CrewBag

Privacy & GDPR

Last updated 28 August 2026 · Contact: gdpr@crewbag.app

CrewBag is built by a working airline pilot on a simple rule: your data is yours, we keep as little of it as possible, and you can see and delete everything. Everything we run is hosted in the EU.

This website

Your account

The app

Usage signals

Who processes what

If something goes wrong — breach protocol

If we ever suffer a personal-data breach, we commit to:

Report a suspected breach or vulnerability: security@crewbag.app. We answer fast and we don't shoot messengers.

What survives deletion

Three things, by design and legal obligation: the security audit trail (who created/deleted an account, sign-ins with IP address, consent changes — kept 2 years, containing only your email and the event); your handle, retired forever so nobody can impersonate you after you leave; and — only if you asked us to build or curate an airline setup — the record of that contribution (your account, the setup, the dates of our checks), kept for the defence of legal claims (GDPR Art. 17(3)). Nothing beyond the provenance itself. Sign-in IPs are stored for account security; we never store or derive your location.

Your rights

Access, rectification, erasure, restriction, portability, objection — GDPR Arts. 15–21. Most are self-service on your account page; for anything else, gdpr@crewbag.app, answered within 30 days. You may also complain to your national data-protection authority.