AeroLuxe Privacy Policy
Effective September 22, 2026.
Operator: AeroLuxe LLC, doing business as AeroLuxe ("AeroLuxe," "we," "us").
Privacy contact: privacy@aeroluxesupport.com.
1. Scope and responsibility
This Policy describes personal information handled through aeroluxesupport.com, its service-request forms and related inquiry communications, and the AeroLuxe Command maintenance workspace and client portal. Command-specific practices apply only when you use that application; simply browsing our public website does not create a Command account. It does not cover unrelated websites or a provider's separate services. Aircraft and business records may contain personal information, including owner names, technician names and certificate references.
The operator administers this Service. If your employer, aircraft operator or another organization provides your workspace, that organization determines which records to enter, who may access them and why they are used. Its own privacy notices and any agreement with AeroLuxe may also apply. Contact your workspace administrator about organization-managed records, or use the privacy contact above for assistance identifying the responsible organization.
2. Information handled
- Website inquiries and communications: name, company or flight department, phone number, email address, requested service, aircraft registration or type, airport, requested date, message details and correspondence you or your organization send to us. Which fields are collected depends on the form or contact method you use. Do not send confidential maintenance files, credentials or unrelated sensitive information through an initial inquiry.
- Command account and access information: names, usernames, account identifiers, roles, account status, hashed app passphrases, private-link labels, assigned aircraft, access expiry and revocation details. ChatGPT sign-in and Site access approval are managed through the hosting platform; the app checks for an authenticated platform identity. The app does not receive your ChatGPT password.
- Command records you or authorized colleagues enter: aircraft registration, model and serial information; aircraft and equipment counters; routes and schedules; maintenance tasks, discrepancies, deferrals, work orders, source references, notes, technician names, certificate references, approvals and reports.
- Command files and photographs: supporting PDFs and images, filenames, file types, sizes, integrity checks and upload times; aircraft photos or references to external photos. Supporting documents may contain their own metadata and personal information. Only upload material appropriate for the workspace.
- Command activity and security information: sign-in events, account and access changes, timestamps, record revisions, actor names, review history, alert acknowledgments, login-attempt controls and session activity.
- External aircraft information: public-source registration, manufacturer, model, aircraft identifiers, registered-owner or operator information, country, photograph links, source and retrieval time when looked up or saved.
- Technical information handled by providers: hosting, sign-in and external-image providers may receive IP addresses, browser or device information, request timestamps and diagnostic or security logs when they deliver their services.
Information may come from you, your organization, authorized users, public lookup sources or technical interactions with the Service.
3. How information is used
We use website inquiry information to respond to requests, contact you about the requested services, assess scope and availability, coordinate scheduling, keep a record of communications and protect the forms against abuse. A form submission is an inquiry, not a confirmed booking.
We use Command information to provide the workspace and client portal; authenticate and authorize access; organize records and documents; calculate entered-data status and alerts; retrieve requested public information; display aircraft images; prepare reports and exports; maintain change history; create and verify backups; investigate faults or suspected misuse; and respond to support, privacy and legal requests.
The current website and Command code do not include advertising pixels or marketing analytics. Command does not include an automated connection that sends maintenance records to a generative-AI model. Hosting the app on an OpenAI service does not mean this Policy controls OpenAI's independent account or platform processing.
4. Who may receive information
- Your authorized workspace users: internal access is controlled by roles, but internal users may see workspace-wide operational information. Administrator access includes account, sharing and backup controls.
- Assigned clients: client-portal users can see the aircraft/status information assigned to them and the reports and supporting documents specifically approved for sharing. Copies they download or print cannot be recalled by revoking a link.
- Website hosting and form delivery: Netlify hosts aeroluxesupport.com and processes the service-request forms. Submitting a form sends the information you entered to Netlify; form submissions may be stored in the project and sent as email notifications to AeroLuxe's business mailbox. Our email provider processes those notifications and related correspondence. Authorized AeroLuxe personnel may use that information to respond or coordinate your request.
- Website font delivery: pages load typefaces from Google Fonts. Your browser contacts Google's font services, which can receive your IP address and browser request information. The font request does not send your inquiry form fields.
- Command hosting providers: OpenAI Sites provides hosting and Site access/sign-in services for Command. Cloudflare infrastructure supports its application execution, structured records and file storage. Providers process information needed to supply their services under the applicable arrangements and their own notices where relevant.
