Privacy Policy

Last updated: 1 May 2025

1. Who we are

Aviation Infinity ("we", "us", "our") operates the website aviationinfinity.com and the Aviation Infinity mobile application. We are the data controller for the personal data described in this policy.

Contact: privacy@aviationinfinity.com

2. Data we collect

  • Account data: email address, display name, country, chosen authority and licence target.
  • Learning data: exam session results, question responses, streak counts, XP, badges.
  • Payment data: subscription status and invoice history. Card details are processed by Stripe and never stored on our servers.
  • Usage data: pages visited, features used, device type, locale — collected via PostHog (EU Cloud) only with your consent.
  • Support data: messages you send to our support team.

3. Legal basis (GDPR)

  • Contract: account, learning, and payment data — required to provide the service.
  • Legitimate interest: error monitoring (Sentry) to maintain service reliability.
  • Consent: analytics cookies (PostHog). You may withdraw consent at any time via the cookie settings banner.

4. How we use your data

  • Provide, personalise, and improve the learning experience.
  • Process subscription payments via Stripe.
  • Send transactional emails (account events, weekly digests) via Resend.
  • Match you with relevant flight schools (school marketplace).
  • Detect and fix technical errors (Sentry).

5. Data sharing

We share data only with:

  • Stripe — payment processing (USA, SCCs in place).
  • Resend — transactional email delivery.
  • PostHog EU Cloud — analytics (EU, consent-only).
  • Sentry — error monitoring (USA, SCCs in place, PII stripped before sending).
  • MongoDB Atlas — database hosting (EU region: Frankfurt).
  • Vercel — web hosting.
  • Flight schools — only when you submit an inquiry; limited to the information in your inquiry form.

We never sell personal data.

6. Cookies

Necessary cookies (always active): session token, CSRF protection.
Analytics cookies (consent required): PostHog session and distinct ID cookies.

You can change your cookie preferences at any time by clicking the cookie settings link in the footer.

7. Data retention

  • Active account data: retained while your account exists.
  • Deleted accounts: anonymised within 30 days, some records retained for legal/tax obligations (7 years for invoices).
  • Analytics data: 1 year rolling window.

8. Your rights (GDPR)

  • Access, rectify, or erase your personal data.
  • Withdraw consent for analytics at any time.
  • Request data portability (JSON export).
  • Lodge a complaint with your local supervisory authority.

To exercise these rights, email privacy@aviationinfinity.com or use the "Delete my account" option in Settings.

9. Security

Data is encrypted in transit (TLS 1.2+) and at rest (MongoDB Atlas encryption). Access to production data is restricted to authorised staff only. We run regular dependency audits and penetration tests.

10. Changes to this policy

We will notify registered users by email of material changes at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.