Controller
Aviatefinder UG (haftungsbeschränkt)
Lukas Lehmann
Kuhnkestraße 6
24118 Kiel
Germany
Email address: impressum@Aviatefinder.com
Managing Director: Lukas Lehmann
Legal notice: www.Aviatefinder.com/impressum
Data protection contact: Lukas Lehmann, impressum@Aviatefinder.com
Types of data processed
- Master data, for example names and addresses
- Contact data, for example email addresses and telephone numbers
- Usage data, for example websites visited, interest in content and access times
- Content data, for example text entries, photographs and videos
- Meta and communications data, for example device information and IP addresses
Categories of data subjects
Visitors to and users of the online service (hereinafter, the data subjects are collectively also referred to as “Users”).
Purposes of processing
- Provision of the online service, its functions and content
- Responding to contact enquiries and communicating with Users
- Security measures
- Audience measurement and marketing
Terminology used
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter the “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier such as a cookie, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically every form of handling data.
“Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data is not attributed to an identified or identifiable natural person.
“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data.
“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.
Relevant legal bases
In accordance with Article 13 GDPR, we inform you of the legal bases for our data processing. Unless the legal basis is specified in this Privacy Policy, the following applies: the legal basis for obtaining consent is Article 6(1)(a) and Article 7 GDPR; the legal basis for processing for the performance of our services, the implementation of contractual measures and responding to enquiries is Article 6(1)(b) GDPR; the legal basis for processing for compliance with our legal obligations is Article 6(1)(c) GDPR; and the legal basis for processing for the purposes of our legitimate interests is Article 6(1)(f) GDPR. Where processing of personal data is necessary in order to protect the vital interests of the data subject or another natural person, Article 6(1)(d) GDPR serves as the legal basis.
Security measures
In accordance with Article 32 GDPR, taking account of the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data as well as access, input, disclosure, availability and separation in relation to the data. We have also established procedures to ensure the exercise of data-subject rights, deletion of data and responses to risks to the data. We further take the protection of personal data into account when developing or selecting hardware, software and procedures, in accordance with the principles of data protection by design and by default under Article 25 GDPR.
Cooperation with Processors and third parties
Where, in the course of our processing, we disclose data to other persons and companies, including Processors or third parties, transfer data to them or otherwise grant them access to the data, we do so only on the basis of a legal permission, for example where a transfer of data to a third party such as a payment service provider is necessary for the performance of a contract under Article 6(1)(b) GDPR, where you have given consent, where a legal obligation requires it or on the basis of our legitimate interests, for example when using agents or web-hosting providers.
Where we engage a third party to process data on the basis of a data-processing agreement, this is done in accordance with Article 28 GDPR.
Transfers to third countries
Where we process data in a third country, meaning outside the European Union (EU) or European Economic Area (EEA), or where this occurs in connection with the use of third-party services or the disclosure or transfer of data to third parties, this takes place only where it is necessary to perform our contractual or pre-contractual obligations, on the basis of your consent, because of a legal obligation or on the basis of our legitimate interests. Subject to statutory or contractual permissions, we process data, or have data processed, in a third country only where the specific requirements of Articles 44 et seq. GDPR are met. This means, for example, that processing is based on special safeguards such as an officially recognised finding of a level of data protection corresponding to that of the EU, for example the “Privacy Shield” for the USA, or compliance with officially recognised special contractual obligations, known as standard contractual clauses.
Rights of data subjects
You have the right under Article 15 GDPR to request confirmation as to whether relevant data is being processed and to request information about that data, further information and a copy of the data.
Under Article 16 GDPR, you have the right to request completion of data concerning you or correction of inaccurate data concerning you.
Under Article 17 GDPR, you have the right to request that relevant data be erased without undue delay or, alternatively, under Article 18 GDPR, to request restriction of the processing of the data.
You have the right under Article 20 GDPR to receive the data concerning you that you have provided to us and to request its transmission to another Controller.
Under Article 77 GDPR, you also have the right to lodge a complaint with the competent supervisory authority.
Right to withdraw consent
You have the right under Article 7(3) GDPR to withdraw consent previously given with effect for the future.
Right to object
Under Article 21 GDPR, you may object at any time to future processing of data concerning you. In particular, you may object to processing for direct-marketing purposes.
