Privacy notice
What data FlyDown processes, why, where it's stored, for how long and how you control it.
Last updated: 17 September 2026
This is a translation: in case of any discrepancy, the Italian version prevails. Read in Italian
In short
- FlyDown only processes the data it needs in order to work: your account, your watches and, if you switch them on, notifications.
- No advertising, no profiling, no third-party analytics, no data sold to anyone. We record how FlyDown is used (pages viewed, buttons pressed) solely to improve it, without cookies and without IP addresses.
- Data is stored on a server in Italy (Oracle Cloud, Milan). Fonts, maps and photos come from our own server: your browser does not contact any external services while you use FlyDown.
- From your profile you can download all your data and delete your account whenever you like.
1. Who the data controller is
The controller is Domenico Pasquale, Via Pola 18B, 75012 Bernalda (MT), Italia (VAT no. IT01391390778), who operates FlyDown. For any questions about your data, write to privacy@getflydown.com.
FlyDown has not appointed a data protection officer (DPO): it is not mandatory for a service of this size.
2. What data we process
Account
Email address, name (optional), chosen plan, date of sign-up and of last login, version and date of acceptance of the terms of use. Your password is never stored: we only keep a non-reversible hash (PBKDF2-SHA256), from which the password cannot be derived.
Use of the service
The watches you create (airports, destinations, countries, dates, budget, number of passengers, airlines, settings for visiting more cities), the destinations you exclude, your notification preferences (including your device's time zone), the deals found for your watches and, if you ask to be notified, the paid plans you are on the waitlist for. We also record the day you last used FlyDown.
Invitation request
If you request an invitation without having an account, we only keep your email, the date and the channel you came from, so we can write to you when a place becomes available. Legal basis: your consent, which you can withdraw at any time by writing to us. We delete it after inviting you or, at the latest, after 12 months.
Emails with news and offers (only if you choose to receive them)
If you tick the box when signing up or switch on the option in your profile, we use your email address to write to you occasionally about FlyDown news and offers, for example when the new plans arrive. We keep the date of your consent. Legal basis: your consent, which you can withdraw at any time from your profile or by writing to us. If you are on the waitlist for a plan, we only write to you about that plan.
Automatic emails: address confirmation and forgotten password
When you sign up, we send you a welcome email with a link to confirm your address (valid for 7 days); we record the date of confirmation. If you ask to reset your password, we send you a single-use link valid for 60 minutes. Of these links we only keep a non-reversible hash, which is deleted at the latest one day after it expires. Legal basis: performance of the service.
Invite a friend
Every account has a personal link for inviting other people. If you sign up through someone's link, we save in your account who invited you, so that they can be given the extra watch provided for when you create your first watch. The person who invited you only sees how many friends have signed up through their link, never who they are. Legal basis: performance of the service. The link between the two is deleted when either account is deleted.
Session
When you log in, your browser receives a technical cookie containing a session code. On the server we only keep its hash, together with the expiry date and an indication of the browser used (user agent), so you can recognise the sessions in your exported data.
Push notifications (only if you switch them on)
Your browser gives us a delivery address with its notification service and the public keys for encrypting messages. We also keep the browser type and the date of the last successful delivery.
Technical data
For each request, the web server and the service log record the IP address, date and time, requested page and browser. This data is used to protect the service from abuse and faults. Login, sign-up and password recovery attempts are counted per IP address in memory only, for a few hours, to block anyone who gets it wrong too many times, creates accounts in bulk or sends too many requests.
Usage statistics
To understand what works and what does not, we record interactions with FlyDown: pages viewed, clicks on links and buttons (the name of the button, never what you type), clicks on "Book" with airline and route, and account actions (sign-up, login, watch created, edited or deleted, waiting list, notifications). For each action we store the date and time, the page, the language of the page and of the browser, the type of device (phone, computer, app), the channel you came from (for example "instagram") and the domain of the website that referred you here.
We do not store IP addresses, email addresses or typed text, we do not use cookies and we do not store identifiers in your browser: a visit is counted when you open a page coming from another website or from a link. The arrival channel is passed from one page to the next within the links. If you are logged in, the action is linked to your account. If your browser sends the Global Privacy Control signal, we do not record interactions on the page.
The data is seen only by the controller. We show airlines at most aggregate figures (for example how many clicks on "Book" an airline has received), never data relating to an individual. Legal basis: legitimate interest in improving the service and measuring its use (Art. 6(1)(f) GDPR); you can object by writing to us. Your recorded actions are included in "Download my data".
What we do not process
Payment data, location, contacts, sensitive data. We do not create profiles for advertising purposes and we do not make automated decisions that produce legal effects concerning you: alerts only follow the rules you set.
