CrewPayDay — Privacy Policy
Last updated 2026-08-27
CrewPayDay is a personal salary-estimation tool for cabin crew. This policy explains exactly what data CrewPayDay handles, why, how long it is kept, and how you can delete it.
CrewPayDay is an independent tool. It is not an official payroll system and is not endorsed by or affiliated with any airline.
1. Data you provide when requesting access
To request access you submit three pieces of information. CrewPayDay also generates one identifier for you:
- First name
- Last name
- Company email address
- Client ID — generated by CrewPayDay so the administrator can identify your request
2. Account and approval information
Together with the details above, CrewPayDay stores your approval status (pending, approved or rejected), the date your account was created and the date it was approved. The administrator can see this information in order to review access requests.
During the normal registration flow, a short-lived verification code is sent to your company email address through Brevo, our transactional email provider. CrewPayDay stores only the verification challenge needed to validate the code and removes it after the challenge expires; the code is not used for marketing.
An administrative activity log records approval, rejection and deletion actions (who acted, on which account, and when) so access decisions remain auditable.
3. Roster, calendar and file data
When you connect a crew calendar, CrewPayDay reads only the calendar you select. Calendar events are converted on your device into normalized duty information. Raw calendar descriptions are not stored and are not sent to the CrewPayDay server.
When you select a CrewAccess .ics file, the file is read and parsed locally on your device. The raw .ics file and its descriptions are not uploaded. When you upload a PDF roster, the PDF is sent to the CrewPayDay server so its text can be extracted.
For a salary calculation, the resulting normalized roster data (such as duty dates, times, routes and flight numbers) is sent to the CrewPayDay server. Roster files, raw calendar descriptions and normalized roster data are processed in memory for that request and are NOT retained in the CrewPayDay database after the response is sent.
When you evaluate a roster scenario, the normalized original roster and the hypothetical roster copy are sent together for an in-memory salary comparison and FTL/compliance comparison. Neither roster state nor the comparison is retained in the CrewPayDay database.
Normalized duties may also be written to the on-device Roster Calendar so you can review duties, absences, layovers, changes, short-rest advisories and compliance findings inside the app.
If you choose the Crew Missing Flight Crew feature, CrewPayDay opens the third-party CrewBuddy service in an embedded browser. CrewBuddy handles the sign-in page, credentials, cookies and its own service data under its policies. CrewPayDay reads only limited flight, role and missing-crew information needed for this feature, converts it to an anonymous shortage snapshot and stores that snapshot and local session-ready state on your device. This flow does not send CrewBuddy credentials, cookies or the shortage snapshot to the CrewPayDay server.
4. Salary calculation results and history
Calculation results are stored ONLY on your own device, so you can reopen past results offline. They are not uploaded to or retained on the CrewPayDay server, and the administrator cannot see them.
Deleting a history entry, or deleting the app, removes that data from your device.
5. Settings you configure
Your crew position, seniority, base airport, exchange-rate preference, theme, privacy-mode preference, app-lock preference, selected calendar metadata and alert preferences are stored on your device. Pay rates themselves are resolved on the server and are not editable by you.
6. Notifications and device information
If you explicitly grant notification permission, CrewPayDay can show local, on-device alerts for roster changes, new actionable FTL findings and short-rest advisories. These alert messages use limited summaries and do not include raw roster descriptions, flight numbers, airports, hotel details or personal information.
Remote push notifications can alert the administrator that an access or position/seniority request is waiting, and can tell an authenticated crew member the decision on their own access or profile request. Messages use generic wording and do not include names, email addresses, roster details or salary amounts.
A device push token is registered only after notification permission is granted and is scoped by the authenticated server role or account. The token is relayed to the push delivery provider, is not stored in the CrewPayDay user database and is never shown to other users.
7. Device identifier and fair use of the free allowance
CrewPayDay generates an identifier for the device you use and links it to your account. It exists for one reason: to apply the free-analysis allowance fairly. It lets the server recognise that a free analysis has already been used on that device, so the same person cannot create several accounts on one device to obtain extra free analyses, and it keeps one account bound to one device.
The device identifier is stored with your account and with the free-usage record for that device, together with the platform (iOS or Android) and the dates it was first and last seen.
This identifier is used ONLY for the purpose described above. It is not used for advertising, marketing, profiling or tracking, it is not an advertising identifier and no advertising identifier is read, and it is not shared with or sold to any third party.
8. Subscription and payment processing
CrewPayDay Premium is an in-app subscription. The purchase itself is processed by the Apple App Store or Google Play through your own store account. CrewPayDay never sees, receives or stores your payment card details, and has no access to your store account.
RevenueCat is used to manage and verify subscription status. It receives the subscription identifier associated with your purchase so that the CrewPayDay server can confirm with it whether the subscription is currently valid. Every Premium check is verified server-side; the app itself cannot grant Premium.
