Data Privacy
A plain-language explanation of how we treat the financial and operational data flowing through AeroXpense. This complements our full Privacy Policy.
1. What Plaid shares with us — and what it does not
When an admin connects a bank or credit-card account through Plaid Link, Plaid acts as the secure broker between your bank and AeroXpense. We receive:
- Institution and account metadata (account name, type, subtype, last 4 digits of the card / account — the “mask”).
- Transactions on the connected accounts: date, merchant, amount, currency and whether the charge is pending.
- A Plaid access token stored only on our server.
We do not receive and we do not store:
- Your online banking username or password — Plaid handles those directly with your bank.
- Full card numbers, CVVs or PINs.
- Statements, transfers or transactions on accounts you did not connect.
2. Why we use this data
Only to power the Service for your operator:
- Match a card charge to the receipt the pilot uploaded.
- Assign the charge to the right pilot, aircraft and flight leg.
- Flag missing receipts and produce reconciled monthly reports.
We never use your bank data, your receipts or your flight data to train third-party AI models, and we never sell it.
3. Retention & deletion
- The Plaid access token is deleted immediately when an admin disconnects the account.
- Cached transactions are kept while your operator's account is active so reports remain auditable.
- You can request export or deletion at any time — see Your Choices.
- Encrypted backups roll off on a 30-day cycle.
4. Who else processes the data
A short list of sub-processors, each under a written data-processing agreement:
- Cloudflare — application runtime and edge delivery.
- Netlify — static asset hosting.
- Supabase — managed Postgres database, authentication and object storage.
- Plaid — bank and card connectivity.
- FL3XX — flight operations data (only if your operator enables it).
5. How we protect it
- Encrypted in transit (TLS 1.2 or better) and at rest (AES-256).
- Row-level security in the database isolates one operator from another.
- Plaid access tokens are stored only server-side and never exposed to the browser.
- Production access is restricted to named administrators with MFA, reviewed periodically.
6. Your rights
You can ask for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. Email hi@sidd.hu from the account's admin address.
Connecting a bank account?
See exactly what Plaid will share before you connect.