Layover
HomeHelpSign in →
Layover · LegalDoc 01

Privacy policy.

Last updated 16 June 2026 · Effective 16 June 2026
Contents
  1. Who we are
  2. What we collect
  3. Why we collect it
  4. How long we keep it
  5. Who we share it with
  6. International transfers
  7. Your rights
  8. Security
  9. Children
  10. Changes
  11. Contact
Short version

Layover collects only the data it needs to calculate your pay, plus an email so you can sign in. We don't link to your bank, we don't sell data, and we don't track you across the internet. You can export or delete everything at any time.

01

Who we are

Layover is operated by Billy Redwood, trading as Layover, based in the United Kingdom. For the purposes of UK GDPR and the Data Protection Act 2018, Layover is the data controller of the personal data described in this policy.

You can reach us at privacy@getlayover.app.

02

What we collect

We collect only what's needed to run Layover. Today, that's three categories:

CategoryExamples
AccountEmail address, display name, sign-in timestamps.
Pay settingsHourly rates, contract type, overtime rules, holiday accrual configuration, employer/base (e.g. LGW).
Duty & pay dataSectors flown, block hours, duty hours, dates, commission entries, computed pay outputs.

We do notconnect to your bank, your airline's payroll system, or your roster system. Everything in Layover is entered by you or generated from what you've entered.

We collect minimal technical data — IP address and browser type — when you load the app, used solely for security and abuse prevention. We use Vercel Analytics for privacy-first, cookieless page view analytics — no advertising trackers or cross-site tracking (see the cookies policy).

03

Why we collect it (lawful basis)

Under UK GDPR, every use of your data needs a lawful basis. Ours are:

  • Performance of a contract— to provide the service you've signed up for (calculating your pay, storing your duty log, letting you sign in).
  • Legitimate interests — to keep the service secure, prevent abuse, and improve how Layover works. We balance this against your privacy and only do what a reasonable person would expect.
  • Legal obligation — where the law requires us to retain or disclose data.
04

How long we keep it

While your account is active, we keep your data so the service works. If you delete your account, we delete your personal data within 30 days, except where we're required to retain a record (e.g. for fraud, security, or legal reasons), in which case we keep the minimum we need for the minimum time required.

If you invite a colleague by email, their email address is stored only until they sign up (at which point it is deleted immediately) or for a maximum of 7 days if the invitation is not used.

Backups are rotated and overwritten on a rolling schedule of no more than 35 days.

05

Who we share it with

We don't sell your data. We share it only with the service providers Layover runs on top of, each acting as a data processor under contract with us:

ProviderWhat for
VercelHosting the web app and cookieless page view analytics (Vercel Analytics).
SupabaseAuthentication and database storage.
ResendSending transactional email (sign-in links, account notices, monthly pay summaries, and usage nudges). Monthly summary emails include pay totals and route data.

We may also disclose data if compelled by a valid legal request, or to protect the rights, property, or safety of Layover, our users, or others.

06

International transfers

Our providers may process data in the EU, the UK, or the US. Where data is transferred outside the UK, we rely on the UK International Data Transfer Agreement (IDTA) or equivalent safeguards (e.g. Standard Contractual Clauses, adequacy decisions). You can request a copy of the relevant transfer mechanism by emailing us.

07

Your rights

Under UK GDPR, you have the right to:

  • Access — ask for a copy of the personal data we hold about you.
  • Rectify — correct anything that's wrong.
  • Erase — ask us to delete your data (right to be forgotten).
  • Restrict — limit how we use your data.
  • Port — receive a copy in a portable format (we offer CSV export from the app).
  • Object — to processing based on legitimate interests.
  • Withdraw consent— where we rely on consent (currently we don't, but this remains your right).

To exercise any of these, email privacy@getlayover.app. We aim to respond within 30 days.

If you're not satisfied with our response, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

08

Security

Data is encrypted in transit (TLS) and at rest. Authentication uses one-time email links — there are no passwords stored on our side. Access to production data is limited to the founder and is reviewed regularly.

No system is unbreakable. If a breach occurs that affects your data, we will notify you and the ICO within 72 hours, as required by law.

09

Children

Layover is intended for working cabin crew, who are by definition adults. We don't knowingly collect data from anyone under 18. If you believe a child has signed up, please contact us and we'll delete the account.

10

Changes to this policy

If we make a meaningful change to how we handle your data, we'll update this page and email you. The “last updated” date at the top reflects the most recent change. Continuing to use Layover after a change means you accept the updated policy.

11

Contact

Privacy questions: privacy@getlayover.app
Everything else: hello@getlayover.app

Layover

The salary app for cabin crew. Built between sectors, not in a boardroom.

On this page
  • Privacy policy
  • Cookie policy
  • Terms of service
  • Help centre
Get help
  • Help centre
  • Contact support
  • Sign in →
Legal
  • Privacy
  • Cookies
  • Terms
© 2026 LAYOVER · GETLAYOVER.APP · BUILT BY CREWLayover is an independent product, not affiliated with any airline.