural advertising. Production subprocessors and their locations must be recorded in the deployment’s subprocessor register.

7International transfers

Production providers may process information outside the United Kingdom. Before making a restricted transfer, we will use a lawful mechanism such as UK adequacy regulations or appropriate safeguards, which may include the UK International Data Transfer Agreement or the UK Addendum, and complete the required data-protection test. You may contact the privacy address for information about the mechanism applying to a particular transfer.

8How long we keep information

RecordTypical retention approach
Account and pilot contentWhile the account is active, then deleted or de-identified following an accepted deletion request unless an exception applies.
Uploaded private filesWhile the related active or archived record is retained; file bytes are removed through account deletion where applicable.
Sessions and security eventsFor the active security lifecycle and then for a limited period needed to investigate incidents and protect the service.
Billing, tax and transaction recordsFor the period required by tax, accounting, anti-fraud and legal-claims obligations.
Consent and legal acceptance recordsFor as long as needed to demonstrate the version, decision and context of consent or contract acceptance.
De-identified audit eventsWhere necessary to preserve system integrity and accountability without retaining the user’s identity or record contents.
BackupsUntil overwritten or expired under the approved backup schedule; deleted data is not restored into the live service except for disaster recovery and is removed again when practicable.

FlightHours uses an approved retention-policy register rather than inventing automatic periods. We may retain information longer where required for law, a dispute, fraud prevention or the establishment, exercise or defence of legal claims. Account deletion has a 14-day cooling-off period and can be cancelled before execution.

9Security

Measures include scoped authorisation, password hashing, optional multi-factor authentication, encrypted sensitive revision data, private file storage, request forgery protection, rate limiting, session controls, audit history, security-focused logging and recoverable backups. No service can guarantee absolute security. If we identify a personal-data breach, we will assess it and notify affected people and the ICO when required by law.

10Cookies, device storage and analytics

FlightHours uses strictly necessary cookies and similar storage for authentication, request security, organisation portal access, preferences, offline state and recoverable local flight drafts. These are required to provide or secure features you request. The current product does not use third-party advertising cookies or a third-party behavioural analytics SDK. If non-essential analytics or marketing technologies are introduced, we will update this notice and obtain consent where PECR requires it.

11Your data-protection rights

Depending on the circumstances, you may ask us to:

  • provide access to your personal information and supplementary information;
  • correct inaccurate or incomplete information;
  • erase information, or restrict how it is used;
  • provide information you supplied in a portable format;
  • stop processing based on consent by withdrawing that consent;
  • object to processing based on legitimate interests or to direct marketing; and
  • review a qualifying decision made solely by automated means.

Rights are not absolute and lawful exemptions may apply. We may need to verify your identity. You can correct many records, prepare a full account export, manage sessions and schedule account deletion from Settings. Otherwise contact Privacy contact to be configured before production. We normally respond within the period required by law and do not charge unless a request is manifestly unfounded, excessive or repeated where the law permits a fee.

12Privacy complaints

Send a complaint to Privacy contact to be configured before production with enough information for us to investigate. We will acknowledge it, investigate fairly and provide an outcome. If you remain unhappy, you may complain to the UK Information Commissioner’s Office through the ICO complaint service or call 0303 123 1113. You may also have the right to seek a judicial remedy.

12AChildren

FlightHours is not designed for children to open paid accounts independently. If a user is under 18, their parent or guardian and, where relevant, their training organisation should ensure they have the legal capacity and appropriate permission to use the service. Do not enter information about a child unless you are authorised and have provided the required privacy information.

13Changes to this notice

We may update this notice to reflect changes in law, providers or product features. Material changes will be presented in the service or sent to the account email where appropriate. The version and effective date at the top identify the notice that applies. Earlier acceptances remain recorded against the version shown at the time.

Read the Terms of Service →

FlightHours
For pilotsFor organisationsPricingPrivacyTermsSign in
© 2026 FlightHours · v0.1.0Planning support only. UK example rules remain unverified.A clearer record of where you have been—and what could come next.