Privacy policy
Effective date: September 11, 2026
Last updated: September 11, 2026
TheFlightWall is operated by AxisNimble Inc., a Delaware corporation ("AxisNimble," "TheFlightWall," "we," "us"). This Privacy Policy explains how we collect, use, disclose, and protect personal information when you:
- visit our website at theflightwall.com or purchase from our online store (the "Site" and "Store");
- use our mobile application (the "App");
- use a physical Flight Wall display (a "Device"); or
- subscribe to TheFlightWall Plus, our optional paid flight-schedule syncing service ("Plus").
This policy forms part of our Store Terms of Service and, for Plus subscribers, our Plus Terms of Service. By using the Site, Store, App, Devices, or Plus, you agree to the practices described here.
How this policy is organized
Part 1 applies to everyone who uses the Site, Store, App, or a Device. You do not need an account for any of these, and we do not collect your name or email through the App or Device.
Part 2 applies only if you create a TheFlightWall Plus account. Plus is a separate, optional subscription that requires an account and involves your flight schedule. If you never sign up for Plus, Part 2 does not apply to you.
Part 3 covers changes to this policy and how to contact us.
For any privacy question or request, contact us at privacy@theflightwall.com.
Part 1 — Site, Store, App, and Devices (everyone)
1. Who We Are and Scope
AxisNimble Inc. is the controller for personal information processed in connection with the Site, Store, App, and Devices (together, the "Core Services"). Part 1 applies to information we process when you visit our Site, buy from our Store, use our App, or connect a Device to our services.
2. No-Account Model and Identification
The Core Services do not require an account, and we never ask for your name or email address in order to use them. The one exception is support: if you send us a bug report from the App, you may choose to include an email address so we can reply to you (Section 3G). Apart from that, the personal information we process for the Core Services is associated with your Device or your network connection, not with a named account.
When you contact us for support or to exercise privacy rights about a Device, we may ask for the Device serial number, MAC address, or another device identifier to verify and fulfill your request.
3. Information We Collect
We collect only what we need to provide, secure, and support the Core Services.
A. Purchase Information
When you buy a Device, our Store platform and payment processor collect your name, billing and shipping address, email address, phone number, and payment card details. We receive only what is necessary to fulfill and support your order (name, shipping address, contact details, and order details). We never receive your full card number.
B. Device Data
- Device serial number or hardware identifier
- Device MAC address
- Local network IP address
- Public (WAN) IP address, received when the Device connects to our servers
- Connectivity status, uptime, firmware version, and basic health indicators
C. User-Selected Configuration Data
- The geographic area you select in the App (coordinates or region) for flight tracking
- Display filters and Device display preferences
We do not collect continuous precise geolocation from the Device. If you allow the App to access your phone's location, it is used only to help you pick an area; you can also enter a location manually.
D. Wi‑Fi Setup Information
During setup, the App sends your Wi‑Fi network name (SSID) and password directly to the Device so it can join your home network. This is transmitted only between your phone and the Device. It is never transmitted to or stored on our servers.
E. Site and App Usage Data
IP address, approximate location derived from IP, browser type, operating system, device type, access times, pages viewed, referring address, and general log information.
F. Device Diagnostics
Limited diagnostic information from the Device (uptime, connection status, error logs) to monitor performance, find bugs, and improve reliability. Where feasible this is de-identified or aggregated.
G. Bug Reports You Send Us
If you submit a bug report from the App, we receive the description you write, the App's installation identifier, your phone's platform and version, the relevant Device identifier, and — only if you choose to enter one — an email address so we can follow up. Email is optional; leaving it blank does not stop the report from being sent. Bug reports are handled in our support help desk (Section 5).
H. Terms Acceptance
When you accept our terms in the App, we record the App's installation identifier, your phone's platform and version, your IP address, and the time, as evidence of acceptance.
4. How We Use Information
Device operation. Connect and authenticate the Device; fetch and display flight data for your selected area and filters; deliver firmware and software updates.
Security and service integrity. Keep the service connected and stable, prevent abuse, detect anomalies, and troubleshoot.
Orders, support, and communications. Fulfill and support your order; respond to support requests; send technical notices, updates, security alerts, and administrative messages.
5. How We Share Information
We do not sell, trade, or rent personal information, and we do not share it for cross-context behavioral advertising. We share information only:
- with service providers that act on our behalf under contract — hosting providers, flight-data providers, our Store platform and payment processor, shipping carriers, and support and diagnostics vendors — who may use it only for the purposes we specify. Support requests and App bug reports, including any email address you choose to give us, are handled in Help Scout, our support help desk;
- for legal and safety reasons: to comply with law or legal process, enforce our terms, or protect the rights, property, or safety of users, the public, or AxisNimble;
- in a business transfer such as a merger, acquisition, or sale of assets, subject to this policy; or
- at your direction or with your consent.
