+Resyrv policy
Privacy Policy
This Privacy Policy explains how Resyrv collects, uses, shares, protects, and retains information when you use our website, application, and related services. By using Resyrv, you agree to this Privacy Policy. If you do not agree, you should not use Resyrv.
1. Information we collect
We collect information needed to provide aircraft organization, scheduling, maintenance tracking, document, billing, reporting, and member management tools.
- Account information: name, email address, login credentials or authentication identifiers, profile photo if provided, login status, and account settings.
- Organization information: organization name, role, permissions, membership status, titles, notes, club standing, aircraft assignments, location assignments, and administrative records.
- Operational profile information: phone number, home airport, emergency contact information, pilot certificate information, ratings, endorsements, medical dates, flight review dates, renter insurance information, TSA status, checkout records, instructor/student relationships, and related operational fields.
- Aircraft and operations information: aircraft records, schedules, reservations, flight logs, squawks, maintenance items, inspection records, documents, announcements, training records, billing records, cost-sharing records, invoices, reports, and related notes.
- Payment and billing information: billing contact information, subscription status, plan details, invoices, payment status, and payment processor identifiers. Resyrv does not intentionally store full payment card numbers when payments are handled by a third-party processor.
- Usage and technical information: device type, browser, IP address, log data, session information, analytics events, security events, errors, and diagnostic records.
Mapped to the categories California's privacy law uses, with how long we keep each:
- Identifiers (name, email address, authentication identifiers, IP address): kept while your account exists, then purged on our deletion schedule (currently 90 days after account deletion), except where a record must survive for the reasons in section 9.
- Customer records (billing contact, phone number, home airport, emergency contact): kept while your account or your organization membership exists, then purged with the account.
- Professional information (pilot and mechanic certificates, ratings, endorsements, flight review and checkout records, instructor and student relationships): kept as part of the organization's operational history for as long as the organization keeps its account, because it belongs to shared aviation records.
- Commercial information (subscriptions, invoices, payments, cost-sharing records): kept for as long as tax and accounting law requires, typically seven years.
- Internet or network activity (log data, analytics events): server logs are kept only as long as security and troubleshooting need them and then rotated; analytics events are held by the analytics provider under its retention setting.
- Sensitive personal information (medical certificate dates, identity documents collected for flight training, TSA training status): kept while the organization needs them for the aviation purpose they were collected for, and removed with the account; see section 12.
- Inferences: we draw none. Resyrv does not profile users or build inferences about them.
2. OAuth sign-in
If you sign in using Google, Apple, Facebook, LinkedIn, or another OAuth provider, Resyrv receives information needed to authenticate your account, such as your provider user ID, email address, and profile name when available. OAuth providers do not provide Resyrv with your provider password.
3. How we use information
We use information to:
- Create, authenticate, and secure user accounts.
- Provide organization, aircraft, schedule, maintenance, document, billing, training, and reporting features.
- Show information to authorized organization users based on roles and permissions.
- Support organization owners and admins in managing members, aircraft, access, and records.
- Process subscriptions, billing, invoices, and payment-related workflows.
- Send service messages, support replies, security alerts, and operational notifications.
- Troubleshoot issues, prevent abuse, detect unauthorized access, and improve Resyrv.
- Maintain audit logs, security records, billing records, and operational integrity.
- Comply with legal, tax, billing, security, and dispute-resolution obligations.
4. Organization visibility
Resyrv is built for shared aircraft organizations. Information you enter may be visible to organization owners, admins, managers, instructors, maintainers, billing admins, or other authorized users depending on your organization's settings and permissions.
Organization owners and admins are responsible for granting appropriate access and managing how their organization uses member, aircraft, billing, document, training, and maintenance records.
5. Emergency contact information
If you provide emergency contact information, you are responsible for ensuring you have permission to provide that information. Emergency contact information may be visible to authorized organization users for safety, administrative, or operational purposes.
6. Sharing information
We do not sell personal information.
We may share information with service providers that help us operate Resyrv, such as hosting providers, authentication providers, analytics tools, email providers, support tools, payment processors, security tools, and infrastructure providers.
We may also share information when required to comply with law, enforce our Terms, prevent fraud or abuse, protect the service, respond to legal requests, or protect the rights and safety of Resyrv, users, organizations, or others.
7. Third-party services
Resyrv relies on third-party services to operate. Depending on the features your organization uses, information may be processed by:
- Payment processing: Stripe processes Resyrv subscriptions and, for organizations that use it, member payments and payouts. Organizations may instead connect their own Authorize.net merchant account. In both cases card details are entered in the processor's own hosted form and go directly to the processor; Resyrv keeps only the card brand, the last four digits, and the processor's token, never a full card number, expiry date, or security code.
- Accounting sync: if your organization connects QuickBooks or Xero, the financial records you choose to export (such as invoices, payments, customers, and related billing data) are sent to that provider.
- Authentication: Google, Apple, Facebook, and LinkedIn when you sign in with an OAuth provider.
- Advertising: Meta and Google receive measurement information about our own ad campaigns if you allow targeting cookies. This covers visits to our public marketing pages only, never your organization operational records.
- Infrastructure: hosting, email delivery, analytics, security, and aviation data providers that support the service.
These providers process information according to their own privacy policies and terms. We share only the information needed for each provider to perform its function.
8. Cookies and analytics
Resyrv uses cookies, local storage, logs, and similar technologies in three categories:
- Necessary: sign-in sessions, security, fraud prevention, and remembering your preferences. These are required for the site to work and do not need consent.
