Summary
Cloudridge Studios ("we", "us") is the data controller for all data collected through the Jetpath app and our websites. We collect only what is necessary, store it securely, never sell it, and provide you full control over it. This policy applies to anyone who uses Jetpath or visits cloudridgestudios.com.
01 Who We Are
Cloudridge Studios is the data controller responsible for your personal data. We develop Jetpath — a travel companion application — and operate the associated website and services.
Data Controller
Cloudridge Studios
Email: info@cloudridgestudios.com
Website: cloudridgestudios.com
For all data protection enquiries, please use the email above with the subject line "Privacy Request".
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the rights described in Section 8 under GDPR / UK GDPR respectively.
02 What Data We Collect
2.1 Data you provide to us
| Data | How collected | Required? |
|---|---|---|
| Email address | Launch notification sign-up form on our website | Yes (for sign-up) |
| Flight numbers & trip details | Entered manually in the Jetpath app | Yes (for core features) |
| Boarding pass images | Camera or image import — processed on-device only | No (optional) |
| Family member details | Added voluntarily via Family Hub | No (optional) |
| Support messages | Email communication to our support address | No (only if you contact us) |
| Account profile data | Created at registration via Google Sign-In, Apple Sign-In, or email — stored in your account profile | Yes (for account features) |
| Promo code & email hash | When you redeem a promotional code in-app — we store only a salted, irreversible hash of your sign-in email | No (only if you redeem a code) |
2.2 Data collected automatically
| Data | Source | Purpose |
|---|---|---|
| Device information | Android system | Crash reporting, compatibility |
| App crash reports | Crash analytics SDK | Bug fixing and stability |
| Aggregated feature usage | Analytics SDK (anonymised) | Product improvement |
| Push notification tokens | Firebase Cloud Messaging | Delivering notifications you opt into |
| Purchase receipts | Google Play | Subscription validation (Pro tier) |
| IP address, approximate location & timestamp | Launch sign-up form (MailerLite) | Spam prevention & proof of consent (double opt-in) |
| Advertising identifiers & signals | Google AdMob (free tier only) | Serving contextual ads; personalised ads only with your explicit consent |
2.3 Data we do NOT collect
- We do not collect or transmit the content of boarding pass images — scanning is performed entirely on your device.
- We do not collect precise GPS location data unless you explicitly grant location permission for a specific feature.
- We do not collect payment card details — all payments are handled exclusively by Google Play.
- We do not serve personalised ads without your explicit consent. The free tier is ad-supported with contextual ads; personalised advertising is enabled solely when you opt in via the in-app privacy settings.
- We do not use third-party social media tracking pixels or cookies on our websites.
03 Legal Bases for Processing (GDPR Art. 6)
Every time we process your personal data, we do so under one of the following legal bases:
| Processing activity | Legal basis | GDPR Article |
|---|---|---|
| Launch day email notification | Art. 6(1)(a) | |
| Marketing emails (future) | Art. 6(1)(a) | |
| Delivering Pro subscription features | Contract | Art. 6(1)(b) |
| Processing in-app purchases | Contract | Art. 6(1)(b) |
| Crash reporting & bug fixes | Art. 6(1)(a) | |
| Anonymised analytics | Art. 6(1)(a) | |
| Responding to support requests | Legitimate Interest | Art. 6(1)(f) |
| Legal compliance obligations | Legal Obligation | Art. 6(1)(c) |
| Promo-code abuse prevention (one redemption per email) | Legitimate Interest | Art. 6(1)(f) |
Legitimate Interest Balancing
Where we rely on legitimate interest, we have assessed that our interests (stability, security, product improvement) do not override your fundamental rights. We use anonymised or pseudonymised data wherever possible, and you can object to this processing at any time (see Section 8).
04 How We Use Your Data
4.1 Launch notification email
When you submit your email through our sign-up form, we use a double opt-in process: you receive a confirmation email, and your address is added to our launch list only after you click the confirmation link. We then use it solely to send you a notification when Jetpath becomes available on Google Play. We do not use open- or click-tracking in these emails, and we will not add you to any ongoing marketing list without separate consent.
4.2 Core app functionality
Flight and trip data you enter is stored locally on your device. When features require network requests (live flight status, TSA wait times, weather), your query parameters (e.g. flight number, airport code) are sent to our API or the relevant third-party data provider. We do not store these queries linked to your identity.
4.3 Pro subscription
If you purchase a Pro subscription, Google Play processes the payment and provides us a purchase token to validate your entitlement. We store this token alongside an anonymous app installation identifier to unlock Pro features. We do not store billing addresses or payment card information.
4.4 Family Hub
Family Hub allows you to share trip information with people you invite. Each invited member must explicitly accept the invitation. Shared data is only visible to the members of that family group. You can remove members or leave a group at any time, at which point shared data is no longer accessible to the removed party.