Cookies
“Cookies” are small files stored on Users’ computers. Different types of information may be stored within cookies. A cookie primarily serves to store information about a User, or the device on which the cookie is stored, during or after a visit to an online service. Temporary cookies, also known as session cookies or transient cookies, are deleted after a User leaves an online service and closes their browser. Such a cookie may store, for example, the contents of a shopping basket in an online shop or a login status. “Permanent” or “persistent” cookies remain stored after the browser is closed. A login status can therefore be retained when Users return after several days. Such a cookie may also store Users’ interests for audience-measurement or marketing purposes. “Third-party cookies” are cookies provided by providers other than the Controller operating the online service. If only the Controller’s cookies are used, these are referred to as first-party cookies.
We may use temporary and permanent cookies and provide information about them within this Privacy Policy.
If Users do not want cookies to be stored on their computer, they should disable the relevant option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. Excluding cookies may restrict the functionality of this online service.
A general objection to the use of cookies for online-marketing purposes can be declared for a number of services, particularly in the case of tracking, through the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Cookies can also be prevented from being stored by disabling them in the browser settings. Please note that not all functions of this online service may then be available.
Deletion of data
The data processed by us is erased or its processing restricted in accordance with Articles 17 and 18 GDPR. Unless expressly stated otherwise in this Privacy Policy, data stored by us is erased as soon as it is no longer required for its intended purpose and no statutory retention obligations prevent its erasure. If the data is not erased because it is required for other legally permissible purposes, its processing is restricted. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax-law reasons.
Under statutory requirements in Germany, records are retained in particular for ten years pursuant to sections 147(1) of the German Fiscal Code (AO), 257(1) nos. 1 and 4 and section 257(4) of the German Commercial Code (HGB), including books, records, management reports, accounting vouchers, commercial books and documents relevant for taxation, and for six years pursuant to section 257(1) nos. 2 and 3 and section 257(4) HGB, including commercial correspondence.
Under statutory requirements in Austria, records are retained in particular for seven years pursuant to section 132(1) of the Austrian Federal Fiscal Code (BAO), including accounting documents, receipts and invoices, accounts, vouchers, business documents and statements of income and expenditure; for 22 years in connection with real property; and for ten years for documents relating to electronically supplied services and telecommunications, radio and television services supplied to non-business customers in EU Member States for which the Mini One Stop Shop (MOSS) is used.
Account deletion and disclosure of data to authorities
Users may close their account at any time directly in the profile area of the app using the “Delete account” function. When this function is used, all personal data is erased or anonymised without undue delay insofar as no statutory retention obligations apply.
Personal data is not disclosed to third parties unless we are legally required or permitted to do so. This may be the case, in particular, where competent authorities request data in the course of legally permissible proceedings, for example to review flight operations or to comply with aviation-law requirements.
Business-related processing
We also process:
- Contract data, for example the subject matter of the contract, its term and customer category
- Payment data, for example bank details and payment history
This data is processed in relation to our customers, prospective customers and business partners for the purposes of performing contractual services, providing service and customer support, marketing, advertising and market research.
Order processing in the online shop and customer account
We process our customers’ data in connection with orders placed through our online shop in order to enable them to select and order the products and services they have chosen and to enable payment, delivery or performance.
The data processed includes master data, communications data, contract data and payment data. The persons affected by the processing include our customers, prospective customers and other business partners. Processing takes place for the purpose of providing contractual services in connection with the operation of an online shop, invoicing, delivery and customer service. We use session cookies to store the contents of the shopping basket and persistent cookies to store login status.
Processing is based on Article 6(1)(b) GDPR for the performance of order transactions and Article 6(1)(c) GDPR for legally required archiving. Information marked as required is necessary to establish and perform the contract. We disclose the data to third parties only in connection with delivery, payment or statutory permissions and obligations involving legal advisers and authorities. Data is processed in third countries only where this is necessary to perform the contract, for example at the customer’s request in connection with delivery or payment.
