Privacy Policy

Last updated: 25 February 2026

1. Who We Are

FlightBuddy ("we", "us", "our") is a travel planning service that helps passengers find train connections to UK airports. Our website is available at flightbuddy.app.

We are committed to protecting your personal data and operating transparently in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data We Collect

2.1 Account Information

When you create an account, we collect:

  • Your name and email address
  • A hashed (encrypted) version of your password — we never store passwords in plain text
  • Your account type (free or premium) and registration date

2.2 Search & Journey Data

When you use the service, we may record:

  • Train routes you have searched for (origin station, destination airport, date)
  • Flight numbers used in journey searches
  • Journeys you choose to save to your account

2.3 Payment Information

Premium subscriptions are handled by Stripe. We do not store your card details on our servers. Stripe processes and stores payment information in accordance with PCI-DSS standards. For Stripe's privacy practices, see stripe.com/gb/privacy.

2.4 Usage Analytics

We use Umami Analytics, a privacy-friendly, open-source analytics tool. Umami does not use cookies, does not collect personally identifiable information, and is fully compliant with GDPR, PECR, and CCPA. No data is shared with third parties for advertising purposes through this service.

2.5 Technical Data

Like most websites, we may automatically receive:

  • Your IP address (used for rate limiting and fraud prevention)
  • Browser type and device type
  • Pages visited and time of access (via anonymised analytics only)

3. How We Use Your Data

We use your data to:

  • Provide and improve the FlightBuddy service
  • Manage your account and authenticate your sessions
  • Process subscription payments via Stripe
  • Save and retrieve your journey history (if you opt in)
  • Send account-related emails (e.g. password resets, email verification)
  • Protect the service from abuse and fraud
  • Understand how the service is used in aggregate, to improve it

We will never sell your personal data to third parties, and we do not use your data for automated decision-making or profiling.

4. Advertising (NitroPay)

Free-tier users of FlightBuddy may see advertisements served by NitroPay. NitroPay may use cookies and similar tracking technologies to serve contextually relevant ads.

You may opt out of personalised advertising by visiting NitroPay Opt-Out.

Premium subscribers and administrators do not see any advertisements.

5. Third-Party Services

FlightBuddy integrates with the following third-party services:

NitroPay

Advertising network for free-tier users. May set advertising cookies.

nitropay.com/privacy

Google Sign-In (OAuth)

Optional sign-in method. If used, Google shares your name and email address with us.

policies.google.com/privacy

Stripe

Payment processing for premium subscriptions. We never see or store your card details.

stripe.com/gb/privacy

National Rail Open Journey Planner

Live train timetable data provided under a National Rail Type B Data Licence. No personal data is shared with National Rail.

nationalrail.co.uk

Umami Analytics

Privacy-friendly analytics. No cookies, no PII, GDPR compliant.

umami.is

6. Cookies

CookiePurposeType
auth_tokenKeeps you logged in to your accountEssential
NitroPayContextual advertising for free-tier usersAdvertising
UmamiAnonymous usage analytics — no cookies setCookie-free

You can control or delete cookies at any time through your browser settings. Disabling essential cookies may affect your ability to stay logged in.

7. Data Retention

  • Account data — retained for as long as your account is active. You may delete your account at any time from your account settings.
  • Search history — retained for up to 12 months, or until you clear it manually.
  • Payment records — retained for 7 years as required by UK tax law.
  • Analytics data — Umami retains anonymised event data for up to 24 months.

8. Your Rights Under UK GDPR

Under UK GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate or incomplete data
  • Erasure — request deletion of your personal data ("right to be forgotten")
  • Restriction — ask us to limit how we process your data
  • Portability — receive your data in a machine-readable format
  • Object — object to us processing your data for certain purposes
  • Withdraw consent — where processing is based on consent, withdraw it at any time

To exercise any of these rights, please contact us at privacy@flightbuddy.app. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data rights have been violated.

9. Data Security

We take reasonable technical and organisational measures to protect your personal data, including encrypted data transmission (HTTPS), hashed password storage, and access controls limiting who can access user data. However, no internet transmission is completely secure and we cannot guarantee absolute security.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "last updated" date at the top of this page. For significant changes, we will notify registered users by email. Continued use of FlightBuddy after changes are published constitutes acceptance of the updated policy.

11. Contact Us

If you have any questions or concerns about this Privacy Policy or how we handle your data, please contact us:

FlightBuddy

Email: privacy@flightbuddy.app

Website: flightbuddy.app