Back to haverlog

How haverlog handles personal data

Last updated: 8 August 2026. This notice explains what Haverlog collects, why it is used, where it goes, how long it is kept, and the choices available to you.

Controller details to complete before launch

Registered office: [REGISTERED OFFICE ADDRESS]
Luxembourg Trade and Companies Register number: [RCS NUMBER]

Controller and contact

Haverlog S.à r.l.-S. is the controller responsible for the processing described in this notice. Its registered office and Luxembourg Trade and Companies Register number will be inserted in the fields above before launch.

For privacy questions or to exercise a data-protection right, email [email protected] or use the Contact form and choose Account help. Haverlog has not appointed a data protection officer. Privacy requests are handled through the contact details above.

Personal data we process

  • Account and profile: email address, password credential managed by Supabase, name, username, avatar, home airport, account dates, age-eligibility confirmation, loyalty status, visibility settings, and authentication information.
  • Flight journal: dates, routes, times, durations, flight numbers, airlines, aircraft, registrations, seats, cabin, travel reason, notes, delays, fares, booking classes, import source, and booking relationships.
  • Bookings and mileage: booking titles, ticket-number prefixes, currency and fare information, uploaded booking PDFs, manual points entries, and Miles & More calculations.
  • Social activity: friend requests, friendships, profile visibility, and the journal information you choose to make visible to friends or other users.
  • Contact requests: name, email, request type, message, reply choice, attachments, and limited logged-in account context needed to investigate the request.
  • Technical information: IP address, session identifiers, authentication cookies, browser and request metadata, security events, and map-tile requests.
  • Generated information: maps, routes, statistics, achievements, mileage estimates, and other summaries calculated from journal entries.

Please do not place sensitive personal information, unnecessary information about another person, or confidential documents in notes, contact messages, or uploads.

Purposes and legal bases

Provide the Haverlog service
Account creation, authentication, journal storage, maps, bookings, calculations, exports, privacy controls, and social features are processed to perform the service requested by you under Article 6(1)(b) GDPR.
Keep the service secure
Request data, IP addresses, authentication events, and limited logs are processed under Article 6(1)(f) GDPR. Haverlog's legitimate interests are preventing abuse, protecting accounts, diagnosing faults, and maintaining reliable infrastructure.
Handle contact requests
Service and account requests are processed under Article 6(1)(b) GDPR. Other questions, feedback, and bug reports are processed under Article 6(1)(f) GDPR, based on Haverlog's legitimate interest in responding and improving the service.
Meet legal obligations
Information may be processed where required by law under Article 6(1)(c) GDPR, or where necessary to establish, exercise, or defend legal claims under Article 6(1)(f) GDPR.

Haverlog does not currently use consent as the legal basis for necessary account or journal processing, and it does not use personal data for targeted advertising.

Visibility and sharing with other users

Your journal is private by default. Profile and social privacy settings determine whether maps, flights, achievements, mileage information, friend counts, and friend lists are visible only to you, to accepted friends, or more broadly where that option is offered. Your username, name, and avatar may be shown where needed for search, friend requests, and accepted social connections.

Review these controls in Settings before sharing. Removing a friendship or changing a visibility setting limits future access through Haverlog, but it cannot recall copies another person may already have made.

Service providers and recipients

  • Cloudflare, Inc. provides DNS, traffic proxying, TLS, caching, and security. It receives IP addresses and request information before traffic reaches Haverlog.
  • Haverlog-controlled infrastructure runs the application origin on privately controlled hardware physically located in Luxembourg.
  • Supabase provides authentication, the database, and file storage. Haverlog's project data region is AWS eu-west-1 in Ireland.
  • Proton AG provides email delivery and mailbox services for account and contact communications.
  • CARTO and Esri provide map tiles. They receive tile coordinates and normal network request information such as IP address and browser metadata. Haverlog draws journal routes separately in the browser and does not send the flight journal itself as map-tile content.
  • Other users receive information only as directed by Haverlog's social and visibility controls. Authorities or professional advisers may receive information where required by law or necessary for legal claims.

