Skip to content
All airports
LegalLast updated

Privacy Policy

What HonestAirport collects when you browse, sign in, post a review, create an API token, or join Members through Whop — and what we do with it.

1.Overview

This policy explains what personal data HonestAirport collects when you use honestairport.com, its API and MCP endpoints, and the HonestAirport Members subscription, why we collect it, who else processes it, how long we keep it, and the rights you have. The operator named below is the data controller.

Operator
TODO: legal entity operating HonestAirport
Address
TODO: registered address
Email
TODO: legal contact email

Short version: you can read almost everything on the site without telling us anything. We collect data when you create an account, buy a membership through Whop, post a review, create an API token, or use the assistant. We use privacy-friendly aggregate analytics by default, and marketing pixels only where they are switched on.

2.What we collect and why

Account. When you sign up we store your email address, the name you enter, a salted hash of your password (never the password itself), whether your email is verified, and your account role. If you sign in with GitHub or Apple we store the identifier and email that provider returns; we do not receive your provider password. We use this to run your account, secure it, and send account emails (verification, password reset).

Membership. Whop processes your payment for the $8 per month membership. We receive your Whop user ID and, when you restore access, the Whop receipt (pay_…) ID. We store the Whop user ID on your account and in an encrypted cookie so we can check whether your membership is active. We never receive or store card numbers, bank details, or billing addresses; those stay with Whop. When Whop notifies us that a payment succeeded, we may forward that conversion event to analytics and advertising services as described under Analytics and advertising.

Reviews and photos. If you post a review we store the rating, text, the airport it is about, the time, and a link to your account. Photos you attach are re-encoded and published without embedded metadata. Before stripping it, we read the capture date and GPS position from the original file, if present, and store them together with the distance to the airport for internal moderation only. These values are never shown publicly or returned by the API, and we do not treat them as proof of anything.

Personal access tokens. When you create a token we store only a hash of it on your account; the token itself is shown to you once and cannot be recovered. Requests made with a token count against short-lived rate-limit counters so we can enforce limits and spot abuse.

Assistant. Questions you type into the assistant, and the airport data our tools return to answer them, are sent to a large language model through Vercel AI Gateway (currently an OpenAI model). Do not include personal data in your questions. Conversations are not linked to your account and are not used to train models by us.

Approximate location. To show a “Near you” airport we read the approximate city-level location that our hosting provider derives from your IP address on each request. We do not store it, and we do not ask the browser for precise geolocation.

Campaign attribution. If you arrive with UTM parameters or ad click IDs (fbclid, gclid) in the URL, we keep them in first-party cookies and pass them along to the Whop checkout so we know which campaign led to a membership.

Technical data. Like every website we receive your IP address, browser and device information, the pages you request, and referrer URLs in server logs, which we use for security, debugging, and capacity planning.

3.Cookies

We use the following first-party cookies. Analytics and advertising cookies are only set when the respective service is enabled for this deployment.

CookiePurposeLifetime
better-auth.* (session)Keeps you signed in after login.Session; renewed while you use the site.
whop_sessionEncrypted, HTTP-only cookie holding your Whop user ID so member-only pages open in this browser without re-checking Whop on every request.Until it expires or you clear cookies.
ha_attr_firstThe UTM / click-id parameters on the first page you landed on, so a later membership purchase can be attributed to the campaign that brought you here.180 days.
ha_attr_lastThe most recent UTM / click-id parameters, for the same purpose.30 days.
_ga, _ga_* (Google Analytics)Distinguishes visitors and sessions for aggregate usage statistics. Only set when Google Analytics is enabled.Up to 2 years.
_fbp, _fbc (Meta Pixel)Meta advertising measurement. Only set when the Meta Pixel is enabled.Up to 90 days.

You can delete or block cookies in your browser. Blocking the session cookie signs you out; blocking whop_session means member-only pages will ask you to restore access.

4.Analytics and advertising

  • Vercel Web Analytics records page views and Web Vitals in aggregate. It does not use cookies and does not track you across sites.
  • Whop Pixel records page views on this site so Whop can attribute checkouts that start here. It is on by default in production.
  • Google Analytics 4 and the Meta Pixel run only when they are configured for the deployment. When enabled, they set the cookies listed above and receive page views and, after a successful Whop payment, a subscribe/purchase event. For Meta, the email on the membership is sent only as a SHA-256 hash together with the Meta browser IDs (_fbp, _fbc) and IP address, as Meta requires for matching. Where the law where you live requires consent for this kind of tracking, we rely on your consent and you can withdraw it by clearing cookies or using your browser’s tracking-protection features.

6.Who processes your data

We do not sell personal data. We share it with service providers that act on our instructions, and with Whop as an independent controller for payments:

  • Vercel, Inc. — hosting, server logs, Web Analytics, file storage for review photos (Vercel Blob), and AI Gateway for the assistant.
  • Managed PostgreSQL provider — the database that holds accounts, tokens, reviews, and membership links.
  • Whop, Inc. — checkout, payment processing, subscription management, the Whop Pixel, and the Members community. Whop’s processing is governed by Whop’s privacy policy.
  • Resend, Inc. — sends verification and password-reset emails.
  • GitHub, Inc. and Apple Inc. — if you choose to sign in with them.
  • OpenAI (via Vercel AI Gateway) — answers assistant questions.
  • Google LLC and Meta Platforms, Inc. — analytics and advertising measurement, only when enabled.

We may also disclose data when the law requires it, to protect our rights or the safety of others, or as part of a merger or sale of the Service, in which case this policy continues to apply to the data transferred.

7.International transfers

Our providers are mostly based in the United States and may process data there and in other countries. Where data leaves the EU, EEA, UK, or Switzerland we rely on the providers’ certification under the EU-U.S. Data Privacy Framework or on standard contractual clauses.

8.How long we keep data

  • Account data: until you delete your account or ask us to, then removed from the live database within 30 days.
  • Reviews: while published. Deleting your account removes the link to you; you can ask us to delete the reviews themselves as well.
  • Review photo metadata (capture time, GPS, distance): as long as the photo is stored.
  • Tokens: until you revoke or regenerate them. Rate-limit counters expire automatically once their window ends.
  • Membership link (Whop user ID): while your account exists. Payment records live with Whop under its retention rules.
  • Server logs: up to 30 days unless needed for an ongoing security investigation.
  • Attribution cookies: 180 days (first touch) and 30 days (last touch).

9.Your rights

Depending on where you live you can ask us to access, correct, delete, or export your personal data, to restrict or object to processing, and to withdraw consent at any time without affecting processing that already happened. You can update your name and password and revoke tokens yourself in Settings. For anything else, contact us using the details below; we answer within one month.

If you are in the EU, EEA, or UK you can also complain to your local data protection authority. California residents have the rights described in the CCPA/CPRA; we do not sell or share personal information for cross-context behavioural advertising except through the advertising pixels described above when they are enabled, which you can opt out of by blocking them in your browser.

10.Security

Traffic is encrypted in transit (TLS). Passwords are stored as salted hashes, API tokens as hashes, and the membership cookie is encrypted and HTTP-only. Access to production systems is limited to the people who operate the Service. No system is perfectly secure; if you believe your account has been compromised, change your password and contact us.

11.Children

The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

12.Changes to this policy

We will update this page when our data practices change and adjust the date at the top. For material changes we will notify you on the Service or by email where we have one.

13.Contact

Privacy questions and requests to exercise your rights go to the operator listed below. The Terms of Service cover the rules for using the Service.

Operator
TODO: legal entity operating HonestAirport
Address
TODO: registered address
Email
TODO: legal contact email