HangarKeepHangarKeep

Privacy Policy

Version 2026-08-27

Overview

HangarKeep is an expense management platform for private aviation teams, operated by HangarKeep LLC. This policy describes how we collect, use, share, and protect information when you use the HangarKeep web application and iOS app.

The data controller for this policy is HangarKeep LLC, 12311 NE Laura Ct, Vancouver, WA 98684. Contact: privacy@hangarkeep.com.

Our Role: Controller and Processor

HangarKeep is a tool organizations use to manage their own records, so our role depends on the data:

  • We are the controller for account and login data — the name, email address, and authentication details of the people who sign in, plus server logs and support correspondence.
  • We are a processor for the business records an organization puts into HangarKeep — expenses, receipts, invoices, vendors, aircraft, and any personal information about crew, passengers, clients, or vendors contained in them. The organization is the controller of that data and decides what to upload, who can see it, and how long to keep it.

If you are a member of an organization on HangarKeep and want data corrected or removed, contact that organization's administrator first — they control it directly through the application. Business customers who need a Data Processing Addendum can request one at privacy@hangarkeep.com.

Information We Collect

Information you provide directly:

  • Account information (first and last name, email address, password hash, organization name)
  • Authentication data (two-factor secrets, passkey credentials, recovery codes — all stored hashed or encrypted)
  • Expense records (dates, amounts, descriptions, categories, cost centers)
  • Receipt images and PDFs uploaded via the web, the iOS app, or email forwarding
  • Invoice, billing party, and payment-method details you enter
  • Aircraft, trip reference, and vendor data
  • Support correspondence you send us

Information collected automatically:

  • Server access logs — IP address, request path, user agent, timestamp, and response status. Session cookies and authorization headers are stripped from these logs before they are written. Access logs are retained for 30 days and then rotated out.
  • Application logs containing a request identifier and, for signed-in requests, the acting user and account identifier.
  • iOS device push tokens, if you enable notifications in the iOS app.

We do not use analytics, advertising, or tracking services, and we do not build behavioral profiles.

How We Use Your Information

  • Provide and operate the expense management service
  • Process receipt images using AI-powered text extraction
  • Generate reports, invoices, and PDF exports
  • Send transactional emails (invoices, statements, password resets, invitations, verification, receipt notifications)
  • Send push notifications to the iOS app about receipt processing
  • Authenticate users, enforce roles, and maintain audit logs of changes
  • Enforce plan limits and protect against abuse
  • Maintain backups for disaster recovery
  • Respond to support requests

We do not sell or rent personal data, we do not share it for advertising or marketing purposes, and we do not use your data to train AI models.

Legal Bases (EEA/UK)

Where the GDPR or UK GDPR applies, we process personal data on these bases: performance of a contract (operating your account and delivering the Service), legitimate interests (securing the Service, preventing abuse, maintaining audit logs and backups, and responding to support requests), and legal obligation where applicable. Where we act as a processor, our customer determines the legal basis.

AI Receipt Processing

When you upload a receipt, the image or PDF is sent to Anthropic's API to extract fields such as amount, date, vendor, and currency.

Under Anthropic's commercial terms, content sent through their API is not used to train their models, and inputs and outputs are automatically deleted from their systems within 30 days. We do not use your receipts to train any model of our own.

Extraction is automated and imperfect — extracted values are suggestions for a person to review, not verified data, and no automated decision with legal or similarly significant effects is made about you.

Third-Party Services

We use the following processors to operate HangarKeep. Each is bound by contractual confidentiality and data-protection obligations, and none is permitted to use your data for its own purposes.

  • Anthropic — AI-powered receipt text extraction (receipt images and PDFs)
  • Resend — transactional email delivery (recipient addresses, email content)
  • Cloudflare R2 — file storage for receipts, attachments, and exports
  • Amazon Web Services (S3) — encrypted database and file backups
  • Hetzner — application and database hosting
  • Apple (APNs) — push notification delivery to the iOS app (device tokens only)
  • Frankfurter — currency exchange rates (currency codes and dates only; no personal data)

We may also disclose information where required by law, to enforce our Terms of Service, or to protect the rights, safety, and security of our users and the Service. If HangarKeep is ever acquired or merged, we will notify you before your data becomes subject to a different privacy policy.

International Data Transfers

The HangarKeep application and its databases are hosted in the European Union. Backups are replicated to Amazon S3 in the United States (us-west-2) for disaster recovery, and our AI, email, storage, and push providers may process data in the United States and other countries.

This means your data is transferred outside the EEA and the UK. Where required, these transfers rely on the European Commission's Standard Contractual Clauses or an equivalent transfer mechanism offered by the provider.

Data Security

All data is transmitted over encrypted connections (TLS, with HSTS enforced). Each organization's data is stored in a physically isolated database file rather than a shared multi-tenant table. Receipt files are stored in private cloud storage reachable only through authenticated, expiring links. Passwords are hashed with bcrypt; two-factor secrets are encrypted at rest; recovery codes are stored hashed. Backups are encrypted at rest and their restores are verified nightly. Two-factor authentication and passkeys are available on every account, and every change to a record is written to an audit log.

No system is perfectly secure. If a breach affects your personal data, we will notify affected account administrators and, where required, the relevant supervisory authority without undue delay. See our Security page for more detail and for how to report a vulnerability.

Cookies

HangarKeep sets only strictly necessary cookies. There are no analytics, advertising, or tracking cookies, so no consent banner is required.

  • Session cookie — keeps you signed in. Expires when your session ends.
  • CSRF token cookie — protects forms against cross-site request forgery.
  • Timezone cookie (tz) — stores your browser's timezone so dates display correctly in your local time.

Data Retention

  • Active accounts — we retain your data for as long as the account is active.
  • Deleted accounts — when you request deletion, the account is immediately locked and scheduled for permanent removal after 30 days. During that window a system administrator can cancel the deletion if you ask. After 30 days, personal data is permanently deleted and financial records are anonymized.
  • Unverified accounts — an account created but never email-verified is automatically and permanently deleted after 7 days, provided it has no other members and contains no data. No notice is sent before this deletion.
  • Server access logs — 30 days.
  • Backups — database backups are retained for 30 days; files deleted from storage remain recoverable from backup for 30 days. Data deleted from the live service may therefore persist in backups for up to 30 days before ageing out.

Your Rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our processing of your personal data, to receive a portable copy, and to withdraw consent. Californian residents additionally have the right to know what is collected and to not be discriminated against for exercising these rights — note that we do not sell or share personal information as those terms are defined under the CCPA.

In practice, most of these are self-service:

  • Account administrators can export organization data, and download a full account backup, from Settings.
  • Administrators can add, correct, and remove records and members directly in the application.
  • You can delete your own account at any time from your profile settings or the iOS app.

For anything you cannot do in the application, email privacy@hangarkeep.com and we will respond within 30 days. We will ask you to verify your identity before acting on a request. If you are in the EEA or UK and are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

Children

HangarKeep is a business tool intended for use by adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, contact privacy@hangarkeep.com and we will delete it.

Changes to This Policy

We may update this policy as the Service evolves. When we make material changes, we will update the version at the top of this page and notify account administrators by email before the changes take effect. Continued use of the Service after the effective date means you accept the updated policy.

Contact

For privacy-related questions or requests, email privacy@hangarkeep.com.

HangarKeep LLC
12311 NE Laura Ct, Vancouver, WA 98684