StatusRunner · Privacy

StatusRunner Privacy Policy

How StatusRunner collects, uses, protects, and lets you control your personal data — written to meet the EU/UK General Data Protection Regulation (GDPR), in plain English.

Version 1.0 Last updated [TODO: publication date] Applies to StatusRunner for iOS & Android
This document was AI-drafted. It is a starting point, not legal advice. Have it reviewed by a qualified privacy lawyer before you publish it.

01Who we are

StatusRunner ("StatusRunner", "the app", "we", "us", or "our") is a mobile app that helps frequent flyers track their airline loyalty program status — status credits and points, membership tiers, annual goals, flight history, and the credit cards they use to earn travel rewards. It is available on the Apple App Store and Google Play for iOS and Android.

For the purposes of the GDPR, the data controller — the person who decides how and why your personal data is used — is the developer of StatusRunner, based in Australia.

Fill in before publishing

Controller identity: [TODO: your legal entity name and ABN if you operate as a business, or your full legal name if you are a sole trader].

Registered / business address: [TODO: a postal or business address — some regulators require one; a PO box or business address is common for individuals].

Privacy contact: [TODO: an email address, e.g. privacy@statusrunner.app].

If you have any question about this policy or about how your data is handled, you can reach us at the email above. This is also the address you use to exercise any of your rights (see Your rights under the GDPR).

02Scope & why the GDPR applies to us

StatusRunner is published globally, so people in the European Union, the United Kingdom, and elsewhere can download and use it even though the developer is based in Australia. Because we offer the app to people located in the EU and UK, the GDPR applies to us under its "extraterritorial" reach (Article 3(2)) — regardless of where we are based. This policy is written to meet those obligations. It also reflects our commitments under Australian privacy law.

Legal review recommended

Because the GDPR applies to a controller outside the EU/UK, Article 27 may require you to appoint an EU representative (and the UK GDPR a separate UK representative) unless an exemption applies. As an Australian business you may also have obligations under the Privacy Act 1988 and the Australian Privacy Principles. Please confirm both points with a qualified adviser and add representative details here if required.

03How we follow the GDPR principles

The GDPR sets out seven core principles for handling personal data (Article 5(1)). Here is how StatusRunner meets each one — the rest of this policy fills in the detail.

Lawfulness, fairness & transparency

We only collect data where we have a clear legal basis for it (set out in the table below), we use it only in ways you would reasonably expect, and we explain all of it plainly in this policy.

Purpose limitation

Each piece of data is collected for a specific, stated purpose — running your account and the tracking features you asked for, and keeping the service secure. We do not reuse it for unrelated purposes.

Data minimisation

We collect the minimum needed to make the app work. We deliberately do not collect device location, contacts, payment card numbers, advertising identifiers, or behavioural analytics.

Accuracy

Most of your data is entered and edited by you inside the app, so you can keep it accurate at any time. You can also ask us to correct anything we hold about you (see your rights).

Storage limitation

We keep your data only while your account is active, plus limited security and diagnostic logs for a bounded period. When you delete your account we delete your data. See How long we keep your data.

Integrity & confidentiality (security)

We protect your data with encryption in transit and at rest, secure OS-level storage for login tokens, and passwordless sign-in. See How we protect your data.

Accountability

We take responsibility for the above: we document what we collect and why, we choose processors that offer GDPR-compliant terms, we honour your rights, and we commit to reporting breaches. This policy is part of how we demonstrate that.

04What we collect and our legal basis for it

StatusRunner collects only what it needs to run your account and the tracking features you use. The table below lists every category of personal data we collect, why we collect it, and our lawful basis for it under Article 6 of the GDPR.