4.5 Push notifications
Push notifications (gate changes, check-in reminders, and cancellation alerts) are delivered via Firebase Cloud Messaging. We only send notifications for events directly related to trips you have saved in the app. You can manage notification preferences at any time via:
- Android system settings — Settings → Apps → Jetpath → Notifications, where you can disable all or individual notification categories.
- In-app settings — Settings → Notifications, where you can configure which alert types you receive without disabling system-level permissions.
Withdrawing notification permissions does not affect your use of any other app feature.
4.6 Analytics and crash reporting
We collect anonymised, aggregated analytics data to understand how features are used. Crash reports help us identify and fix bugs. This data cannot be linked back to you individually. You can opt out of analytics in the app's Settings → Privacy menu.
05 Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected or to comply with legal obligations.
| Data type | Retention period | Reason |
|---|---|---|
| Launch notification email | Until Jetpath launches + 90 days, or until you unsubscribe | Consent-based; deleted once purpose fulfilled |
| Support email correspondence | 3 years | Legitimate interest — legal claims window |
| Crash reports | 90 days (rolling) | Bug resolution; auto-deleted after period |
| Anonymised analytics | 24 months (rolling) | Product improvement; aggregated only |
| Pro subscription token | Duration of subscription + 30 days | Entitlement validation |
| Trip data (app) | Stored on your device; deleted when you delete trips or uninstall | User-controlled local storage |
| Consent audit log | Life of account | Legal obligation — Art. 7 GDPR proof of consent |
| Promo redemption hash | Lifetime of the promotional programme — retained after account deletion | Legitimate interest — prevents repeated redemptions; stored only as an irreversible salted hash |
When data is no longer required, we securely delete or anonymise it. You may also request deletion at any time (see Section 8 — Right to Erasure).
06 Sharing & Third Parties
We do not sell, rent, or trade your personal data. We share data with third parties only where necessary to deliver our services, and only under strict data processing agreements.
6.1 Service providers
| Provider | Purpose | Data shared | Region |
|---|---|---|---|
| Google / Firebase | Push notifications, crash reporting, anonymised analytics | Device token, anonymised usage events, crash logs | USA (SCCs) |
| Google Play | App distribution, subscription billing | Purchase receipts | USA (SCCs) |
| Flight data API | Live flight status, schedules | Flight number, airport codes (no personal identifiers) | EU / USA |
| TSA (US Government) | Airport security wait times | Airport code only — public API | USA |
| Weather API | Destination weather forecasts | Coordinates or city name only | EU / USA |
| MailerLite | Sending launch notification emails | Email address, IP address, sign-up timestamp | EU preferred / USA (SCCs) |
| RevenueCat | Subscription management, entitlement validation, and purchase event processing | App user ID, subscription status, and purchase receipt data | USA (SCCs) |
| Google AdMob | Serving in-app advertisements (free tier only) | Ad request signals; device advertising ID (personalised ads with your consent only) | USA (SCCs) |
6.2 Legal disclosure
We may disclose personal data if required by law, regulation, or court order, or where necessary to protect the rights, property, or safety of Cloudridge Studios, our users, or the public.
6.3 Business transfers
If Cloudridge Studios is acquired, merged, or its assets transferred, personal data may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website before any such transfer, and the acquiring party will be required to honour this Privacy Policy.
07 International Data Transfers
Some of our service providers are located outside the European Economic Area (EEA). Where we transfer personal data outside the EEA, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) — approved by the European Commission under Art. 46(2)(c) GDPR, used with all US-based providers.
- Adequacy decisions — for countries the European Commission has determined provide adequate protection.
- Supplementary technical measures — including encryption in transit (TLS 1.2+) and at rest.
You may request a copy of the safeguards we have in place by contacting us.
EEA Representative (Art. 27 GDPR)
Where required under Art. 27 GDPR, Cloudridge Studios will designate a representative within the European Economic Area. If you are an EU/EEA resident and wish to contact us regarding your data rights, you may do so directly at info@cloudridgestudios.com. Details of our EEA representative will be published here when appointed.
08 Your Rights
Under GDPR (and equivalent national laws), you have the following rights regarding your personal data. These rights are free to exercise and we will respond within 30 days.
Right of Access
Request a copy of the personal data we hold about you (Art. 15 GDPR).
Right to Rectification
Request correction of inaccurate or incomplete data (Art. 16 GDPR).
Right to Erasure
"Right to be forgotten" — request deletion of your data where no overriding legal basis applies (Art. 17 GDPR).
Right to Restriction
Request that we limit processing of your data in certain circumstances (Art. 18 GDPR).
Right to Portability
Receive your data in a structured, machine-readable format to transfer to another controller (Art. 20 GDPR).
Right to Object
Object to processing based on legitimate interests or for direct marketing (Art. 21 GDPR). We will stop unless we have compelling legitimate grounds.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing (Art. 7(3) GDPR).
Right to Lodge a Complaint
You have the right to lodge a complaint with your local supervisory authority if you believe we have not handled your data lawfully (Art. 77 GDPR).
