Privacy Policy
Last updated: July 16, 2026 (version 2026-07-16)
1. Introduction
This Privacy Policy describes how Crossfeed Consulting LLC (“we”, “us”, or “our”) collects, uses, and protects information through Flight Desk Pro (“the App”). The App is operated by and for a single Certificated Flight Instructor (CFI) to manage their flight training clients.
By using the App, the CFI agrees to the practices described in this policy.
2. Information We Collect
The CFI enters the following information about their clients into the App:
- Personal identifiers: full name, date of birth, email address, phone number
- Government-issued ID references: FAA certificate number, FTN (IACRA), driver’s license or state ID, passport or birth certificate identifier
- Medical information: medical certificate class and examination date
- Training history: flight hours, solo dates and hours, endorsements, stage check results, checkride dates and outcomes
- Aircraft information: aircraft ownership status and associated aircraft records
- For minor clients (under 18): parent or guardian name and email address
The App also collects the CFI’s own profile information: name, FAA certificate number and expiration date, email, phone number, and push notification token (if notifications are enabled).
We also collect the following, from CFIs and pilots alike, where applicable:
- Location: if you enable location access, the App uses your device’s location solely to pre-fill the origin airport on a new trip log entry. Location is not collected or stored in the background.
- Device information: a device identifier, device name, and model name, used to enforce our per-account device limit and to let you view and remove devices from your account in Settings.
- Photos and signatures: photos you upload for photo endorsements or your profile, and signature images captured for digital endorsements.
- Billing information: if you subscribe to a paid plan, your subscription status and a Stripe customer/subscription reference ID. Your payment card details are entered directly with Stripe and are never sent to or stored on our servers — see Section 3.
3. How We Use Information
Information collected through the App is used for flight training management between the CFI and their clients, and to operate the App itself. Specifically:
- To display and track client training progress, endorsements, and certifications
- To allow clients to view their own training record through the client portal
- To send push notifications regarding training alerts or reminders (if enabled)
- To process subscription payments through Stripe and manage your billing status
- To enforce our per-account device limit and let you manage your own devices
We use Vercel Analytics on our website to understand aggregate traffic (e.g., page views and referring sites). It is cookie-free and does not track you across other websites or build an advertising profile. We do not use any collected information for advertising, and we do not sell personal information.
4. Children’s Privacy (COPPA)
The App is aware that flight training clients may include minors. We take the following position regarding children’s data:
- The App does not knowingly provide client portal access to users under the age of 13.
- The CFI is responsible for obtaining and retaining verifiable parental or guardian consent before adding any client under the age of 13 to the App.
- If a client’s date of birth indicates they are under 13, the App will display a warning to the CFI and require acknowledgment before the record is saved. The client will not be able to create or use a portal login.
- For clients aged 13–17, the CFI is required to provide the parent or guardian’s name and email address when creating the client record. The CFI affirms they have obtained appropriate consent.
If you believe we have inadvertently collected data from a child under 13 without proper consent, please contact us immediately using the information in Section 9.
5. Parental Access Rights
Parents or legal guardians of minor clients have the following rights:
- Access: You may request a summary of the personal data the CFI has recorded about your child.
- Correction: You may request that inaccurate data be corrected.
- Deletion: You may request that your child’s data be deleted from the App.
Requests should be directed to the CFI who manages your child’s training record. The CFI is responsible for honoring these requests within 30 days. If you are unable to reach the CFI, you may contact us using the information in Section 9 and we will facilitate the request.
6. The CFI as Data Controller
The CFI is the primary account holder and the responsible party for all client data within their account. This means:
- The CFI decides what data to enter and is responsible for its accuracy.
- The CFI is responsible for obtaining any consents required by law before adding a client’s information.
- Crossfeed Consulting LLC provides the App infrastructure but does not independently review, audit, or control the data the CFI enters.
7. Pilot Accounts and Direct Subscribers
An adult pilot may create their own client portal account and subscribe to a paid plan directly, independent of the CFI who added them. For that pilot’s own account and subscription data (login email, password, and billing status), the pilot is the account holder in their own right — not merely the subject of data the CFI entered.
A pilot may access, correct, or request deletion of their own account data at any time through the App’s Settings screen, or by contacting us using the information in Section 9. This is separate from, and in addition to, the CFI’s responsibility for the training records described in Section 6.
8. Data Retention and Deletion
Client data is retained in the App for as long as the CFI account remains active.
- If a CFI deletes their account, all associated client records will be permanently deleted within 30 days.
- A parent or guardian may request deletion of a minor client’s data at any time (see Section 5).
- Individual client records can be removed by the CFI at any time through the App.
Data is stored using Supabase, a third-party database provider, used solely for storage and App delivery. Subscription payments are processed by Stripe, which handles and stores your payment card details directly — we never receive or store your card number. Our website is hosted on Vercel, which also provides the aggregate analytics described in Section 3. Each of these providers operates under its own data processing agreements.
9. Contact Information
If you have questions about this Privacy Policy, wish to exercise your data rights, or need to report a concern, please contact the CFI directly through the App’s Settings screen.
For matters that cannot be resolved through the CFI, you may contact the App developer via the feedback form in the Settings screen.
Flight Desk Pro — Crossfeed Consulting LLC © 2026