Privacy
Privacy Policy
Last updated: July 27, 2026
This policy explains how personal data is handled when you visit the WindowSeat website or use the WindowSeat web and iOS apps. Local flights can be used without an account. Account, sync, and social features are optional and are available from age 16.
1. Controller and contact
AMRV GbRRepresented by: Armin Miranda & Rene Vogels
An Lyskirchen 7
50676 Köln, Germany
Email: trywindowseat@gmail.com
2. Local use without an account
You can use the core flight experience without signing in. Flight state, schedules, progress, map state, preferences, and similar app data may then be stored locally in browser storage or on your device. It is not associated with a WindowSeat account or synced to our database.
On iOS, Cabin Door uses Apple's Screen Time frameworks. Your app and category selections are represented by opaque Apple tokens and are kept on your device or in the WindowSeat app group. WindowSeat does not receive the names of the apps you select. The blocked-attempt count and Cabin Door state are also stored locally.
Local notifications for scheduled flights and return reminders are created and managed on your device. You can change permissions in system settings. Removing the app or clearing browser/app storage removes local data according to your device or browser controls.
4. Accounts and sign-in
If you choose to create or use an account, we process your email address, authentication provider, provider account identifier, session information, and the basic profile fields the provider makes available. The web and iOS apps support Sign in with Apple and Google; Apple may provide a private relay email address. We receive this sign-in data from the provider you select. Apple and Google also process it under their own privacy terms.
You may add a unique display name and, where supported, an avatar. If you enable friend requests, your display name and avatar can appear in search results for other signed-in users. Existing friends and pending request participants can continue to find the relationship. A display name is locked after it is first set, so choose one that does not reveal more about you than you want to share.
Account data is optional. If you do not provide the sign-in and profile information needed for an account, local flights remain available but cloud sync, account recovery, friends, and social push notifications will not be available.
5. Synced product data
When you are signed in, WindowSeat can store and sync profile and audio preferences; scheduled, active, completed, ended-early, and missed flights; route, origin, destination, duration, status, and timestamps; streaks and aggregate statistics; and map-reveal progress. We may also sync your Miles balance and transaction ledger, shop unlocks and selected customisations, and your First Class entitlement. This data is used to run the service, recover active flights, apply earned rewards and purchases, and show your history and progress across devices.
6. Purchases and First Class
If you start a web purchase, Stripe processes the payment and billing information you provide. We send Stripe the selected plan, your account reference, email address, and the information needed to create and reconcile the checkout. We receive identifiers and status information for the checkout, payment, customer, and any subscription so that we can grant, renew, or end the corresponding entitlement. We do not receive your full payment-card number.
If you purchase through the iOS app, Apple processes the payment. We receive and verify StoreKit transaction information such as the product, original transaction, purchase, expiry or revocation status, and StoreKit environment so that the purchase can be restored and the entitlement kept in sync. We do not receive your full Apple payment details.
We use purchase and entitlement data to perform the purchase contract, provide First Class, prevent fraud and duplicate rewards, respond to billing support, and keep records required for tax and accounting. See the Terms and Withdrawal Information for your contractual rights.
7. Friends and social features
Social features store friend requests and accepted friendships, privacy choices, and fly-together invitations. A fly-together invite includes the relevant route, start time, and duration. Other signed-in users can find your display name and avatar, if set, when you enable friend requests. Only accepted friends can access the friend data made available by the service.
Social discovery and sharing are off by default. You can separately enable friend requests and choose whether accepted friends may see your current flight activity, statistics, or map progress. Base flight records remain private and access is enforced through restricted service functions.
You can block another profile. We then retain a blocked-relationship state so the accounts no longer appear to each other in search, requests, friends, or invitations. If you choose Report profile, your email app prepares a message to us containing the reported display name and profile ID, your account ID, app version or client type, and the reason you add. Nothing is sent until you choose to send that email.
8. Push notifications
If you allow social push notifications on iOS, we process the Apple Push Notification service device token, APNs environment, app version, locale, time zone, notification preference, and last-seen time. A short-lived delivery record can include the notification type, related invitation or friendship identifier, title, message, status, attempts, expiry time, and delivery error. Apple processes the notification for delivery. You can disable notifications in the app or iOS settings.
9. Sharing and support
When you create a share link or arrival poster, it may contain the route, duration, start time, display name, focus totals, activity, streak, flight count, or map progress shown in the preview. The app prepares the content and opens your device's share controls. The service you choose to share with receives the content under its own terms. If you contact support, we process your contact details, message, and any screenshots, recordings, or diagnostic details you choose to provide.
