
Privacy Policy
Page version: 2026-09-22
1. Controller
Enes Yakup Krughöfer, NorthTrack General Aviation, Rotdornschleife 23, 59063 Hamm, Germany. Email: info@northtrackaviation.com.
2. Scope
This Policy covers the NorthTrack General Aviation Main App, the NorthTrack Procedure Trainer, northtrackaviation.com and the associated account, support, Community and cloud functions. The data processed depends on the functions you actually use.
3. Legal bases
Where necessary to provide the core functions you have booked (account, flight planning, checklists and logbook), we process your data under Article 6(1)(b) GDPR. Optional Community and sharing functions with individually configurable visibility are based on your consent under Article 6(1)(a) GDPR, which you can withdraw at any time for the future. Security, misuse prevention and moderation are based on our legitimate interest under Article 6(1)(f) GDPR in a secure and functional service. Processing required by law, for example tax retention duties, is based on Article 6(1)(c) GDPR.
4. Account
Email address, user ID, verification status, display name, authentication provider, settings and voluntary profile information are processed to provide, authenticate and synchronise your account.
5. Flight and planning data
Aircraft profiles, checklists, flight plans, routes, weight-and-balance calculations, fuel/performance data, logbook entries, tracks and associated time, speed, altitude and location data are processed for the functions you use.
6. Location
Your location data may be used for tracking, map/navigation functions, weather/radar and relevant Community functions. Granting location access does not automatically mean that a permanent track is stored.
7. Learning content
Your progress in quiz, exercise, maintenance, Walkaround, Aircraft Basics, Aviation English and ATIS functions may be stored.
8. Procedure Trainer
Your local settings and history data are retained for up to 20 detailed sessions and up to 200 compact history entries. Training reset and complete local reset are separate functions. Procedure Trainer is not an approved FSTD/FNPT and does not provide creditable flight-training time.
9. Microphone and speech recognition
Speech functions access the microphone and Apple speech recognition only after you deliberately start them and grant system permission. Current recognition is not configured as exclusively on-device; depending on the Apple device, language and system state, Apple may process the audio required for recognition on its servers. NorthTrack does not retain raw microphone audio as a permanent user file. The app may store the recognised or entered text of an exercise transmission locally for that scenario until the scenario is reset or private local state is cleared on sign-out.
10. Community
Connections, blocks, invitations, content you expressly share, groups, Community content and messages are processed according to your use. “Privacy by Default” and “Connections-first” apply: content is not automatically made public and is shared only after your express action.
11. Messages and moderation
New normal direct and group messages created under the current retention schema receive an expiry of no more than 30 days and are selected for deletion after expiry by a bounded server process. Messages under a moderation hold are excluded. No universal automatic 30-day deletion is proved for older or unmarked messages. Reports, moderation evidence and resulting measures are handled separately.
12. Minors
NorthTrack Main as a whole is intended for persons aged 16 or older. All interpersonal Community, directory and sharing functions are currently designed as an 18+ area. Private non-social Main functions and required privacy/security actions remain available to users aged 16 or 17. For this purpose NorthTrack processes only a coarse age band (16-17 or 18+), its provenance and confirmation time after an explicit user action; the band may be self-declared or shared through Apple's Declared Age Range. NorthTrack stores no date of birth, identity document or biometric age characteristic in this flow. This is not official identity or age verification. If paid subscriptions are activated later, a purchase by a 16- or 17-year-old requires the consent of their legal representatives.
13. Push notifications
Where push notifications are enabled, device or push tokens can be processed for delivery. You can disable push at any time.
14. Firebase/Google Cloud
NorthTrack uses Google/Firebase for email/password Authentication, Firestore, Cloud Storage, Cloud Functions/Cloud Run and Firebase Cloud Messaging. Depending on the function, data is processed in europe-west1, europe-west3 or us-central1; Google also processes technically necessary operational, security and audit logs. Firebase Analytics and Crashlytics are not active products in the current Main App, and Firebase Performance collection is not enabled in the release configuration. SDK/platform diagnostics and operational cloud logs remain distinct.
15. Weather, radar, maps and aviation data
Depending on the function, NorthTrack uses separate sources and processing paths:
Apple Weather/WeatherKit provides general forecast context for one explicitly selected aerodrome or coordinate through a NorthTrack server function. Apple receives the resolved coordinate and technically the server IP, not the Firebase user ID. Apple Weather is not a METAR/TAF observation or official aviation-weather briefing.
Open-Meteo Commercial supplies model fields to the signed-in wind/model-weather path through an authenticated NorthTrack server function. The NorthTrack function receives the requested flight altitude; Open-Meteo receives the target coordinate rounded to four decimal places for the provider and shared cache, model, variables and time window, but neither the altitude nor the Firebase user ID. NorthTrack interpolates the requested altitude from returned model levels. The Firebase user ID is not included in the provider payload. The shared cache is fresh for 30 minutes; eligible objects have a seven-day deletion target and the technical bucket lifecycle deletes after eight days.
AviationWeather.gov/NOAA/NWS supplies explicitly requested METAR/TAF products using station/product parameters; OurAirports is used server-side to resolve aerodromes, runways, frequencies and navaids.
