Privacy Policy · Updated 6 August 2026

Privacy in the operating record.

This policy explains the personal and operational information Taltrax processes, why it is used, where it is held, and the choices available to operators and pilots.

Taltrax is operated by [entity name pending registration], an Australian business. ABN: pending. Contact:support@taltrax.com. This information will be updated when the ABN is issued.

1. Our role

The operator controls the operational records it enters into Taltrax. For that operator data, the operator is the controller and Taltrax acts as its processor. Taltrax separately controls account, support, security, billing, and service-operation information needed to provide and protect the service.

2. Information we collect

  • Account and profile details, including name, email, phone, licence or ARN details, emergency-contact details, preferences, and authentication identifiers.
  • Operator details, memberships, aircraft, maintenance, flight and duty records, work orders, documents, checklists, registers, rosters, certifications, safety reports, feedback, and related audit history.
  • Files you choose to upload, such as job paperwork, reference documents, safety attachments, and certification evidence.
  • Billing and transaction references supplied by Stripe. Taltrax does not store full payment-card details.
  • Security, delivery, support, and diagnostic records needed to operate the service and investigate failures or misuse.
  • Contact-page details: name, company, email, phone, current system, message, consent, and the result of a Cloudflare Turnstile security check.

3. Why we use it

We process information to:

  • provide the Taltrax record-keeping and visibility functions;
  • authenticate users and enforce operator permissions;
  • store, retrieve, export, and protect operator and pilot records;
  • deliver support, service messages, and requested demos;
  • process test-mode billing workflows and later approved subscription services;
  • detect misuse, preserve integrity, respond to incidents, and meet legal duties; and
  • improve the product from direct feedback without active product analytics.

4. Hosting, subprocessors, and cross-border processing

Core database data, private file storage, and backups are hosted with Supabase in Sydney, Australia. Other service providers (Vercel, Stripe, Resend, Cloudflare, and OpenAI) may process data outside Australia, including in the United States, as part of their global infrastructure. Current service providers are:

  • Supabase — database, authentication, storage, and Edge Functions;
  • Vercel — web and marketing-site delivery;
  • Resend — transactional and support email delivery;
  • Stripe — test-mode billing and payment interfaces;
  • Cloudflare Turnstile — abuse prevention on public forms; and
  • OpenAI — checklist text processing only when the optional AI draft feature is enabled. Only extracted checklist text is sent. The API is called without requesting response storage; a formal zero-data-retention agreement has not yet been executed. PDFs, flight records, and pilot personal information are not intentionally sent.

The providers above may use global processing infrastructure as described in their service terms. PostHog is deferred and not enabled; it is not a current transfer. Plausible, Sentry, and third-party uptime analytics are also not active.

5. Cookies and analytics

Taltrax does not currently set marketing or analytics cookies and does not send product-analytics events. Essential browser storage and security technologies may be used for authentication, preferences, offline work, and Turnstile verification. If analytics is enabled later, this policy and the cookie notice must be updated before that collection starts.

6. Retention and deletion

Operational and audit records are retained while the operator account exists unless a shorter legal or contractual rule applies. User-facing deletion generally uses soft-delete so integrity and audit history are preserved. Soft-deleted file content is scheduled for purge after 30 days. An operator deletion request has a 30-day cancellable, read-only grace period before the controlled deletion process runs.

Personal certification files and global pilot profile data are not automatically destroyed merely because one operator relationship ends. A pilot is prompted to export their data before deactivation.

7. Access, correction, and export

Users can correct available profile and operational details through Taltrax, subject to role and audit controls. Active pilots can export their own in-scope records. A deactivated pilot may request a pilot-scoped export throughsupport@taltrax.com. Taltrax verifies control of the account email, checks any legal hold, records a redacted request reference, and delivers a time-limited export. Taltrax provides data; it does not decide employment disputes.

8. Security and incidents

Taltrax uses role-based access, row-level security, private storage, audit controls, and incident-response procedures. No service can promise absolute security. If a breach is suspected, Taltrax assesses impact, contains access, preserves evidence, and makes required operator or regulatory notifications.

9. Contact

Privacy questions, correction requests, or complaints can be sent tosupport@taltrax.com. Include enough information to identify the account or operator, but do not email passwords, one-time codes, or unnecessary identity documents.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) atoaic.gov.au or 1300 363 992.