Every category of personal data StatusRunner collects, and the Article 6 lawful basis for each.
DataWhy we collect itLawful basis
Email addressTo create and identify your account and to sign you in. We use passwordless login: we email you a one-time 6-digit code instead of storing a password.Contract
Art 6(1)(b)
Authentication tokens (access & refresh tokens)To keep you signed in without re-entering a code every time. Stored in your device's secure storage (iOS Keychain / Android Keystore), never in plain text.Contract
Art 6(1)(b)
Device name & platform (e.g. "iPhone 15, iOS")Sent once when you sign in, used only for security context — recognising your trusted devices. Not used for tracking or advertising.Legitimate interest
Art 6(1)(f)
IP addressRecorded on our servers for every request, for security monitoring, abuse and rate-limit detection, and diagnosing backend faults. See the note below — we do log this.Legitimate interest
Art 6(1)(f)
Travel data (flight dates, airports, routes, airline)Core feature: tracking your past and planned flights toward loyalty status goals. Entered by you — not read from device location. See the note below.Contract
Art 6(1)(b)
Loyalty program data (program, membership number, tier, status credits, goals)Core feature: tracking your membership status and progress toward your annual goals.Contract
Art 6(1)(b)
Credit card tracking metadata (card label, signup bonus, annual fee, key dates, reminder preference)Core feature: helping you work out which rewards card is most cost-effective. This is not payment data — see the note below.Contract
Art 6(1)(b)

What "legitimate interest" means here

For device details and IP addresses we rely on legitimate interest — our genuine need to keep the service secure and working, balanced against your privacy. We use these only for security and diagnostics, never to build a profile of you or to advertise to you. You can object to this processing at any time (see your rights).

Legal review recommended

Where you rely on legitimate interest (device details, IP addresses), the GDPR expects a documented Legitimate Interests Assessment weighing your interest against the user's rights. Consider recording one to support the accountability principle.

IP addresses are logged

We want to be clear about this: your IP address is collected on our servers on every request through Azure Application Insights, and used for security monitoring and diagnostics. We do not claim your IP is anonymised or unlogged — it is logged, and kept for the retention period described in How long we keep your data.

05A note on your travel data

StatusRunner does not use your device's GPS or location services, and it does not ask for location permission. Every flight, airport, route, and date is information you type in yourself.

That said, we treat your travel history with extra care. Taken together over time, a record of where and when you have flown can reveal patterns about your movements. So even though it is not device-tracked location data, we handle it as sensitive, location-adjacent personal information — kept private to your account, used only for the tracking features, and never sold or shared for marketing.

06Not financial or payment data

Your card details are safe with your bank, not us

The credit card features in StatusRunner are for tracking rewards, not for payments. We store only descriptive details you enter — a card nickname, the signup bonus, the annual fee, open/renewal/exclusion dates, and whether you want a renewal reminder.

We do not collect or store card numbers, CVV codes, expiry dates, or any actual payment credentials. No payment is ever processed in the app. Because we never handle real cardholder data, StatusRunner falls outside the scope of the PCI-DSS payment card security standard.

07No advertising, analytics or tracking

StatusRunner contains no advertising or analytics SDKs — no Firebase Analytics, AdMob, Facebook SDK, App Center, Crashlytics, or similar. We do not track your behaviour, we do not collect advertising identifiers, and we do not track you across other apps or websites.

Because we do not track you, Apple's App Tracking Transparency prompt does not apply. The only server-side telemetry we keep is operational — error logs and the IP-based security diagnostics described above — and it is never used for advertising.

08Who processes your data for us

We keep the list of third parties deliberately short. All of StatusRunner's backend runs on Microsoft Azure, which acts as our data processor (and sub-processor) under GDPR-compliant terms in Microsoft's Online Services Terms / Data Protection Addendum. Specifically we use:

  • Azure Functions — the secure API the app talks to (all traffic over HTTPS, TLS 1.2 minimum).
  • Azure SQL Database — the main store for your account and tracking data, encrypted at rest.
  • Azure Key Vault — safekeeping of our secrets and keys.
  • Azure Communication Services / Email Services — sends your one-time login code emails from the statusrunner.app domain.
  • Azure Application Insights — server-side error logging and operational telemetry, which includes IP addresses (as described above).
We do not sell your data

We do not sell your personal data, and we do not share it with data brokers or advertisers. The only parties that process it are the infrastructure providers listed above, acting on our instructions to run the service.

09International data transfers

StatusRunner has an international shape, and we want to be upfront about it. The developer is based in Australia. The app is used by people all over the world, including in the EU and UK. And our backend is hosted with our cloud provider (Microsoft Azure) in whichever region is most cost-effective at the time — which may be outside Australia and outside the EU/EEA, and currently is in the United States. We may move between regions or countries over time as a cost decision, so we describe this in general terms rather than naming a fixed location that could go out of date.

