Privacy Policy

Privacy Policy

Effective date: 9 September 2026 Version: 1.1.0 · Supersedes the version dated 27 July 2026

Flyb Digital Solutions, LLC (“FlyB”, “we”, “our”, “us”) provides a platform for building websites, capturing leads, managing a sales pipeline, taking bookings and sending e-mail. This policy explains what personal data we handle, why, with whom we share it and what rights you have.

It applies to every tier of service — Check-in (Free), Plus and Prime — and forms part of the Terms of Use.

We aim to comply with the privacy laws applicable where we operate, including the GDPR (EEA), the UK GDPR, the Swiss nFADP, PIPEDA (Canada), the LGPD (Brazil) and United States state privacy statutes including the CCPA/CPRA.


1. The two roles FlyB plays

This distinction determines which rules apply, so it comes first.

Account dataCustomer Content
What it isYour registration details, billing records, usage telemetry, support correspondenceThe data you put into FlyB: your leads, customers, blog members, booking guests, and everything about them
Who decides why it is processedFlyBYou
FlyB’s roleControllerProcessor — we act on your instructions
Governed byThis policyThis policy and the Data Processing Addendum

If you are a visitor, lead, customer, booking guest or blog member of a FlyB customer, that customer — not FlyB — is the controller of your data. Please direct your requests to them. We will help them respond, and we will forward a request we receive directly.


2. Data we collect

2.1 Data you give us

CategoryExamples
Identity and contactName, business e-mail, phone number, country, profile picture
OrganisationOrganisation name, logo, address, business sector, website, social profiles
BillingBilling name and address, subscription and invoice records. We never see or store your card details — Stripe processes and holds them
Content and configurationPages, blog posts, forms, calendars, templates, automation rules, prompts, uploaded images and files
Customer ContentThe contacts, deals, bookings and communications you place in the platform, together with what the Services derive from them on your instruction — such as which member of your team a lead is assigned to, and the lead score produced by scoring rules you write. For a booking, it also records whether the guest agreed to receive its confirmation and reminders on WhatsApp, and when they answered or changed their answer. It includes the internal notes your team writes about a contact, which are never sent to that contact, and the notes and tasks your team records on a contact — the text and pictures of each note, its earlier versions, and the record of what each scheduled task did, including the reminder e-mails described in section 13. Where you connect a WhatsApp number, this also covers the conversations carried on it: the messages exchanged in both directions, including those your team types in the WhatsApp Business app on the phone (or, for a number linked through WhatsApp Web, in WhatsApp on the phone), and the message automation rules you write together with the record of which contact each rule wrote to, when, and why a message was not sent. It also covers FlyB Chat conversations — the messages exchanged, in both directions, through the chat window on your pages and blogs — together with when the person last had that chat open and whether they have read or dismissed your replies, which is what shows your team that they are online. Where your team’s replies do not reach that chat within 15 minutes, or where a member of your team chooses to send a reply the person has not yet read, a copy of them — with the person’s last message, when there is one — is sent to the person’s e-mail address on your organization’s behalf, and the platform records that it was sent and which member sent it
SupportThe messages, screenshots and recordings you send us, including through the support chat in the dashboard — together with which member of your organisation wrote each message and when you last had that chat open
Integration credentialsOAuth tokens and API credentials for services you connect, held encrypted

2.2 Data collected automatically

CategoryExamples
TechnicalIP address, browser type and version, device type, operating system, timestamps, error logs
Approximate locationCountry, region and city derived from IP address. We do not collect precise geolocation
UsagePages visited inside the dashboard, features used, Flight consumption, API call volume
Site analyticsFor content FlyB hosts for you, aggregated daily counts of visits by page, country, region, city, browser, path and campaign parameters. Campaign parameters are the UTM tags on the link followed, or — where the link carries none — the advertising platform and channel we recognise from the link (for example a Google Ads click, from its gclid parameter)
Advertising click identifierWhere a visit arrives from an advertisement, the identifier the advertising platform added to the link (such as Google Ads’ gclid or Meta’s fbclid). It identifies the AD CLICK, not the person. It is held in a cookie for 30 days and written to the contact record if that visit goes on to create one — a sign-up, a form submission or a booking — so the resulting lead can be reported back to the platform that produced it. It is not stored in the daily analytics counts
E-mail engagementWhether an e-mail was delivered, opened, bounced or reported as spam, and — for the buttons a customer marks as tracked — which button was clicked, when, and how many times. A tracked button’s link passes through FlyB, which records the click and immediately forwards the reader to the destination; clicks made by automated e-mail security scanners are discarded

FlyB’s own site analytics are stored as aggregated daily buckets, not as a per-visitor event log with a persistent visitor identifier.

