Data Privacy

A plain-language explanation of how we treat the financial and operational data flowing through AeroXpense. This complements our full Privacy Policy.

1. What Plaid shares with us — and what it does not

When an admin connects a bank or credit-card account through Plaid Link, Plaid acts as the secure broker between your bank and AeroXpense. We receive:

  • Institution and account metadata (account name, type, subtype, last 4 digits of the card / account — the “mask”).
  • Transactions on the connected accounts: date, merchant, amount, currency and whether the charge is pending.
  • A Plaid access token stored only on our server.

We do not receive and we do not store:

  • Your online banking username or password — Plaid handles those directly with your bank.
  • Full card numbers, CVVs or PINs.
  • Statements, transfers or transactions on accounts you did not connect.

2. Why we use this data

Only to power the Service for your operator:

  • Match a card charge to the receipt the pilot uploaded.
  • Assign the charge to the right pilot, aircraft and flight leg.
  • Flag missing receipts and produce reconciled monthly reports.

We never use your bank data, your receipts or your flight data to train third-party AI models, and we never sell it.

3. Retention & deletion

  • The Plaid access token is deleted immediately when an admin disconnects the account.
  • Cached transactions are kept while your operator's account is active so reports remain auditable.
  • You can request export or deletion at any time — see Your Choices.
  • Encrypted backups roll off on a 30-day cycle.

4. Who else processes the data

A short list of sub-processors, each under a written data-processing agreement:

  • Cloudflare — application runtime and edge delivery.
  • Netlify — static asset hosting.
  • Supabase — managed Postgres database, authentication and object storage.
  • Plaid — bank and card connectivity.
  • FL3XX — flight operations data (only if your operator enables it).

5. How we protect it

  • Encrypted in transit (TLS 1.2 or better) and at rest (AES-256).
  • Row-level security in the database isolates one operator from another.
  • Plaid access tokens are stored only server-side and never exposed to the browser.
  • Production access is restricted to named administrators with MFA, reviewed periodically.

6. Your rights

You can ask for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. Email hi@sidd.hu from the account's admin address.

Connecting a bank account?

See exactly what Plaid will share before you connect.

See your choices