Privacy Policy
Last updated: August 15, 2026
The short version
We collect what Flydar needs to watch your trips, email you, and see how the app is actually used. We never sell your data. There are no ad trackers on this site, and nothing you do here follows you around the web. You can get a copy of everything we hold, or have it deleted, by sending one email.
Who we are
Flydar is a flight-deal alert service, and we're the controller of the personal data described here. Reach us at [email protected]. That's a real inbox, and it's also where privacy requests go.
What we collect
Your account
- your email address
- your name, if the sign-in method you chose passes it to us
- an account identifier from our authentication provider
- your timezone and your email preferences
What you ask us to watch
- your home airports
- the routes you track: origins, destinations, and whole cities where you pick one
- the shape of each trip: your travel window or dates, how long you'd go for, one-way or round trip, and any target price you set
What Flydar produces for you
- your deal history: the fares we found for your trips, their dates, how far below normal they were, and when we found them
- your notification history: which alerts we sent you, and when
Billing
- We never see or store your card number. Your subscription is sold by Creem, our merchant of record, which holds the billing relationship and is its own data controller for it.
- We keep a summary so the app knows where you stand: your plan, subscription status, trial end date, renewal dates, and the identifiers Creem gives us.
- We keep a one-way fingerprint of the payment method (not the card number, and not reversible), so one card can't open an endless run of free trials.
How you use Flydar
- the pages you open and the things you do on them: landing on the site, starting a sign-up, building a trip, opening a deal, starting a subscription
- the basics that come with any web request: your browser and device type, the page that sent you here, and a rough country. Your IP address is anonymized before it's stored, so we don't keep it
- an identifier stored in a first-party cookie, so the pages in one visit read as one visit rather than a pile of strangers
- Session recordings. A replay of your own screen on this site (the pages you open, clicks, scrolling, and the trips you set up), so we can see where Flydar confuses people instead of guessing. Everything you type into a field is masked before it leaves your browser, including your email and password, and your account email and name are masked where the app displays them. We record our own pages only, and we don't record anything that isn't Flydar.
Once you're signed in, this is tied to your account, so we can tell whether the product works for real people rather than for an average. It's used to build and fix Flydar, and for nothing else.
Technical
Our hosting keeps standard server logs (IP address, browser user-agent, timestamps) for security and debugging. We don't use them to profile you.
What we don't collect
No advertising identifiers, no ad or marketing pixels, no location tracking, no record of your browsing anywhere else. Our analytics are first-party and stop at the edge of this site. We don't ask for your date of birth, your home address, or your passport.
Why we collect it
- To run the service and send your alerts: this is performance of our contract with you.
- To keep accounts secure and stop abuse, including trial farming: our legitimate interests.
- To understand how Flydar is used, and to fix what doesn't work: our legitimate interests. That means measuring which parts of the product people reach, where they get stuck, and watching replays of sessions on our site. It's a small product, so this is how a bug gets found at all.
Where we'd ever ask for consent for something optional, you could withdraw it at any time.
What we'll never do
We will never sell your data. We don't share it with advertisers. We don't send spam. If we email you, it's because a deal or something about your account is actually worth your time.
Who we share it with
Only providers that help us run Flydar, only what each one needs, and only on our instructions:
- an authentication provider, which holds your sign-in identity
- cloud hosting and database providers, which run the app and store its data
- an email delivery provider, which delivers your alerts and account emails
- a product analytics provider: PostHog, which stores the usage data and session recordings described above, on our instructions, on servers in the EU
- the payment processor: Creem, our merchant of record, which sells you the subscription, takes the payment, and handles tax and receipts. Creem is a separate controller for the billing relationship, under its own privacy policy.
We describe recipients by category, which is what data-protection law asks for. If you need the actual named list (for a data-processing agreement, say), email us and we'll send it.
We don't sell personal data, and we don't share it for cross-context behavioral advertising. We may disclose data where the law requires it, or where it's needed to protect the service or someone's safety.
Where your data is processed
Flydar runs on infrastructure in the United States, and some of our providers operate globally. If you're in the EEA, the UK, or Switzerland, that means your data is transferred outside your country. Those transfers are covered by the European Commission's Standard Contractual Clauses (with the UK Addendum where it applies) or by an adequacy decision, with every provider involved.
The usage data and session recordings are the exception, and deliberately so: they stay in the EU. We chose our analytics provider's EU region, so that data is stored in Germany and never leaves it.
How long we keep it
- Your account, home airports, and tracked trips: for as long as your account exists. Gone when you ask us to delete it.
- Your notification history: with your account, and deleted along with it.
- Your deal history: kept, but de-identified once your account is gone. Deals are a permanent record of what the service found; after deletion the identifier attached to them no longer points at any person, so what remains is statistics, not you.
- Product event logs: kept, with your identifier removed on deletion.
- Session recordings: 30 days, then they're deleted automatically. Ask us and we'll delete yours sooner.
- Usage data: kept while your account exists, and detached from you when it's deleted.
- Fare data itself: kept indefinitely. It's about routes and prices rather than about you, so it isn't personal data.
- Billing records: held by Creem, which keeps them for as long as its own tax and accounting obligations require. That retention is Creem's, not ours.
- Server logs: short-lived, on our providers' own schedules.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, export it in a portable format, or restrict or object to how we use it. We honor these for everyone, including under GDPR (EU/UK) and CCPA/CPRA (California).
How to ask: email [email protected] from the address on your account and tell us what you want. We may need to confirm it's really you. We'll get it done within 30 days (usually much sooner), and there's no charge.
Two things worth knowing:
- Deletion is a request, not a button. We run it by hand so it's done completely: your account, your home airports, your tracked trips, your notification history, your session recordings, your analytics profile, and your sign-in record with our authentication provider all go, and your deal history is de-identified as described above. Ask us and we'll also flag your billing record to Creem for removal, though Creem keeps what its tax obligations require.
- Stopping the emails doesn't need a request: delete a trip in the app and its alerts stop, or reply to any Flydar email and ask us to switch them off.
If you're in the EEA or the UK you can also complain to your local data protection authority, though we'd much rather you told us first.
Children
Flydar isn't for under-18s, and we don't knowingly collect their data. If you think a child has signed up, email us and we'll remove the account.
Cookies
Two kinds, both first-party, and neither one follows you anywhere else:
- Sign-in cookies, which keep you signed in and keep that session secure.
- One analytics cookie, which holds the identifier that ties the pages of a visit together. It's what lets us see how the product is used and where it trips people up. What it feeds is stored in the EU, your IP address is anonymized, and it is never sold and never used for advertising.
No advertising cookies, and no cookies from ad networks or data brokers. If you'd rather we didn't hold usage data about you at all, say so at [email protected]: you can object at any time, and we'll delete what we have and leave your account out of it from then on.
Security
Traffic is encrypted in transit, access to production data is restricted, and credentials live in a managed secret store. We don't hold card numbers, so we can't leak them. No service is perfectly secure. If something happens that affects you, we'll tell you, and the relevant regulator where we're required to.
Changes
If anything here changes, we'll update this page and the date above. If a change materially affects you, we'll email you.
Contact
Anything at all: [email protected].