Text-messaging originator opt-in data and consent are excluded from all of the above and are never shared with third parties.
6. IP Addresses
When your Device or browser connects to our services we automatically receive your IP address. We use it to enable connectivity, maintain stability, prevent abuse, and troubleshoot. IP addresses are retained for the period in Section 7.
7. Data Retention
- IP addresses and server logs: up to 90 days, unless needed longer for security or legal reasons.
- Device configuration (area, filters): for as long as needed to operate your Device; deleted on request or when you stop using the service. We may keep minimal records where the law requires.
- Wi‑Fi credentials: never transmitted to or stored on our servers.
- Diagnostics logs: up to 180 days, in de-identified or aggregated form where feasible.
- Bug reports and support conversations: for as long as needed to resolve the issue and keep a support history, and deleted on request.
- Terms-acceptance records: for as long as we need to evidence that the terms were accepted.
- Order records: for as long as required for tax, accounting, warranty, and consumer-protection obligations.
8. Lawful Bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on:
- Contractual necessity — to fulfill your order and provide the Device and App functionality you request;
- Legitimate interests — to secure our services, prevent abuse, and improve reliability;
- Legal obligations — to comply with applicable law; and
- Consent — where you grant App-level permissions (for example, location access) or where the law requires it. You may withdraw consent at any time through your phone's settings.
9. International Data Transfers
We process and store information in the United States. If you are in the EEA or UK and your information is transferred outside your jurisdiction, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable).
10. Your Privacy Rights
GDPR / UK GDPR. You may have the right to request access, rectification, erasure, restriction, objection, and portability, and to withdraw consent where processing is based on consent.
CCPA / CPRA (California). You may have the right to know, delete, and correct personal information; to opt out of sale or sharing (not applicable — we do not sell or share for cross-context behavioral advertising); and to non-discrimination for exercising your rights.
Notice at collection. In the past 12 months we have collected these categories of personal information:
- Identifiers (Device identifiers, IP address, an App installation identifier; an email address if you choose to give one in a bug report; and, for Plus only, name and email address)
- Commercial information (order details; and, for Plus only, subscription details)
- Internet or other electronic network activity (Site and App interactions, logs)
- Geolocation data (limited to a user-selected configuration area; not precise geolocation)
- Professional or employment-related information (for Plus only, your crew schedule)
Device-based verification. Because the Core Services have no accounts, we may ask for your Device serial number, MAC address, or another device identifier to verify a request about a Device. Plus requests are verified through your Plus account email (see Part 2).
How to exercise your rights. Email privacy@theflightwall.com. We aim to respond within 30 days (GDPR / UK GDPR) or 45 days (CCPA / CPRA), subject to extensions permitted by law. We honor these requests regardless of where you live.
11. Security
We use industry-standard administrative, technical, and physical safeguards designed to protect your information. No electronic transmission or storage is 100% secure. The security of your Device's connection to your Wi‑Fi network depends on the safeguards you apply to your own network.
12. Children
The Site, App, and Devices are not directed at children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have, we will delete it. You must be 18 or older to purchase from the Store or to use Plus (see Section 22).
Part 2 — TheFlightWall Plus (only if you have a Plus account)
This part applies to you only if you create a TheFlightWall Plus account. Plus is an optional paid subscription that lets pilots, flight crew, and their households sync a flight schedule to a Flight Wall display via our website, the App, and linked Devices. If you use a Device or the App without a Plus account, only Part 1 applies to you.
Plus is currently offered in the United States, and Plus data is stored in the United States. As we open Plus in other regions, region-specific notices will be published alongside this one.
13. Information We Collect for Plus
Account and profile information. Email address, name, password (stored in hashed form by our authentication provider — we never see or store your plain-text password), and the country you select during account setup.
Schedule data. Flight schedule information you add or import, including flights, dates and times, airports and routes, duty periods, and any notes you attach. This can come from:
- Google Calendar import — if you connect your Google account, we access your calendar on a read-only basis to import schedule events (see Section 15);
- Calendar file or URL import — ICS files you upload or calendar URLs you subscribe to;
- Manual entry — flights you add directly.
Linked Device information. Identifiers for the Devices you link to your Plus account, their link status, and display configuration settings.
Billing information. Web subscriptions are processed by Stripe. Subscriptions purchased in the App are billed by the Apple App Store or Google Play, and we use RevenueCat to validate those purchases and keep your subscription status in sync. We do not receive or store your full card number; we store your subscription status, plan details, and store transaction identifiers.
Support communications. If you email us, the contents of your message and your contact details are handled in our support help desk (see Section 17).
Technical data. Standard server logs (IP address, browser type, timestamps) generated when you use Plus, used for security and operations.
We do not use third-party advertising trackers or analytics pixels in Plus.