Users may optionally create a User account, in particular to view their orders. Users are informed of the mandatory information required during registration. User accounts are not public and cannot be indexed by search engines. If Users terminate their User account, their account-related data is erased, unless retention is necessary for commercial or tax-law reasons under Article 6(1)(c) GDPR. Information in the customer account remains there until the account is deleted, followed by archiving where required by law. Users are responsible for backing up their data before the end of the contract following termination.
During registration, subsequent logins and use of our online services, we store the IP address and the time of the relevant User action. Storage is based on our legitimate interests and those of Users in protection against misuse and other unauthorised use. This data is not generally disclosed to third parties unless disclosure is necessary to pursue our claims or a legal obligation exists under Article 6(1)(c) GDPR.
Data is erased once statutory warranty and comparable obligations expire. The need to retain the data is reviewed every three years. Where statutory archiving obligations apply, the data is erased when they expire, at the end of the commercial-law retention period of six years and the tax-law retention period of ten years.
Brokerage services
We process the data of our customers, clients and prospective customers, collectively referred to as “Customers”, in accordance with Article 6(1)(b) GDPR in order to provide contractual or pre-contractual services to them. The data processed and the nature, scope, purpose and necessity of processing are determined by the underlying engagement. The data generally includes Customer master and core data, such as name and address, contact data, such as email address and telephone number, contract data, such as the content of the engagement, remuneration, terms and information about the companies, insurers or services brokered, and payment data, such as commissions and payment history. We may also process information concerning the characteristics and circumstances of people or property belonging to them if this forms part of our engagement. This may include information concerning personal circumstances and movable or immovable property. In the course of our engagement, it may also be necessary for us to process special categories of data under Article 9(1) GDPR, in particular information concerning a person’s health. Where necessary, we obtain the Customer’s express consent in accordance with Article 6(1)(a), Article 7 and Article 9(2)(a) GDPR. Where necessary for performance of the contract or required by law, we disclose or transfer Customer data in connection with coverage enquiries and the conclusion and handling of contracts to providers of the brokered services or objects, insurers, reinsurers, broker pools, technical service providers and other service providers such as cooperating associations, as well as financial service providers, banks and investment companies, social-security institutions, tax authorities, tax advisers, legal advisers, auditors, insurance ombudsmen and the German Federal Financial Supervisory Authority (BaFin). We may also engage subcontractors, such as sub-brokers. We obtain Customer consent where consent is required for the disclosure or transfer, for example in the case of special categories of data under Article 9 GDPR. Data is erased after statutory warranty and comparable obligations expire, with the need to retain data reviewed every three years; statutory retention obligations otherwise apply. Where statutory archiving obligations apply, data is erased when they expire. Under German law, records subject to retention in the insurance and financial sector include advice records for five years, broker closing notes for seven years and brokerage agreements for five years, as well as, generally, documents relevant under commercial law for six years and documents relevant under tax law for ten years.
External payment service providers
We use external payment service providers through whose platforms Users and we can carry out payment transactions. Examples, each with a link to the relevant privacy policy, include PayPal (https://www.paypal.com/de/webapps/mpp/ua/privacy-full), Klarna (https://www.klarna.com/de/datenschutz/), Skrill (https://www.skrill.com/de/fusszeile/datenschutzrichtlinie/), Giropay (https://www.giropay.de/rechtliches/datenschutz-agb/), Visa (https://www.visa.de/datenschutz), Mastercard (https://www.mastercard.de/de-de/datenschutz.html) and American Express (https://www.americanexpress.com/de/content/privacy-policy-statement.html).
We use payment service providers for the performance of contracts on the basis of Article 6(1)(b) GDPR. We otherwise use external payment service providers on the basis of our legitimate interests pursuant to Article 6(1)(b) GDPR in order to offer our Users effective and secure payment options.
The data processed by payment service providers includes master data such as name and address, bank data such as account numbers or credit-card numbers, passwords, transaction authentication numbers and checksums, as well as information relating to contracts, amounts and recipients. The information is required to carry out transactions. However, the data entered is processed and stored only by the payment service providers. This means that we do not receive account or credit-card information, but only confirmation or negative notification of the payment. Payment service providers may transfer data to credit agencies in certain circumstances. The purpose of such transfer is to verify identity and creditworthiness. Please refer to the payment service providers’ terms and privacy information.
