Privacy Policy
Last updated: July 9, 2026
1. Who We Are
VATWatch is operated by FS-Dev | A Firestorm Company, Cleveland, Texas. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.
2. Data We Collect
We collect the minimum data necessary to provide the Service:
Account Data (via VATSIM OAuth)
When you sign in with VATSIM, we receive and store your VATSIM CID (Certificate ID), name, and email address. We do not receive or store your VATSIM password.
Flight Plan Data
When you use Route Watch, we import your active flight plan from the VATSIM data feed (departure, arrival, route string) to determine which ARTCC/center regions are relevant to your flight.
Discord Webhook URLs
If you configure Discord notifications, we store the webhook URL you provide in order to deliver alerts to your Discord server or channel.
Push Notification Subscriptions
If you enable browser push notifications, we store your Web Push subscription endpoint and keys to deliver push alerts to your device.
Billing Data
Payment information (card numbers, billing addresses) is collected and processed entirely by Stripe. We store only your Stripe customer ID and subscription status — never your payment details.
3. How We Use Your Data
Your data is used solely to operate and deliver the Service:
- To authenticate your identity via VATSIM OAuth.
- To monitor relevant ARTCC/center regions based on your selected regions or active flight plan.
- To deliver ATC alerts via push notifications and Discord webhooks.
- To manage your subscription and billing through Stripe.
We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.
4. Third-Party Services
The Service relies on the following third-party providers:
- Cloudflare — Infrastructure provider. VATWatch is deployed on Cloudflare Workers. Cloudflare may process request metadata (IP addresses, request headers) as part of normal infrastructure operation. See Cloudflare's Privacy Policy.
- Stripe — Payment processing. Stripe handles all payment card data. See Stripe's Privacy Policy.
- Neon — Database hosting. Your account and alert data is stored in a Neon-hosted PostgreSQL database.
- VATSIM — Authentication provider. We use VATSIM OAuth for sign-in and pull publicly available data from the VATSIM data feed.
5. Data Retention
We retain your account data for as long as your account is active. Alert history is retained according to your subscription tier (last 5 alerts for Free, full history for paid plans). When you delete your account, all associated data — including your VATSIM profile information, alert history, watch configurations, Discord webhook URLs, and push notification subscriptions — is permanently deleted from our database.
6. Data Deletion
You can request deletion of all your data at any time by using the Delete Account option on the account settings page. This action is immediate and irreversible. All your data will be permanently removed from our systems.
7. Cookies & Local Storage
VATWatch uses a session cookie to keep you signed in. We do not use tracking cookies, analytics cookies, or advertising cookies. Push notification subscription data is stored in your browser's local storage.
8. Children's Privacy
VATWatch is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, please contact us so we can delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this page. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy.
10. Contact
If you have questions about this Privacy Policy or your data, contact FS-Dev | A Firestorm Company, Cleveland, Texas.