Privacy

How we handle your data.

FloorPilot uses role- and event-based controls to limit access to operational information. The exact visibility rules depend on the module, role and pilot configuration. This page explains what happens on the website itself.

Website and pilot form

What the pilot request form collects.

When you submit the pilot request form, it can collect:

  • Name
  • Organisation
  • Role
  • Business email address
  • Phone number (optional)
  • Organisation website (optional)
  • Event type
  • Expected visitor size
  • Desired start period
  • Events per year (optional)
  • Description of your operational challenge
  • Package interest
  • Technical sending and status information
Purpose

Why we collect this.

  • To respond to your request.
  • To assess whether FloorPilot is a good fit.
  • To prepare a demo, pilot or proposal.
  • To prevent spam and abuse.
  • To follow up on the conversation.
Processing

What actually happens with your request.

  • Your request is stored in the FloorPilot database.
  • An email notification may be sent through our configured email provider.
  • We do not sell your information.
  • Request data is not automatically shared with a municipality, organiser or other customer.
  • Operational customer data is kept separate from public marketing requests.
Your rights

Access, correction, deletion, objection.

You can ask us to access, correct or delete your data, or object to how it is used. Contact us at info@wearefloorpilot.com.

Retention and processors

How long we keep data and who processes it.

Retention period

Event data is kept for twelve months by default, counted from the moment an event is closed. After that the file becomes eligible for deletion. An event that has not been closed is never deleted automatically. The period is fixed per organisation and cannot yet be changed inside the app. The clean-up job currently runs as a trial round: it determines which files have expired and records that, but it does not delete anything yet. If we switch that on, we say so in advance. Every round is recorded.

Processors we rely on
  • Supabase — database, authentication and file storage.
  • Vercel — application hosting.
  • Sentry — error reporting, so failures become visible.
  • Postmark — processing of inbound email with attachments.
  • Anthropic — the assistant that recognises and summarises documents.

The assistant proposes; a person decides. No medical data is sent to an external party.

Mobile app

What the FloorPilot app does on your device.

On-device features
  • Camera — only to scan a QR code when joining an event as crew. No photos are stored or uploaded.
  • Face ID / fingerprint / PIN — to unlock the app after first sign-in. Biometric data never leaves your device; we only receive "unlocked".
  • Push notifications — for operational alerts you sign up for. You can disable them in your device settings.
  • Local storage — your session and offline queue, so the app keeps working with poor connectivity on event grounds.
What the app does not do
  • No location tracking.
  • No advertising and no advertising identifiers.
  • No analytics profiles of individual users.
  • No access to your contacts, photos or files beyond what you explicitly upload.

The app talks to the same platform as the web portal; everything above about retention and processors applies equally.

Still to be finalised

What this notice does not yet cover.

The legal basis per processing purpose and the international transfer mechanism have not been legally reviewed yet, and no signed data processing agreement is available. We would rather say that honestly than invent it. If you work at a municipality and need these documents for a tender or an assessment, ask for them and we will provide them before any data is exchanged.

Last updated: 9 September 2026