Legal

Privacy Policy for Airport.Social

Last updated July 26, 2026

Airport.Social (the "App" or "Service"), operated by Airport.Social, Inc. (collectively, "Airport.Social," "we," "us," or "our"), is committed to protecting the privacy, safety, and discretion of our users.

This Privacy Policy explains how we collect, use, share, protect, and programmatically delete your Personal Information when you use our mobile application and related services. By downloading, registering for, or using Airport.Social, you consent to the collection, processing, and storage of your personal data as described in this Policy.

1. Scope and Core Architecture Definitions

To understand this Privacy Policy, it is critical to define the structural boundaries of our application data. Our platform utilizes a "Modular Passport" architecture designed to minimize cross-contamination of professional, casual, and romantic user profiles:

1.

The Core Passport Profile: Contains your basic, permanent traveler profile (First Name, Age, Home Hub, Profile Photo, and verified Flight Itinerary).

2.

Business Class (Professional Overlay): Contains professional data fields (industry, company, job title, LinkedIn URL, and networking goals).

3.

Layover (Casual Overlay): Contains platonic social data fields (interests, coffee/dining meet-up preferences, and general travel icebreakers).

4.

Mile High (Romantic Overlay): Contains romantic, flirty social data fields, specific romantic goals, and a separate "Private Photo Vault."

2. Information We Collect and Processing Grounds

We collect several categories of Personal Information from and about our users. Below are the specific categories of information we collect, along with our legal processing grounds under GDPR (Article 6) and CCPA/CPRA:

2.1 Information You Provide to Us Directly

Account Credentials: When you register, we collect authentication data via third-party providers (Apple, Google, or phone OTP). (GDPR: Performance of a Contract)

Core Passport Data: First name, age, primary profile photo, and seat preference. (GDPR: Performance of a Contract)

Active Mode Data: Dependent on your active toggle selection, we collect your Business Class, Layover, or Mile High profile fields. (GDPR: Consent / Performance of a Contract)

Private Photo Vault: 1 to 2 photos uploaded specifically to your Mile High profile. (GDPR: Explicit Consent)

2.2 Flight Itinerary and Boarding Pass Verification Data

To match with other travelers, you must check into an airport terminal. This check-in confirms a flight exists on the route and date you entered against public flight schedule data — it does not confirm you hold a ticket on it or that you have cleared a security checkpoint:

Manual Input or Boarding Pass Scans: We collect your flight number, airline, date of travel, and scheduled departure/boarding times.

Third-Party Integration: We transmit this flight identifier to FlightAware AeroAPI or similar airline data partners to retrieve real-time terminal designations, gate assignments, and current flight status. We do not transmit your name, credit card details, or sensitive passenger data to these third-party flight APIs. (GDPR: Performance of a Contract)

2.3 Precise, Real-Time Location Data (Inside Airport Security)

Precise Location (GPS and Wi-Fi Triangulation): To match you with other travelers in your exact terminal concourse, we collect your precise geographic coordinates (latitude and longitude) with your explicit consent.

How We Track Location: We collect precise location data when the App is open and active in the foreground, or in the background if background permissions are explicitly granted.

The "Airside" Limit: This coordinate tracking is restricted geographically to airport terminal boundaries ("geofenced airspace"). Once our system registers that you have boarded your flight or left the airport, background location tracking is immediately deactivated. (GDPR: Explicit Consent)

The "At the Airport" Badge: If your precise location is confirmed near an airport terminal, we store only the timestamp of that confirmation to power a badge on your profile. We do not store your coordinates themselves for this purpose, and the badge stops displaying a few hours after the check.

