Legal
Privacy Notice
How GlobalAirData handles information across our websites, public map, account dashboard, feeder network, APIs, and mobile applications.
1. Scope and who we are
This Privacy Notice applies to the GlobalAirData service, including globalairdata.com and its subdomains, the public aircraft map, account dashboard, APIs, GlobalAirData feeder software and receiver services, and GlobalAirData mobile applications (collectively, the “Service”). GlobalAirData is the controller of the personal information described here.
This notice does not govern a third party’s independent handling of information when you follow a third-party link or enable a third-party map, imagery, weather, airport, or aircraft-content layer. See Data Sources & Aviation Disclaimers for more information.
2. Information we collect
Information you provide
- Account and profile information: email address, display name, first and last name, city, state or region, country, password hash, verification status, security settings, and notification preferences.
- Feeder information: feeder name, receiver and antenna details, notes, timezone, precise latitude and longitude, altitude, visibility choice, and claim or pairing information.
- Communications: information included in support, privacy, correction, or other messages you send us.
Information collected through the Service
- Aircraft observations: decoded ADS-B, Mode S, UAT, and related fields such as aircraft address, position, altitude, speed, track, callsign, squawk, signal strength, message counts, receiver timestamps, and derived tracks or coverage metrics.
- Feeder and device telemetry: install and device identifiers, hostname, software and operating environment, capabilities, receiver serial or label, network and service status, resource use, data-source configuration, update results, error messages, and operational health history.
- Optional VHF information: receiver configuration and status, channel and frequency settings, radio audio, recording metadata, transcripts, speaker labels, confidence values, and related operational logs when VHF features are enabled.
- App permissions and device information: with permission, the iOS app may access location to center the map or fill a feeder or antenna-test position, the local network to discover and configure a feeder, and notifications to deliver feeder alerts. We receive a device push token and app/build information when push alerts are enabled. Location used only to center the map remains on the device; a coordinate is sent to us when you choose to save or submit it.
- Network, security, and usage information: IP address, browser or app user agent, requested URL, timestamps, session activity, security events, and similar server-log information. The account service stores hashed session and trusted-device tokens; authentication cookies contain random tokens rather than your password.
- Local data: the web dashboard and app may store account summaries, map preferences, and cached feeder or map information on your device for sign-in continuity, performance, and offline or degraded-network use.
Information from other sources
We receive aviation, aircraft, airport, mapping, airspace, imagery, and weather information from community feeder operators, public agencies, open-data projects, and other data providers. Some aircraft information can relate to an identifiable owner, operator, pilot, or flight even when it is broadcast or publicly available.
3. How we use information
We use information to:
- create and secure accounts, verify identity, maintain sessions, and prevent abuse;
- register, claim, configure, update, troubleshoot, and monitor feeders and receivers;
- display live and historical aircraft positions, tracks, maps, airport and weather context, and feeder analytics;
- deliver requested email and push notifications about account security and feeder health;
- operate optional VHF reception, live listening, recording, and transcription features for authorized users;
- measure coverage, signal performance, traffic patterns, route efficiency, aircraft utilization, fuel-burn patterns, and climate-related aviation questions;
- maintain, debug, protect, audit, and improve the Service; and
- comply with law, enforce our terms, and protect users, the public, and the Service.
We do not use personal information for third-party advertising or to make decisions that produce legal or similarly significant effects about you.
4. How we disclose information
- Service providers: hosting, network, database, backup, email-delivery, security, and support vendors process information for us under appropriate restrictions.
- Apple services: Apple processes push tokens and notification delivery for iOS push alerts, and Apple MapKit may process map requests in the mobile app under Apple’s terms and privacy practices.
- External map and content providers: when a map or optional layer loads directly from another provider, that provider may receive your IP address, user agent, referrer, requested map area or tile, and request time. Providers can include OpenStreetMap Foundation services, Esri, NOAA, NASA, Iowa Environmental Mesonet, DWD, and other sources identified on our data sources page.
- Password security: when checking whether a password appears in a known breach corpus, we may send a short prefix of a one-way password hash to the Have I Been Pwned password service. We do not send the password, email address, or complete hash.
- Public and research uses: aircraft observations and derived data may be displayed publicly or provided for research. Feeder locations or metadata may be displayed according to your visibility setting or in aggregated, generalized, or de-identified form. Account contact and authentication information are not public.
- Legal and safety reasons: we may disclose information if reasonably necessary to comply with law or legal process, investigate fraud or security incidents, enforce our terms, or protect rights, safety, and the Service.
- Business changes: information may transfer as part of a merger, financing, reorganization, sale of assets, or similar transaction, subject to applicable law.
We do not sell personal information or share it for cross-context behavioral advertising.
