Legal

Privacy Policy

At AeroRobust, your privacy is not an afterthought — it is a core part of how we built this platform. We do not sell your personal data. We do not share your FAA credentials without your consent. We never will. This policy explains exactly what we collect, why we collect it, and how it is protected.

01
Overview

AeroRobust, LLC ("AeroRobust," "we," "us," or "our") operates the AeroRobust platform at aerorobust.ai — a verified aviation mechanic marketplace that connects FAA certified A&P mechanics and IA inspectors with contractors, MROs, airlines, and repair stations across the United States.

This Privacy Policy applies to all users of our platform including mechanics, contractors, administrators, and visitors. By using AeroRobust, you agree to the collection and use of information as described in this policy.

The short version: We collect only what we need to run the platform, we protect it with industry-standard security, we never sell it, and you can request its deletion at any time by contacting us.

02
Information We Collect

We collect information you provide directly to us, information generated through your use of the platform, and in some cases information from third-party sources such as the FAA Airmen Registry.

Account Information

  • Full name, email address, and password (encrypted)
  • Phone number (optional)
  • Your role on the platform (mechanic, contractor, or admin)
  • Profile photo or company logo (if uploaded)

Mechanic-Specific Information

  • City, state, and zip code
  • Work preferences, availability, and willingness to travel
  • Years of aviation experience and aircraft types worked on
  • Special skills and certifications
  • Uploaded resume (if provided)
  • FAA A&P certificate number and IA certification number (see Section 3)
  • Uploaded certificate documents (encrypted at rest)
  • Subscription and payment status

Contractor-Specific Information

  • Company name, type, location, and website
  • Company description and logo
  • Job posting details including pay rates, locations, and requirements
  • Subscription plan and billing status

Automatically Collected Information

  • IP address and approximate geographic location
  • Browser type, operating system, and device type
  • Pages visited, time spent, and actions taken on the platform
  • Session data and authentication tokens
03
FAA Credential Data

This section is especially important. Your FAA certificate number is sensitive professional information. We treat it with the highest level of care.

When you submit your FAA A&P certificate number or IA certification number, we use it exclusively for the following purposes:

  • Verification: We cross-reference your certificate number against the official FAA Airmen Inquiry database to confirm your credentials are valid and active
  • Re-verification: We re-check your credentials against the FAA registry every 14 days to ensure ongoing accuracy, as the FAA updates their registry regularly
  • Badge display: If verified, your profile displays a "FAA Verified" badge visible to contractors who view your profile
  • Admin review: In cases where automatic verification cannot be completed, our admin team may manually review your submitted documents

Your FAA certificate number is never shared publicly, never shared with third parties for marketing purposes, and never sold. It is visible only to you and authorized AeroRobust administrators.

Uploaded certificate documents (PDF, JPG, PNG) are stored encrypted using AES-256 encryption in Supabase secure storage and are accessible only to you and admin staff for verification purposes.

04
How We Use Your Data
PurposeData UsedLegal Basis
Create and manage your accountName, email, passwordContract performance
Verify FAA credentialsCertificate number, license typeContract performance + consent
Match mechanics to relevant jobsSkills, aircraft types, locationLegitimate interest
Allow contractors to find mechanicsProfile (name visible on Pro+ plans)Contract performance
Process subscription paymentsEmail, Stripe customer IDContract performance
Send platform notificationsEmail, phone (if provided)Consent / legitimate interest
Improve the platformAnonymized usage dataLegitimate interest
Prevent fraud and abuseIP address, session dataLegitimate interest
Comply with legal obligationsAs required by lawLegal obligation
05
Sharing & Disclosure

We do not sell your personal information. We do not rent it, trade it, or share it with advertising networks. Period.