Payment transactions are subject to the terms and privacy information of the respective payment service providers, which can be accessed on their respective websites or transaction applications. We also refer to these for further information and for exercising rights of withdrawal, access and other data-subject rights.
Administration, financial accounting, office organisation and contact management
We process data in the course of administrative tasks, organisation of our operations, financial accounting and compliance with legal obligations such as archiving. In doing so, we process the same data that we process when providing our contractual services. The legal bases are Article 6(1)(c) and Article 6(1)(f) GDPR. Customers, prospective customers, business partners and website visitors are affected by the processing. The purpose of, and our interest in, the processing lies in administration, financial accounting, office organisation and data archiving, meaning tasks that serve to maintain our business operations, carry out our duties and provide our services. Erasure of data relating to contractual services and contractual communications is governed by the information provided for those processing activities.
In this context, we disclose or transfer data to the tax authorities, advisers such as tax advisers or auditors, other fee offices and payment service providers.
On the basis of our business interests, we also store information concerning suppliers, event organisers and other business partners, for example for subsequent contact. We generally store this predominantly business-related data permanently.
Business analyses and market research
In order to operate our business economically and identify market trends and customer and User requirements, we analyse data available to us concerning business transactions, contracts and enquiries. We process master data, communications data, contract data, payment data, usage data and metadata on the basis of Article 6(1)(f) GDPR. The data subjects include customers, prospective customers, business partners, visitors to and Users of the online service.
The analyses are carried out for business evaluations, marketing and market research. In doing so, we may take account of registered Users’ profiles, including information concerning the services they have used. The analyses help us improve User-friendliness, optimise our service and improve commercial efficiency. The analyses are for our use only and are not disclosed externally unless they are anonymous analyses containing aggregated values.
Where these analyses or profiles relate to individuals, they are erased or anonymised when the User terminates the agreement, otherwise two years after conclusion of the agreement. Overall business analyses and general assessments of trends are otherwise prepared anonymously wherever possible.
Registration function
Users may create a User account. During registration, Users are informed of the mandatory information required, which is processed on the basis of Article 6(1)(b) GDPR for the purpose of providing the User account. The data processed includes, in particular, login information such as name, password and email address. Data entered during registration is used for the purposes of using the User account and its intended functions.
Users may be informed by email of information relevant to their User account, such as technical changes. If Users terminate their User account, the data relating to the User account is erased, subject to statutory retention obligations. Users are responsible for backing up their data before the end of the contract following termination. We are entitled to irretrievably erase all User data stored during the term of the contract.
When our registration and login functions and the User account are used, we store the IP address and the time of the relevant User action. Storage is based on our legitimate interests and those of Users in protection against misuse and other unauthorised use. This data is not generally disclosed to third parties unless disclosure is necessary to pursue our claims or a legal obligation exists under Article 6(1)(c) GDPR. IP addresses are anonymised or erased after no more than seven days.
Comments and posts
If Users leave comments or other posts, their IP addresses may be stored for seven days on the basis of our legitimate interests under Article 6(1)(f) GDPR. This is for our protection in case a person posts unlawful content in comments or contributions, including insults or prohibited political propaganda. In such a case, we may be held liable for the comment or post and therefore have an interest in identifying the author.
We further reserve the right to process User information for spam detection on the basis of our legitimate interests under Article 6(1)(f) GDPR.
Data provided in comments and posts is stored by us permanently until the User objects.
Contact
When contacting us, for example by contact form, email, telephone or social media, the User’s information is processed to handle and process the enquiry in accordance with Article 6(1)(b) GDPR. User information may be stored in a customer relationship management system (“CRM system”) or a comparable enquiry-management system.
We erase enquiries when they are no longer required. We review necessity every two years. Statutory archiving obligations also apply.
Newsletter
The following information explains the content of our newsletter, the registration and dispatch procedure, statistical evaluation and your rights to object. By subscribing to our newsletter, you agree to receive it and to the procedures described.
Newsletter content: we send newsletters, emails and other electronic notifications containing promotional information (hereinafter “Newsletter”) only with the recipient’s consent or statutory permission. Where the Newsletter content is described specifically during registration, that description is decisive for the User’s consent. Otherwise, our Newsletters contain information about us and our services.
