Privacy Policy
What we hold, why we hold it, and how to get rid of it. Written specifically for this service rather than copied from a template — everything listed is data PointsRadar genuinely stores.
PointsRadar tracks Virgin Atlantic reward flight availability and emails you when the points cost of a flight you are watching drops below a limit you set.
This policy explains exactly what personal data we hold, why, and what you can do about it. We have kept it specific rather than generic: everything listed below is data the service genuinely stores.
Who is responsible for your data
PointsRadar is operated by James Arscott, who is the data controller for the purposes of UK GDPR and the Data Protection Act 2018. Contact: info@pointsradar.co.uk.
What we collect and why
| Data | Why | Lawful basis |
|---|---|---|
| First name, last name, email address | To create and identify your account, and to address emails to you | Performance of a contract |
| Password, stored only as a bcrypt hash | To sign you in. We never store or can see your actual password | Performance of a contract |
| Alerts and holiday alerts you create — airports, dates, cabins, points limits | They are the service. We check them after each data refresh and email you on a match | Performance of a contract |
| IP address and browser/app user agent, recorded per sign-in session | Session security — recognising your session and spotting misuse | Legitimate interests (securing accounts) |
| Failed sign-in count and any temporary lockout time | To slow down password guessing against your account | Legitimate interests (securing accounts) |
| Last sign-in time and account creation time | Account administration and support | Legitimate interests (running the service) |
| If you turn on two-factor authentication: your authenticator secret and backup codes | To verify your 2FA codes. Only stored if you choose to enable 2FA | Performance of a contract |
| Your account tier and how it was set | Decides which features and limits your account has | Performance of a contract |
| Display preference (light or dark theme) | So the app looks the way you left it | Legitimate interests (running the service) |
| Short-lived email verification and password reset tokens | To confirm your email address and let you reset a forgotten password | Performance of a contract |
We do not collect payment details, location data, contacts, photos, device identifiers or advertising identifiers, and we do not build any profile of you.
How the service is used
We keep a record of what happens on the website and in the app, so we can see which routes, dates and cabins people are interested in and improve the service. Each record holds the action — a search, a destination viewed, an alert created — along with the flight details it related to, the country it came from, whether it came from the website or the iPhone app, and the time.
If you are signed in, the record is linked to your account. If you are not, it is grouped under a temporary identifier worked out on our server; nothing is stored on your device for this.
We determine the country from your IP address at the moment of the request and then discard the address. These usage records do not contain IP addresses. Your IP address is separately recorded when you sign in, for security, and appears in our web server logs — see Sign-in sessions.
We do not use this for advertising, we do not build profiles for marketing, and we use no third-party analytics or tracking services: nothing about your activity is sent to another company.
We may publish, share or sell summary statistics — for example the most-searched routes in a month, or which travel months are most in demand. These are totals only: they contain no personal data, are never broken down to a level that could identify an individual, and are not linked to any account. Any figure covering fewer than ten people is withheld rather than released.
Lawful basis: legitimate interests — understanding how the service is used so that it can be run and improved.
How long we keep it
- Account data — until you delete your account (see below).
- Sign-in sessions — 30 days, then they expire. Expired sessions are purged automatically every night at 04:00 UTC.
- Part-completed two-factor sign-ins — 10 minutes.
- Password reset links — 1 hour, and each can only be used once.
- Email verification links — 24 hours.
- Usage records that identify you — 30 days. After that we remove the account and visit identifiers and keep the remaining details for 12 months.
- Summary totals — kept indefinitely. They cannot identify anyone.
Who else sees your data
We use a small number of service providers to run PointsRadar. They act on our instructions and are not permitted to use your data for their own purposes.
- Email provider — transactional email only (verify your address, reset your password, alert you to a flight). Your name and email address are shared in order to deliver these. We send no marketing email.
- Hosting provider — the server the application and database run on.
- Google Fonts — our web pages load a font from Google's servers, so your browser's IP address and user agent are visible to Google when a page loads. This is used only to serve the font; we receive no data back and set no Google cookies.
We will also disclose data where we are legally required to do so.
Cookies
We set exactly one cookie, pr_session, which keeps you signed in. It is
strictly necessary for the service to work, is not readable by JavaScript, is sent only
over HTTPS, and expires after 30 days. We use no analytics, advertising or tracking
cookies, which is why you are not asked to accept a cookie banner.
Deleting your account
You can delete your account yourself at any time, either in the mobile app under account settings, or by contacting us at info@pointsradar.co.uk.
Deletion is immediate and permanent. It removes your account record, your alerts and holiday alerts, your saved preferences and all of your sign-in sessions, and unlinks your account from our usage records so they can no longer be traced back to you. It is not a soft delete and there is no hidden retained copy. Once deleted, we cannot recover it.
Your rights
Under UK GDPR you have the right to:
- ask for a copy of the personal data we hold about you (access);
- have inaccurate data corrected (rectification) — you can change your name and password in the app directly;
- have your data deleted (erasure) — see above;
- ask us to restrict how we use it, or object to processing we carry out under legitimate interests;
- receive your data in a portable format.
To exercise any of these, email info@pointsradar.co.uk. We will respond within one month. If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk.
Where your data is held
Your data is stored on servers in the United Kingdom. Email delivery may involve systems outside the UK; where that happens the transfer is covered by the safeguards required under UK data protection law.
Security
Passwords are stored only as bcrypt hashes and never in plain text. Traffic is served over HTTPS. Session cookies are HTTP-only and marked Secure. Two-factor authentication is available on request in your account. No system is perfectly secure, but we aim to hold as little personal data as the service needs.
Children
PointsRadar is not directed at children and we do not knowingly collect data from anyone under 13.
Changes
If we change this policy we will update the date at the top of this page. Material changes affecting how we use your data will be notified by email.
Contact
Questions about this policy or your data: info@pointsradar.co.uk.