- Aircraft lookup and image providers: a lookup sends the entered aircraft registration to adsbdb. The automatic photo workflow may do this when you add an aircraft, without a separate lookup-button click. Loading an Airport-Data.com image makes a browser request to that provider, which can receive your IP address and browser request information. Bundled manufacturer model images load from this app; following a source-credit link visits the external source. The lookup feature does not send maintenance documents or counter history to the aircraft lookup provider.
- Public-source websites: the app retrieves regulatory publications from the Federal Register. Following source links opens the relevant external website, which applies its own practices.
- Other recipients when necessary: information may be disclosed as required by law, to respond to a valid legal process, to protect rights or investigate misuse, or at the direction of an authorized organization. We will provide notice of materially different uses or disclosures and obtain consent where required.
The website and Command do not implement the sale of personal information or cross-context behavioral advertising.
5. Cookies and browser storage
The public website code does not set tracking cookies. Its interactive demonstrations keep their working state in the current page. Hosting and font providers may process technical requests under their own practices.
Command uses the aeroluxe_session cookie to maintain an authenticated session. Its maximum age is eight hours; app access expires sooner after 30 minutes of inactivity or when the underlying access is disabled or expires. Browser session storage remembers link-access state and temporary safety-alert acknowledgments. These functions support access and workflow behavior, not advertising. Platform sign-in and external providers may use their own cookies under their policies.
You can clear cookies and browser storage or block them using browser controls. Doing so may sign you out or prevent the Service from working. Acknowledgment storage does not clear maintenance issues. The app does not implement a separate response to a browser "Do Not Track" signal.
6. Retention, backups and removal
Website inquiries and correspondence may remain in Netlify form records, our email system and business records while needed to respond, coordinate requested services, meet applicable obligations or handle a dispute. Removing an email does not necessarily remove the form-provider copy, and clearing your browser does not delete a submission. Contact us for a retention or deletion review; this Policy does not promise a fixed automatic purge period for those systems.
Command retains operational records, documents and audit history until they are addressed through an authorized administrative process. Command does not have a general automatic purge schedule for those records or its stored backups. Backups may be created manually or before the first eligible write on a day; an automatic backup is not a guarantee of continuous backup coverage.
Account deactivation, link expiry and report withdrawal restrict access but do not necessarily erase underlying information. Copies may remain in audit history, backups, exported files or another recipient's possession. Administrators must consider legitimate operational needs, legal recordkeeping requirements, disputes and security needs when deciding retention. This Policy does not promise immediate deletion or a fixed deletion period that the Service does not implement.
Contact the privacy contact to request a retention explanation or removal review. We will coordinate with the responsible organization, explain applicable restrictions and honor legal obligations. Provider logs and platform account information are governed by the relevant provider's retention arrangements.
7. Security and processing locations
The Service uses access controls, session protections, passphrase hashing, restricted document access and activity history. No system, transmission or backup is completely secure. Protect your devices, accounts, private links and exported copies, and report suspected unauthorized access promptly.
Service providers may process information outside your state or country. No particular storage location or data-residency guarantee is made by this Policy. Any required regional processing terms or international-transfer arrangements must be confirmed for your organization before relying on the Service for that requirement.
8. Your choices and requests
Depending on your location, applicable law and the organization's role, you may have rights to access, correct, obtain a copy of, delete or restrict use of personal information, object to certain processing, opt out of a sale of personal information, targeted advertising or qualifying automated profiling where applicable, withdraw consent where processing relies on consent, or complain to a privacy regulator. These rights are not unlimited and do not automatically authorize changes to regulated maintenance records or another person's information.
Send requests to privacy@aeroluxesupport.com. Describe the request and your relationship to the workspace; do not send a password or private access token. We may need proportionate verification of identity and authority and may refer organization-controlled requests to the workspace operator. We will respond within the time required by applicable law and explain applicable exceptions. If you disagree with a response, email the same address with the subject "Privacy request appeal" and explain the decision you want reviewed. We will review the appeal and respond within the period required by applicable law. You may also contact the New Jersey Division of Consumer Affairs or another competent privacy regulator. We will not unlawfully discriminate against you for exercising applicable privacy rights.
9. Children
The Service is intended for authorized adult professional users, not children. Do not create an account for a child or submit children's personal information. If you believe a child has provided personal information, contact us so the responsible operator can investigate and take appropriate action.
10. Changes and contact
We will update the effective date when this Policy changes and provide notice of material changes through the Service or an available contact channel. Where required, we will obtain consent for a new use. For questions about privacy, security concerns or this Policy, contact AeroLuxe LLC at privacy@aeroluxesupport.com.
