Privacy Policy
Last updated: 3 August 2026
This policy describes how personal data is collected and processed for users of the airshowdisplay.fr website and the Airshow Display mobile application (iOS and Android). It is the single reference document for both services.
Data controller
Guillaume Noguera, sole proprietor registered with the Tarascon Trade Register under number 834 811 440, 60 avenue de la République, 13310 Saint-Martin-de-Crau, France. Contact: [email protected].
Data we collect
We only collect data that is necessary for the service, its security and, with your consent, for personalisation and ad-based funding:
- User account: e-mail address, first name, last name, nickname, password (bcrypt-hashed), profile picture (optional).
- Preferences: follows (aircraft, teams, events), bookmarks, notification settings, language, country.
- Contributions: airshow and line-up submissions, news, contest entries (photos, texts, associated metadata).
- Geolocation (mobile app only, optional): only when you open the map, to show nearby events. Position is not stored on our servers.
- Mobile technical identifiers: device UUID and push notification token (FCM / APNs).
- Technical logs: access logs (IP address, timestamp, called endpoint, user-agent), kept 30 days for security and troubleshooting.
- Cookies and trackers (web): technical authentication cookies and, subject to your consent, analytics and advertising cookies (see Cookie Policy).
Purposes and legal bases
- Provide the service (account, follows, bookmarks, notifications, contests) — performance of the contract.
- Secure access and prevent abuse (logs, CSRF tokens, bot detection) — legitimate interest.
- Send you push notifications and e-mails related to your follows — consent, revocable at any time.
- Send you the newsletter — consent, revocable via the unsubscribe link in each e-mail.
- Transactional e-mails (account validation, password reset, moderation notices) — performance of the contract.
- Measure audience and improve content — consent (analytics cookies).
- Display personalised or non-personalised advertising and fund the service — consent (IAB TCF 2.2 advertising cookies).
- Answer your requests (contact, support) and meet our legal obligations — performance of the contract / legal obligation.
Processors and recipients
We use processors for hosting, e-mail delivery, mobile distribution, audience measurement and advertising. Some are located outside the European Union; transfers are covered by the European Commission's Standard Contractual Clauses and, where applicable, by the EU-US Data Privacy Framework.
- IONOS SARL (France) — hosting of the site, API and databases.
- Amazon Web Services — SES (eu-west-3 region, Paris) — transactional e-mails and newsletter delivery.
- Firebase Cloud Messaging (Google) — mobile push notification delivery (transfer outside the EU covered).
- Apple / Google — app distribution via App Store and Google Play.
- Google AdSense (site) — advertising display and ad performance measurement (transfer outside the EU covered).
- Google Analytics (site) — anonymised audience measurement (transfer outside the EU covered).
- Matomo (site) — audience measurement.
- Meta Platforms (Facebook SDK) (site) — share button and social integrations (transfer outside the EU covered).
- Impact.com, Amazon Associates and other affiliate networks (site) — click and conversion tracking on partner links.
- IAB TCF 2.2 advertising partners (site) — full and evolving list available from the consent management modal.
No data is sold to third parties. We do not perform profiling other than for the purposes described above.
Retention periods
- Account data: kept as long as the account is active; erased or anonymised within 30 days of account deletion.
- Published contributions: kept as long as the account is active; upon deletion, they may be anonymised and preserved as community content.
- Technical logs: 30 days.
- Push tokens: removed on sign-out or uninstall.
- Cookies: maximum lifetime of 13 months (consent preferences and functional cookies).
- Newsletter data: until unsubscription, then erased within 30 days.
- Accounting data (where applicable): 10 years, as per legal obligations.
Cookies and trackers
The website uses technical, analytics and advertising cookies. Non-essential cookies are only set after your consent is collected via the consent banner compliant with the IAB TCF 2.2 standard. You can change your choices at any time from the "Manage my cookies" link in the footer. Detailed categories, purposes, durations and partners are provided in the Cookie Policy.
The mobile application does not currently set advertising cookies. Should advertising or analytics be added to the app, an equivalent consent mechanism will be implemented (App Tracking Transparency on iOS, dedicated consent screen on Android) and this policy will be updated accordingly.
What we do NOT do
- We do not sell personal data to third parties.
- We do not perform cross-app advertising tracking in the mobile app today (no IDFA, no App Tracking Transparency).
- We do not perform profiling with legal or significant effects on you.
- We do not take fully automated decisions based on your data.
Your rights (GDPR)
Under Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act, you have the following rights at any time: access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and post-mortem instructions.
- Edit your information from Settings → My information.
- Delete your account from Settings → Delete my account (effective within 30 days).
- Withdraw your cookie consent via the "Manage my cookies" link in the footer.
- Unsubscribe from the newsletter via the link in each e-mail.
- Write to [email protected] for any other request.
- Lodge a complaint with the CNIL (cnil.fr) if you believe your rights are not respected.
Security
All exchanges with the site and API are encrypted over HTTPS/TLS. Passwords are hashed (bcrypt). Mobile authentication tokens are stored in the OS secure keystore. Database access is restricted and logged. In case of a personal data breach that may pose a risk to your rights, we will notify the CNIL and, where required, the individuals concerned, within the timeframes set by the GDPR.
Children
The service is intended for people aged 15 or over. We do not knowingly collect data about children under 15. If you believe a child has provided us with data without parental authorisation, please contact us and we will delete it.
Changes to this policy
Any substantial change to this policy will be notified on the site and in the app. The last update date appears at the top of this document.
Related documents
This policy is to be read alongside the Terms of Use and the Cookie Policy.