- Analytics: Google Analytics helps us understand how visitors use the site, such as which pages are read and where visitors run into trouble. Analytics starts when you arrive and continues unless you turn it off, which you can do at any time in Cookie Settings. Turning it off stops collection immediately.
- Targeting: these technologies measure whether our advertising works and may be used to show you more relevant ads. The Meta Pixel covers advertising on Facebook and Instagram, and information it collects, such as pages visited and browser details, is shared with Meta Platforms, Inc. Google Ads covers advertising on Google Search, and where our Google Analytics and Google Ads accounts are linked, conversion events such as submitting a form or starting a free trial are shared with Google for the same purpose. Each provider processes this information under its own privacy policy. Targeting cookies load only if you allow them, and declining them turns off the advertising signals we send to Google even when you have allowed analytics cookies.
When you first visit, a consent banner lets you accept all cookies, decline optional ones, or choose per category. The two categories start differently: analytics runs from your first page view unless you turn it off, while targeting never runs until you explicitly allow it. You can change either choice at any time using the Cookie Settings link in the site footer, and turning a category off takes effect straight away rather than on your next visit. If your browser sends a Global Privacy Control (GPC) signal, targeting is off by default and we treat the signal as an opt-out of sharing unless you explicitly turn targeting on.
Declining optional cookies does not limit what you can do on Resyrv.
9. Data retention
We keep information for as long as needed to provide Resyrv, support organizations, maintain security, comply with legal or billing obligations, resolve disputes, preserve audit history, and protect the integrity of shared aircraft records.
Some records may remain after an individual user leaves an organization because they are part of shared operational, billing, aircraft, maintenance, flight, audit, or compliance history.
10. Data access, correction, and deletion
You may update many profile fields in your account settings.
You can download a copy of the personal information Resyrv holds about you at any time from Settings > Advanced (Download my data), as a machine-readable file, without asking anyone. You may also request access, correction, export, or deletion by contacting us at [email protected], or by following our Data Deletion Instructions. We answer within 45 days, and tell you if we need longer.
Authorized agents: you may have someone make a request on your behalf. Send the request to [email protected] with the agent's signed authorization from you, and we will confirm the request with you directly at the email address on your account before acting on it. A power of attorney under applicable law is also accepted.
Deletion may be limited when information is needed for billing, tax, legal, security, dispute-resolution, audit, backup, or shared organization record purposes. Organization-owned records may need to be requested through the organization owner or admin, especially where the data is part of aircraft, maintenance, billing, flight, training, or operational history.
11. State privacy rights
Depending on where you live and whether applicable privacy laws apply to Resyrv, you may have rights to access, correct, delete, obtain a copy of, or opt out of certain uses of your personal information.
Resyrv does not sell personal information. If you allow targeting cookies, information collected by the Meta Pixel, and conversion events shared with Google Ads, are "shared" for cross-context behavioral advertising as some state privacy laws define that term. You can opt out of this sharing at any time by turning off targeting cookies in Cookie Settings, or automatically by using a browser that sends the Global Privacy Control signal. We will not discriminate against users for exercising privacy rights.
California residents have the rights to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information (section 12), and to non-discrimination. Resyrv is below the thresholds at which the California Consumer Privacy Act applies and honors these rights voluntarily for every user, wherever they live, through the self-service tools in section 10 and the contact below.
12. Sensitive personal information and your right to limit
Some fields an organization may ask for are sensitive: medical certificate class and dates, identity documents collected for flight training (for example, the citizenship evidence 49 CFR 1552 requires), and TSA security awareness training status. Resyrv uses these only for the aviation purpose the organization collected them for, such as checking currency before a flight or keeping a training file, and never to infer characteristics about you, for advertising, or for any purpose beyond providing the service. That is the use the law allows without a right to limit; if you believe we are using sensitive information beyond it, you may ask us to limit that use at [email protected] and we will.
13. Where your information is processed
Resyrv is operated from the United States, and your information is stored and processed on servers in the United States by Resyrv and the service providers in section 7. If you use Resyrv from Canada, the European Economic Area, the United Kingdom, or elsewhere, your information is transferred to the United States, where privacy law differs from your own and where it may be reachable by United States courts, law enforcement, and government authorities under United States law.
For Canadian organizations: the Personal Information Protection and Electronic Documents Act (PIPEDA) requires that individuals be told their information is processed outside Canada. An organization that adopts Resyrv should tell its members and customers that their information is stored in the United States and subject to the laws there. Questions about this go to our privacy officer (section 20).
14. If a breach happens
If we learn of a breach of security that affects personal information, we contain it, assess what information was involved and whose, and notify the affected organizations and individuals without unreasonable delay, and within the time applicable law requires. Where a breach creates a real risk of significant harm to individuals in Canada we report it to the Office of the Privacy Commissioner of Canada; where a law such as California's requires notice to a regulator or attorney general, we give it. We keep a record of every breach, including those we judge not to require notice, for at least 24 months.
15. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. No system is completely secure, and we cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur.
You are responsible for keeping your login credentials secure and promptly notifying us if you believe your account has been compromised.
16. Children
Resyrv is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will take appropriate steps to delete it.
17. Business transfers
If Resyrv is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, information may be transferred as part of that transaction.
18. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we may notify users through the app, by email, or by posting an updated version.
19. Contact
Privacy questions or requests can be sent to [email protected].
20. Privacy officer
Jonathon Carr is the person accountable for Resyrv's handling of personal information under this policy, including under PIPEDA's accountability principle, and is reachable at [email protected]. If you are not satisfied with our answer, you may complain to the privacy regulator where you live, including the Office of the Privacy Commissioner of Canada or the California Privacy Protection Agency.