Legal

Privacy Policy

Last updated 29 August 2026

What we hold, why we hold it, and how to get rid of it. Written specifically for this service rather than copied from a template — everything listed is data PointsRadar genuinely stores.

PointsRadar tracks Virgin Atlantic reward flight availability and emails you when the points cost of a flight you are watching drops below a limit you set.

This policy explains exactly what personal data we hold, why, and what you can do about it. We have kept it specific rather than generic: everything listed below is data the service genuinely stores.

We run no advertising and no third-party tracking of any kind. There are no third-party tracking SDKs in the website or the mobile app, and we do not sell, rent or share your data with anyone for marketing. We do keep our own record of how the service is used — described under How the service is used below.

Who is responsible for your data

PointsRadar is operated by James Arscott, who is the data controller for the purposes of UK GDPR and the Data Protection Act 2018. Contact: info@pointsradar.co.uk.

What we collect and why

DataWhyLawful basis
First name, last name, email address To create and identify your account, and to address emails to you Performance of a contract
Password, stored only as a bcrypt hash To sign you in. We never store or can see your actual password Performance of a contract
Alerts and holiday alerts you create — airports, dates, cabins, points limits They are the service. We check them after each data refresh and email you on a match Performance of a contract
IP address and browser/app user agent, recorded per sign-in session Session security — recognising your session and spotting misuse Legitimate interests (securing accounts)
Failed sign-in count and any temporary lockout time To slow down password guessing against your account Legitimate interests (securing accounts)
Last sign-in time and account creation time Account administration and support Legitimate interests (running the service)
If you turn on two-factor authentication: your authenticator secret and backup codes To verify your 2FA codes. Only stored if you choose to enable 2FA Performance of a contract
Your account tier and how it was set Decides which features and limits your account has Performance of a contract
Display preference (light or dark theme) So the app looks the way you left it Legitimate interests (running the service)
Short-lived email verification and password reset tokens To confirm your email address and let you reset a forgotten password Performance of a contract

We do not collect payment details, location data, contacts, photos, device identifiers or advertising identifiers, and we do not build any profile of you.

How the service is used

We keep a record of what happens on the website and in the app, so we can see which routes, dates and cabins people are interested in and improve the service. Each record holds the action — a search, a destination viewed, an alert created — along with the flight details it related to, the country it came from, whether it came from the website or the iPhone app, and the time.

If you are signed in, the record is linked to your account. If you are not, it is grouped under a temporary identifier worked out on our server; nothing is stored on your device for this.

We determine the country from your IP address at the moment of the request and then discard the address. These usage records do not contain IP addresses. Your IP address is separately recorded when you sign in, for security, and appears in our web server logs — see Sign-in sessions.

We do not use this for advertising, we do not build profiles for marketing, and we use no third-party analytics or tracking services: nothing about your activity is sent to another company.

We may publish, share or sell summary statistics — for example the most-searched routes in a month, or which travel months are most in demand. These are totals only: they contain no personal data, are never broken down to a level that could identify an individual, and are not linked to any account. Any figure covering fewer than ten people is withheld rather than released.

Lawful basis: legitimate interests — understanding how the service is used so that it can be run and improved.

How long we keep it

Who else sees your data

We use a small number of service providers to run PointsRadar. They act on our instructions and are not permitted to use your data for their own purposes.

We will also disclose data where we are legally required to do so.

Cookies

We set exactly one cookie, pr_session, which keeps you signed in. It is strictly necessary for the service to work, is not readable by JavaScript, is sent only over HTTPS, and expires after 30 days. We use no analytics, advertising or tracking cookies, which is why you are not asked to accept a cookie banner.

Deleting your account

You can delete your account yourself at any time, either in the mobile app under account settings, or by contacting us at info@pointsradar.co.uk.

Deletion is immediate and permanent. It removes your account record, your alerts and holiday alerts, your saved preferences and all of your sign-in sessions, and unlinks your account from our usage records so they can no longer be traced back to you. It is not a soft delete and there is no hidden retained copy. Once deleted, we cannot recover it.

Your rights

Under UK GDPR you have the right to:

To exercise any of these, email info@pointsradar.co.uk. We will respond within one month. If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk.

Where your data is held

Your data is stored on servers in the United Kingdom. Email delivery may involve systems outside the UK; where that happens the transfer is covered by the safeguards required under UK data protection law.

Security

Passwords are stored only as bcrypt hashes and never in plain text. Traffic is served over HTTPS. Session cookies are HTTP-only and marked Secure. Two-factor authentication is available on request in your account. No system is perfectly secure, but we aim to hold as little personal data as the service needs.

Children

PointsRadar is not directed at children and we do not knowingly collect data from anyone under 13.

Changes

If we change this policy we will update the date at the top of this page. Material changes affecting how we use your data will be notified by email.

Contact

Questions about this policy or your data: info@pointsradar.co.uk.