Privacy Policy

Last updated: 7 July 2026

This Privacy Policy explains how AeroXpense (“AeroXpense”, “we”, “us”) collects, uses, shares and protects information when you or your organisation use the AeroXpense web application and related services (the “Service”). AeroXpense is expense management and bank-feed reconciliation software built specifically for aviation flight departments and charter operators. This document is intended to be transparent and specific; it is not legal advice, and final language should be reviewed by your counsel before relying on it for a regulated engagement.

1. Who we are and our role

The Service is offered on a per-company (per-operator) basis. Each operator that subscribes is the data controller for its own users (pilots, accountants, admins) and for the receipts, flight legs and financial data it brings into the Service. AeroXpense acts as a data processor on that operator's behalf. Companies are isolated from one another in the database using row-level security so one operator cannot see another operator's data.

2. Information we collect

2.1 Account and profile data

  • Name, work email, role (pilot, accountant, admin), company assignment.
  • Authentication identifiers, hashed password, MFA enrolment status.
  • Invitation and audit metadata (who invited whom, last sign-in, IP of sign-in).

2.2 Expense and receipt data

  • Receipt images or PDFs you upload, plus fields extracted from them (merchant, date, amount, currency, tax, category).
  • Tail number, flight leg, cost centre, notes and any attachments you add.
  • Approval status, reviewer, timestamps, comments.

2.3 Financial account data via Plaid

When an administrator connects a corporate card or bank account through Plaid, Plaid acts as the secure broker between the bank and AeroXpense. From Plaid we receive:

  • Institution and account metadata: institution name, account name, type and subtype, and the last 4 digits (“mask”) of the card or account.
  • Transactions on the connected accounts only: date, merchant/description, amount, currency, and whether the charge is pending.
  • A Plaid access token which is stored only on our server, encrypted at rest, and never exposed to the browser.

We do not receive and we do not store:

  • Your online banking username or password — Plaid handles those directly with your bank.
  • Full card numbers (PAN), CVV, expiry date or PIN.
  • Statements, transfers or transactions on accounts you did not explicitly connect.
  • Data from any other Plaid product you have not enabled for AeroXpense.

Your use of Plaid is also governed by Plaid's own end-user privacy policy, which you accept in the Plaid Link flow when you connect an account.

2.4 Flight-operations data (FL3XX, JetInsight and other providers)

When an administrator connects a flight-operations system, we read operational data so we can match expenses to the correct trip and pilot. Supported providers today include FL3XX and JetInsight, and an operator may configure an “other” provider by supplying an API endpoint and key. From these providers we may read:

  • Flight legs: date, departure and arrival airports, block/flight times, aircraft tail number.
  • Crew assignments for those legs (pilot names / identifiers) so we can attach expenses to the operating crew.
  • Trip and quote references where the provider exposes them.

The API key or credential used to reach the flight-ops provider is supplied by the operator's admin, stored per company, encrypted at rest, and never shown back in full in the UI. We do not use it to write to the provider unless the admin has explicitly enabled a write-back feature.

2.5 AI-assisted processing

We use machine-learning models operated by a third-party AI processor to run receipt OCR and to suggest matches between card transactions and receipts. When you upload a receipt, the image and a short prompt are sent to the model provider through the gateway solely to return structured fields (merchant, date, amount, etc.). When we propose a match, a compact description of the candidate transaction and receipt is sent for the same purpose. These requests are not used to train third-party models, and the outputs are advisory — a human reviewer confirms or corrects them before anything is posted to accounting.

2.6 Usage, device and log data

Log records, IP address, browser and device information, pages viewed and errors encountered, used to operate and secure the Service and to investigate incidents.

3. How we use information

  • To provide the Service: capture receipts, extract fields, match receipts to bank/card transactions, attach expenses to flight legs, produce reconciled reports.
  • To administer accounts: invitations, roles, plan tier, billing.
  • To support customers and respond to your requests.
  • To secure the Service and detect or prevent fraud and abuse.
  • To comply with legal obligations (tax, accounting, lawful requests).

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use your data, your receipts, your bank transactions or your flight data to train third-party AI models.

4. Legal bases

Depending on your jurisdiction we rely on:

  • Performance of a contract with your operator, to provide the Service to you as a user.
  • Legitimate interest in operating, securing and improving the Service.
  • Consent for the Plaid bank connection and for connecting FL3XX / JetInsight / other flight-ops providers, and for optional marketing email.
  • Legal obligation for tax, accounting and lawful requests.

5. Sharing and sub-processors

We share information only with the providers needed to operate the Service, under written data-processing terms:

ProviderPurposeRegion
CloudflareApplication runtime, edge delivery, DDoS/WAFGlobal
NetlifyStatic asset hosting & CDNGlobal
SupabaseManaged Postgres database, authentication, object storage (receipts, statements)US / EU
PlaidBank and credit-card account connectivity and transactionsUS
FL3XXFlight-operations data sync (only if your operator enables it)EU
JetInsightFlight-operations data sync (only if your operator enables it)US
Other flight-ops providerCustom API configured by your operator's admin (only if enabled)Operator-selected
AI processing providerReceipt OCR and transaction-match suggestionsUS / EU
StripePayment processing for paid plans (when billing is enabled)US / EU
Email delivery providerTransactional email (invites, password reset, receipts, alerts)US / EU

We do not sell or rent personal information to third parties. We will update this list as sub-processors change.

6. International transfers

Our sub-processors may process data outside your country. Where required, transfers are governed by Standard Contractual Clauses or an equivalent lawful mechanism. If your operator has a data-residency requirement, contact us before enabling an integration.

7. Retention

  • Account, expense and receipt data is retained for as long as your operator's account is active, plus any period your operator sets for audit purposes.
  • Plaid access tokens are deleted immediately when the connection is disconnected; cached transactions are retained for the reconciliation period configured by your operator.
  • Flight-ops API keys (FL3XX, JetInsight, other) are deleted when the admin removes the integration; cached flight legs remain so historical expense-to-leg links stay auditable.
  • Encrypted backups are retained on a rolling 30-day basis and then purged.
  • On account deletion we permanently remove customer data within 30 days, except where retention is required by law.

8. Your rights

Depending on your jurisdiction (e.g. GDPR, UK GDPR, CCPA/CPRA) you may have rights to access, correct, delete, restrict, or port information about you, and to withdraw consent. To exercise a right, contact us at hi@sidd.hu from the email associated with your account.

  • Revoke Plaid: Settings → Bank connection → Disconnect, or from your bank's own app / Plaid Portal.
  • Disconnect FL3XX / JetInsight / other: Settings → FL3XX (integrations) → remove the credential.
  • Delete your user account: ask your operator's admin, or contact us directly.

9. Security

  • Encrypted in transit with TLS 1.2 or better; encrypted at rest with AES-256.
  • Row-level security in the database isolates one operator from another.
  • Plaid access tokens and third-party API keys (FL3XX, JetInsight, other) are stored only server-side, encrypted at rest, and never exposed to the browser.
  • Production access is restricted to named administrators, protected with MFA, and reviewed periodically.
  • Audit logging of sign-ins, admin actions and integration changes.

No system is perfectly secure. We do not currently hold SOC 2, ISO 27001 or HIPAA certification and do not claim compliance with those frameworks. See our Account Security and Security & Compliance pages for more.

10. Children

The Service is not directed at individuals under 18 and we do not knowingly collect data from them.

11. Changes

We will post material changes to this policy on this page and update the “Last updated” date. If the change is significant we will notify operator admins by email.

12. Contact

Privacy questions: hi@sidd.hu (Siddharth Gupta, Security Lead).