Privacy Policy
1. Overview
HAVERIS ("we," "us," or "our") provides airworthiness directive and service bulletin intelligence tools for aircraft owners, mechanics, and maintenance organizations. This Privacy Policy explains how we collect, use, and protect information when you use haverisaero.com and related services (the "Service").
By using the Service, you agree to the practices described below. If you do not agree, please do not use the Service.
Data controller
The data controller responsible for processing your personal data is:
For privacy or data protection questions, write to info@haverisaero.com.
2. Information we collect
Information you provide
- Account data: name, email address, password (stored as a salted hash), and profile type (owner, mechanic, shop).
- Aircraft data: registration numbers, serial numbers, installed equipment, engine and propeller details, and compliance records you upload.
- Billing data: handled by our payment processor Lemon Squeezy, who acts as Merchant of Record. We store only limited metadata (plan, last four digits of card, billing country).
- Communications: messages you send us via email or contact forms.
Information collected automatically
- Usage data: pages viewed, searches performed, features used, and timestamps.
- Device data: IP address, browser type, operating system, and referring URL.
- Cookies and similar technologies: see Section 9. 9. Cookies.
Information from public sources
To provide applicability matching, we automatically retrieve aircraft registration data from public government registries (e.g., the FAA N-Number registry). We do not cross-reference this with personal data beyond what you have linked to your account.
Information from Google sign-in
- What we receive: when you sign in with Google, we receive your email address, your full name, and your Google profile picture URL.
- How we use it: solely to (a) create or authenticate your account, (b) display your name in the dashboard, and (c) send transactional emails.
- What we don't do: we do not share, sell, or use Google account data for advertising. We do not access any other Google service beyond the basic OAuth profile (no Gmail, Drive, Calendar, Contacts, etc.).
- Deletion: you can disconnect Google sign-in or delete all data we hold about you at any time by emailing info@haverisaero.com. The deletion is processed within 30 days.
3. How we use data
We use your information to:
- Provide, maintain, and improve the Service;
- Match airworthiness directives to your aircraft and generate compliance reports;
- Process payments and manage subscriptions;
- Send transactional emails (receipts, security alerts, AD notifications);
- Respond to support requests;
- Detect, investigate, and prevent fraud or abuse;
- Comply with legal obligations.
We do not sell your personal data. We do not use your aircraft data to train third-party AI models.
4. Data sharing
We share limited data with trusted service providers who help us operate the Service, including:
- Hosting and database: Supabase (database, authentication, file storage) and Vercel (web hosting and edge runtime). Both store data on our behalf within their own infrastructure.
- Payment processing: Lemon Squeezy is the Merchant of Record — they handle all card transactions, tax collection (VAT, sales tax), and billing receipts. We never store full card numbers.
- Email delivery: Resend sends our transactional email (account verification, password reset, billing receipts, AD notifications).
- AI content enrichment: Anthropic (Claude) and Groq receive public regulatory documents (FAA / EASA / UKCAA AD text) for summarisation and enrichment. Your account data, aircraft information, and personal data are never sent to these services.
- Analytics: we use privacy-respecting, aggregate-level analytics to understand usage patterns. No individual cross-site tracking.
We may also disclose data when required by law, to enforce our Terms, or to protect the rights, property, or safety of our users or the public.
If HAVERIS is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
5. Data retention
We retain account data for as long as your account is active. If you close your account, we delete or anonymize personal data within 90 days, except where we are required to keep records for legal, accounting, or tax purposes.
Compliance reports and aircraft data you have exported remain yours. You can request a full export of your data at any time.
6. Security
We use industry-standard safeguards to protect your data, including TLS encryption in transit, encryption at rest for sensitive fields, role-based access controls, and regular security reviews. No system is perfectly secure, however, and we cannot guarantee absolute security.
If we become aware of a breach affecting your data, we will notify you without undue delay, as required by applicable law.
7. Your rights
Depending on where you live, you may have the following rights:
- Access: request a copy of the personal data we hold about you;
- Correction: ask us to correct inaccurate data;
- Deletion: ask us to delete your data;
- Portability: receive your data in a machine-readable format;
- Objection: object to certain types of processing;
- Withdraw consent: where processing is based on consent, you can withdraw it at any time.
To exercise these rights, email info@haverisaero.com. We will respond within 30 days.
For users in the EU, UK, and Switzerland: the legal bases for processing include performance of a contract, legitimate interests, legal obligations, and consent where applicable. You have the right to lodge a complaint with your local data protection authority.
For users in California: the CCPA gives you specific rights regarding your personal information. We do not sell personal information as defined under the CCPA.
For users in Türkiye: under KVKK Article 11 (Kişisel Verilerin Korunması Kanunu) you have the right to learn whether your personal data is being processed, request information on its purpose, request correction or deletion of incorrect or unlawfully processed data, object to automated decisions producing adverse effects, and seek compensation for damages caused by unlawful processing. The data controller is identified at the top of this policy. Complaints can also be filed with the Turkish Data Protection Authority (KVKK).
8. International transfers
HAVERIS operates globally. Your data may be processed in countries other than the one you live in, including the United States. Where required, we use appropriate safeguards such as Standard Contractual Clauses to protect transfers.
9. Cookies
We use cookies and similar technologies to keep you signed in, remember preferences, and measure how the Service is used. You can control cookies through your browser settings. Disabling certain cookies may affect functionality.
Cookie categories we use:
- Strictly necessary: required for the Service to function (authentication, security);
- Preferences: remember your settings;
- Analytics: understand aggregate usage (no individual tracking across sites).
10. Children's privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe we have, please contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through the Service at least 14 days before the changes take effect. The "Last updated" date at the top of this page shows when the policy was last revised.
12. Contact us
If you have questions about this policy or how we handle your data, please reach out:
- Email: info@haverisaero.com
- General contact: haverisaero.com/contact