2.3 Data from third parties

  • Google, when you sign in with Google or connect a calendar — see section 6.

  • Stripe, the outcome and metadata of a payment, never the card number.

  • Google Places, business listing information you retrieve through Active Search.

  • Meta (WhatsApp Business Platform), for each WhatsApp number you connect: the messages sent to and from it, the phone numbers and WhatsApp profile names of the people who write to it, and delivery and read receipts. Where you ask for it, the contacts saved in your WhatsApp Business app. FlyB never requests your past conversations.

    Attachments are stored by FlyB. An image, voice message, video or document sent on WhatsApp is copied into your organisation’s file storage when it arrives, and is held there as part of the conversation. Meta itself keeps such files for only about 30 days; without the copy, the record of what was said would be incomplete after that. The copy is subject to the same access controls as the rest of your conversation data, and is deleted when the conversation is deleted — including when you delete the WhatsApp number the conversation belonged to.

  • WhatsApp (WhatsApp Web), for each number you link through WhatsApp Web — as a linked device of the phone, through a WhatsApp Web session: the messages sent to and from it, including those typed on the phone after it was linked; the phone numbers and WhatsApp profile names of the people who write to it; delivery and read receipts; and, where you switch on a number’s online status, whether the contacts it follows are online and when they were last seen. FlyB never requests the conversation history from before the number was linked. To keep the device linked, FlyB stores the session credentials WhatsApp issues to it (encryption keys), encrypted, until the number is disconnected. Attachments are stored as described above.

    Numbers set to send only. For either kind of number you can switch off what it receives. While it is off, FlyB discards the messages, attachments and reactions that arrive on that number — including those typed on the phone — as they arrive and does not keep them; it keeps only the messages sent from FlyB and their delivery and read receipts.

  • Your SMTP provider and delivery feedback loops, bounce and complaint reports.

  • Affiliate referrals, the fact that an account arrived through a given link.

2.4 Children

The Services are for professional use and are not directed to anyone under 18. We do not knowingly collect data from a minor. If we learn we have, we delete it. Write to [email protected] if you believe this has happened.

2.5 Sensitive data

We do not intentionally collect special categories of personal data (GDPR Article 9) or sensitive personal data (LGPD Article 5, II), and we instruct customers not to upload it. Restrictions on the data you may place in the Services are in Terms of Use, section 11.3. We may delete data we identify as falling into a prohibited category, to protect the integrity of the Platform.


For account data, where FlyB is the controller:

PurposeLegal basis (GDPR)
Providing and operating the ServicesPerformance of a contract
Authenticating you and securing your accountContract; legitimate interests
Metering Flights, measuring plan allowances, and notifying the account owner when one is reachedContract
Sending the account owner and admins a daily summary of the traffic your own content receivedLegitimate interests, with an off switch in the organization settings
Billing, invoicing and collectionsContract; legal obligation
Support and service communicationsContract; legitimate interests
Detecting, preventing and investigating fraud, abuse and security incidentsLegitimate interests; legal obligation
Improving the reliability and performance of the Services using aggregated and de-identified dataLegitimate interests
Product and marketing communicationsConsent, or legitimate interests where the law permits, with an opt-out in every message
Complying with law, tax, accounting, audit, export control and sanctionsLegal obligation
Establishing, exercising or defending legal claimsLegitimate interests

Under the LGPD the corresponding bases are execution of a contract, legitimate interests, compliance with a legal obligation, and consent where required. Where we rely on consent you may withdraw it at any time, without affecting processing already carried out.