2.4 Photo Verification Data (Biometric — Optional)

If you choose to request the "Photo Verified" badge, you may submit a live selfie captured from your device camera. This is sensitive/biometric data under GDPR (Article 9) and CCPA/CPRA (and may be treated as biometric identifiers under laws such as the Illinois Biometric Information Privacy Act), and we process it only with your explicit, opt-in consent:

Purpose Limitation: Your selfie is used for exactly one purpose — an automated one-to-one comparison against your existing primary profile photo via a third-party facial comparison service (currently AWS Rekognition CompareFaces) to produce a similarity score. We do not use your selfie to train general facial recognition models, build a face gallery, or identify you against government or third-party identity databases. (GDPR: Explicit Consent)

Immediate Deletion: Your selfie is uploaded to a private, access-restricted storage location, scored, and then permanently deleted within the same request — typically within seconds. We do not retain a copy of your selfie, and it is never shown to other users.

What We Retain: We retain only the outcome of the comparison (verified/rejected) and, if verified, the timestamp, so your "Photo Verified" badge can display on your Core Passport profile. We do not retain the similarity score or the images themselves. The badge reflects a successful match at the time of verification only — it is not continuous identity monitoring.

Withdrawal of Consent: Photo verification is optional. You may decline to submit a selfie, and you may request that we clear your verification status or delete your account by contacting privacy@airport.social or using in-app account controls where available.

3. Data Isolation and "Mode Guard" Security Architecture

To protect your professional reputation and personal privacy, Airport.Social utilizes a strict, backend-enforced Data Isolation Architecture designed to completely quarantine "Mile High" (Romantic) data from users in "Business Class" (Professional) mode:

1.

Database-Level Quarantine: Your Mile High (Romantic) profile attributes, bio, and Private Photo Vault are stored in separate, isolated data tables in our database (Supabase/PostgreSQL).

2.

Row-Level Security (RLS) & Server-Level Policies: Our backend servers strictly reject any API queries or data requests for Mile High profile data unless: (a) the requesting user is currently, actively toggled into Mile High (Romantic) mode; AND (b) the requested profile is currently, actively toggled into Mile High (Romantic) mode; AND (c) both users have mutually matched.

3.

No Cross-Mode Information Leaks: If you are toggled into Business Class mode, your profile is entirely invisible to users in Mile High mode. If a colleague or business contact matches with you in Business Class, they can never query, access, or view any data, photos, or history related to your Mile High profile.

4. The "Departure Wipe" (Data Retention and Purging)

Unlike traditional social networks that permanently archive your personal connections and conversations, Airport.Social enforces a strict, privacy-first "Departure Wipe" policy to protect your privacy and promote fleeting, secure transit connections:

1.

The Purge Timeline: Exactly two (2) hours after your verified flight is scheduled to depart (or immediately upon detecting that your flight has completed its route, whichever occurs first), our database initiates an automated, destructive script.

2.

Data Erased During the Wipe: The following data categories are programmatically and permanently deleted from our primary servers, storage buckets, and memory caches: your active airport terminal "Check-In" status and historical airport transit logs; all active matches formed during that specific layover/check-in period; and all chat messages, media, photos, and meet-up coordinates exchanged with other users during that check-in period.

3.

Information Retained Post-Wipe: We retain only your permanent Core Passport profile (including optional "Photo Verified" status and timestamp, if any), permanent mode configurations, and an encrypted hash of your account identifier for billing and security purposes (such as maintaining active bans against malicious actors). No location history, matching history, conversation content, or verification selfies are archived or retained after the Departure Wipe.

5. Data Sharing and Disclosure

We do not sell, rent, or lease your Personal Information. We only disclose your data to trusted service providers who are contractually bound to implement industry-standard security measures and delete data according to our instructions:

1.

Database Hosting (Supabase): To store and secure your profile, authentication, and chats.

2.

Flight Verification (FlightAware AeroAPI): To validate your boarding pass and flight details.

3.

Indoor Mapping & Geofencing (Mapbox SDK): To render terminal meet-up suggestions and calculate concourse-level proximity.

4.

Facial Comparison (AWS Rekognition): If you opt into the "Photo Verified" badge, your selfie and profile photo bytes are transmitted to Amazon Web Services Rekognition solely to run a one-time CompareFaces similarity score. Images are processed for that request and are not retained by us after scoring; we instruct and configure the comparison as a transient API call rather than a stored face collection.

5.

