ASTRAIOS legal

Privacy Policy

This policy describes the information ASTRAIOS handles, why we use it, who can access it, and the choices available to users and company customers.
Effective and last updated: July 25, 2026
01

Scope and our role

This Privacy Policy explains how ASTRAIOS Tracking ("ASTRAIOS," "we," "us," or "our") handles information through our websites, company workspaces, mobile and desktop experiences, support tools, and related services (collectively, the "Service").

ASTRAIOS provides private aviation operations workspaces to businesses and other organizations. The company that creates or controls a workspace (the "Customer") decides which people, aircraft, flights, maintenance records, dispatch records, and checkout information are placed in that workspace. For that Customer Data, the Customer is responsible for its instructions, notices, permissions, and lawful use, and ASTRAIOS processes the data to provide and support the Service.

ASTRAIOS separately controls account registration, billing administration, platform security, fraud prevention, service diagnostics, and platform-level support records. If you use ASTRAIOS through your employer, flight school, or another organization, that organization may have its own privacy policy and may administer your workspace account.

02

Information we collect

Depending on the features used, we collect or process the following categories of information:

  • Account and profile information: name, email address, phone number, job title, base location, password hash, multi-factor authentication status, role, permissions, company memberships, and profile preferences.
  • Company and billing information: company name, contacts, logo, business settings, billing email, selected package, subscription status, payment dates, and Stripe customer, subscription, price, and invoice references.
  • Aircraft and operational information: registrations, ICAO addresses, aircraft details, live and historical positions, routes, flight records, phase analysis, replays, utilization, dispatch status, maintenance discrepancies, alerts, notes, airports, and related timestamps.
  • Cadet checkout information: GroupMe sender name and identifier, aircraft and route selections, checkout and check-in times, Hobbs entries, route progress, commands, warnings, and image URLs and attachment metadata supplied through GroupMe. ASTRAIOS stores references to GroupMe-hosted images rather than copying the image file into ASTRAIOS storage.
  • Uploaded information: company logos, CSV imports, G3X flight logs and samples, notes, and other files or content a permitted user submits.
  • Communications and support information: invitations, support requests, GroupMe channel configuration and delivery history, support-session reasons, actions taken during support access, and related correspondence.
  • Device, usage, and security information: IP address, browser and device information, user agent, login and activity times, request identifiers, authentication and support sessions, error details, audit events, and feature or display preferences.
  • Public and third-party aviation information: aircraft registry details, ADS-B reports, airport and waypoint data, weather products, aeronautical hazards, imagery, terrain, and other data obtained from public or configured providers.

Please do not submit Social Security numbers, full payment card numbers, medical records, government identity documents, biometric identifiers, or other regulated sensitive information unless ASTRAIOS has expressly agreed in writing to support that data.

03

How information reaches us

We receive information directly from users and Customers, automatically from browsers and the Service, from authorized integrations, and from public or licensed aviation-data sources.

Company administrators may create accounts, assign roles, enter records, upload files, and review activity. GroupMe sends configured bot callbacks when that optional integration is enabled. ADS-B, weather, airport, registry, mapping, and geospatial providers return information requested by the ASTRAIOS backend.

04

How we use information

We use information to:

  • create and operate accounts, company workspaces, permissions, and subscriptions;
  • track configured aircraft, build flight history, display routes and replays, and support dispatch, maintenance, checkout, reporting, weather, and alerting workflows;
  • send invitations, password resets, service notices, GroupMe messages, and other requested communications;
  • process billing, maintain subscription status, and prevent duplicate or fraudulent transactions;
  • secure the Service, enforce tenant boundaries, investigate misuse, diagnose errors, maintain audit history, and recover from failures;
  • provide customer support, onboarding, configuration help, and company-scoped support access;
  • maintain, analyze, and improve reliability, performance, usability, and feature quality; and
  • comply with law, enforce our agreements, and protect users, Customers, ASTRAIOS, and the public.

We do not sell personal information. We do not use Customer Data for third-party behavioral advertising. We may create aggregate or de-identified statistics that do not reasonably identify a person or Customer.

05

Cookies and browser storage

ASTRAIOS uses strictly necessary cookies or similar session mechanisms for authentication, company selection, privileged support sessions, security, and continuity. The browser may also store interface preferences such as map layers, weather display mode, aircraft marker color and icon style, and approved developer-view settings.

Disabling required cookies may prevent login or other secured features from working. ASTRAIOS does not currently operate a third-party advertising network or use advertising cookies in the Service.