5. How long we keep information
| Information | Typical retention |
|---|---|
| Account and profile records | While the account is active, then deleted or de-identified after an account-deletion request, except for records needed for security, legal compliance, dispute resolution, or fraud prevention. |
| Authentication challenges, sessions, and trusted-browser records | Challenges are short-lived and removed after use or expiration. Standard sessions expire after up to 7 days and trusted-browser records after up to 7 days unless revoked earlier. Security-event history is generally retained for 90 days. |
| Raw aircraft updates and feeder heartbeats | Generally 6 hours. Current-aircraft records expire much sooner when no longer current. |
| Aircraft track history | Higher-resolution history is generally retained for 30 days and lower-resolution archive history for up to 180 days. |
| Feeder telemetry samples | Generally 7 days. The latest feeder state and registration/configuration records remain while the feeder is registered or as needed to operate the Service. |
| VHF audio, transcripts, alerts, and operational records | For as long as the feature, operational, research, security, or legal purpose requires. Authorized operators may delete feeder-associated VHF and operational data by deleting the feeder where supported. |
| Server logs, backups, and communications | For the shortest period reasonably necessary for security, operations, backup rotation, support, and legal obligations. |
These periods are defaults, not guarantees. We may keep information longer when law requires it, a dispute or security investigation is active, or deletion from encrypted backups must wait for the ordinary backup cycle. We may retain aggregated or de-identified information that can no longer reasonably identify a person.
7. Security and international processing
We use technical and organizational safeguards designed to protect information, including encrypted transport, hashed passwords and session tokens, limited access, security event monitoring, multi-factor authentication controls, and data-retention limits. No system is completely secure, and we cannot guarantee absolute security.
GlobalAirData and its providers may process information in the United States and other countries. Where required, we use an appropriate legal mechanism for international transfers and apply protections consistent with this notice.
8. Your choices and privacy rights
- Review and update available profile, feeder, location-visibility, notification, and security settings in your account.
- Decline or revoke iOS location, local-network, or notification permission in device settings. Some related features will stop working.
- Delete your account from the GlobalAirData app or account settings. Account deletion releases claimed feeders and removes associated account records, subject to the exceptions described above.
- Request access, correction, deletion, portability, restriction, or an explanation of our processing by emailing privacy@globalairdata.com. Depending on your location, some rights may not apply or may be subject to exceptions.
We may verify your identity before completing a request. You may use an authorized agent where law permits. We will not discriminate against you for exercising a privacy right.
9. Regional disclosures
California
The table below describes categories of personal information we may have collected and disclosed for a business purpose during the preceding 12 months. We do not sell these categories or share them for cross-context behavioral advertising.
| California category | Examples | Sources, purposes, and recipients |
|---|---|---|
| Identifiers | Name, email, account and device identifiers, feeder identifiers, IP address, push token | From you, your app/browser, and feeder; used for accounts, security, feeder operations, and alerts; disclosed to operational service providers. |
| Customer-record and profile information | Name, city, state/region, country, account preferences | From you; used to manage and personalize the account; disclosed to operational service providers. |
| Internet or electronic-network activity | User agent, session activity, request and security logs, feeder service health | From browsers, apps, and feeders; used for functionality, diagnostics, and security; disclosed to infrastructure and security providers. |
| Geolocation data | Feeder coordinates, saved antenna-test positions, approximate network location | From you, an authorized mobile permission, the feeder, or IP-derived context; used for maps, coverage, MLAT, setup, and security; displayed only as described in this notice. |
| Audio and electronic information | Optional VHF radio audio, transcripts, support communications | From enabled receivers and from you; used for authorized VHF features, operations, and support; disclosed to service providers and authorized users as needed. |
| Inferences | Coverage, reception, traffic-pattern, and device-health analytics | Derived from feeder and aircraft observations; used for service features, diagnostics, and research; may be shared in aggregated, de-identified, or research form. |
| Sensitive personal information | Account credentials and precise feeder or submitted device location | From you and your authorized devices; used only for account access, security, mapping, receiver operation, coverage, and research purposes described here—not to infer sensitive characteristics. |
California residents may request to know, access, correct, or delete covered personal information and may appeal or use an authorized agent where applicable. Because we do not sell or share personal information for cross-context behavioral advertising, we do not provide a “Do Not Sell or Share” link. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law.
European Economic Area, United Kingdom, and Switzerland
We process information as needed to perform our agreement with you (accounts and requested feeder features), for legitimate interests (operating, securing, improving, and researching the Service and presenting aviation information), with consent where required (such as optional device permissions), and to comply with legal obligations. You may have rights to access, correct, erase, restrict, object, or receive a portable copy of personal data, and to withdraw consent without affecting earlier processing. You may also complain to your local data-protection authority.
10. Children
The Service is a general-audience aviation and research service and is not directed to children under 13. Children under 13 may not create an account or submit personal information. If we learn that we collected personal information from a child under 13 without legally valid authorization, we will delete it. If you believe this has occurred, contact us.
11. Changes to this notice
We may update this notice as the Service or law changes. We will post the revised notice here, update the date above, and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.
12. Contact us
For privacy requests or questions, email privacy@globalairdata.com. Please do not send passwords, authentication codes, receiver secrets, or other sensitive credentials by email.