This Privacy Policy applies to FBOTrack (fuel and ground-service logging) and FBOShift (shift scheduling) on iOS, Android and the web. The two apps share one account and one backend, so one policy covers both. "The platform" means both apps.
1. Information collected
All information is collected to run the platform. None of it is sold, used for advertising, or used to track anyone across other companies' apps or websites.
- Contact info — name, username and email address, entered when an account is created.
- Identifiers — an account ID, and a push-notification token for each device that allows notifications.
- Work records (user content) — what the FBO enters while working:
- FBOTrack: fuelings, refills, transfers, deliveries, tank readings, ground services, service orders, schedules, route board entries, aircraft tail numbers, tenants, customer companies, notes and documents.
- FBOShift: shifts, time-off and swap requests, availability, call-offs and holiday sign-ups.
- Photos and files — hangar photos, profile pictures and documents uploaded to an FBO's records. The camera is used only when the user chooses to take a photo or scan a tail number.
- Location — only when an FBO turns on its geofence setting: the device's location is checked when a fueling or service is logged, and the location where it was logged is saved with that record. Location is not tracked in the background.
- Usage data — sign-in times and devices, and an activity log of changes made inside an FBO, so managers can see activity and so stale or suspicious sessions can be detected.
- Diagnostics — crash reports from Apple's and Google's systems, not linked to identity.
Not collected: contacts, audio, browsing or search history, health data, or payment card numbers (payments are handled entirely by Stripe).
2. How information is used
To provide the platform: sign-in and security, keeping each FBO's service, inventory and schedule records, sending notifications the user allows, syncing to an FBO's own Excel workbook when the FBO connects one, billing, and support.
3. Who can see an FBO's data
- Inside the FBO: people in that FBO, according to the roles and permissions its managers set. A corporate admin can see the locations in their own organization.
- Other FBOs: never. Each FBO's data is separated by database security rules.
- FBOTrack staff: the platform administrator account sees only account-level information — FBO name, plan, billing status, dates and usage totals (for example, number of users or fuelings) — not individual records. Because FBOTrack hosts the platform, its staff have technical access to the database. They look at an FBO's records only:
- while that FBO's manager has turned on support access in Settings (it switches off automatically after the period the manager chooses), or
- when needed to keep the platform secure, investigate abuse, or comply with the law.
Every support-access grant is recorded — who turned it on, when, and for how long — and the FBO's managers can see that history in Settings.
- Service providers (section 4) process data only to run the platform.
4. Service providers
- Supabase — database, sign-in and file storage.
- Vercel — website and server hosting.
- Stripe — subscription billing and payments.
- Resend — account, onboarding and account-notice emails.
- Apple and Google — push notifications and app distribution.
- Microsoft — only for an FBO that connects Excel sync, to write its records to its own workbook.
- FlightAware — arrival and departure information (aircraft flight data, not user data).
- AI development and support tools — used to build and fix the platform; FBO records are shared with them only under the support-access rules in section 3.
5. Security
Data is encrypted in transit (HTTPS) and stored with database security rules that limit each FBO to its own records. PINs and passwords are stored only as secure hashes. Microsoft (Excel) connection tokens are stored encrypted.
6. Retention
Records are kept while the FBO's subscription is active and for 90 days after it ends. The FBO's owner and managers are emailed when 30 days and 7 days remain. After the 90 days, the FBO's records and files are deleted, along with the accounts of people who belong only to that FBO. Renewing the subscription before then keeps everything. When a user account is deactivated, that user's records stay with the FBO for its own billing and audit needs.
7. Deleting an account
A user can permanently delete their account in either app under Settings → Delete Account; because the apps share one account, this removes the user from both. Personal information is erased; the FBO's work records are kept without the person's identity, as described in section 6. Deletion cannot be undone.
8. Rights
Users can access, correct or request deletion of their personal information in the app, through their FBO's manager, or by emailing support@fbotrack.com.
9. Children
The platform is for FBO staff and is not intended for anyone under 13. FBOTrack does not knowingly collect information from children under 13; if it learns that it has, that information is deleted.
10. Changes
When this policy changes, the new version is shown in the apps and on the website, and users are asked to agree before continuing.