3.1 Automated decision-making

FlyB does not carry out automated decision-making producing legal or similarly significant effects on an individual (GDPR Article 22). Flight consumption and plan limits are automated, but any account suspension for suspected abuse is subject to human review.

Features you configure yourself — in particular lead scoring, which adds or subtracts points on your contacts when an action you chose occurs — run on rules you write, as your processor and on your instruction. FlyB does not decide anything about those contacts and does not act on a score: the score is a number shown to your team, alongside the record of every point that produced it. Where the way you use it amounts to profiling under the applicable law, you are the controller of that processing and the obligations in the Data Processing Addendum apply to it like any other instruction you give us.

FlyB Hunt AI works the same way: it scores your contacts against a question your team writes, with an AI model, to help your team decide whom to contact. FlyB does not act on a Hunt AI score either — nothing is sent to, changed about or decided for a contact because of it — and the same controller obligations apply to the way you use it.

The AI conditions of CRM automations are different in one respect, and it is the point of them: when your team writes one, the automation acts on its own — moves the contact in your pipeline, assigns it to a member, sends it a message, adds points to its score — whenever an AI model judges that the messages the contact sent, or the contact’s record, match the condition. That is processing you configure and switch on, run as your processor and on your instruction; you are the controller of it, decide what each automation does and to whom, and should not configure one to produce legal or similarly significant effects on a person without human review. The same controller obligations apply.


4. We do not sell your data

FlyB does not sell personal data, and does not share it for cross-context behavioural advertising, as those terms are defined in the CCPA/CPRA and comparable United States state laws. We have not done so in the preceding twelve months.

We do not use your Customer Content to advertise to your contacts, and we do not disclose it to any other customer.


5. Who we share data with

We share personal data only where it is necessary to run the Services, where you direct us to, or where the law requires it.

5.1 Sub-processors

We use service providers who process data on our behalf under contract, bound to confidentiality and to use the data only for the purpose we specify. The complete, current list — with each provider’s function, location and privacy policy — is maintained at Sub-processors.

At the date of this policy it includes, among others: Amazon Web Services (hosting, storage and e-mail infrastructure), Stripe (payments), OpenRouter (the image and video generation), Google Cloud / Google APIs (calendar integration, Places, indexing), Google Analytics (product analytics) and Unsplash (stock image suggestions).

5.2 Integrations you enable

When you connect Stripe, Google Calendar, WhatsApp/Meta, Make, an SMTP server or OpenRouter, you instruct us to exchange data with that service. Those services then handle the data under their own privacy policies, over which FlyB has no control. Reviewing them is your responsibility. See section 7 for AI providers and section 6 for Google.

We may disclose data where we reasonably believe it necessary to comply with a law, regulation, subpoena, court order or lawful government request; to enforce our Terms of Use; to detect or prevent fraud, spam or abuse; or to protect the rights, property or safety of FlyB, our users or the public.

Where we are legally permitted, we will notify the affected customer before disclosing.

5.4 Corporate transactions

If FlyB is involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of it. The acquirer remains bound by this policy until it is superseded, and we will notify you of a change of controller and of any material change in how your data is handled.


6. Google User Data, OAuth Scopes and Limited Use

This section describes exactly how FlyB requests, accesses, uses, stores, shares and deletes data obtained from Google APIs. It applies in addition to the rest of this policy and prevails over any conflicting provision elsewhere in it.

6.1 Limited Use disclosure

FlyB’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Without limitation, FlyB affirms that:

  • We do not use Google user data to serve advertising of any kind, including retargeting, personalised or interest-based advertising.
  • We do not sell, rent, license or otherwise monetise Google user data.
  • We do not transfer Google user data to third parties, except (a) to the limited sub-processors strictly necessary to operate the feature you enabled, as listed in 6.6; (b) where required by law or valid legal process; or (c) as part of a merger or acquisition, subject to notice and consent where the law requires it.
  • We do not use Google user data to develop, improve or train generalised or standalone artificial intelligence or machine-learning models. Google user data is never sent to any AI model, whether operated by FlyB or by a third party.
  • Humans do not read Google user data, except (a) with your explicit, affirmative consent for a specific case, such as a support ticket you ask us to investigate; (b) where strictly necessary for security purposes, such as investigating abuse or a suspected breach; (c) to comply with law; or (d) where it has been aggregated and anonymised and is used solely for internal operations.

