Privacy Policy
Privacy at PointPilot.
This policy explains how PointPilot processes personal data during the closed beta.
Last updated 30 July 20261. Controller and contact
PointPilot is responsible for processing personal data in the PointPilot service. Privacy enquiries may be sent to hello@pointpilot.no.
2. Data we process
Depending on how you use the service, we may process:
- account information such as your email address, authentication status and necessary security data;
- the EuroBonus and travel profile you provide, including points balance, card benefits, Companion Tickets, travel party and relevant dates of birth;
- Travel Goals, searches, saved trips and requests for manual verification;
- technical security and operational data required for sign-in, troubleshooting and protection of the service.
PointPilot does not request or store SAS passwords or passport numbers.
3. Purposes and legal basis
We use the information to:
- provide and secure your account and the beta service;
- calculate and explain EuroBonus strategies;
- store and follow your Travel Goals;
- respond to support and privacy enquiries;
- prevent abuse and resolve technical issues.
Processing will normally be based on the beta access agreement, steps taken before entering that agreement, our legitimate interests in secure and stable operation, and applicable legal obligations.
4. Providers and international transfers
PointPilot uses trusted providers for hosting, authentication, databases and necessary transactional email. Vercel and Supabase are key technical providers in the current service. Providers may process data only for agreed purposes and with appropriate safeguards.
Where data is processed outside the EEA, the transfer must rely on a valid transfer mechanism and appropriate safeguards.
5. Retention and deletion
We retain data while your account or beta participation is active, or for as long as it is required for its purpose, security or legal obligations. You may request access, correction or deletion by contacting us.
Any demonstration data is kept separate from authenticated accounts and is not transferred automatically into your profile.
6. Cookies and local storage
The service uses necessary cookies for sign-in, session security and multi-factor authentication. Local storage may be used for the user’s own presentation preferences and explicit demonstration mode. PointPilot does not use marketing tracking in the current beta.
7. Your rights
Where the legal requirements are met, you may request access, correction, deletion, restriction or data portability, or object to processing. You may also lodge a complaint with the Norwegian Data Protection Authority. Contact hello@pointpilot.no to exercise your rights.
8. Security and changes
PointPilot uses access controls, multi-factor authentication, row-level security and separated environments to protect data. No online service can be guaranteed entirely risk-free. Material changes to this policy will be published on this page with a new date.