Privacy Policy
This Privacy Policy explains how we process your personal data in accordance with the EU General Data Protection Regulation (GDPR).
Effective: 2025-10-01
Controller
Trade:Aero - a project by Dross:Media. Owner: Alexander Dross. Address on request (stated on issued invoices). Email: info@trade.aero
Scope
This policy applies to the website, marketplace features, and communication channels offered by Trade:Aero. It covers users, sellers, and visitors.
Data Protection Contact
You can contact our privacy team at privacy@trade.aero regarding any data protection questions or requests.
Data We Collect
- Account data (e.g., name, email, password hash, role).
- Usage data (e.g., pages viewed, searches, bookmarks, device/rough location if enabled).
- Cookies and similar technologies for essential functions, preferences and analytics.
- Communication data (support requests, messages, email preferences).
Where We Obtain Data
We collect data directly from you, from your use of the service (device and usage data), and in some cases from third parties where lawful (e.g., anti-fraud providers).
External Aircraft Listings & Claim Invites
We re-publish publicly-available aircraft-for-sale ads from third-party aviation classifieds on trade.aero, with attribution + a link back to the original ad. When a seller's public contact email appears on such an ad, we may send one (and only one) email from invites@aircraftinvites.com inviting the owner to claim the listing and run it natively on trade.aero at no cost. Legal basis: legitimate interest under GDPR Art. 6(1)(f) + UWG §7 (public seller, narrowly-relevant offer, documented balancing test on file). Every invite carries a one-click List-Unsubscribe header (RFC 2369/8058); unsubscribed addresses are permanently added to our suppression list and never re-contacted. We do not send follow-ups. You can opt out anytime by clicking the unsubscribe link in the email, or by writing to unsubscribe@aircraftinvites.com.
Right to Object
You have an unconditional right to object to this processing under GDPR Art. 21. Sending any email to unsubscribe@aircraftinvites.com or clicking the one-click unsubscribe link in any invite email fulfils that right immediately.
Purposes of Processing
- To provide and operate the marketplace and related features.
- To ensure security, prevent abuse and detect fraud.
- To respond to requests and send service-related notifications.
- To send optional marketing communications where permitted.
- To analyze usage and improve our services.
Legal Bases
GDPR Art. 6(1)(b) contract performance, Art. 6(1)(f) legitimate interests (security, improvement), and Art. 6(1)(a) consent (marketing, non-essential cookies).
Storage and Retention
We store personal data only as long as necessary for the purposes above or as required by law. Specific retention periods are: account profile data - for the lifetime of your account plus 30 days after account deletion (then anonymised); active listings - until you remove them or 90 days after they expire (then archived for an additional 30 days, then anonymised); transactional records (payments, invoices) - 10 years per German § 147 AO and § 257 HGB; email notifications and admin activity logs - 24 months; newsletter subscribers - until unsubscription plus a 30-day grace window; backups - rolling 30-day window; web server access logs - 14 days.
Recipients of Personal Data
We disclose data only to recipients necessary for the purposes described (e.g., hosting, analytics, email providers, payment and security providers) and only under appropriate safeguards.
Your GDPR Rights
- Right of access to your personal data.
- Right to rectification of inaccurate data.
- Right to erasure (‘right to be forgotten’).
- Right to restriction of processing.
- Right to data portability.
- Right to object to processing based on legitimate interests or direct marketing.
- Right to lodge a complaint with a supervisory authority.
How to Exercise Your Rights
Submit a request to privacy@trade.aero. We may need to verify your identity. We respond without undue delay and within statutory deadlines.
Cookies
We use essential cookies to operate the site and, with your consent, analytics cookies. You can manage preferences via your browser and in-product settings.
- Essential cookies for core functionality (authentication, security, preferences).
- Analytics cookies to measure usage and improve features (only with consent).
- Marketing cookies for personalized content (only with consent).
- Preference cookies to remember settings such as language and locale.
Analytics
We use privacy-friendly analytics to understand feature usage and improve performance. IP addresses may be shortened or anonymized where possible.
Processors and Recipients
We engage service providers under data processing agreements in compliance with Art. 28 GDPR.
The specific providers we use are: Supabase (database, authentication, file storage), Vercel (website hosting, content delivery), Cloudflare (CDN, DDoS protection, Turnstile CAPTCHA), Stripe (payment processing), AWS Simple Email Service (transactional and newsletter email), Anthropic (AI translation of listing content), ipapi (IP-based country detection), European Central Bank / Frankfurter API (exchange rate data), and CARTO + OpenStreetMap (map tile rendering). Each provider is described in detail in the next section.
International Transfers
Where data is transferred outside the EEA, we rely on adequacy decisions or Standard Contractual Clauses and take additional safeguards where necessary.
Third-Party Service Providers
We use the following third-party service providers to operate our platform:
- Supabase Inc. (USA) - Database hosting, authentication, and file storage. Data is processed on servers in the EU (Frankfurt). Privacy policy: https://supabase.com/privacy
- Anthropic PBC (USA) - AI-powered translation of listing content (headlines, descriptions, image alt texts) into multiple languages. Your listing text is sent to Anthropic's Claude API for translation. Privacy policy: https://www.anthropic.com/privacy
- Stripe Inc. (USA) - Payment processing for checkout, subscriptions, and billing management. Stripe processes your payment information (card details, billing address) directly and acts as an independent controller for payment fraud prevention. Privacy policy: https://stripe.com/privacy
- Vercel Inc. (USA) - Website hosting and content delivery. All web requests are routed through Vercel's infrastructure. Privacy policy: https://vercel.com/legal/privacy-policy
- Cloudflare Inc. (USA) - CDN, DNS, DDoS protection, web analytics, and Turnstile CAPTCHA for bot protection. Your IP address, browser information, and request metadata are processed for content delivery, security verification, and performance analytics. Privacy policy: https://www.cloudflare.com/privacypolicy/
- ipapi (Germany) - IP-based geolocation for country detection. Your IP address is sent to determine your approximate location for default country settings. Only used with your consent (functional cookies).
- CARTO (OSM-derived basemap CDN) - Map tile rendering for location pages. Your IP address and map interactions are sent to CARTO + OpenStreetMap servers when the map loads. No cookies are set. Privacy policies: https://carto.com/privacy + https://wiki.osmfoundation.org/wiki/Privacy_Policy
- European Central Bank / Frankfurter API - Exchange rate data. No personal data is transmitted.
Data Security
We implement technical and organizational measures including encryption in transit, access controls, least-privilege principles, and regular reviews of our security posture.
Automated Decision-Making
We do not engage in automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR.
Children’s Data
Our services are not directed to children under 16. If you believe we have collected data from a minor, contact us to request deletion.
Contact
For privacy inquiries or to exercise your rights, contact privacy@trade.aero.
Changes to This Policy
We may update this policy from time to time. Material changes will be communicated through the service and will indicate a new effective date.