6.2 Google Sign-In (openid, email, profile)

Why we request it. Exclusively for authentication and account creation, so you can sign in without managing a separate password.

How it is used. We receive your Google account identifier, verified e-mail address, display name and profile picture URL. The e-mail address is the unique identifier of your FlyB account; the name and picture populate your profile.

What we store. Your e-mail address, display name and profile picture URL on your user record. We do not store Google access or refresh tokens for the sign-in flow — the credential is verified at the moment of login and then discarded.

What we never do. These scopes are never used to reach your Google contacts, to send e-mail through Google, or for any purpose other than authenticating you and provisioning your account.

6.3 Google Calendar — read-only availability (calendar.readonly)

Why it is needed. To check your existing availability and prevent double-booking.

How it works in practice. Two narrow operations only:

  1. Listing your calendars when you connect and when you open the calendar’s Google settings, so you can choose which one to link and, optionally, which other calendars of the same account should also block your availability. We read only each calendar’s identifier, display name, time zone and your access role.
  2. Querying busy time ranges (freeBusy) on the linked calendar — and on the other calendars you chose to have block your availability — within the window your visitor is viewing, and again for the single time a visitor confirms. That endpoint returns only the start and end timestamps of periods marked busy.

Important limitation. FlyB does not read the titles, descriptions, locations, attendees, attachments or any other content of your existing calendar events. Availability is determined solely from opaque busy/free ranges. The change detection described in 6.4 reads only identifiers, statuses and times.

What we store. Nothing from the busy ranges. They are held in a short-lived in-memory cache for up to sixty (60) seconds, purely so that a visitor paging through the booking widget does not trigger redundant calls to Google, and are never written to our database, our logs or our backups. We store the identifier, name and time zone of the single calendar you selected, so we know where to sync, and the identifiers of any other calendars you chose to have block your availability.

6.4 Google Calendar — event management (calendar.events)

Why it is needed. To create, update and delete the calendar events that correspond to FlyB bookings, and to keep those bookings in step when you change their events directly in Google Calendar.

How it works in practice. Four narrow operations only:

  1. Creating an event when a booking is confirmed, carrying the title, description, location, start and end times, time zone and the guest’s name and e-mail address, plus a private marker identifying the FlyB booking (visible only to FlyB). For a remote appointment we additionally ask Google to attach a Google Meet conference.
  2. Updating an event FlyB previously created, when the booking is rescheduled.
  3. Deleting an event FlyB previously created, when the booking is cancelled.
  4. Detecting changes to the events FlyB created, unless you switch this off in the calendar’s Google settings. Google notifies FlyB when an event of the linked calendar changes — a notification that carries no event data — and FlyB then reads the list of events that changed, requesting only each event’s identifier, status, start time and last-modified time. Those of the events FlyB created that were deleted or moved cancel or reschedule the corresponding upcoming booking. Entries about any other event are discarded immediately and are never stored or logged.

Important limitation. FlyB only ever writes to, modifies or deletes events FlyB itself created, identified by the event identifier recorded at creation. We never touch events created by you or by anyone else.

What we store. The Google event identifier, the generated Meet URL, the identifier of the Google calendar holding the event and the event’s last-modified time, against the corresponding FlyB booking. For the linked calendar, an opaque synchronisation token issued by Google and the identifiers of the notification channel Google uses to tell FlyB about changes.

6.5 Credentials and security

To keep a connected calendar in sync without re-authorising on every booking, FlyB requests offline access and stores the resulting refresh token and short-lived access token against the specific FlyB calendar you connected.

  • Tokens are stored on encrypted volumes, are never exposed to the browser or to any client-side code, and are never transmitted to any party other than Google.
  • Access is scoped to the organisation that owns the calendar; every request is isolated by organisation identifier.
  • All communication with Google APIs uses TLS.
  • The OAuth state parameter is cryptographically signed and verified on callback, so an authorisation cannot be bound to the wrong account.