Double opt-in and logging: registration for our Newsletter uses a double opt-in procedure. This means that after registering you receive an email asking you to confirm your registration. This confirmation is required to prevent a person from registering using another person’s email address. Newsletter registrations are logged so that the registration process can be demonstrated in accordance with legal requirements. This includes storing the time of registration and confirmation and the IP address. Changes to your data stored by the dispatch service provider are also logged.
Registration data: to register for the Newsletter, it is sufficient to provide your email address. We may optionally ask you to provide a name so that the Newsletter can address you personally.
The Newsletter is sent and its performance is measured on the basis of the recipient’s consent under Article 6(1)(a) and Article 7 GDPR in conjunction with section 7(2) no. 3 of the German Unfair Competition Act (UWG), or on the basis of the statutory permission under section 7(3) UWG.
The registration procedure is logged on the basis of our legitimate interests under Article 6(1)(f) GDPR. Our interest lies in using a User-friendly and secure Newsletter system that serves our business interests, meets Users’ expectations and enables us to demonstrate consent.
Cancellation and withdrawal: you can cancel receipt of our Newsletter at any time, meaning that you can withdraw your consent. A link for unsubscribing is included at the end of every Newsletter. On the basis of our legitimate interests, we may store unsubscribed email addresses for up to three years before erasing them in order to demonstrate that consent was previously given. Processing of this data is restricted to the purpose of defending possible claims. An individual erasure request can be made at any time, provided that the previous existence of consent is confirmed at the same time.
Newsletter dispatch service provider
Newsletters are sent using the dispatch service provider Mailjet GmbH. The dispatch service provider’s privacy policy can be viewed at https://www.mailjet.com/de/rechtliches/datenschutzerklaerung/. The dispatch service provider is used on the basis of our legitimate interests under Article 6(1)(f) GDPR and a data-processing agreement under Article 28(3), first sentence, GDPR.
The dispatch service provider may use recipients’ data in pseudonymous form, meaning without attribution to a User, to optimise or improve its own services, for example for technical optimisation of dispatch and display of the Newsletter or for statistical purposes. However, the dispatch service provider does not use our Newsletter recipients’ data to contact them itself or to disclose the data to third parties.
Newsletter performance measurement
Newsletters contain a web beacon, meaning a pixel-sized file that is retrieved from our server or, if we use a dispatch service provider, from that provider’s server when the Newsletter is opened. As part of this retrieval, technical information is initially collected, including information about the browser and system, the IP address and the time of retrieval.
This information is used for technical improvement of the services based on technical data, or to evaluate the audience and reading behaviour based on the location of retrieval, which can be determined using the IP address, or the access time. Statistical analysis also includes determining whether Newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be attributed to individual Newsletter recipients. However, neither we nor, where used, the dispatch service provider seeks to monitor individual Users. The evaluations instead help us understand our Users’ reading habits, adapt our content to them and send different content according to our Users’ interests.
Hosting
The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, security services and technical maintenance services, which we use to operate this online service.
In this context, we or our hosting provider process master data, contact data, content data, contract data, usage data and meta and communications data relating to customers, prospective customers and visitors to this online service on the basis of our legitimate interests in efficient and secure provision of this online service under Article 6(1)(f) GDPR in conjunction with Article 28 GDPR, through the conclusion of a data-processing agreement.
Collection of access data and log files
On the basis of our legitimate interests within the meaning of Article 6(1)(f) GDPR, we or our hosting provider collect data concerning every access to the server on which this service is located, known as server log files. Access data includes the name of the page or file retrieved, the date and time of retrieval, the volume of data transferred, notification of successful retrieval, browser type and version, the User’s operating system, referrer URL, meaning the previously visited page, IP address and requesting provider.
Log-file information is stored for no more than seven days for security reasons, for example to investigate misuse or fraud, and is then erased. Data whose further retention is necessary for evidential purposes is excluded from erasure until the relevant incident has been finally resolved.
Cloudflare content delivery network
We use a content delivery network (“CDN”) provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare is certified under the Privacy Shield framework and thereby provides a guarantee of compliance with European data-protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnZKAA0).
A CDN is a service that enables content from our online service, in particular large media files such as graphics or scripts, to be delivered more quickly using regionally distributed servers connected over the internet. User data is processed solely for the purposes described above and to maintain the security and functionality of the CDN.