Law Enforcement and Airport Authorities: We will fully cooperate with the Transportation Security Administration (TSA), Federal Aviation Administration (FAA), local airport police, or federal border control agencies. We will disclose your precise location, account information, or communications if required by a valid subpoena, warrant, or court order, or to prevent immediate physical harm.

6. Your Rights (GDPR and CCPA/CPRA Compliance)

Depending on your region, you have specific legal rights regarding your Personal Information. These rights are protected and respected by Airport.Social:

6.1 General Data Protection Regulation (GDPR) Rights (European Economic Area / UK)

Under the GDPR, you have the following rights:

1.

Right of Access (Art. 15): The right to obtain copies of the personal data we hold about you.

2.

Right to Rectification (Art. 16): The right to correct inaccurate or incomplete personal data.

3.

Right to Erasure (Art. 17): The right to request the deletion of your personal data. (Note: Our Departure Wipe automatically handles the erasure of your transactional data, but you may request complete account deletion at any time).

4.

Right to Restrict Processing (Art. 18): The right to limit the processing of your data.

5.

Right to Data Portability (Art. 20): The right to transfer your data to another service provider.

6.

Right to Withdraw Consent (Art. 7): You can withdraw consent for location tracking, matchmaking, or optional photo verification at any time by toggling off permissions in your mobile operating system or profile settings, declining to submit a verification selfie, or contacting privacy@airport.social to clear your Photo Verified status.

6.2 California Consumer Privacy Act (CCPA/CPRA) Rights

If you are a California resident, you possess the following rights:

1.

Right to Know: The right to request a disclosure of the categories and specific pieces of Personal Information we have collected about you, the sources of collection, and the business purposes of such collection.

2.

Right to Delete: The right to request that we delete Personal Information we collected from you.

3.

Right to Correct: The right to request correction of inaccurate Personal Information.

4.

Right to Opt-Out of Sale or Sharing: Airport.Social does not sell or share your Personal Information for cross-context behavioral advertising.

5.

Right to Non-Discrimination: We will not discriminate against you (e.g., by charging different rates or denying features) for exercising any of your privacy rights.

6.3 How to Exercise Your Rights

To submit an access, deletion, correction, or portability request, please contact our Data Protection Officer at privacy@airport.social. We will verify your identity using your linked third-party authentication method before processing your request within thirty (30) days.

7. Data Security Measures

We implement rigorous administrative, physical, and technical safeguards to protect your personal data from unauthorized access, loss, misuse, or alteration:

Encryption in Transit and at Rest: All data exchanged between your mobile device and our backend servers is encrypted using Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols. All active databases and storage buckets are encrypted using AES-256.

Access Control: Server access is strictly restricted to authorized employees using multi-factor authentication (MFA) and is limited to administrative troubleshooting.

No Local Device Storage: To protect you in the event of device loss or confiscation by customs, no chat history or matching history is permanently saved or cached to your local mobile device's physical storage. All chat features operate dynamically in-memory and terminate upon app exit or account log-out.

8. Third-Party Links and External Services

Our App may suggest public transit meet-up points operated by third-party concessions (e.g., Starbucks, airline lounges, airport restaurants). This Privacy Policy does not cover the privacy, data, or safety practices of these external physical spaces or concessions. We encourage you to review their respective policies when making purchases or visiting their facilities.

9. Children's Privacy

Airport.Social is strictly restricted to individuals eighteen (18) years of age or older. We do not knowingly collect, process, or store personal information from children under the age of eighteen (18). If we discover that a user under eighteen (18) has created an account, we will immediately delete all associated data from our servers.

10. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time. If we make material changes to how we collect, use, isolate, or delete your Personal Information, we will notify you through a prominent notice inside the App or via the email address associated with your registration. Your continued use of the Service following these notices constitutes binding acceptance of the updated Policy.

11. Contact Information and Data Protection Representative

If you have questions, concerns, or requests regarding this Privacy Policy, please contact our privacy compliance team:

Entity: Airport.Social, Inc.

Email Support: support@airport.social

Data Protection Officer: privacy@airport.social

Mailing Address: [Insert Legal Mailing Address]