3. Why we process it and on what basis
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and managing your account, searching for deals, showing them to you and alerting you | Account, use of the service, session, notifications | Performance of the contract, i.e. the terms of use you accept (Art. 6(1)(b) GDPR) |
| Usage statistics, to understand how FlyDown is used and to improve it | Usage statistics | Legitimate interest (Art. 6(1)(f) GDPR); you can object by writing to us |
| Emails with news and offers, and invitations for those who requested one | Email, language, date of consent | Consent (Art. 6(1)(a) GDPR), which you can withdraw at any time |
| Security, abuse prevention, backups and recovery in the event of a fault | Technical data, all data in backups | Legitimate interest in protecting the service and its users (Art. 6(1)(f) GDPR) |
| Complying with legal obligations and establishing or defending legal claims | The data needed on a case-by-case basis | Legal obligation (Art. 6(1)(c) GDPR) and legitimate interest (Art. 6(1)(f) GDPR) |
Email and password are required to have an account; without them, FlyDown cannot be used. Your name is optional. Notifications are always optional and can be switched off from your profile or in your browser settings.
4. Where the data is and who sees it
- Server: Oracle Cloud Infrastructure, Milan region (Italy). Oracle acts as a data processor under its own data processing agreement.
- Backups: every night a copy of the database is made, kept on the server and on Oracle Object Storage (Milan region) and, once a week, on the controller's computer, which has an encrypted disk.
- Browser notification services (only if you switch notifications on): the message passes through your browser's service, for example Google (Chrome, Android), Apple (Safari, iPhone), Mozilla (Firefox) or Microsoft (Edge). The content travels encrypted and the service cannot read it; it only sees the delivery address. These services may be located outside the European Union: transfers take place with the safeguards provided for by the GDPR, such as the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.
- Email: if you write to FlyDown, your email is handled by the controller's mailbox provider. The mailbox and the sending of automated emails (welcome and address confirmation, password links, and news and offers if you have chosen to receive them) are entrusted to Hostinger International Ltd. (Cyprus, European Union), which acts as a data processor.
Nobody else receives your data. We do not sell it or share it for advertising.
Links to airlines and FlixBus. When you tap "Book" or a bus journey, you open that company's website, which processes data according to its own privacy notice. The link only contains the route, dates and number of passengers, not your data. If in the future some links are affiliate links, they may contain a code identifying FlyDown, never you, and they will be marked as such.
5. How long we keep it
| Data | Retention |
|---|---|
| Account, watches, preferences | For as long as you have the account. If you delete it, they are removed from the database immediately. |
| Backups | Daily copies for 7 days, monthly copies for 12 months. After your account is deleted, your data remains only there, is not used and disappears within 12 months at the latest. |
| Sessions | 30 days from the last renewal, or until you log out. |
| Email confirmation and new password links | Until one day after expiry (7 days for confirmation, 60 minutes for the password). |
| Push notifications | Until you switch them off, or until the browser's service reports that the subscription is no longer valid. |
| Consent to emails with news and offers | Until you withdraw it or delete your account. |
| Invitation requests | Until you are invited or, at the latest, 12 months. |
| Web server and service logs | 14 days. |
| Usage statistics | Link to your account: 90 days, after which the actions remain anonymously. Everything is deleted after 13 months. If you delete your account, your actions become anonymous immediately. Daily totals: 13 months. |
| Price history | The prices collected relate to routes, not to you: they remain in the history even after your account is deleted, with no link to you as a person. |
6. Your rights
At any time you can ask to access your data, rectify it, erase it, restrict its processing, receive it in a machine-readable format (portability) and object to processing based on legitimate interest (Arts. 15–21 GDPR).
- By yourself, straight away: in your profile you will find "Download my data", which produces a file with everything FlyDown holds about you, and "Delete account".
- By email: write to privacy@getflydown.com. We reply within 30 days.
- Complaint: if you believe your data is not being processed correctly, you can contact the Garante per la protezione dei dati personali (the Italian Data Protection Authority, garanteprivacy.it) or the authority of the country where you live.
7. Security
Passwords and session codes are stored only as non-reversible hashes, cookies are protected from access by scripts, repeated logins with a wrong password are blocked and notification messages travel encrypted. No system is 100% secure: in the event of a personal data breach affecting you, we will notify you as required by the GDPR.
8. Minors
FlyDown is restricted to adults. If we become aware that an account belongs to a minor, we will delete it.
9. Changes
If FlyDown changes the way it processes data, for example by adding affiliate links or payments, this notice will be updated before the change, with the new date at the top. Significant changes will be flagged to you in the app.