6.6 Sharing of Google user data

Google user data is not shared with any third party for that party’s own purposes. Within the operation of the feature you enabled, it is handled by:

RecipientRoleGoogle data involved
Google LLCSource and destination of the integrationAll of it, by definition
Amazon Web ServicesHosting infrastructure where FlyB’s database and servers runStored OAuth tokens, linked calendar identifiers, Google event identifiers and last-modified times, Meet URLs, synchronisation tokens and notification channel identifiers

Google user data is not shared with our AI providers, analytics providers, advertising networks or any other third party.

6.7 Retention and deletion of Google user data

  • Disconnecting. You may disconnect Google Calendar from the calendar’s settings at any time. Doing so immediately and permanently deletes the stored refresh token, access token, linked calendar identifier, calendar name, connected account e-mail and time zone, the identifiers of any other calendars you chose to block your availability, the synchronisation token and the notification channel identifiers from our database, and asks Google to close the notification channel.
  • Revoking at Google. You may also revoke FlyB’s access at myaccount.google.com/permissions. FlyB can then no longer read availability from, notice changes on, or write events to, your calendar — and tells the calendar’s team once that the connection stopped working.
  • Existing events. Disconnecting does not delete events already on your Google Calendar — they remain yours. FlyB simply stops syncing.
  • Account deletion. All Google credentials and Google-derived identifiers are deleted along with your account data, within the periods in section 11.
  • No independent retention. FlyB keeps no separate archive of your calendar contents.

Both Google integrations are entirely optional. FlyB is fully usable without a Google account: you can sign in with an e-mail code, and you can run calendars and bookings without linking them to Google. Access is requested only when you initiate the connection, and only for the scopes described above.


7. Artificial Intelligence and Model Providers

FlyB uses artificial intelligence in two structurally different ways, and the privacy consequences of each are different. Please read both.

7.1 AI features FlyB operates

The AI landing page builder, the AI blog post writer, the AI e-mail template writer, the AI section generator, the AI Advisor, FlyB Hunt AI and the AI conditions of CRM automations run on FlyB’s own provider accounts.

  • Your prompts, briefings and the context needed to answer them are transmitted to our AI provider, listed in Sub-processors, to produce the output.
  • We send only what the feature needs. We do not send your whole contact base to a model to write a landing page.
  • FlyB Hunt AI sends, for each contact active in the period a member of your team searches, the parts of that period’s record that bear on the Hunt Rule — drawn from messages, notes, tasks, appointments, e-mail activity, CRM history, purchases, custom fields and profile attributes — to its model provider, which returns a score. Which parts bear on the rule is decided before the search from the rule itself, with your organization’s name, sector and website and the names of your custom fields, without any contact’s data; a contact with nothing in a part the rule requires is not sent at all. Names, e-mail addresses, phone numbers and street addresses are removed before anything is sent, including from inside the text of messages and notes; of the e-mail address and the phone number, only the domain of the address (with whether it belongs to a free e-mail provider) and the country calling code of the number are sent, beside the city and state.
  • An AI condition of a CRM automation about a message sends, once the conversation has gone quiet and while the condition’s other requirements are met, the condition your team wrote, your organization’s name and sector, the messages the contact sent since the conversation was last quiet and up to 20 messages of that conversation (your team’s replies included) — and nothing else about the contact. An AI condition about the contact — when the contact enters a stage, once per entry, or when they write, under the same conditions as above — sends the condition, your organization’s name and sector and the same parts of the contact’s record Hunt AI reads, from the last 90 days, messages of the period included. Both with the same removals. Each returns the probability that the condition is true, which is kept in the automation’s history, beside a reference to the messages or the entry it judged, for 90 days.
  • Our provider processes that content under contract with FlyB, on our instructions, and is bound to confidentiality.
  • We do not use your prompts or your Customer Content to train general-purpose AI models that benefit other customers.
  • Data obtained from Google APIs is never sent to any AI model — see 6.1.

7.2 AI features that run on your own provider account

The AI video generator and the AI image generator work differently, and the difference matters for your privacy.

These features run on an account you hold with OpenRouter, Inc., using an API key you supply.

