Privacy Policy
Last updated 1 August 2026
This policy explains what personal data RavnView collects when you use the service, why we hold it, who it is shared with, and the rights you have over it. It is written to be read — if anything here is unclear, ask us and we will explain it.
1. Who is responsible for your data
RavnView is operated by SunCom Consulting OÜ (registry code 16612900), Padriku tee 12/3-4, Pirita linnaosa, 11912 Tallinn, Harju maakond, Estonia. We are the data controller for the personal data described below.
For any privacy question, or to exercise any of the rights in section 8, contact us at support@ravnview.com.
2. What we collect
- Account details
- Your email address, a hash of your password (we never store the password itself), your subscription tier, your unit and temperature preferences, and the dates your account was created and last changed. If you sign in with Google we also store that fact and your Google account identifier.
- Flight data you upload
- Flight logs and, optionally, video. From these we derive telemetry — position, altitude, speed, attitude, battery state and similar — along with the take-off coordinates, a place name for that location, the flight's start time and its duration. Flight logs describe where and when an aircraft flew, so they can reveal your movements and locations. Treat them accordingly.
- Questions you ask the AI assistant
- The questions you type about a flight and the answers given, stored with that flight so the conversation is there when you return.
- Billing information
- A Stripe customer identifier, your subscription identifier, the current billing period and any scheduled plan change. Card numbers are entered on Stripe's own payment pages and never reach our servers — we cannot see them.
- Connected services
- If you connect DJI FlightHub 2, your API key is stored encrypted (AES-256-GCM) and used only to make requests to DJI on your behalf.
- Security and diagnostic logs
- Records of significant events — sign-in attempts, uploads, plan changes, receipt downloads — with the time, the account involved and the originating IP address. These exist to detect abuse and to investigate problems.
- Cookies and usage measurement
- One strictly necessary cookie,
ravnview.sid, keeps you signed in. It carries no advertising function and is required for the service to work at all. - Analytics — only with your consent
- Google Tag Manager loads in "consent denied" mode (Google Consent Mode): until you accept analytics cookies in the consent banner — or if you decline — it sets no cookies and we measure nothing about your visit. Only after you accept do the measurement tags we have configured begin to record which pages you visit and technical details such as your browser, device and approximate location derived from your IP address, and may set their own cookies. Your choice is stored in your browser; clearing site data resets it. We use analytics only to understand how the service is used. We do not use advertising cookies and we do not build advertising profiles.
3. Why we hold it, and on what legal basis
- To provide the service — performance of a contract
- Holding your account, storing and processing your flights, running your subscription. Without this data there is no service to give you.
- To keep the service secure — legitimate interests
- Security logging, rate limiting and abuse prevention. We consider this proportionate: the data is minimal, retained briefly, and used only to protect accounts including your own.
- To communicate with you — performance of a contract
- Address verification, password resets and essential notices about your account or subscription. We do not send marketing email.
- To understand usage — consent
- Analytics runs only after you accept it in the cookie banner. You can withdraw that consent at any time using Cookie settings; withdrawing stops future measurement and removes RavnView's Google Analytics cookies.
- To meet legal obligations
- Retaining billing records for the period required by tax and accounting law.
4. Who we share it with
We do not sell your data, and we do not share it for advertising. We use the following providers, each processing only what their function requires:
- Stripe — payments
- Receives your email and billing details to take payment and issue receipts.
- Simply.com — email delivery
- Delivers verification and password-reset messages to your address.
- Google Tag Manager — usage measurement
- Its script loads on each visit but in "consent denied" mode, setting no cookies and receiving no usage data. Only after you have accepted analytics cookies do the measurement tags configured for the site receive the pages you visit and technical details of your device and browser.
- Google — sign-in
- Only if you choose to sign in with Google. Google confirms your verified email address to us; we do not receive your password, and we do not access or post anything else in your Google account.
- Anthropic — AI features
- When you ask a question about a flight, the question and the relevant flight context are sent to Anthropic to generate an answer. Do not include anything in a question that you would not want processed by a third party.
- Mapping and terrain — MapTiler, Cesium ion, Google
- Your browser requests map tiles and 3D terrain for the area a flight took place in, which necessarily discloses that area to those providers.
- OpenStreetMap Nominatim and Open-Meteo
- A flight's take-off coordinates are sent to these services to resolve a place name and the historical weather for that time and place.
- DJI
- Only if you connect FlightHub 2, and only to retrieve your own data from it.
We may also disclose data where we are legally required to, or to establish or defend legal claims.
5. Where your data is held
SunCom Consulting OÜ is established in Estonia, and the servers holding your account and flight data are located in Sweden. Both are within the European Economic Area, so your data stays in the EEA in our own systems.
Some of the providers listed in section 4 operate outside the EEA. Where that is the case, transfers are made under the European Commission's Standard Contractual Clauses or an equivalent safeguard.
6. Flights you choose to make public
A flight is private by default. If you set one to public, anyone with the link can view it and everything it contains — including the route, the take-off location, the times and any video. This is a deliberate act on your part and it cannot be undone for anyone who has already seen or copied the data. Consider what a flight reveals about where you live or work before sharing it.
7. How long we keep it
Your account and flights are kept until you delete them or close your account. Deleting a flight removes it from your library immediately and erases the underlying files shortly afterwards. Closing your account removes your account record and flight data.
Security logs are kept for a limited period for their stated purpose. Billing records are retained for as long as tax and accounting law requires, which is independent of account deletion.
8. Your rights
Under the GDPR you have the right to:
- ask what personal data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to how we process it, including processing based on legitimate interests;
- receive your data in a portable, machine-readable form;
- withdraw consent at any time, where processing is based on consent.
Email support@ravnview.com and we will respond within one month. If you are not satisfied with our response, you may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — https://www.aki.ee — or to the supervisory authority where you live.
9. How we protect it
Passwords are hashed with Argon2id and are never stored or transmitted in readable form. Connected service credentials are encrypted at rest. Traffic is served over HTTPS. Sessions use signed, HTTP-only cookies, and sensitive actions require a matching anti-forgery token.
No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will notify you and the supervisory authority as the GDPR requires.
10. Children
RavnView is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect data from children; if you believe we have, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the service changes. The date at the top always reflects the current version, and we will tell you directly about any change that materially affects your rights. Continued use after a change means you accept the updated policy. This policy is governed by the law of Estonia.