The DWD RV radar path requests layer Radar_rv_product_1x1km_ger directly from WMS endpoint https://maps.dwd.de/geoserver/dwd/wms. The request contains product, viewport, image size and data/reference time; DWD technically receives the device IP. The WMS capabilities response is held for no more than five minutes and the bounded image cache holds at most six frames; there is no persistent radar/offline cache. DWD ICON-EU model fields may be obtained through the separate commercial Open-Meteo model-weather path; this is not a direct DWD Open Data request by the current Main App.
Online standard map tiles are requested directly from OpenStreetMap/OSMF with tile identity, a NorthTrack user agent and ordinary network metadata. Downloadable offline vector maps are separate locally rendered derivatives from OSM/Geofabrik data using an OpenMapTiles-compatible schema.
The current Main App uses the admitted offline architecture with 143 complete map regions, locally installed terrain/elevation products derived from Copernicus DEM GLO-30 and 77 admitted OpenAIP packages. Installed OpenAIP packages are used locally for aerodromes, runways, frequencies, navaids and airspaces and do not send a location-bearing map-use request to OpenAIP. OpenAIP is not an official aviation authority.
The current app downloads admitted map/OpenAIP packages from Firebase Storage. The packages contain no account-linked user data; Firebase receives ordinary network and object-request metadata during delivery. Backblaze B2 is documented only in historical publication receipts as a technical release archive and is not a direct mobile runtime recipient in this download path.
Depending on the feature, coordinate, region, viewport, aerodrome/station identifier, route, forecast time, altitude or product parameters may reach the stated NorthTrack function or source. NorthTrack shows source, time, freshness, cache/offline state and required attribution on relevant surfaces and under “Data Sources & Licences”. Model forecasts are not observations; missing or stale values are not represented as favourable weather or calm wind.
16. Website/Wix
The website is operated on Wix. Based on current documentation, the contact form processes email address and message; first and last name are optional. Entries may be stored in Wix Forms, certain contact data in Wix Contacts and a sent request in the receiving email system. A contact request does not automatically subscribe you to marketing messages.
17. Cookies and device storage
The cookies, tags and comparable technologies actually used by the website depend on the published Wix configuration and enabled services.
18. Diagnostics and security
For service stability and security, error and performance signals, network and loading times, device and installation data and security/misuse signals may be processed. This data is not used for personalised advertising.
19. Retention
Private account, profile, flight, planning, aircraft, checklist, logbook, track and learning information generally remains until feature deletion, the relevant reset or account deletion, except where shared records require separate treatment. Messages follow the limited rule in section 11. Device/push identifiers are processed until deregistration, identifier change, revocation or account deletion. Export archives use a 15-minute download link and are scheduled for server deletion no later than 24 hours. Local Procedure Trainer history is bounded as described in section 8. Public offline packages remain until expiry, update or manual removal. Statutory duties and provider-controlled backup, security and log cycles remain unaffected.
20. Recipients
Depending on the function used, Google/Firebase, Apple, Wix, the weather, map and aviation-data providers listed in section 15 and NorthTrack users expressly chosen by you may receive your data. Community users receive data only through the sharing function you select.
21. International transfers
Google, Apple, Wix and certain data providers may process data outside the European Union and European Economic Area depending on the service and infrastructure. The final provider register must identify the applicable entity, role, region and safeguard under Articles 44 et seq. GDPR for each service. A copy of the applicable safeguard can be requested through the contact address.
22. Data export and access
Through “Your Data”, signed-in users can request an export of their published NorthTrack cloud account corpus after recent re-authentication. It covers the user's tree and defined account-related records under full, redacted or metadata-only rules and, where present, JSON/account data, logbook CSV and tracks as GeoJSON/GPX. Secrets and other people's data are protected, redacted or omitted. The signed link lasts 15 minutes and the export object is scheduled for deletion no later than 24 hours. Local-only/unsynchronised state, device caches, the separate local Procedure Trainer corpus, external support email, provider/platform logs and recipient-controlled copies are outside this cloud export. On request, NorthTrack additionally provides the information legally required for access under Article 15 GDPR.
23. Account deletion
Account deletion, sign-out, learning reset and cancellation of an Apple subscription are separate actions. Account deletion is phased and resumable; the Firebase Authentication identity is removed only after prior phases succeed. Private data and named Storage prefixes are deleted. Shared message, group, share, ledger or moderation records may be deleted, left content-free, detached from your account or pseudonymised to protect other participants, shared-object integrity or a lawful evidence need. Local data in the separate Procedure Trainer container, provider backups/logs, external support email and recipient-controlled copies are not removed by Main cloud deletion. Deleting the NorthTrack account does not cancel an active Apple subscription.
24. Your rights
Subject to the statutory requirements, you have rights of access (Article 15 GDPR), correction (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), objection (Article 21) and withdrawal of consent for the future. Contact privacy@northtrackaviation.com.
25. Right to complain
You have the right to complain to a data-protection supervisory authority, in particular the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, which is competent for our establishment.
26. Changes to this Policy
This Policy may be amended when our functions, processing, service providers or legal requirements change. Each published version carries a date.