  • Your OpenRouter API key is stored in your browser only, in a cookie scoped to the FlyB dashboard host. It is never transmitted to, or stored on, FlyB’s servers.
  • Your briefing, your prompt, your reference images and the resulting video or image travel directly between your browser and OpenRouter. They do not pass through FlyB’s infrastructure, and FlyB does not store the generated file.
  • OpenRouter is a router: it forwards your request to the model provider you selected. That provider is a further independent party.
  • FlyB is not a party to your relationship with OpenRouter and has no control over, and no visibility into, how OpenRouter or the model providers behind it use, retain, disclose, log or train on what you send. OpenRouter is not a FlyB sub-processor, because FlyB does not determine or instruct that processing.
  • Your use of these features is governed by your own agreement with OpenRouter, including OpenRouter’s Privacy Policy. Please read it — and the policy of the individual model you select — before you use these features. Data-retention and training practices vary considerably from one model to another, and OpenRouter provides its own account-level controls for them.
  • OpenRouter bills you directly. FlyB charges nothing for these operations.

Do not submit confidential, personal or regulated data to these features unless you have satisfied yourself that OpenRouter and the model you select handle it appropriately. Where the data you would submit is personal data of someone else, you — not FlyB — are the controller of that transfer, and you are responsible for having a lawful basis for it.

7.3 AI output is generated, not verified

AI output may be inaccurate, incomplete or fabricated. Do not rely on it without review, and do not use it as the operative basis for decisions producing legal or similarly significant effects on a person. See Terms of Use, section 8.


8. International transfers

FlyB is established in the United States and its infrastructure is operated there. Our sub-processors are located in the United States and other countries. Using the Services therefore involves transferring personal data outside your country.

Where personal data is transferred out of the EEA, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum, and the Swiss adaptations, where applicable), together with supplementary technical measures including encryption in transit and at rest and access control.

Where personal data is transferred out of Brazil, we rely on the mechanisms permitted by Articles 33 to 36 of the LGPD, principally contractual clauses offering equivalent protection.

A copy of the relevant transfer terms is available on request to [email protected].


9. Security

We apply technical and organisational measures appropriate to the risk, including:

  • Encryption in transit (TLS) for all connections, and encryption at rest for stored data and backups.
  • Tenant isolation — every query is scoped by organisation identifier, so one customer’s data cannot be reached from another’s session or API key.
  • Access control — role-based permissions in the product, and least-privilege access to production systems for our personnel.
  • Credential handling — API keys are stored as encrypted fingerprints and can never be read back, only replaced; OAuth tokens and SMTP passwords are held encrypted and are never exposed to client-side code.
  • Logging and monitoring of access and of anomalous activity.
  • Backups on encrypted storage, for disaster recovery.

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for the security of your own credentials and of the devices you use.

9.1 Breach notification

If we become aware of a personal-data breach affecting your data, we will notify you without undue delay and, where we act as processor, in time for you to meet your own notification obligations. The notice will describe what we know of the nature of the breach, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed.


10. Cookies and similar technologies

We use cookies and browser storage to keep you signed in, to remember your organisation and preferences, to measure use of our own sites and to attribute leads to the visit that produced them. The full inventory, and how to control them, is in the Cookie Policy.


11. How Long We Keep Your Data

DataRetention
Active accountsFor as long as the account is active
Cancelled paid subscriptions, account not deletedProject data (pages, blogs, contacts, calendars) is kept for a grace period of ninety (90) days to allow reactivation, after which we may delete non-active project data
Account termination or a deletion requestPersonal data is deleted or anonymised within thirty (30) days, except where we must keep it
Google credentials and identifiersDeleted immediately on disconnection or account deletion. Never subject to the grace period
WhatsApp attachmentsKept for as long as the conversation exists. Deleted with the conversation, and with the WhatsApp number it belonged to
WhatsApp Web session credentialsKept, encrypted, while the number is linked. Deleted when the number is disconnected or logged out
Contacts’ WhatsApp online statusOnly the latest state is kept, on the conversation it concerns, and it is deleted with that conversation
Billing and tax recordsRetained for the period required by tax and accounting law, typically five to ten years
Fraud, abuse and security logsRetained as long as necessary for prevention and for the defence of legal claims
Consent and acceptance recordsRetained for the life of the account plus the applicable limitation period, as evidence of consent
BackupsResidual copies may persist in encrypted backups for up to ninety (90) days after deletion from production
Aggregated, de-identified dataMay be retained indefinitely, as it no longer identifies anyone

Expiry or forfeiture of unused Flights does not delete your personal data; your account simply reverts to the Free plan until you ask for deletion.