Only the resulting subscription status is stored on the CrewPayDay server: whether Premium is active or inactive, the store product identifier, the expiry/renewal date reported by the store and the time the status was last verified. No payment details, card numbers or billing addresses are ever stored by CrewPayDay.
9. Authentication information
Crew accounts are passwordless: after registration your device holds a signed access token, kept in your device secure storage. CrewPayDay never asks crew users for a password.
The administrator account uses a username and password. The password is never stored in readable form — only a one-way hash held in the server environment — and is never sent to or stored on any user device.
10. Why your data is processed
CrewPayDay does not use your data for advertising, profiling, marketing or tracking, and does not sell your data.
- To verify that you are cabin crew and to let the administrator approve or reject your access request
- To restrict the app to approved users only
- To normalize a roster, maintain your on-device Roster Calendar and calculate a salary estimate
- To provide on-device roster-change, rest and compliance information when you choose to use those features
- To show an on-device, anonymous summary of missing crew when you choose to connect the authorized CrewBuddy service
- To compare an optional roster scenario with your selected real roster without changing the real roster or salary history
- To notify the administrator that an access or profile request is waiting and to notify a crew member about the decision on their own request
11. Analytics and tracking
CrewPayDay contains no analytics SDK, no advertising SDK and no cross-app or cross-site tracking. No advertising identifier is read.
12. Third-party services actually used
CrewPayDay does not sell your personal data and does not send your CrewPayDay account, roster or salary data to an airline.
- Push notification delivery — used for generic administrator review alerts and access/profile decisions belonging to the authenticated crew account; receives a scoped device token and notification text. Crew roster alerts are scheduled locally on the crew member's device.
- Public exchange-rate sources — queried for the EUR/TRY rate. These requests contain no personal data.
- Apple App Store / Google Play — process the subscription purchase itself. CrewPayDay receives no payment details from them.
- RevenueCat — manages and verifies subscription status; receives the subscription identifier for your purchase and returns whether Premium is active.
- Brevo — sends the short-lived verification code to the company email address you provide during normal registration. It receives that email address and the transactional verification message.
- CrewBuddy — its service is opened only when you choose Crew Missing Flight Crew. CrewBuddy handles its own sign-in, cookies and service data inside the embedded browser; CrewPayDay keeps only the limited anonymous shortage snapshot described above on your device.
- WhatsApp — opened only when you choose the support action. A privacy-filtered diagnostic message is placed in the draft for you to review and decide whether to send.
13. Data storage and retention
Account data (name, surname, company email, Client ID, approval status and dates) is stored on the CrewPayDay server for as long as your account exists.
Roster files, raw calendar descriptions and server-side roster data are never retained — they exist only for the duration of local parsing or the calculation request.
Salary results, history, the Roster Calendar, calendar connection metadata, settings, named roster-scenario operations and alert-deduplication records live on your device until you delete the applicable data or remove the app. Saved scenario documents contain operation references, not a duplicate roster or salary result.
The CrewBuddy anonymous shortage snapshot and local session-ready state remain on your device until the feature clears them or you remove the app. CrewBuddy may retain data under its own privacy policy when you use its service.
Support Diagnostics keeps at most the five most recent completed, privacy-filtered reports on your device. Raw PDF or ICS content, authorization tokens, calendar UIDs and raw event notes are not stored in those reports. Optional unrecognized-event labels are shown only in memory when you explicitly enable them for preview and are not persisted.
Administrative activity-log entries are retained so access decisions remain auditable.
The device identifier, the free-usage record for that device and your subscription status (active/inactive only) are retained for as long as they are needed to apply the free allowance and Premium access correctly.
14. Account deletion
You can delete your account at any time from inside the app: Settings → Account → Delete Account. No email, phone call or message to support is required.
Deletion is immediate and permanent: your account record and the personal data in it (name, surname, company email, Client ID, approval status) are removed from the server, and your session stops working straight away.
Deleting your CrewPayDay account does not automatically cancel an App Store or Google Play subscription. If you have an active subscription, cancel it in your store subscription settings to prevent future renewal charges; deleting the account does not provide a refund.
Device-local results and diagnostics have their own in-app delete controls. Removing the app clears its remaining device-local data.
15. Security
- All communication with the CrewPayDay server uses HTTPS.
- Every data endpoint requires a valid access token and an approved account, re-checked on every request.
- Access tokens are held in device secure storage.
- Requests are rate limited, and cross-origin access is restricted.
- Pay rate tables and salary formulas exist only on the server and are never shipped inside the app.
16. Your rights
You can ask what account data is held about you, ask for it to be corrected, and delete your account yourself at any time using the in-app Delete Account flow. You can separately delete on-device history and Support Diagnostics from their in-app controls. Because roster data and results are never stored on the server, there is no server-side roster history to export.
17. Children
CrewPayDay is intended for professional cabin crew and is not directed at children.
18. Changes to this policy
If data handling changes, this policy is updated and the date at the top of the page changes with it.
19. Contact
For privacy questions or a data request, contact the CrewPayDay administrator using the support option in Settings.