06

How information is shared

We disclose information only as reasonably necessary for the Service, including:

  • Within a Customer workspace: to authorized members according to company roles and permissions. Company owners and administrators may manage users and review permitted operational or security activity.
  • Service providers: to infrastructure, database, email, security, monitoring, and support vendors that process information for ASTRAIOS under appropriate obligations.
  • Billing: to Stripe for checkout, subscription management, billing portals, and payment processing. ASTRAIOS does not store full payment card numbers.
  • Optional integrations: to GroupMe when a Customer enables messaging or checkout commands, and to configured aviation, weather, geospatial, registry, or communications providers when needed to deliver a requested feature.
  • Platform support: to specially authorized ASTRAIOS personnel operating in a company-scoped support session. Support entry requires a reason, is time-limited, and is recorded. Customers may be shown support-access history according to their company settings.
  • Legal and safety: when we reasonably believe disclosure is required by law, legal process, or to protect rights, security, property, or safety.
  • Business changes: in connection with financing, due diligence, reorganization, merger, acquisition, or sale, subject to appropriate confidentiality and continued protection.

External sites and integrations have their own terms and privacy practices. For example, payment information is governed by the Stripe Privacy Policy.

07

Retention and deletion

We retain information for as long as needed to operate the Service, fulfill Customer instructions, protect the platform, meet legal or accounting obligations, resolve disputes, and enforce agreements. Retention varies by record and workspace configuration.

  • Live position and flight-point retention may be configured by authorized administrators, and destructive history cleanup is disabled unless intentionally enabled.
  • Operational records remain until deleted by an authorized user, removed under a Customer instruction, or handled after account termination.
  • G3X source logs and replay samples remain until an authorized user deletes them or the Customer requests deletion.
  • Security, audit, support, billing, and transaction records may be retained longer when necessary for integrity, fraud prevention, legal compliance, or dispute resolution.
  • Backups and company restore points may retain information for a limited recovery period before replacement or expiration.
  • GroupMe-hosted photos and other third-party content remain subject to the third party's own retention practices even after an ASTRAIOS reference is removed.

Deletion may not be immediate in encrypted backups, system logs, or records we must retain by law, but access remains limited and the information is removed or overwritten through the applicable lifecycle.

08

Security

ASTRAIOS uses administrative, technical, and organizational safeguards designed for the nature of the Service. These include password hashing, encrypted transport, backend-enforced company scoping, role-based permissions, rate limits, audit logging, secret masking, production configuration checks, restricted support sessions, and multi-factor authentication requirements for highly privileged platform access.

No system can guarantee absolute security. Customers must use strong unique passwords, protect GroupMe bots and callback URLs, limit permissions, remove former users promptly, maintain appropriate independent records and backups, and notify us if they suspect unauthorized access.

09

Your choices and privacy rights

Users can update certain profile information and passwords in the Service. Company administrators can manage many workspace records and memberships. For additional requests, contact us at support@astraiostracking.com.

Depending on where you live and subject to legal exceptions, you may have rights to request access, correction, deletion, portability, or information about our handling of personal information. You may also have a right to appeal a denied request or to avoid discriminatory treatment for exercising a right. We may need to verify your identity and authority before acting.

If your information belongs to a Customer workspace, we may direct the request to that Customer because it controls the record. Authorized agents must provide proof of authority. We do not charge for ordinary privacy requests, but applicable law may permit limits for excessive, repetitive, or unfounded requests.

10

Children and cadet accounts

The Service is a business operations platform and is not directed to children under 13. Do not create an account for, or intentionally submit personal information about, a child under 13 without first contacting ASTRAIOS and establishing all legally required authorization and consent.

A Customer that permits a cadet or other user below the age of majority to use the Service is responsible for obtaining any required organizational and parent or guardian authorization, limiting the information collected, and configuring access appropriately.

11

Processing locations

ASTRAIOS and its providers may process information in the United States and other locations where they operate. Those locations may have different data-protection rules. Where required, we use appropriate contractual or legal measures for cross-border processing.

12

Changes to this policy

We may update this policy as the Service, providers, or legal requirements change. We will post the revised policy with a new effective date and provide additional notice when a change is material and applicable law requires it. Continued use after the effective date is subject to the updated policy.

13

Contact us

For privacy questions or requests, email support@astraiostracking.com. Include enough information for us to identify your account and company, but do not send passwords, payment card information, GroupMe bot tokens, or other secrets by email.

Questions about use of the Service are also governed by our Terms of Service.