StickTime FPV Privacy Policy

Last Updated: September 2026

This Privacy Policy describes how StickTime FPV ("StickTime," "we," "us," or "our") collects, uses, discloses, and protects information when you or your organization use the StickTime FPV web application, websites, client portals, and related services (together, the "Service"). The Service helps pilots, squadrons, schools, and commercial operators track FPV drone flight hours, manage equipment hangers, log flight sessions and telemetry, and deliver work to clients.

This Policy should be read together with our Terms of Service. Where an organization (such as a business, club, school, or district) provides you with access to the Service, that organization may have its own policies governing how it uses the information it stores in StickTime.

1. Our Role: Controller and Processor

  • Individual accounts. For information you provide on your own behalf, StickTime acts as the party responsible for that information.
  • Organization accounts. For information an organization stores in the Service about its members, equipment, flights, clients, and jobs ("Customer Data"), the organization decides what is collected and why. StickTime processes Customer Data on the organization's behalf and under its instructions, as set out in our agreement with that organization.

2. Information We Collect

2.1 Account and Profile Information

  • Email address, display name or callsign, and profile preferences.
  • Authentication details. Passwords are handled by our authentication provider and are stored only in hashed form; StickTime staff cannot read them. If you sign in with Google, we receive your basic Google profile (such as name, email address, and profile image) but never your Google password.
  • Organization, squadron, school, or district membership, and the role and permissions you hold within each.
  • Records of your acceptance of our Terms of Service.

2.2 Drone Equipment and Hanger Details

  • Drones, radios (transmitters), goggles, batteries, parts, and other gear you register, including names, specifications, serial numbers, and notes.
  • Maintenance logs, part installs, battery cycles, firmware and configuration records, and equipment checkout and check-in history for shared organization gear.

2.3 Flight Logs and Session Records

  • Flight and simulator sessions, including date, duration, location or flying site, gear used, weather conditions, notes, and pre-flight checklists or job hazard analyses.
  • Certifications and compliance documents you upload (for example, a Part 107 certificate) and their expiration dates.
  • Incident, safety, and job records your organization chooses to keep.

2.4 Session Telemetry

  • When you import a flight log file (for example, DJI, Autel, or Betaflight logs, or CSV exports), we process the file to extract flight metrics such as duration, altitude, speed, distance, battery information, and GPS coordinates, including the takeoff ("home") point and the geographic area of the flight.
  • The original log file may be retained for a period set by you or your organization and is then purged automatically; the extracted flight metrics remain part of your flight history until you delete them or your account.

2.5 Client, CRM, and Billing Records

  • Organizations using client management features may store client contacts, companies, jobs, quotes, invoices, delivery files, and messages. This information is Customer Data controlled by that organization.
  • Subscription payments are processed by Stripe. Card details are entered directly with Stripe; we receive subscription and payment status, but we never receive or store card numbers.

2.6 App Usage and Technical Data

  • Security and audit logs, which can include IP address, browser user agent, timestamps, and the actions taken in an account (such as sign-ins, permission changes, and administrative actions).
  • Bug reports and feedback you submit, along with the browser information attached to them.
  • Browser storage used to keep you signed in, cache data for faster loading, and remember interface preferences such as read notices. We do not use advertising cookies or third-party advertising trackers. Our Cookie Policy lists each item we store.

2.7 Demo Requests

  • If you start the live demo without an account, we collect the email address you type and your browser's user agent string. We use them to open a time-limited demo session, to limit abuse, and to see which organizations have tried the demo. We do not send email to that address or add it to a mailing list.

3. How We Use Information

We use information to:

  • Provide, operate, and maintain the Service, including flight tracking, gear and maintenance tracking, analytics, scheduling, client delivery, and exports.
  • Authenticate users, enforce organization roles and permissions, and prevent fraud, abuse, and unauthorized access.
  • Process subscription payments and manage plans.
  • Send service messages, such as account, security, billing, and job notices. We do not send marketing email to student accounts.
  • Respond to support requests and investigate bugs.
  • Comply with legal obligations and enforce our Terms of Service.

We do not use Customer Data for advertising, and we do not build advertising profiles.

4. Data Ownership

  • Your data belongs to you. Flight logs, session telemetry, equipment records, and other content you submit remain the property of the user or organization that submitted them. Enterprise and organization Customer Data belongs entirely to that organization.
  • Limited use. We access and process that data only to provide, secure, and support the Service for you, or as required by law.
  • We never sell user data. We do not sell, rent, or trade personal information or Customer Data, and we do not share it with data brokers or advertisers.
  • No training of public AI models. We never use your private flight logs, session telemetry, or Customer Data to train public or third-party artificial intelligence or machine learning models.

5. How We Share Information

We share personal information only in the circumstances below.

