PRIVACY · TELEMETRY · GDPR
Privacy notice
What Three Flights stores today, what the simulator recorder collects, why it is needed, and the controls every pilot has.
What Three Flights does today
Signing in creates an account holding your email address, your flying preferences and your logbook. There is no password to store.
No card or billing information is collected. Nothing is charged and no payment provider is connected.
Telemetry only leaves your PC if you install the recorder and link it with a pairing code. Without that step no flight data is sent.
We use privacy-first page analytics that set no cookies, follow no one between sites, and are never sold or shared.
Browser storage holds your language choice and interface preferences. Your account, logbook and any recorded flights are stored on our behalf by Supabase, and the site is hosted by Vercel; both also process ordinary technical request and security logs. You can delete a recorded flight yourself, and you can ask us to delete the account entirely.
Privacy facts to complete before launch
This notice already follows the information structure required by UK GDPR and EU GDPR. Before public registration, payment or live telemetry begins, insert the facts that no generic policy can truthfully guess: the controller’s legal name and address, privacy contact, final processor and subprocessor list, hosting locations, transfer safeguards, enforced retention settings, and any Data Protection Officer or UK/EEA representative. The controller remains responsible where specialist providers process information on its behalf.
The English, German and French notices should share one controlled data map so a change to telemetry, analytics, payments or retention updates all three. The short notice shown at account creation and connector activation must link to this full notice and explain the collection at the moment it happens.
1. Scope
This notice is designed for the Three Flights website, customer account, MSFS 2020/2024 connector, recommendation engine, evidence-led flight review and logbook. It distinguishes between what happens today and processing that begins only when paid subscriptions are introduced. It does not cover Microsoft, SimBrief, Navigraph, aircraft developers or other third parties operating under their own privacy notices.
2. Information we expect to process
| Category | Examples | Why it is needed |
|---|---|---|
| Account and profile | Name or display name, email, country/region, language, simulator version, preferred aircraft, home airport, interface depth | Create the account and personalise the experience |
| Flight and logbook | Origin, destination, aircraft, route, timestamps, duration, distance, altitude, fuel-plan comparison, review, score, notes and corrections | Provide the chosen flight, review, trends and World Passport |
| Simulator telemetry | Position, altitude, heading, airspeed, groundspeed, vertical speed, configuration when available, touchdown rate and g, route deviation and relevant flight events | Create evidence-based debriefs and safety-aware coaching |
| Subscription and billing | Plan, renewal date, payment status, currency, tax location, invoices and payment-provider reference | Manage the contract, billing, refunds and records |
| Device and diagnostics | Connector version, simulator version, operating system, IP address, error records, security events and coarse technical performance | Secure, support and improve the service |
| Communications and choices | Support messages, fairness feedback, research responses, consent choices and marketing preference | Respond, investigate disputes and respect choices |
We do not need your SimBrief password, Microsoft password or full payment-card number. Approved integrations should use secure authorisation or access tokens where available. Full card details should be handled by the selected payment provider rather than stored by Three Flights.
Account email and billing confirmation will be contractually necessary for a paid account. Live telemetry is not a statutory requirement and recording begins only when you choose to connect and record a flight; without it, web recommendations can still work but an evidence-based debrief cannot. Marketing, optional analytics and non-essential diagnostics remain optional. We do not intend to collect health, biometric, political, religious, sexual-life or criminal-offence information.
3. Telemetry boundaries
The connector should collect only values needed for the flight record, declared targets, fair scoring, diagnosis and user-requested features. Core aircraft tracking may include position, altitude, speed, flight path, approach stability and touchdown geometry. Aircraft-specific LVars, BVars or private SDK values must not be collected until a verified adapter, documented purpose and appropriate developer permission exist.
- High-frequency raw samples should be minimised and separated from the long-term logbook.
- Voice, video, unrelated files, keystrokes and general PC activity are outside scope.
- Unverified performance assumptions must be labelled and must not be presented as observed facts.
- A user correction should create an audit entry rather than silently rewrite original telemetry.
- Connector diagnostics beyond what is strictly necessary should be switchable.
4. Sources of information
Information may come from:
- you, when you create a profile, choose a flight, confirm a target, write a note or contact support;
- the Three Flights connector and standard MSFS interfaces during a flight you choose to record;
- approved integrations that you actively connect, such as a flight-planning service;
- the payment provider for payment status and transaction references; and
- essential hosting, security and diagnostic systems.
5. Purposes and lawful bases
| Purpose | Proposed lawful basis |
|---|---|
| Account, recommendations, connector, review and logbook | Contract – necessary to provide the service you request |
| Subscription administration, cancellation and refunds | Contract and legal obligation |
| Invoices, tax and legally required records | Legal obligation |
| Security, fraud prevention and core service diagnostics | Legitimate interests in protecting users and the service |
| Support, complaint handling and fairness review | Contract and legitimate interests in resolving problems |
| Optional analytics, non-essential diagnostics and product research | Consent, where consent is required |
| Email marketing | Consent, or the limited existing-customer exception where legally available and an opt-out is always offered |
| Legal claims and regulatory enquiries | Legal obligation and legitimate interests |
A legitimate-interest assessment should be documented before production. Consent can be withdrawn at any time without affecting earlier lawful processing. Optional consent must not be bundled into acceptance of the subscription.
