Layover collects only the data it needs to calculate your pay, plus an email so you can sign in. We don't link to your bank, we don't sell data, and we don't track you across the internet. You can export or delete everything at any time.
Who we are
Layover is operated by Billy Redwood, trading as Layover, based in the United Kingdom. For the purposes of UK GDPR and the Data Protection Act 2018, Layover is the data controller of the personal data described in this policy.
You can reach us at privacy@getlayover.app.
What we collect
We collect only what's needed to run Layover. Today, that's three categories:
| Category | Examples |
|---|---|
| Account | Email address, display name, sign-in timestamps. |
| Pay settings | Hourly rates, contract type, overtime rules, holiday accrual configuration, employer/base (e.g. LGW). |
| Duty & pay data | Sectors flown, block hours, duty hours, dates, commission entries, computed pay outputs. |
We do notconnect to your bank, your airline's payroll system, or your roster system. Everything in Layover is entered by you or generated from what you've entered.
We collect minimal technical data — IP address and browser type — when you load the app, used solely for security and abuse prevention. We use Vercel Analytics for privacy-first, cookieless page view analytics — no advertising trackers or cross-site tracking (see the cookies policy).
Why we collect it (lawful basis)
Under UK GDPR, every use of your data needs a lawful basis. Ours are:
- Performance of a contract— to provide the service you've signed up for (calculating your pay, storing your duty log, letting you sign in).
- Legitimate interests — to keep the service secure, prevent abuse, and improve how Layover works. We balance this against your privacy and only do what a reasonable person would expect.
- Legal obligation — where the law requires us to retain or disclose data.
How long we keep it
While your account is active, we keep your data so the service works. If you delete your account, we delete your personal data within 30 days, except where we're required to retain a record (e.g. for fraud, security, or legal reasons), in which case we keep the minimum we need for the minimum time required.
If you invite a colleague by email, their email address is stored only until they sign up (at which point it is deleted immediately) or for a maximum of 7 days if the invitation is not used.
Backups are rotated and overwritten on a rolling schedule of no more than 35 days.
International transfers
Our providers may process data in the EU, the UK, or the US. Where data is transferred outside the UK, we rely on the UK International Data Transfer Agreement (IDTA) or equivalent safeguards (e.g. Standard Contractual Clauses, adequacy decisions). You can request a copy of the relevant transfer mechanism by emailing us.
Your rights
Under UK GDPR, you have the right to:
- Access — ask for a copy of the personal data we hold about you.
- Rectify — correct anything that's wrong.
- Erase — ask us to delete your data (right to be forgotten).
- Restrict — limit how we use your data.
- Port — receive a copy in a portable format (we offer CSV export from the app).
- Object — to processing based on legitimate interests.
- Withdraw consent— where we rely on consent (currently we don't, but this remains your right).
To exercise any of these, email privacy@getlayover.app. We aim to respond within 30 days.
If you're not satisfied with our response, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Security
Data is encrypted in transit (TLS) and at rest. Authentication uses one-time email links — there are no passwords stored on our side. Access to production data is limited to the founder and is reviewed regularly.
No system is unbreakable. If a breach occurs that affects your data, we will notify you and the ICO within 72 hours, as required by law.
Children
Layover is intended for working cabin crew, who are by definition adults. We don't knowingly collect data from anyone under 18. If you believe a child has signed up, please contact us and we'll delete the account.
Changes to this policy
If we make a meaningful change to how we handle your data, we'll update this page and email you. The “last updated” date at the top reflects the most recent change. Continuing to use Layover after a change means you accept the updated policy.
Contact
Privacy questions: privacy@getlayover.app
Everything else: hello@getlayover.app
