"Discretion is part of the service. So is candor about what we hold and why."
01 — What we collect
To charter you a flight we need a small, specific set of facts. We do not collect data we cannot use to fly you, bill you, or protect you.
- Identity: name, date of birth, government-issued ID number (where required by Part 135 manifests).
- Contact: email, phone, billing and mailing address.
- Itinerary: origin, destination, dates, passenger names, dietary preferences.
- Payment: tokenised card data via Stripe — Aerion never sees the full card number.
- Operational: session logs, IP, browser, device — for fraud prevention only.
02 — Why we collect it
The lawful bases under GDPR and CCPA we rely on are: contract (to operate your flight), legal obligation (FAA recordkeeping), and legitimate interest (security, fraud prevention, service improvement). We never sell your information to anyone, ever.
03 — Who we share with
The shortest possible list:
- FAA / customs / TSA: when legally required for manifests and clearance.
- Stripe: payment processing only.
- Better Auth: authentication & session management.
- Postmark: transactional email (your itinerary, your captain's note).
We do not feed advertising networks, "data brokers", or AI training sets. Your charter history is not training data for anyone.
04 — How long we keep it
- Flight manifests: 5 years (FAA Part 135 minimum).
- Billing records: 7 years (IRS).
- Authentication logs: 90 days.
- Marketing preferences: until you ask us to forget you.
05 — Your rights
Wherever you are, you may always: access the data we hold on you, correct it, export it as a portable file, restrict processing, or request deletion. Email privacy@aerion.co; we acknowledge within 72 hours and complete within 30 days.
Children
We do not knowingly collect data from anyone under 13. Charters with minors are arranged through their accompanying adult.
06 — How we protect it
Encryption at rest (AES-256), in transit (TLS 1.3), single-tenant database on isolated infrastructure, mandatory MFA for all employees, quarterly third-party penetration tests, and an annual SOC 2 Type II audit. Breach notification within 72 hours, in plain English.
07 — Contact us
Aerion Charter Co.
Attn: Data Protection Officer
14 Sawkill Road, Kingston, NY 12401
privacy@aerion.co · +1 845 555 0127
Last revised 2026-04-26. Material changes will be announced by email at least 30 days before they take effect.