6. Automated recommendations and scoring
Three Flights will use profile settings, available time, chosen aircraft, route context and flight evidence to recommend three flights and generate a review. This is automated personalisation or profiling, but it is not intended to make a legal or similarly significant decision about you. It must not be used for employment, licensing, insurance, real-world pilot assessment or regulatory action.
The product should expose the reason for each recommendation, the evidence behind each score, missing data and any assumptions. You should be able to correct a target, challenge an event and request human review of a disputed record without the original evidence being erased.
7. Sharing and processors
We expect to share only what is necessary with carefully selected providers in these categories:
- cloud hosting, database, content delivery and security;
- account authentication;
- payment processing, invoicing and tax support;
- transactional email and customer support;
- error monitoring and optional analytics, subject to the correct consent controls;
- professional advisers, insurers, auditors and regulators where necessary; and
- a buyer or successor if the business is reorganised, with appropriate safeguards and notice.
We do not propose to sell personal information or flight histories. A named processor and subprocessor list, location, purpose and relevant privacy link must be published before production processing begins. Processor contracts must require confidentiality, security, deletion or return, assistance with rights requests and controlled subprocessors.
8. International transfers
A global service may use providers or support teams outside the UK or EEA. Restricted transfers must use a lawful mechanism such as an adequacy decision, approved contractual safeguards including the UK International Data Transfer Agreement or Addendum and EU Standard Contractual Clauses, plus a transfer risk assessment where required. The final notice must identify the applicable safeguard and explain how a copy can be requested.
9. Proposed retention schedule
| Record | Proposed retention |
|---|---|
| Account profile and derived logbook | While the account is active, then deleted or anonymised within 30 days of closure; protected backups expire within 90 days |
| High-frequency raw flight telemetry | 30 days after the flight, unless the user keeps a disputed event for review; long-term logbook retains only the derived record |
| Security and connector diagnostic logs | Normally 90 days, longer only for an active security investigation |
| Support and complaint records | 24 months after closure, or longer where a legal dispute requires it |
| Invoices and statutory transaction records | For the period required by tax, accounting and consumer law |
| Marketing consent and suppression record | Until withdrawal, plus the minimum record needed to prove and respect the opt-out |
| Local language and privacy preference | Until changed, cleared from the device or after a planned maximum of 12 months |
Production retention must be technically enforced and reviewed. Where a record is needed for fraud prevention, a legal claim or statutory duty, access should be restricted and the record deleted when that reason ends.
10. Cookies and device storage
Three Flights sets no advertising cookies and no cross-site tracking cookies. Page analytics are cookieless: they count visits and pages without storing an identifier on your device or following you to other sites. It stores these first-party browser preferences on the device:
| Storage item | Purpose | Type |
|---|---|---|
three-flights-language | Remember English, German or French | Functional preference |
three-flights-language-interest | Remember the future-language button you explicitly selected | Feedback you chose to give, stored on this device |
Browser storage can be cleared in browser settings. Before any non-essential analytics, advertising, fingerprinting or similar technology is introduced, users must receive clear information and a genuine accept/reject choice before it runs. Rejecting optional storage must not block the core product. Essential security, authentication and requested preference storage will be explained even where consent is not legally required.
11. Your data protection rights
Depending on the law and circumstances, you may have the right to:
- be informed about how your information is used;
- access a copy of your personal information;
- correct inaccurate or incomplete information;
- request erasure;
- restrict processing;
- receive portable account and logbook data in a commonly used, machine-readable format;
- object to legitimate-interest processing and direct marketing;
- withdraw consent at any time; and
- complain to a supervisory authority or seek a judicial remedy.
Requests should be free and answered without undue delay, normally within one month after identity is reasonably verified. Complex or repeated requests may lawfully take longer, but the user must be told why. Production should provide an account export and deletion control wherever practical.
12. Complaints
Please contact the published Three Flights privacy address first so the issue can be investigated. UK users may also complain to the Information Commissioner’s Office. People in the EEA may contact the supervisory authority in their country. These rights are not conditional on contacting us first.
13. Security
Production controls should include encryption in transit, secure password or passkey handling, least-privilege access, protected secrets, auditable administrative access, dependency and vulnerability management, backups, incident response, connector signing or verification, and separation of raw telemetry from account identity where practical. No system is risk-free, so users must be told promptly about a personal-data breach where law requires notification.
14. Children
Three Flights is intended for users aged 16 or over and does not intentionally seek special-category information. If we learn that a child below the stated age supplied personal information without valid parental authority, we will take reasonable steps to remove it. Country-specific age and parental-consent rules must be assessed before targeted marketing outside the UK.
15. Changes to this notice
The current version and date will remain available here. Material production changes – such as a new telemetry purpose, processor, international transfer, retention period or advertising technology – should be explained before they take effect. Where processing depends on consent, a new purpose may require new consent rather than a silent privacy-policy update.
16. Contact details to publish
Data controller: To be supplied before public registration
Registered/trading address: To be supplied
Privacy and rights email: To be supplied and tested
Data Protection Officer: To be stated if one is appointed or legally required
EEA/UK representative: To be stated if legally required
17. Official privacy drafting sources
The production notice and the shorter just-in-time messages will be maintained against the ICO right-to-be-informed guidance, the CNIL transparency checklist and GDPR Article 13. These sources define the required information; the final Three Flights data map supplies the business-specific facts.