Privacy Policy
Last updated 9 August 2026
Path to Sky is operated by Path to Sky, 2705 Burgundy Trail, Rowlett, TX 75088, United States. Questions about this policy or about your data go to ww8932@gmail.com.
Who the data belongs to
A flight school that uses Path to Sky is the controller of the records it keeps here about its own staff and students. We are the processor: we hold and process that data to run the service for them, on their instructions. If you are a student or instructor and want your records changed or removed, ask your school first, since they decide what their records contain.
What we collect
People at a school
- Name, email address, phone number, and role.
- Pilot certificates and ratings held, and instructor rates where a school sets them.
- Documents a school chooses to upload against a person, which in practice includes pilot certificates, medical certificates, and government-issued identification, along with any expiration dates recorded for them.
- Availability preferences and assigned instructor.
- Optional profile photograph.
Operations
- Bookings, flights, hobbs and tach readings, and maintenance records.
- Aircraft records, including inspection timers and maintenance documents.
- Invoices, account balances, and the ledger of every balance movement.
Technical
- An audit log of significant actions, recording who did what, when, and from which IP address.
- Server logs of requests made to the service.
- Session tokens, held in your browser so you stay signed in.
People who contact us
When you request a demo we keep the organization name, your name, email, phone, fleet size, and whatever you write in the message, so that we can reply and so that we remember the conversation.
Payment information
We never see or store card numbers. Payments are handled by Stripe, and card details go directly to Stripe. When a student pays their school, the charge is made on that school's own connected Stripe account and the money goes to the school, not to us. We keep a record that an invoice was paid, the amount, and Stripe's reference for it. Stripe's handling of card data is governed by Stripe's privacy policy.
Why we hold it
To provide the service a school is paying for: scheduling flights, checking that a pilot and aircraft are eligible, tracking maintenance, and billing. Certificate and medical expiry dates are held because a school has a regulatory reason to know whether someone is currently eligible to fly. We also hold data to keep the service secure, to detect and investigate misuse, and to meet our own legal and accounting obligations.
We do not sell personal data. We do not use it to train machine learning models. We do not use it for advertising.
Who else touches it
The service runs on infrastructure operated by others, each of whom processes data on our behalf:
- Supabase hosts the database, in the United States.
- Railway runs the application server.
- Vercel serves the web interface.
- Stripe processes payments.
- SendGrid sends email, and Twilio sends text messages, where a school has these enabled.
- Sentry receives error reports, where enabled. We strip credentials and request bodies before sending.
We will also disclose data where the law requires it. If the business is ever sold or merged, data would transfer with it, and schools would be told before that happened.
Where it is stored
Data is stored in the United States. If you use the service from elsewhere, your data is transferred there.
How long we keep it
- While a school has an account, its records are kept so it can run its operation and meet its own record-keeping duties.
- After an account closes, we keep the data for 90 days so it can be exported or the account restored, then delete it.
- Audit logs are kept for two years, because their whole purpose is to be able to look back at who did what.
- Invoices and payment records are kept for seven years to meet tax and accounting obligations.
- Demo requests are kept for two years unless you ask us to remove them sooner.
Your rights
Depending on where you live, you may have the right to see the personal data held about you, to correct it, to have it deleted, to get a copy in a portable form, and to object to some processing. To exercise any of these, contact your school if they are the controller of your records, or write to us at the address above and we will route the request. We answer within 30 days. We will not treat you differently for asking.
Security
Traffic is encrypted in transit. Passwords are stored as bcrypt hashes and are never recoverable, by us or by anyone. Each school's data is isolated at the database level, and access is scoped by role within a school. Sessions expire, and password resets sign out every other device. No system is perfectly secure, but if a breach affects your data we will tell affected schools without undue delay.
Children
The service is sold to flight schools, not to individuals, and is not directed at children under 13. Where a school enrolls a minor, the school is responsible for holding the appropriate consent from a parent or guardian.
Cookies and similar technology
We use browser storage to keep you signed in and to remember which school's branding to show on the login page. We do not use advertising or third-party tracking cookies.
Changes
If this policy changes in a way that matters, we will tell schools by email before it takes effect, and update the date at the top of this page.