KFRG · Republic Airport · Farmingdale, NY AOG929-286-7954

AeroLuxe Privacy Policy

Effective September 22, 2026.

Operator: AeroLuxe LLC, doing business as AeroLuxe ("AeroLuxe," "we," "us").

Privacy contact: privacy@aeroluxesupport.com.

1. Scope and responsibility

This Policy describes personal information handled through aeroluxesupport.com, its service-request forms and related inquiry communications, and the AeroLuxe Command maintenance workspace and client portal. Command-specific practices apply only when you use that application; simply browsing our public website does not create a Command account. It does not cover unrelated websites or a provider's separate services. Aircraft and business records may contain personal information, including owner names, technician names and certificate references.

The operator administers this Service. If your employer, aircraft operator or another organization provides your workspace, that organization determines which records to enter, who may access them and why they are used. Its own privacy notices and any agreement with AeroLuxe may also apply. Contact your workspace administrator about organization-managed records, or use the privacy contact above for assistance identifying the responsible organization.

2. Information handled

Information may come from you, your organization, authorized users, public lookup sources or technical interactions with the Service.

3. How information is used

We use website inquiry information to respond to requests, contact you about the requested services, assess scope and availability, coordinate scheduling, keep a record of communications and protect the forms against abuse. A form submission is an inquiry, not a confirmed booking.

We use Command information to provide the workspace and client portal; authenticate and authorize access; organize records and documents; calculate entered-data status and alerts; retrieve requested public information; display aircraft images; prepare reports and exports; maintain change history; create and verify backups; investigate faults or suspected misuse; and respond to support, privacy and legal requests.

The current website and Command code do not include advertising pixels or marketing analytics. Command does not include an automated connection that sends maintenance records to a generative-AI model. Hosting the app on an OpenAI service does not mean this Policy controls OpenAI's independent account or platform processing.

4. Who may receive information

The website and Command do not implement the sale of personal information or cross-context behavioral advertising.

5. Cookies and browser storage

The public website code does not set tracking cookies. Its interactive demonstrations keep their working state in the current page. Hosting and font providers may process technical requests under their own practices.

Command uses the aeroluxe_session cookie to maintain an authenticated session. Its maximum age is eight hours; app access expires sooner after 30 minutes of inactivity or when the underlying access is disabled or expires. Browser session storage remembers link-access state and temporary safety-alert acknowledgments. These functions support access and workflow behavior, not advertising. Platform sign-in and external providers may use their own cookies under their policies.

You can clear cookies and browser storage or block them using browser controls. Doing so may sign you out or prevent the Service from working. Acknowledgment storage does not clear maintenance issues. The app does not implement a separate response to a browser "Do Not Track" signal.

6. Retention, backups and removal

Website inquiries and correspondence may remain in Netlify form records, our email system and business records while needed to respond, coordinate requested services, meet applicable obligations or handle a dispute. Removing an email does not necessarily remove the form-provider copy, and clearing your browser does not delete a submission. Contact us for a retention or deletion review; this Policy does not promise a fixed automatic purge period for those systems.

Command retains operational records, documents and audit history until they are addressed through an authorized administrative process. Command does not have a general automatic purge schedule for those records or its stored backups. Backups may be created manually or before the first eligible write on a day; an automatic backup is not a guarantee of continuous backup coverage.

Account deactivation, link expiry and report withdrawal restrict access but do not necessarily erase underlying information. Copies may remain in audit history, backups, exported files or another recipient's possession. Administrators must consider legitimate operational needs, legal recordkeeping requirements, disputes and security needs when deciding retention. This Policy does not promise immediate deletion or a fixed deletion period that the Service does not implement.

Contact the privacy contact to request a retention explanation or removal review. We will coordinate with the responsible organization, explain applicable restrictions and honor legal obligations. Provider logs and platform account information are governed by the relevant provider's retention arrangements.

7. Security and processing locations

The Service uses access controls, session protections, passphrase hashing, restricted document access and activity history. No system, transmission or backup is completely secure. Protect your devices, accounts, private links and exported copies, and report suspected unauthorized access promptly.

Service providers may process information outside your state or country. No particular storage location or data-residency guarantee is made by this Policy. Any required regional processing terms or international-transfer arrangements must be confirmed for your organization before relying on the Service for that requirement.

8. Your choices and requests

Depending on your location, applicable law and the organization's role, you may have rights to access, correct, obtain a copy of, delete or restrict use of personal information, object to certain processing, opt out of a sale of personal information, targeted advertising or qualifying automated profiling where applicable, withdraw consent where processing relies on consent, or complain to a privacy regulator. These rights are not unlimited and do not automatically authorize changes to regulated maintenance records or another person's information.

Send requests to privacy@aeroluxesupport.com. Describe the request and your relationship to the workspace; do not send a password or private access token. We may need proportionate verification of identity and authority and may refer organization-controlled requests to the workspace operator. We will respond within the time required by applicable law and explain applicable exceptions. If you disagree with a response, email the same address with the subject "Privacy request appeal" and explain the decision you want reviewed. We will review the appeal and respond within the period required by applicable law. You may also contact the New Jersey Division of Consumer Affairs or another competent privacy regulator. We will not unlawfully discriminate against you for exercising applicable privacy rights.

9. Children

The Service is intended for authorized adult professional users, not children. Do not create an account for a child or submit children's personal information. If you believe a child has provided personal information, contact us so the responsible operator can investigate and take appropriate action.

10. Changes and contact

We will update the effective date when this Policy changes and provide notice of material changes through the Service or an available contact channel. Where required, we will obtain consent for a new use. For questions about privacy, security concerns or this Policy, contact AeroLuxe LLC at privacy@aeroluxesupport.com.