Flight Ops

Legal

Privacy Policy

Effective 20 July 2026 Version 1.0 Boeve Solutions LLC

The short version

1. Who we are

Flight Ops is aviation management software published by Boeve Solutions LLC, a Washington limited liability company ("Boeve Solutions", "we", "us"). The software is licensed to aviation businesses — fixed-base operators, flight schools, charter companies, and flight departments — each of which we call an Operator.

This policy explains what personal information we handle, in what capacity, and what you can do about it. It covers both this website and the Flight Ops application.

2. Our two roles

This distinction determines who you should contact about your data, so it comes first.

As a controller

For this website and for our own business contacts — someone who emails us asking for a demo, or an Operator's billing contact — we decide what to collect and why. We are the controller, and this policy governs.

As a processor

For everything inside an Operator's instance of Flight Ops — schedules, dispatch records, maintenance history, training files, timeclock entries, invoices — the Operator decides what is collected, who may see it, and how long it is kept. We store and process it on their instructions under our agreement with them. Their own privacy notice governs that relationship, and requests about those records go to them.

In plain terms: if you are a student, renter, charter customer, or employee of an FBO that uses Flight Ops, your records belong to that FBO. We are the filing cabinet, not the record-keeper.

3. This website

This site is static. It sets no cookies, runs no analytics or tracking scripts, embeds no fonts, pixels, or media from third parties, and has no forms. There is nothing here to opt out of.

The site is served by Amazon CloudFront and Amazon S3. Like any web server, those services record standard request data — IP address, timestamp, requested path, user agent, and response status — which we use only to keep the site running and to investigate abuse or outages. We do not use it to build a profile of you.

If you email the address on our contact section, we keep your message and address so we can reply and maintain a record of the conversation.

4. Information in the application

What an Operator's instance holds depends on the modules they use and the role you have. Broadly:

CategoryExamples
Identity and contact Name, email, phone, mailing address, emergency contact
Account and security Hashed password, role and permissions, sign-in times, agreement acceptance, audit log of record changes
Airman credentials Pilot and instructor certificate details, ratings, medical certificate class and expiry, flight review and currency dates
Training records Lesson and stage-check results, curriculum progress, instructor notes, endorsements
Operational records Reservations, dispatch and flight times, squawks and maintenance actions you recorded, fuel transactions
Employment and payroll For an Operator's staff: position, timeclock entries, pay codes, and government identifiers where the Operator uses the payroll features
Billing Invoices, statements, payment history, and a tokenized reference to a saved payment method

Some of this is sensitive. Medical certificate details, training performance, and government identifiers are restricted inside the application to the roles that need them, and access is logged.

5. How we use it

As a processor, we use the Operator's data only to:

  • provide, host, secure, and support the application;
  • send the transactional email the application generates on the Operator's behalf;
  • back it up and restore it;
  • investigate security incidents, abuse, or faults; and
  • comply with law.

We may produce aggregated, de-identified statistics about how the software is used — feature adoption, error rates, performance — to operate and improve it. These never identify an individual, an Operator, an aircraft, or a customer.

We do not sell personal information, share it for cross-context behavioural advertising, or use it to train machine-learning models.

6. Who we share it with

We disclose personal information only to:

  • The Operator whose instance holds it, and the staff they authorize.
  • Service providers who process it on our behalf under contract: Amazon Web Services (hosting, database, storage, and email delivery) and our payment processors. They may use it only to provide their service to us.
  • Authorities, where required by valid legal process. Where we are permitted to, we will tell the affected Operator before responding.
  • A successor, if our business is merged or acquired — subject to this policy or a successor policy at least as protective.

7. Payments

Card payments are handled by third-party payment processors under their own privacy policies and security certifications. Full card numbers are never stored in Flight Ops. The application keeps only a tokenized reference supplied by the processor, plus the limited details needed to recognize a card — brand, last four digits, and expiry.

Prices, charges, refunds, and disputes are set and administered by the Operator, not by us. Direct billing questions to them.

8. Email

The application sends transactional email — account verification, password resets, booking and service-request notifications — through Amazon Simple Email Service. These are not marketing messages, and they are necessary to operate the account; there is no unsubscribe for them, though the Operator can adjust which notifications you receive.

We record delivery outcomes, including bounces and spam complaints, so the Operator can fix bad addresses and so we can protect sending reputation.

9. Retention

The Operator sets retention for the records in its instance. Aviation businesses are subject to record-keeping obligations — maintenance, training, and financial records in particular — that often require keeping data for years, and those obligations can override a request to delete.

When an Operator's agreement with us ends, we delete or return its data according to that agreement. Encrypted backups age out on their normal cycle. Our own business records, such as correspondence and invoices, are kept as long as needed for legal and accounting purposes.

10. Security

Measures we maintain include:

  • encryption in transit (TLS) and at rest;
  • a separate, isolated cloud environment and database per Operator, so one Operator's data is never commingled with another's;
  • role-based access control, with extra restrictions on payroll and financial data;
  • hashed passwords, rate-limited sign-in, and expiring password-reset tokens;
  • an audit trail of sign-ins, permission changes, and record edits;
  • secrets held in a managed secrets store, and infrastructure access limited to those who need it.

No system is perfectly secure. If a breach affects your personal information, we will notify the affected Operator without undue delay and support their notifications to individuals as required by law.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information, and to appeal a refusal.

For records held in an Operator's instance of Flight Ops, contact the Operator. They control that data. If you contact us instead, we will refer you to them and, where we can identify the Operator, let them know. If an Operator instructs us to act on your request, we will.

For information we hold as a controller — website logs, and correspondence with us — write to the address in section 16. We will not discriminate against you for exercising a right.

12. US state privacy rights

Residents of states with comprehensive privacy laws, including California, Colorado, Connecticut, Virginia, and others, have the rights described above. For the purposes of those laws, in the application we act as a service provider or processor to the Operator, who is the business or controller.

We do not sell personal information or share it for cross-context behavioural advertising, and we have not done so in the preceding twelve months. We do not use sensitive personal information for any purpose other than providing the service.

You may use an authorized agent to submit a request. We may need to verify your identity before acting, and for records in an Operator's instance, verification is the Operator's responsibility.

13. Children

Neither this website nor Flight Ops is directed to children under 13, and we do not knowingly collect their personal information. Operators should not create portal accounts for children under 13.

Flight training regularly involves minors aged 13 and older — a student may solo at 16 and train well before that. Where an Operator maintains records for a minor, the Operator is responsible for obtaining any consent the law requires from a parent or guardian. If you believe a child under 13 has an account, tell the Operator and us, and we will support its removal.

14. Where data is held

Flight Ops runs on Amazon Web Services infrastructure in the United States, and personal information is stored and processed there. If you access the service from outside the United States, you understand that your information will be transferred to and handled in the United States, where privacy laws may differ from those in your country.

15. Changes to this policy

We may update this policy. The effective date at the top always reflects the current version. If a change is material, we will give notice through the application, to Operators directly, or by a prominent notice on this page before it takes effect.

16. Contact

Questions, requests, or complaints about this policy or our handling of personal information:

For records held by an aviation business that uses Flight Ops, contact that business directly — they control the data and can act on your request faster than we can.