12. Your rights

Subject to the law that applies to you, you may:

RightWhat it means
AccessObtain confirmation of whether we process your data, and a copy of it
RectificationHave inaccurate or incomplete data corrected
ErasureHave your data deleted, where no legal ground requires us to keep it
RestrictionHave processing limited in certain circumstances
PortabilityReceive your data in a structured, machine-readable format, or have it transmitted to another controller
ObjectionObject to processing based on legitimate interests, and to direct marketing at any time and without reason
Withdraw consentWhere processing is based on consent, at any time, without affecting prior processing
Not be subject to automated decisionsProducing legal or similarly significant effects. We do not carry these out
ComplainTo your supervisory authority — the ANPD in Brazil, your national DPA in the EEA, the ICO in the UK

Under the CCPA/CPRA and comparable United States state laws you also have the right to know the categories of data collected, disclosed and sold or shared; to delete; to correct; to opt out of sale, sharing and profiling — we do none of these; to limit the use of sensitive personal information — we do not collect it for such uses; and not to be discriminated against for exercising a right. You may use an authorised agent, and we will verify their authority.

12.1 How to exercise a right

Write to [email protected] from the e-mail address on your account, or, if you cannot, give us enough information to verify your identity. We may ask for further verification proportionate to the sensitivity of the request.

We respond within thirty (30) days. Where the law allows an extension and the request is complex, we will tell you within that period and explain why.

There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline, and will explain the reason.

12.2 Appeals

If we decline a request, our response will say why. Where the law of your state or country provides a right of appeal, you may appeal by replying to that response with the subject line “Privacy Appeal”. We will review and answer within the statutory period, and will tell you how to escalate to your regulator if you remain dissatisfied.

12.3 If you are someone else’s contact

If your data is in FlyB because a FlyB customer put it there, that customer is the controller. Send your request to them. Where you send it to us, we will forward it and assist them in responding, but we cannot act on their data without their instruction.


13. Marketing communications

We may send you product updates, service notices and marketing about FlyB. Service and security notices cannot be opted out of while you hold an account, because you need them.

Every marketing message carries an unsubscribe link, and you can also write to [email protected].

Task reminder e-mails are sent only to the members of your organization that a colleague put on a Notes & Tasks reminder, at the moment that colleague chose. They carry the words of the reminder and the name, phone number and e-mail address of the contact it is about, so the member can act on it. They are Customer Content sent on your organization’s instruction, not marketing, and a member receives one only when a colleague adds them to a reminder.

The daily summary is a report on your own organization’s activity, not marketing. It goes to the account owner with the organization’s admins in copy, at most once a day, and only when there was activity to report — visits to your content, contacts captured or bookings received. It carries counts and the names of your own content and calendars; it never carries the personal data of the contacts it counts. Turn it off at any time under Settings → Company; it stops for the whole organization.


14. Changes to this policy

We may update this policy. The version and effective date at the top always identify the current one. For material changes that reduce your rights or expand our processing, we will give at least thirty (30) days’ notice by e-mail or by a prominent notice in the product before it takes effect.

The current version is always published at docs.flyb.app/privacy-policy.


15. Contact

Flyb Digital Solutions, LLC, a Wyoming limited liability company, registered in the United States, with a team distributed across several countries.

PurposeAddress
Privacy requests, data rights, appeals[email protected]
General support[email protected]
Security vulnerabilities[email protected]

See also the Contact page and flyb.app/about.


16. Severability and precedence

If any provision of this policy is held unlawful or unenforceable, it will be interpreted to achieve its intent as closely as possible, or severed; the remainder stays in force.

This policy, together with the Terms of Use, the Cookie Policy and, where it applies, the Data Processing Addendum, is the entire agreement between you and FlyB on privacy and data protection. Where the Data Processing Addendum conflicts with this policy on a matter of processing Customer Content, the Addendum prevails.