If you use the electronic withdrawal or contract cancellation function, we process your name, email address, contract and receipt details, purchase or requested end date, cancellation type and reason where provided, submission time, a pseudonymous network-address hash, user-agent information, confirmation-delivery status, and the generated reference. We use this data to receive, prove, confirm, and carry out your consumer request.
10. Purposes and legal bases
- Providing accounts, sync, social features, purchases, entitlements, requested notifications, and support: performance of a contract or steps you request before entering one (Article 6(1)(b) GDPR).
- Hosting, service security, fraud and abuse prevention, profile moderation, reliable operation, limited product analytics, and error diagnosis: our legitimate interests in operating and improving a safe, secure service (Article 6(1)(f) GDPR).
- Optional device permissions or processing for which consent is legally required: your consent (Article 6(1)(a) GDPR). You can withdraw it through the relevant app or system setting.
- Records we must keep or disclosures required by law: compliance with legal obligations (Article 6(1)(c) GDPR).
The local storage and device access needed to provide a feature you request is used under Section 25(2) no. 2 TDDDG. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
11. Service providers and locations
- Stripe processes web checkout, payments, subscriptions, refunds, and payment-related fraud prevention.
- Supabase provides authentication, database, and backend functions. The WindowSeat Supabase project is hosted in Frankfurt, Germany.
- Vercel provides website hosting, content delivery, and Web Analytics.
- Sentry provides error monitoring using its European data region.
- Apple provides Sign in with Apple, APNs, Screen Time frameworks, and device sharing controls.
- Google provides Google sign-in.
We also use an email provider to receive support messages. Providers receive only the data needed for their task. Where they process data on our behalf, they are contractually required to keep it confidential, secure it, use it only on our instructions, and provide protections consistent with this policy and applicable law.
12. International transfers
Some providers are based in the United States or use subprocessors in other countries. Where personal data is transferred outside the European Economic Area, the transfer is protected as applicable by an adequacy decision, including the EU-US Data Privacy Framework for certified recipients, or by the European Commission's Standard Contractual Clauses and supplementary measures. You can contact us for more information about the safeguards relevant to your data.
13. Retention
- Local data remains until you clear it, reset the relevant setting, or remove the app, subject to your browser or device behavior.
- Account and synced product data is kept while your account is active and deleted from the live service when you delete the account, except where limited records must be retained by law. Provider backups are overwritten on their normal protected backup cycle.
- Purchase and entitlement records are kept while needed to provide and restore your purchase, resolve disputes, prevent duplicate rewards or fraud, and meet tax, accounting, and legal-retention duties. Stripe and Apple retain their own transaction records under their policies and legal obligations.
- Active push-device data is kept while the device is registered. Inactive registrations and other push-delivery records are scheduled for deletion after 30 days. Expired delivery records are normally removed by the next scheduled cleanup. Account deletion removes linked push data directly.
- Security logs, aggregated analytics, and error reports are retained only for the configured period needed for security, reliability, and trend analysis.
- Support correspondence is kept until the request is resolved and then only as long as needed for follow-up, legal obligations, or the establishment, exercise, or defense of legal claims.
- Withdrawal and cancellation requests and their delivery evidence are kept for the statutory limitation and record-keeping periods needed to prove receipt and handling of the request.
14. Your rights and choices
Subject to applicable law, you may request access, correction, deletion, restriction, or a portable copy of your personal data. You may object to processing based on legitimate interests and withdraw consent at any time without affecting earlier processing. There is no charge for a normal request, although we may need to verify your identity.
A signed-in user can delete the account directly: on the web under Profile, and in the iOS app under Profile. This removes the account and associated online product and social data. You can also request help at trywindowseat@gmail.com. You can manage social visibility and notifications in the app and device settings.
Deleting your WindowSeat account does not cancel a subscription billed by Stripe or Apple. Cancel an active subscription with the relevant billing provider before deleting the account to prevent future renewals. Limited transaction records may remain where required for accounting, fraud prevention, or legal claims.
You may lodge a complaint with a data-protection authority. Our lead local authority is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.
15. Children and teenagers
The local flight experience can be used without an account and is available to all ages. WindowSeat accounts, syncing, and social features are for people aged 16 or older. We do not knowingly create accounts for children under 16. A parent or guardian who believes a child has provided account data can contact us so we can delete it.
16. Sales, security, and policy changes
We do not sell personal data, share it for cross-context behavioral advertising, or use it for third-party advertising. We use access controls, row-level database security, encrypted transport, and reputable infrastructure providers, but no online service can guarantee absolute security.
We may update this policy when the product or law changes. The latest version will remain on this page and the date above will be updated. If a change materially affects how existing account data is used, we will provide an appropriate notice.