This policy describes how FlightBook (“the Service”) collects, uses, retains and protects your personal data when you use the digital logbook application. We built FlightBook around a simple principle: collect only the data strictly necessary to track your flying activity, and host it ourselves rather than scattering it across third parties.
1. Data controller
The controller of the data collected through FlightBook is [to be completed: legal/company name of the publisher, legal form, registered address, registration number].
For any question about your personal data or to exercise your rights, you can write to us at [to be completed: contact email address].
2. Data we collect
We only collect data that you enter yourself or that is technically necessary for the Service to work. No data is purchased from third parties, and no advertising profiling is carried out.
2.1 Account and identity data
- Identity: last name, first name, email address, and where applicable postal address and pilot licence number (fields required by the EASA FCL.050 regulatory format).
- Authentication: password (never stored in clear text, kept as a hashed digest); session tokens.
- Preferences: interface language (EN/FR), time zone, display and notification settings.
2.2 Flying activity data
- Logbook: flight dates, departure and arrival aerodromes (ICAO codes), times, aircraft used, flight functions, conditions (IFR/VFR, day/night), landings, and FCL.050 fields (SPIC, PICUS, FE, simulator time).
- Ratings and licences: licence and rating types, validity dates and associated certifications, including the validity dates of your medical certificate, in order to calculate recency and alert you before expiry.
- Training: for students of an organisation, the progress record (exercise validation, assessments, session debriefs, milestones and solo authorisations).
- Relationships: instructor–student links and membership of an organisation (school, flying club, association).
2.3 Cryptographic signature data
- Public signature key (stored in clear text, required to verify signatures).
- Encrypted private key: your private key is never transmitted or stored in clear text. It is encrypted in your browser with a key derived from your password (PBKDF2 + AES-GCM) before being sent to our servers. We cannot decrypt it.
2.4 Technical data and logs
- Audit log: traceability of sensitive actions (logins and failed attempts, flight creation/deletion, operations on cryptographic keys, subscription events), with timestamp and IP address.
- Security: IP address used for rate limiting on authentication endpoints to prevent abuse.
- Email log: history of transactional emails sent to your account (recipient, subject, delivery status), for support and proof-of-delivery purposes.
2.5 Subscription and payment data
If you subscribe to a paid plan, we keep the status of your subscription (plan, billing period, dates). Full banking details are never processed or stored by FlightBook: payment is delegated to a specialised provider (see section 4).
3. Purposes and legal bases
Each processing activity relies on a legal basis within the meaning of Article 6 GDPR:
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, providing the logbook and its features | Performance of the contract (Terms of Service) |
| Keeping the logbook, ratings and recency in line with EASA FCL requirements | Performance of the contract / legal and regulatory obligation applicable to the pilot |
| Signature and validation of flights by instructors | Performance of the contract |
| Training tracking (progress record) within an organisation | Performance of the contract / legitimate interest of the training organisation |
| Security, fraud prevention, rate limiting and audit log | Legitimate interest in keeping the Service secure |
| Subscription and billing management | Performance of the contract / legal (accounting) obligation |
| Sending transactional emails (account activation, password reset, expiry alerts, notifications) | Performance of the contract / legitimate interest |
4. Recipients and processors
Your data is never sold, rented or transferred for commercial purposes. It is accessible only to the people authorised to process it (you, your instructor or your organisation within the limits of your training relationship, and our technical team strictly as needed to operate and support the Service).
FlightBook relies on a deliberately small number of processors:
| Processor | Role | Data concerned |
|---|---|---|
| Cloudflare, Inc. | Hosting and delivery of the web interface (front-end); anti-bot and anti-abuse
protection (“challenge”) on the authentication pages /auth/*. |
Technical connection data (IP address, request headers, security signals) when accessing the site and the authentication pages. |
| Stripe (Stripe Payments Europe, Ltd.) | Processing of payments for paid subscriptions. This service will be enabled when the paid plans go live. | Data required for payment (billing identity, card data processed directly by Stripe, never by FlightBook), subscription status. |
Apart from Cloudflare and Stripe, the entire back-end and database are hosted on our own infrastructure (“on premise”). Transactional emails are routed through our own outgoing mail server: no third-party email router is involved. We use no third-party analytics, advertising or behavioural tracking tools.
We may also disclose data where required by law, or upon request from a competent judicial or administrative authority.
5. Hosting and data location
Your logbook, account, signature and training data are stored in a PostgreSQL database hosted on our own infrastructure. Only the delivery of the web interface and the security filtering of the authentication pages pass through Cloudflare's network.
6. Retention periods
- Account and logbook data: kept for as long as your account is active. A logbook and the associated regulatory records have long-term evidential value; you remain in control of deleting or exporting them at any time.
- Training data: kept for the regulatory archiving period applicable to training organisations (as an indication, 3 years for progress records), then archived or deleted according to the organisation's obligations.
- Audit log: kept for a limited period defined by a retention policy, then purged automatically.
- Billing data: kept for the period required by accounting and tax obligations (generally 10 years).
- Inactive or deleted account: when your account is closed, your data is deleted or anonymised, subject to the legal retention periods above.
7. Data security
We implement appropriate technical and organisational measures:
- End-to-end encryption of exchanges over HTTPS/TLS.
- Passwords stored as hashed digests, never in clear text.
- Flight signing through public-key cryptography (ECDSA P-256): once signed, a flight cannot be modified without invalidating the signature.
- Private signature key encrypted in the browser (PBKDF2 300,000 iterations + AES-GCM) before any transmission: our servers cannot decrypt it.
- Role-based access control (RBAC), rate limiting on authentication, and an audit log of sensitive actions.
- Controlled hosting on dedicated infrastructure, with regular backups.
8. Cookies and trackers
FlightBook uses no advertising cookies and no third-party analytics trackers. Only means strictly necessary to the operation and security of the Service are used:
- Session cookie (HttpOnly): essential to keep you signed in; it is not accessible to the page's JavaScript.
- Cloudflare security cookies: set during the anti-abuse “challenge” on the authentication pages
/auth/*to tell legitimate users from bots. - Local storage (localStorage): storing non-sensitive preferences (language, display theme), kept on your device.
As these are strictly necessary, they do not require prior consent. You can delete them through your browser settings, at the cost of degraded operation (sign-out, loss of preferences).
9. Transfers of data outside the European Union
Our servers and database are located within the European Union. The use of Cloudflare (and, in due course, Stripe) may involve a transfer of, or access to, certain technical data outside the EU. These transfers are governed by the appropriate safeguards provided for by the GDPR, in particular the European Commission's standard contractual clauses.
10. Your rights
In accordance with the GDPR, you have the following rights over your data:
- Right of access: obtain a copy of the data concerning you.
- Right to rectification: correct inaccurate or incomplete data — much of it is directly editable from your profile.
- Right to erasure: request deletion of your data, subject to legal retention obligations.
- Right to restriction and right to object to processing, under the conditions set by law.
- Right to portability: retrieve your data in a structured format; the Service notably offers logbook export (CSV, EASA FCL.050 PDF).
- Right to set directives regarding the fate of your data after your death.
To exercise these rights, contact us at the address given in section 1. We may ask you to prove your identity, and we will respond within one month.
11. Complaint to the supervisory authority
If you believe that the processing of your data does not comply with the regulation, you have the right to lodge a complaint with the French data protection authority (CNIL) — www.cnil.fr — or with the data protection authority of your country of residence.
12. Changes to this policy
We may update this policy to reflect changes to the Service or to the regulation. The last-updated date appears at the top of the page. In the event of a substantial change, we will inform you by an appropriate means (email or in-app notification).