14. How We Use Plus Information
We use Plus personal information to:
- provide the service: sync, parse, and display your flight schedule on your linked Devices;
- create and manage your account and authenticate you;
- process subscription payments and manage entitlements;
- send transactional service emails (for example, account verification and schedule re-sync notifications);
- provide customer support;
- secure, maintain, and improve Plus; and
- comply with legal obligations.
We do not sell Plus personal information, and we do not share it for cross-context behavioral advertising.
15. Google User Data
If you choose to connect Google Calendar, we request the read-only Google Calendar scope (calendar.readonly) and use it solely to read calendar events so we can import your flight schedule into Plus. Specifically:
- We access calendar event data (event titles, descriptions, times, and locations) only to identify and import schedule entries you choose to sync.
- We store the resulting schedule entries in your account, along with the tokens needed to keep your schedule in sync. Refresh tokens are stored encrypted.
- We do not use Google user data for advertising, and we do not sell it.
- Humans do not read your Google Calendar data except with your explicit consent (for example, in a support case you initiate), where necessary for security or debugging, or where required by law.
- You can disconnect Google Calendar at any time from the import settings, which stops further access; you can also revoke our access from your Google Account permissions.
TheFlightWall Plus' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
16. Automated Schedule Parsing (AI)
To convert imported calendar events into structured flight entries, the text of imported events is processed by OpenAI, acting as our service provider under a signed data processing agreement. This processing is limited to parsing your schedule; the data is not used by us or, per that agreement, by OpenAI to train AI models. OpenAI retains the submitted text for 30 days for abuse and misuse monitoring, then deletes it. You can always review, correct, or delete the parsed results in Plus.
17. How We Share Plus Information
In addition to the legal, safety, and business-transfer circumstances in Section 5, we share Plus personal information only with:
Service providers that process data on our behalf under a data processing agreement (DPA). Each provider's DPA is linked below:
| Provider | Purpose | Data processing agreement |
|---|---|---|
| Supabase (on AWS, US region) | Database, authentication, storage, and account verification emails | Supabase DPA |
| Vercel | Web application hosting and server logs | Vercel DPA |
| Stripe | Web subscription payments | Stripe DPA |
| RevenueCat | Mobile in-app purchase validation and subscription status | RevenueCat DPA |
| Resend | Transactional email (e.g. schedule re-sync notifications) | Resend DPA |
| OpenAI | Automated schedule parsing (Section 16) | OpenAI DPA |
| Help Scout | Customer support help desk for emails you send us | Help Scout DPA |
Data sources and app stores that act under their own privacy policies rather than as our processors:
- Google provides your calendar data to us only if you connect Google Calendar (Section 15), under the Google Privacy Policy.
- Apple and Google Play bill and manage mobile subscriptions under their own terms; see the Apple Privacy Policy and Google Privacy Policy.
18. Plus Data Retention
- Schedule data is retained for as long as your account is active — historical reference is a core function of Plus.
- If you delete your account, personal data is removed from our primary systems within 30 days and ages out of encrypted backups within our backup-retention window.
- Accounts inactive for an extended period (24–36 months) may be flagged for deletion or anonymization.
- You can delete individual schedule records at any time.
19. Your Plus Choices and Rights
In addition to the rights in Section 10:
- Access and export: you can request a copy of your identity and schedule data in a portable format from your account settings or by emailing us.
- Correction: you can edit your profile and schedule data in Plus.
- Deletion: you can delete your account from the App or website, or by emailing us; deletion follows the timelines in Section 18.
- Email: transactional emails are part of the service; any marketing email will include an unsubscribe link.
We verify Plus requests through your account email.
20. Plus Security
In addition to the safeguards in Section 11, for Plus we encrypt data in transit (TLS) and at rest, enforce per-user row-level access controls in our database, restrict internal access on a least-privilege basis with multi-factor authentication, and encrypt stored OAuth tokens. If a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by law.
21. Plus Is US-Only for Now
Plus is currently offered in the United States and Plus data is stored in the United States. Depending on your state of residence you may have additional rights under state privacy laws (such as the right to know, delete, or correct personal information, and the right to non-discrimination for exercising those rights). We honor these requests regardless of state.
22. Age Requirement for Plus
Plus is intended for users 18 years of age or older. We do not knowingly collect Plus personal information from anyone under 18. If you believe someone under 18 has created a Plus account, contact us and we will delete it.
Part 3 — General
23. Changes to This Policy
We may update this policy from time to time. We will post the updated version at this URL with a revised "Last updated" date, and for material changes we will notify you — by email or in the App or Plus where we have a way to reach you — before they take effect.
24. Contact
AxisNimble Inc. (TheFlightWall)
Email: privacy@theflightwall.com
General inquiries: contact@theflightwall.com