Further information is available in Cloudflare’s privacy policy: https://www.cloudflare.com/security-policy.
Imgix content delivery network
We use a content delivery network (“CDN”) for images provided by Zebrafish Labs, Inc., 423 Tehama St, San Francisco, CA 94103, USA. Imgix is certified under the Privacy Shield framework and thereby provides a guarantee of compliance with European data-protection law (https://www.privacyshield.gov/participant?id=a2zt00000008VPfAAM).
A CDN is a service that enables content from our online service, in particular large media files such as graphics or scripts, to be delivered more quickly using regionally distributed servers connected over the internet. User data is processed solely for the purposes described above and to maintain the security and functionality of the CDN.
Further information is available in Imgix’s privacy policy: https://imgix.com/privacy.
Online presence on social media
We maintain an online presence on social networks and platforms in order to communicate with customers, prospective customers and Users active there and to inform them of our services. When accessing the relevant networks and platforms, the terms and data-processing policies of their respective operators apply.
Unless otherwise stated in this Privacy Policy, we process User data where Users communicate with us through social networks and platforms, for example by posting contributions on our social-media pages or sending us messages.
Integration of third-party services and content
On the basis of our legitimate interests, meaning our interest in analysing, optimising and operating our online service economically within the meaning of Article 6(1)(f) GDPR, we use content or service offerings from third-party providers within our online service in order to integrate content and services such as videos or fonts (hereinafter collectively referred to as “Content”).
This always requires the third-party providers of the Content to receive Users’ IP addresses, because without the IP address they could not send the Content to the User’s browser. The IP address is therefore required to display the Content. We endeavour to use only Content whose respective providers use the IP address solely to deliver the Content. Third-party providers may also use pixel tags, meaning invisible graphics also known as web beacons, for statistical or marketing purposes. Pixel tags can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the User’s device and may include technical information concerning the browser and operating system, referring websites, visit time and other information concerning use of our online service, and may be combined with such information from other sources.
Google Maps
We integrate maps from the “Google Maps” service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The data processed may include Users’ IP addresses and location data, although location data is not collected without the User’s consent, generally provided through the settings of the User’s mobile device. The data may be processed in the USA. Privacy policy: https://www.google.com/policies/privacy/. Opt-out: https://adssettings.google.com/authenticated.
Additional provisions for the app Privacy Policy
Processing app-specific data
In Aviatefinder’s mobile application, we process the following data in addition to the data already specified:
- Device identification numbers, for example UUID, IMEI and Advertising ID
- Device operating system and version
- App usage statistics, for example logins, crashes and interactions
- Location data, if the User has granted location permission
- Push notifications, if enabled
2. Access to device permissions
The app requires various permissions in order to provide certain functions:
- Location data: to provide flights nearby. This data is collected only if the User has granted location permission.
- Camera and photos: if the User uploads a profile image or needs to verify documents such as pilot licences.
- Storage access: if the User wishes to save or share content.
- Notifications: for updates on flight enquiries, Bookings or system messages.
Permissions can be adjusted at any time in the device settings.
3. Mobile analytics services and tracking
To improve the User experience, we use mobile analytics services, including:
- Google Firebase Analytics
- Apple App Analytics, when using iOS
- Crashlytics for error analysis
These services may collect anonymous data concerning use of the app, for example to improve app performance or troubleshoot errors.
4. Push notifications and in-app communication
If the User enables push notifications, we may inform them of new flights, Bookings or relevant updates. Users can disable this function at any time in the device settings.
5. App-store payment processing (in-app purchases)
If Aviatefinder offers paid functions or premium subscriptions, payments are processed through:
- the Apple App Store for iOS or the Google Play Store for Android; and
- billing through the respective stores, subject to their privacy policies.
6. Use of location data
If the User enables location permission in the app, we may use real-time location data to:
- find flights nearby;
- provide the User with personalised flight offers; and
- display dynamic prices based on location and flight availability.
Location permission is voluntary and can be disabled at any time.
7. Storage and deletion of app data
Data processed in the app is stored only for as long as it is required for the relevant purpose. Users can delete their data directly in the app or submit an erasure request by email to impressum@Aviatefinder.com.
