Back to AvioDeck Public document

Privacy Policy

Last updated: 28 September 2025

1. Who we are

AvioDeck (“we”, “us”, “our”) is a community project, not a company or registered business. We decide how and why your personal data is processed and are therefore the data controller for AvioDeck.

If you are unhappy with how we use your data, you can raise concerns with the UK Information Commissioner’s Office (ICO) at ico.org.uk.

2. What we collect

  • Account & identity: display name/handle, email (if provided), platform IDs and profile info from services you connect (Discord, Twitch, VATSIM).
  • Auth & connections: OAuth tokens/refresh tokens and scopes for Discord, Twitch and VATSIM Connect; token metadata (expiry, last used); internal AvioDeck user ID.
  • Usage & telemetry: feature usage events and timestamps, approximate device/browser info, server logs (IP address, user agent, request metadata, error traces).
  • Content you submit: configuration and personalisation you create in AvioDeck (e.g., streamer profile, overlays, flight plans).
  • Cookies & local storage: essential cookies for session and security; local preferences (e.g., theme).

3. Why we use data & lawful bases

  • Operate AvioDeck and provide features (login, linked accounts, overlays, VATSIM Connect) — Lawful basis: Contract.
  • Secure the service (authentication, abuse prevention, fraud) — Lawful basis: Legitimate interests.
  • Improve performance and reliability (diagnostics, telemetry, error logs) — Lawful basis: Legitimate interests.
  • Comply with law (respond to lawful requests) — Lawful basis: Legal obligation.

We do not sell your data and we do not profile for marketing.

4. Sources of data

  • You — sign-in, forms, and preferences you provide.
  • Connected platforms — Discord, Twitch, VATSIM via OAuth (limited to the scopes you approve).
  • Your device — IP address, user agent, request metadata when using AvioDeck.

5. Data sharing

We share data only where necessary to run AvioDeck:
  • Connected platforms: Discord, Twitch, VATSIM Connect — to authenticate and provide the features you request.
  • Hosting & infrastructure: Laravel Cloud — region: EU London.
  • Analytics / monitoring: Laravel NightWatch — data stored in Frankfurt.

Providers act under contract and process data under our instructions.

6. International transfers

If any provider stores or processes data outside the UK, we use approved transfer mechanisms (for example UK adequacy regulations or the UK International Data Transfer Agreement / SCCs) and apply appropriate safeguards.

7. Data retention

  • Account data & content you submit: retained for the lifetime of your account and deleted when your account is deleted.
  • Flight plans & temporary data: removed when you delete them.
  • Logs, telemetry, error data: retained only as long as needed for security, reliability or compliance purposes.

8. Your rights

  • Access your personal data and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Request erasure where applicable.
  • Restrict or object to certain processing.
  • Data portability (where technically feasible).

To exercise your rights, contact us on Discord (@StratoGhost). We aim to respond within one month. You can also complain to the ICO at ico.org.uk.

9. Security

We use industry-standard safeguards, including HTTPS/TLS, hashed session cookies, role-based access controls, least-privilege API keys, encrypted storage for tokens (where supported), and logging/monitoring. We will assess and notify you and the ICO if a notifiable breach occurs.

10. Cookies

AvioDeck uses only essential cookies to operate the application (session management, security, required preferences). No optional analytics cookies are used.

11. Children

AvioDeck does not generate or host content requiring parental guidance or supervision. There is no explicit minimum age to use AvioDeck; however, you must comply with the terms of any connected services (e.g., Discord, Twitch, VATSIM) which may impose their own age limits.

12. Automated decision-making

AvioDeck does not perform automated decision-making or profiling that produces legal or similarly significant effects.

13. Contact

Questions or requests about your data? Contact us on Discord:

Contact @StratoGhost

We acknowledge that relying on Discord for contact is unconventional. AvioDeck is a community project and requires a Discord account to use. As such, not providing a separate email address does not create a barrier to raising concerns or exercising your rights, since all users necessarily have Discord access. While AvioDeck remains in closed or pre-public release, Discord will be the sole contact channel. At the point of public release, we will make a dedicated email address available for privacy and contact purposes.

If you remain unhappy, you can complain to the UK ICO at ico.org.uk.

14. Changes to this notice

We may update this notice as AvioDeck’s features, providers, or legal obligations change. We will post updates here with a new “last updated” date and, for material changes, notify signed-in users.