To exercise any of these rights, email us with the subject line "Privacy Request" and specify which right you are exercising. For the right to erasure, you may also delete your account directly in-app via Settings → Delete Account, which immediately initiates secure deletion of all your personal data. We may need to verify your identity before processing the request. Note: if you have redeemed a promotional code, a salted, irreversible hash of your sign-in email is retained after account deletion to prevent the one-code-per-email limit from being reset; it cannot be used to identify you.
Supervisory Authorities
EU residents can contact their national Data Protection Authority (DPA). UK residents can contact the ICO at ico.org.uk.
09 Cookies & Local Storage
9.1 Our website
Our websites use no tracking cookies and no third-party advertising pixels. We use browser localStorage only for essential user preferences:
| Key | Value stored | Purpose | Duration |
|---|---|---|---|
jp_theme | "dark" or "light" | Remembers your chosen colour theme | Until cleared by user |
preferredLanguage | Language code (e.g. "en") | Remembers your selected language | Until cleared by user |
jp_notify_signed_up | Email address | Prevents duplicate sign-ups, shows confirmation on reload | Until cleared by user |
These values never leave your browser and are not transmitted to any server. They are strictly necessary for the functionality you choose and therefore do not require a cookie consent banner.
9.2 The Jetpath mobile app
The app does not use browser cookies. App data (trips, settings, and consent preferences) is stored locally on your device using Android's standard storage APIs. Sensitive data such as family member information is stored in encrypted secure storage. Analytics events are batched, anonymised, and sent to our analytics provider via secure API.
10 Children's Privacy
Jetpath is not directed at children under the age of 13 (or 16 in EU member states where applicable). We do not knowingly collect personal data from children. If we discover that a child under the applicable age has provided us personal data without verifiable parental consent, we will delete it promptly.
If you are a parent or guardian and believe your child has submitted personal data to us, please contact us and we will investigate and delete the data within 30 days.
11 Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures, including:
- Encryption in transit — all data transmitted between the app and our servers uses TLS 1.2 or higher.
- Encryption at rest — sensitive data stored server-side is encrypted at rest using AES-256.
- Boarding pass data is on-device only — boarding pass images are processed locally and never transmitted.
- Access controls — access to personal data is restricted to authorised personnel on a need-to-know basis.
- Regular security reviews — we conduct periodic security assessments of our systems and third-party integrations.
- Minimal data collection — we collect only what is strictly necessary ("data minimisation", Art. 5(1)(c) GDPR).
In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify affected individuals without undue delay (Art. 33–34 GDPR).
12 Automated Decision-Making & Profiling
Jetpath may use historical flight data to display informational indicators within the app. These outputs are informational only and are intended to help you make better-informed travel decisions.
Under GDPR Art. 22, you have the right not to be subject to a decision based solely on automated processing that produces significant legal or similarly significant effects. Our automated features do not produce decisions with legal or similarly significant effects — they are advisory outputs that you are free to disregard.
No automated assessment made by Jetpath is used to restrict your access to services, affect your credit, employment, or any other matter of legal consequence. All predictions are calculated using aggregated third-party statistical data and do not involve building a personal profile of your individual behaviour across time.
13 California Privacy Rights (CCPA / CPRA)
If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), in addition to the rights described in Section 8.
13.1 Right to Know
You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you in the preceding 12 months, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom it was shared.
13.2 Right to Delete
You have the right to request deletion of personal information we hold about you, subject to certain exceptions (e.g., information needed to complete a transaction or comply with a legal obligation).
13.3 Right to Correct
You have the right to request correction of inaccurate personal information we maintain about you.
13.4 Right to Opt Out of Sale or Sharing
We do not sell your personal information, nor do we share it for cross-context behavioural advertising. You therefore have no need to opt out of a sale or sharing under CCPA — there is nothing to opt out of.
13.5 Right to Non-Discrimination
We will not discriminate against you for exercising any of your California privacy rights. You will not receive a different level of service or quality for making a CCPA/CPRA request.
13.6 How to exercise California rights
To exercise any of the above rights, email us with the subject line "California Privacy Request". We will verify your identity and respond within 45 days.
14 Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- We will update the "Last updated" date at the top of this page.
- For material changes that affect how we process your data, we will notify you by email (if you have subscribed) and/or via a prominent notice in the app at least 30 days before the change takes effect.
- For minor or clarificatory changes, the updated policy will take effect immediately upon publication.
Your continued use of Jetpath or our websites after any change constitutes acceptance of the updated policy. If you disagree with changes, you may close your account and stop using our services.
15 Contact Us
For any privacy-related questions, requests, or complaints, please contact us:
Privacy Team
Cloudridge Studios — respond within 3 business days.
This Privacy Policy was drafted to comply with the EU General Data Protection Regulation (GDPR) 2016/679, the UK GDPR, the ePrivacy Directive, and the California Consumer Privacy Act (CCPA).