Privacy policy

Effective 18 August 2026 · VAT Ledger

What we collect

When you sign in through VATSIM Connect, we store your VATSIM CID and, if you grant the requested scope, your display name. We store API-key names, non-secret key prefixes, cryptographic key hashes, creation and last-used times, quota usage and key-management audit events. Complete API keys are never stored and VATSIM access tokens are discarded after sign-in.

Network archive

VAT Ledger receives public VATSIM network data including CIDs, names, callsigns, controller positions, flight plans, aircraft positions and connection times. We process this information to provide searchable operational history and statistics. See the data policy for retention and inference details.

Cookies and security

We use an essential, HttpOnly session cookie to keep Developer users signed in and a short-lived cookie to protect the OAuth callback. We do not use advertising cookies. API usage is stored as daily aggregates by account, key, endpoint and response status; VAT Ledger does not intentionally place IP addresses in these analytics tables, although infrastructure providers may retain security logs.

Retention and sharing

Operational archive records are retained for up to 24 months. Expired login sessions are removed, and revoked keys remain only as security and audit records. We share information only with infrastructure providers necessary to operate the service, when required by law, or when needed to protect the service and its users. We do not sell personal information.

Your choices

You may request access, correction, restriction or deletion of account information. Some public-source or security records may need to be retained where an applicable legal basis permits it. Revoking a key immediately prevents further API use. This policy does not replace VATSIM’s own privacy policy.

Contact

The service operator must configure a privacy contact before production launch.