Privacy policy
Last updated 19 August 2026 · VAT Ledger
What we collect
When you sign in through VATSIM Connect, we store your VATSIM CID and, when you grant the full_name scope, your display name. We store API-key names, non-secret key prefixes, cryptographic key hashes, creation and last-used times, daily API-usage aggregates and key-management audit events. Complete API keys are shown once and are not stored. VATSIM access tokens are used only to retrieve your identity during sign-in and are not persisted.
Network archive
VAT Ledger receives the public VATSIM network and event feeds. Archive records may include CIDs, names, callsigns, controller positions, flight plans, aircraft positions and connection times. We process this information to provide searchable operational history and statistics. See the data and API policy for retention and inference details.
Cookies and security
We use an essential, HttpOnly session cookie to keep Developer users signed in and a short-lived cookie to protect the OAuth callback. We do not use advertising cookies. API usage is stored as daily aggregates by account, key, endpoint and response status. VAT Ledger does not intentionally write IP addresses to these analytics tables, although hosting and network providers may process connection logs for security and service operation.
Map tiles
Flight-track maps load visible geographic tiles directly from OpenStreetMap. Your browser therefore sends OpenStreetMap the requested tile coordinates and ordinary connection information, such as your IP address, browser details and the VAT Ledger site origin. VAT Ledger does not send pilot CIDs, callsigns or raw position samples to OpenStreetMap. OpenStreetMap processes these requests under its own privacy terms.
Retention and sharing
Operational archive records are retained for up to 24 months. Expired login sessions are no longer accepted and are removed during session maintenance. Revoked API-key and audit records may be retained to investigate abuse and protect the service. We disclose information only to infrastructure providers needed to operate VAT Ledger, when required by law, or when necessary to protect the service and its users. We do not sell personal information.
Your choices
You may ask the operator to review, correct or delete account information associated with your Developer account. Depending on applicable law, you may also have rights to access, restrict or object to processing. Public-source archive records and security records may need different treatment where a lawful basis permits their retention. Revoking an API key immediately prevents further use of that key.
Contact
Privacy and data enquiries can be sent to simon@bjerrebakholdt.dk.