Information We Collect
Clear Path is intended to minimize personal data collection. The service may process account information, authentication and session data, saved evaluations, saved reports, organization metadata, password-reset request data, support submissions, operational logs, and other service data needed to run and secure the application.
Account, Profile, and Contact Data
Account records may include name, email address, role, organization affiliation, session state, password-reset request state, MFA-related state, billing metadata, and contact messages sent to support or legal/privacy channels. Contact emails may be retained for support follow-up, legal/privacy handling, product operations, and security review.
Saved Evaluations and Reports
Saved evaluations and saved reports are stored server-side so authorized users can access organization-scoped work product. These records may include project metadata, runway and obstacle inputs, results, assumptions, limitations, exports, and related evaluation context. Evaluation and report records may be retained and reviewed for support, quality review, auditability, product improvement, troubleshooting, abuse prevention, and security.
Technical and Log Data
The service may retain technical logs, audit records, request metadata, error data, and security-related records needed for authentication, troubleshooting, abuse prevention, operational monitoring, and service maintenance.
Operational Analytics and Usage Counters
Clear Path may retain limited operational analytics such as pricing/contact page views, demo or access-request starts, evaluation runs, report exports, unsupported or needs-review outcome counts, failed logins, password-reset activity, and route or API error counts. These records are used for support, reliability, security monitoring, launch readiness, and product improvement.
The service is designed to avoid collecting passwords, reset tokens, session tokens, full payment data, full report payloads, and unnecessary precise coordinates in these analytics records. Where possible, the application uses aggregate counts, route/action names, event timestamps, status/outcome labels, and coarse criteria or airport context instead of detailed payload capture.
When configured, the public site may also use privacy-conscious Google Analytics 4 events to understand page visits, product documentation usage, and conversion activity. Google Analytics and, when configured, Google Ads may receive allowlisted event names, page paths, CTA locations, plan and billing-interval labels, campaign parameters, coarse device categories, and activation status labels. Clear Path does not intentionally send passwords, payment card details, names, email addresses, phone numbers, evaluation inputs, coordinates, report contents, or free-form form body contents to Google Analytics.
Clear Path uses a first-party, pseudonymous analytics visitor cookie and an attribution cookie to preserve first-touch and latest-touch campaign information for up to 90 days. Campaign handling is limited to approved UTM fields and advertising click identifiers; referrers are reduced to a domain rather than retaining a full URL. Optional analytics failures do not prevent access to essential product functions.
The Analytics Preferences page allows visitors to decline or later re-enable optional analytics. Declining removes the first-party analytics and attribution cookies and prevents optional GA4, Google Ads, and internal conversion events from being recorded for subsequent activity in that browser. Essential authentication, billing, security, and audit records remain in place because they are required to operate and protect the service.
Structured product feedback may include a 1–5 usefulness rating, an optional category, a short comment, route and broad workflow stage, plan category, application version, and revision. Users are instructed not to submit sensitive project details. Identity is associated with a feedback record only when a signed-in user explicitly requests contact follow-up, and feedback is restricted to platform administrators.
Payment Provider Data
When paid billing is enabled through a designated third-party payment processor,Clear Path may store billing status, plan, customer identifiers, subscription identifiers, and billing event records, but it is not intended to directly store full card numbers or raw payment instrument data.
Third-Party Services
Clear Path may rely on third-party services for hosting, authentication support, mapping support, operational tooling, future billing support, or future automated email delivery. Those services may process limited information as needed to support the application.
Data Security and Retention
Clear Path uses reasonable administrative and technical measures intended to protect service data, but no system can guarantee absolute security. Data retention periods may depend on operational needs, legal requirements, account status, billing records, troubleshooting needs, and organization-level usage.
Retention or deletion requests may be evaluated in light of account ownership, organization controls, legal obligations, billing records, fraud prevention, operational safety, and security needs.
The current operational schedule retains campaign attribution for up to 90 days, detailed internal conversion events for up to 13 months, and product feedback for up to 24 months unless a shorter period is required by a valid request or a longer period is needed for security, legal, billing, or documented operational reasons. Aggregated reporting may be retained longer after it can no longer be used to reconstruct an individual product journey. Provider-managed analytics retention is controlled in the applicable Google property.
Account deactivation or deletion does not necessarily remove related audit, security, billing, or report records immediately. Some records may be retained to preserve service integrity, contractual history, fraud prevention posture, and legal compliance.
User Responsibility
Users remain responsible for reviewing what information they upload or enter into Clear Path and for ensuring they have authority to provide that information for evaluation, reporting, collaboration, or support purposes.
Privacy Contact and Supplemental Rights
Privacy contact, data request handling, retention detail, deletion workflow detail, and jurisdiction-specific rights handling may vary based on deployment and applicable law. Current privacy contact: support@airspaceevaluator.com.