  • With the service providers that operate the Service, for hosting, database, file storage, email delivery, and payment processing. Each provider receives only the information needed to perform its own function and is bound by contractual confidentiality and security obligations. We do not publish a list of these providers here; organizations with a written agreement with StickTime may request the current list and advance notice of additions.
  • Within your organization, according to the roles and permissions your organization's administrators set. Personal hanger records and private sessions are not shared with an organization unless you link them to shared gear or organization workflows.
  • With clients you choose, when you or your organization send a secure client link, portal, quote, invoice, or delivery. Recipients see only the specific job information and files made available through that link, and access ends when the link is revoked or expires.
  • For legal reasons, when we believe disclosure is required by law, subpoena, or court order, or is necessary to protect the rights, property, or safety of StickTime, our users, or the public.
  • In a business transfer, such as a merger or acquisition, subject to this Policy's protections continuing to apply.

6. Data Security

We use administrative, technical, and physical safeguards appropriate to the nature of the data we handle, including:

  • Encryption in transit. All connections to the Service use HTTPS with TLS, and the Service instructs browsers to use HTTPS only (HTTP Strict Transport Security).
  • Encryption at rest. Databases and stored files are encrypted at rest by our infrastructure providers.
  • Role-based access controls. Database row-level security policies ensure that users can access only their own records and the records of organizations they belong to, further limited by their role (for example, member, administrator, school administrator, or district administrator).
  • Least-privilege file access. Private files are never publicly listed; downloads are checked against the requesting user's or link's permissions and served through short-lived signed URLs.
  • Monitoring and hardening. We maintain security and audit logs, rate limits, security headers, and a content security policy.

No method of transmission or storage is completely secure. If we become aware of a security incident affecting your personal information, we will notify you without undue delay by email to the address on your account and, where applicable, notify your organization, and we will meet any shorter deadline required by law.

7. Schools, Districts, and Student Data (FERPA)

For education organizations, student accounts are provisioned only from a roster entry added by a school or district administrator, and student information is visible only to that school's and district's authorized staff. We process student education records solely on behalf of the school or district, do not use them for advertising, and do not send marketing email to student accounts. The Service is not directed to children under 13 outside of a school-managed account.

8. Data Retention, Export, and Deletion

8.1 Exporting Your Data

  • You can export your data at any time from Settings → Export, as a CSV logbook of your flight sessions or as a complete JSON export of your profile, sessions, gear, parts, batteries, and maintenance records.
  • Organization administrators who need a full export of their organization's Customer Data may contact us using the details in Section 11.

8.2 Deleting Your Account

  • You can delete your account from Settings → Danger Zone. Deletion is scheduled with a 30-day grace period, during which you can cancel and restore your account.
  • When the grace period ends, your profile, sessions, gear, parts, batteries, maintenance history, and other personal records are permanently deleted, and your personal information is removed from the organization rosters you belonged to.
  • You may also request deletion by contacting us using the details in Section 11. We may need to verify your identity before acting on the request.

8.3 Retention

  • We retain account information and Customer Data for as long as your account or your organization's subscription is active, or as needed to provide the Service.
  • Records owned by an organization follow that organization's retention settings and membership rules. Leaving an organization does not delete its shared records, and cancelling a subscription does not delete stored files. An organization with no members left in it for thirty consecutive days is deleted along with everything it holds; if that was not intended, re-inviting a member during those thirty days prevents the deletion. School and district records may be retained as required by education record laws.
  • Original flight log files are purged automatically once their retention period ends.
  • Demo request emails are kept until you ask us to delete them using the details in Section 11.
  • Deleted data may remain in encrypted backups for a limited period until those backups expire in the normal course. Before any account is purged, the sign-in identity is removed, so a backup never contains a usable account.
  • We may retain limited information where required by law, to resolve disputes, or to enforce our agreements, such as billing and tax records.

9. Your Privacy Rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. Many of these actions are available directly in the Service. To exercise any right that is not, contact us using the details in Section 11. We will respond within the time required by applicable law and will not discriminate against you for exercising your rights.

If your account is managed by an organization, we may refer your request to that organization, as it controls that Customer Data.

10. International Data Transfers

StickTime is operated from the United States, and our service providers may process information in the United States and other countries. Where required, we rely on appropriate safeguards for international transfers.

11. Contact Information

For privacy questions, data requests, or to report a security concern, contact us at:

  • Privacy and support inquiries: [Insert Contact Email]
  • Operator: StickTime FPV, Oklahoma, United States

12. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last Updated" date above and notify account holders by email or within the Service before the changes take effect.

13. Governing Law

StickTime FPV is operated from the State of Oklahoma. This Privacy Policy and any disputes arising from it are governed by the laws of the State of Oklahoma, without regard to its conflict of law provisions, except where the privacy laws of your place of residence require otherwise.