We share your information only in the following limited circumstances:

  • With contractors (limited): When a contractor searches for mechanics, they see your name, location, aircraft experience, years of experience, and verification status. Your FAA certificate number, phone number, and email are only visible to contractors on a paid Pro or Premium plan who you have applied to or who have specifically requested contact.
  • With service providers: We use Supabase (database and authentication), Stripe (payment processing), and Cloudflare (content delivery). Each is bound by strict data processing agreements.
  • FAA Airmen Registry: We query the FAA's public database to verify your credentials. We send only your certificate number for lookup — no other personal data.
  • Legal requirements: We may disclose your information if required by law, court order, or government authority, or to protect the rights and safety of AeroRobust users.
  • Business transfer: If AeroRobust is acquired or merged, your data may transfer to the new entity. You will be notified with the option to delete your account before any transfer.
06
Payment Information

All payment processing is handled by Stripe, Inc., a PCI DSS Level 1 certified payment processor. AeroRobust never stores, sees, or has access to your full credit card number, CVV, or bank account details.

When you subscribe to a paid plan, Stripe creates a customer record linked to your account. We store your Stripe Customer ID in our database to manage your subscription status. We also record transaction history (amount, date, plan, status) for billing and support purposes.

Your card details are entered directly into Stripe's secure form and never touch our servers. This is the same payment infrastructure used by Amazon, Google, and Shopify.

07
Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. Specifically:

  • Active accounts: Data retained for the lifetime of your account
  • Deleted accounts: Personal data deleted within 30 days of account deletion request, except where retention is required by law
  • FAA verification logs: Retained for 2 years for compliance and dispute resolution purposes
  • Payment records: Retained for 7 years as required by financial regulations
  • Uploaded documents: Deleted within 30 days of account deletion or upon written request
  • Anonymized analytics data: May be retained indefinitely as it cannot be linked back to you
08
Your Rights

You have the following rights regarding your personal data. To exercise any of these rights, contact us at [email protected].

  • Access: Request a copy of all personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data — most data can be updated directly in your dashboard
  • Deletion: Request deletion of your account and associated personal data (subject to legal retention requirements)
  • Portability: Request your data in a structured, machine-readable format (JSON or CSV)
  • Opt-out of communications: Unsubscribe from marketing emails at any time via the link in any email or through your account settings
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting prior processing
  • Restrict processing: Request that we restrict how we use your data in certain circumstances

We will respond to all requests within 30 days. For complex requests we may extend this by an additional 30 days with notice.

09
Security

We take the security of your data seriously. The following measures are in place to protect your information:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3 (HTTPS)
  • Encryption at rest: Sensitive data including certificate documents is encrypted at rest using AES-256
  • Authentication: Passwords are hashed using bcrypt and never stored in plain text. We use Supabase Auth with JWT tokens.
  • Row Level Security: Our database enforces strict access controls — users can only access their own data. Mechanics cannot see other mechanics' private data.
  • Access controls: Admin access to sensitive data is logged and restricted to authorized personnel only
  • No plain text credentials: FAA certificate numbers are never logged in plain text in application logs

Despite these measures, no method of transmission over the internet is 100% secure. If you believe your account has been compromised, contact us immediately at [email protected].

10
Cookies

AeroRobust uses a minimal set of cookies required to operate the platform. We do not use advertising cookies or third-party tracking cookies.

CookiePurposeDuration
sb-access-tokenKeeps you logged in (Supabase Auth)1 hour (refreshed automatically)
sb-refresh-tokenRefreshes your login session7 days
ar-session-prefRemembers your UI preferences (theme, filters)30 days

You can disable cookies in your browser settings, but this will prevent you from staying logged in to AeroRobust.

11
Children's Privacy

AeroRobust is a professional platform intended for FAA certified aviation mechanics and aviation companies. Our services are not directed to individuals under the age of 18.

We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account on our platform, please contact us at [email protected] and we will promptly delete the account and associated data.

12
Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Send an email notification to all registered users at least 14 days before the changes take effect
  • Display a notice on the platform when you next log in

Your continued use of AeroRobust after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree, you may delete your account before the changes take effect.

13
Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us:

Privacy & Data Requests
Email: [email protected]
General Support: [email protected]
Security Issues: [email protected]

AeroRobust, LLC
United States of America
Response time: within 30 days