Current provider information is available from Cloudflare, Supabase, Proton, CARTO, and Esri.

International transfers

The main Supabase project region and Haverlog origin are in the European Economic Area. Cloudflare's global network and some provider group companies or subprocessors may process information outside the EEA. Proton's email infrastructure may process data in Switzerland, which is covered by an EU adequacy decision. CARTO and Esri are based in the United States.

Where an adequacy decision does not apply, Haverlog relies on provider data-processing terms incorporating approved safeguards such as the European Commission's Standard Contractual Clauses. Some providers also participate in the EU-US Data Privacy Framework. Contact Haverlog to request more information about applicable safeguards.

Retention and deletion

Active accounts
Account, journal, booking, mileage, social, avatar, and uploaded booking-document data are kept while the account remains active or until the user deletes the relevant information.
Inactive accounts
An account is inactive after five years without a successful login. Haverlog will send warning emails approximately 60 and 30 days before deletion. A successful login cancels the pending deletion. If no login occurs, the account and its primary data are deleted after the five-year period.
User-requested deletion
The Delete account control removes the authentication account, primary database records, avatar files, and booking documents. Residual encrypted backup copies are removed when they are overwritten under the applicable provider's rolling backup lifecycle.
Contact requests
Contact messages, email correspondence, and attachments are retained for 12 months after the inquiry is resolved, then deleted unless a longer period is required for an ongoing dispute or legal obligation.
Security and provider logs
The contact form's in-application IP rate-limit record expires after 10 minutes. Provider and infrastructure security logs are retained only for the configured operational or security period, then deleted or aggregated according to the applicable service configuration.

Limited information may be retained longer where required by law or strictly necessary to establish, exercise, or defend a legal claim. Access is restricted for that period.

Cookies and local storage

Haverlog uses Supabase authentication cookies and related session identifiers so users can sign in, remain signed in, and access protected pages. These are necessary for the service and are removed or cease to be usable when the user signs out, deletes the account, clears browser data, or the authentication session otherwise ends.

The browser stores the key haverlog-theme to remember the chosen light or dark appearance. It remains until the preference is replaced or browser data is cleared.

Haverlog does not currently use analytics, advertising, heatmap, marketing, or cross-site tracking technologies. If non-essential browser storage is introduced, Haverlog will request any consent required before using it.

Required and optional information

An email address, password, name, and confirmation that the user is at least 16 are required to create an account. Without them, Haverlog cannot create or secure the account. Flight details marked as required are needed to create a journal entry. Other profile, flight, booking, mileage, social, and document information is optional.

The contact form requires a name, email address, and message so the request can be understood and managed. Attachments and the request to receive an emailed reply are optional.

Automated calculations

Haverlog automatically calculates maps, statistics, achievements, delay summaries, and mileage estimates from journal information. These features are informational. Haverlog does not make decisions based solely on automated processing that produce legal or similarly significant effects concerning users.

Age requirement

Haverlog is intended for people aged 16 or older. Users must confirm that they meet this requirement when creating an account. Haverlog does not intentionally collect account data from children under 16. If you believe a person under 16 has created an account, contact Haverlog so the account can be investigated and, where appropriate, deleted.

Your rights

Subject to the conditions in the GDPR, you may request access to your personal data, correction, deletion, restriction, portability, or object to processing based on legitimate interests. If Haverlog later relies on consent for an optional feature, you may withdraw that consent at any time without affecting earlier lawful processing.

Haverlog will normally respond within one month. It may ask for information reasonably necessary to confirm identity and protect the account. You may also lodge a complaint with Luxembourg's supervisory authority, the Commission nationale pour la protection des données (CNPD).

Security and changes to this notice

Haverlog uses access controls, private storage for booking documents, short-lived signed download links, encrypted transport, account authentication, and database access rules intended to protect personal data. No internet service can guarantee absolute security.

This notice will be updated when processing, providers, retention practices, or legal requirements materially change. The date at the top identifies the current version. Where a change materially affects users, Haverlog will provide an appropriate notice.