Aero Reg is an aircraft-registration lookup and registry-intelligence service. Most of what we publish is already public — aircraft registrations, the owner details that appear on the official registers, and the daily differences between snapshots. The only personal data we hold about you is what we need to run your account, answer your messages, and protect the service. This policy explains exactly what that is, why we hold it, and what you can do about it.
Who we are#
Aero Reg is the data controller for the personal data described in this policy. We are an independent service based in the United Kingdom. You can reach us by post or email:
- Post
- Aero Reg, 99 Birchwood Hill, Leeds, West Yorkshire, LS17 8NT, United Kingdom
- Privacy
- privacy@aeroreg.co.uk
Public registry data is, well, public — we re-publish it. Account data (your name, email, and login details) is yours: we keep only what we need to run the service, and you can ask us to export or delete it at any time. We do not sell personal data, we do not share it with advertisers, and we run no third-party analytics or ad trackers on this site.
Information we collect#
It helps to separate the public aviation data that powers the product from the small amount of personal data we hold about the people who use it. The first is the input to our service; it is not information we gather about you.
Public registry data
We ingest the daily public datasets published by the United States Federal Aviation Administration (FAA), Transport Canada (the Canadian Civil Aircraft Register, CCAR), Australia’s Civil Aviation Safety Authority (CASA), and Switzerland’s Federal Office of Civil Aviation (FOCA). These records — registration marks, aircraft details, and the owner names and addresses that the authorities themselves publish — are sourced from official government registers and re-published here. If your details appear in those registers, the original record is held by the relevant aviation authority, not by us; we mirror what they make public.
Account & identity
If you create a member account, we store the information you give us when you register and manage your profile:
- Username
- The handle you choose at sign-up.
- Name
- Your first and last name, as entered on the registration form.
- Email address
- Used for sign-in, account confirmation, password resets, and service notices.
- Password
- We never store your password. It is converted to a one-way hash using the industry-standard
bcryptalgorithm, and only the hash is kept. - Account activity
- Basic login metadata — when you last signed in, how many times you have signed in, and whether your email has been confirmed.
Messages you send us
When you use the contact form we store the details you provide so we can reply: your name, email address, an optional telephone number and company, the category of your enquiry, the message itself, and the page you contacted us from. We do not store your IP address with contact-form submissions.
Billing & payments
If you take out a paid plan, payments are processed by PayPal. PayPal handles your card or bank details directly — we never see or store them. We receive only a transaction reference, the amount, the currency, and enough information to issue your invoice and recognise your payment.
API usage logs
If you hold an API key, we log each authenticated API request to keep the service secure, enforce rate limits, and investigate abuse. Each entry records the endpoint and method called, the response status and timing, the API key used, the user-agent string, and the IP address the request came from.
API request logs contain the full IP address of the calling client and are not anonymised, because we need them to identify and block abuse. They are kept only for as long as they are useful for security and are not used for advertising or profiling.
Web-server logs
Like almost every website, our web server keeps standard access logs (IP address, the request line, status code, and user-agent) for security, diagnostics, and abuse prevention. These raw server logs are not anonymised.
Analytics
We measure how the site is used with self-hosted analytics software that we run on our own infrastructure. Your visit data is never sent to a third-party analytics company such as Google Analytics. Our analytics is configured to anonymise IP addresses, so the visits it records cannot be tied back to an individual address.
How we use your information#
We use personal data only for the specific purposes below. Each has a lawful basis under the UK GDPR, shown in the right-hand column.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Create and run your account; serve your requests | Username, name, email, password hash | art.6(1)(b) contract |
| Reply to your enquiries | Contact-form details | art.6(1)(b) / (f) |
| Keep the service secure; prevent and investigate abuse | IP address, key ID, request logs | art.6(1)(f) legitimate interests |
| Take payment and issue invoices for paid plans | Billing name, transaction reference | art.6(1)(b) + art.6(1)(c) |
| Understand and improve how the site is used | Anonymised, self-hosted analytics | art.6(1)(f) legitimate interests |
Sell, rent, or barter your personal data · share it with advertisers or data brokers · load third-party ad or tracking scripts onto this site · use your email for marketing without your separate, opt-in consent.
Who we share data with#
We keep your personal data within Aero Reg wherever we can. We share it only in the limited circumstances below, and only with parties who perform a specific function for us.
- PayPal
- Payment processing for paid plans. PayPal acts as a separate data controller for the payment details you give it; see PayPal’s own privacy statement for how it handles them.
- Our hosting provider
- The service, its databases, and its backups are hosted on UK-based infrastructure. Our hosting provider stores data on our behalf and does not use it for any purpose of its own.
We send service emails — sign-up confirmations, password resets, replies to your enquiries, and administrative notices — ourselves, over a standard mail server. We do not use third-party bulk-email, newsletter, or marketing-email platforms, and we never upload your email address to one.
Legal requests
We will disclose personal data where we are legally required to do so — for example, in response to a valid court order or a lawful request from a competent authority. We disclose only what the law obliges us to, and no more.
Cookies#
We use a minimal set of cookies — to keep you signed in and to remember your light/dark theme choice — and no advertising or third-party tracking cookies. Our self-hosted analytics is configured not to set tracking cookies on your device. Full details are in our Cookie Policy.
Security#
The public website and the member area are served over an encrypted HTTPS connection. Passwords are stored only as one-way bcrypt hashes, never in plain text. Access to the systems that hold personal data is restricted to the people who run the service.
Reporting a vulnerability
If you believe you have found a security issue, please email security@aeroreg.co.uk. We will acknowledge your report and keep you updated as we investigate. Please give us a reasonable opportunity to fix an issue before disclosing it publicly.
How long we keep data#
We keep personal data only as long as we need it for the purpose we collected it.
- Account data
- Kept for as long as your account is active. When you close your account, we delete the personal data associated with it.
- Enquiries
- Messages we are dealing with are kept while we handle them and for our records afterwards. Unactioned and spam messages are tidied automatically — moved to a junk folder after about a week, and permanently deleted roughly a month after that.
- API & server logs
- Kept for as long as they are useful for security and abuse prevention, then deleted.
- Billing records
- Kept for as long as we are required to retain them to meet our legal and tax obligations.
- Backups
- Held on UK-based infrastructure on a short, rolling cycle and overwritten in the normal course of operations.
Your rights#
Under the UK GDPR you have the following rights over your personal data. To exercise any of them, email privacy@aeroreg.co.uk. We respond within one month.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything inaccurate, such as your name or email.
- Erasure — deletion of your account and the personal data we hold about you.
- Restriction — to pause our processing while a query is resolved.
- Portability — your data in a structured, machine-readable format.
- Objection — to object to processing carried out on the basis of our legitimate interests.
If you are unhappy with how we have handled your personal data, you can complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk. We would, however, appreciate the chance to put things right first — please contact us before you do.
International transfers#
Our service, databases, and backups are hosted in the United Kingdom. Where a provider we rely on processes personal data outside the UK — most notably PayPal for payments — that transfer is covered by an appropriate safeguard, such as the UK International Data Transfer Agreement or the equivalent Standard Contractual Clauses.
Children#
Aero Reg is a tool for aviation enthusiasts and professionals and is not directed at children. We do not knowingly create accounts for, or collect personal data from, anyone under the age of 16. If you believe a child has given us personal data, please contact us and we will delete it.
Changes to this policy#
We may update this policy from time to time. When we do, we will revise the effective date at the top of the page, and we will tell members about any significant change. The current version is in force from the effective date shown above.