This means your personal data may be transferred to and processed in a country other than your own, including outside the EU/EEA and the UK. Where that happens, the transfer is protected by the safeguards our cloud provider offers under Article 46 of the GDPR — Microsoft's Standard Contractual Clauses and its participation in the EU–US Data Privacy Framework — which are designed to give your data a level of protection comparable to that in the EU/EEA wherever it is processed.

Legal review recommended

Confirm that the specific transfer mechanism you rely on (Standard Contractual Clauses and/or the EU–US Data Privacy Framework, and the UK equivalent — the UK Addendum / International Data Transfer Agreement) matches the Azure regions you actually use, and update the wording if your adviser recommends naming them.

10How long we keep your data

We keep your personal data only as long as we need it:

  • Account and tracking data — kept for as long as your account is active, so your flight history, loyalty status, and card tracking are there when you come back.
  • Security and diagnostic logs (including IP addresses in Azure Application Insights) — kept for a limited period and then automatically removed.
  • After you delete your account — we delete your personal data from our systems, subject to short backup and log-rotation windows.
Fill in before publishing

Log retention: [TODO: confirm your configured Application Insights retention period — the default is 90 days].

Deletion timeframe: [TODO: state the actual period within which you delete data after an account-deletion request, e.g. "within 30 days" — and make sure it matches what your system actually does].

Account deletion flow: [TODO: both Apple (Guideline 5.1.1(v)) and Google Play require an in-app way to delete an account. If this is not built yet, do not claim it exists here — describe requesting deletion by email until it ships].

You can ask us to delete your data at any time by emailing us (see your rights), whether or not the in-app deletion option is available.

11How we protect your data

Security is built into how StatusRunner works. The measures we have in place include:

  • Encryption in transit — all traffic between the app and our servers uses HTTPS with TLS 1.2 as the minimum.
  • Encryption at rest — your data in the database is encrypted using Azure SQL Transparent Data Encryption.
  • Secure token storage — your login tokens are held in your device's OS-level secure storage (iOS Keychain / Android Keystore), never in plain text.
  • Passwordless sign-in — we use one-time email codes, so there are no passwords stored or hashed that could be leaked.
  • Managed secrets — our keys and secrets are kept in Azure Key Vault.

No system can be guaranteed perfectly secure, but these measures reflect our commitment to protecting the confidentiality and integrity of your data.

12Your rights under the GDPR

If the GDPR applies to you, you have the following rights over your personal data. To exercise any of them, email us at privacy@statusrunner.app. We will respond within one month, and we will not charge you for it in normal circumstances.

Right of access Art 15

See what we hold. You can ask for a copy of the personal data we hold about you and information about how we use it.

Right to rectification Art 16

Fix what's wrong. You can correct inaccurate data or complete anything incomplete — most of it you can also edit directly in the app.

Right to erasure Art 17

Be forgotten. You can ask us to delete your personal data — for example by deleting your account.

Right to restriction Art 18

Pause our use of it. You can ask us to limit how we use your data in certain situations, for example while a correction request is being resolved.

Right to data portability Art 20

Take it with you. You can ask for the data you gave us in a structured, commonly used, machine-readable format.

Right to object Art 21

Say no. You can object to processing based on our legitimate interests — for example the security uses of device details and IP addresses.

Rights around automated decisions Art 22

A human, not just a machine. StatusRunner does not make automated decisions with legal or similarly significant effects about you.

Right to withdraw consent Art 7

Change your mind. Where we ever rely on your consent, you can withdraw it at any time, without affecting anything done beforehand.

Right to lodge a complaint Art 77

Escalate to a regulator. You can complain to a data protection supervisory authority — usually in your country of residence or work. In Australia this is the Office of the Australian Information Commissioner (OAIC). We'd appreciate the chance to help first, but that is your right.

13If there is a data breach

We take steps to prevent data breaches, but if one happens we will act on it. In line with Articles 33 and 34 of the GDPR, where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to you, we will also inform you directly and without undue delay, and tell you what happened and what you can do about it.

14Children's data

StatusRunner is not directed at children and is not designed for anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

Fill in before publishing

There is currently no age-gating in the app. [TODO: confirm whether an age gate or age declaration is required for your chosen App Store / Play Store age rating, and add one if needed.]

15Changes to this policy

We may update this policy from time to time — for example if the app gains new features or the way we handle data changes. When we do, we will update the version number and the "Last updated" date at the top of this page. If a change is significant, we will take reasonable steps to let you know. Your continued use of StatusRunner after an update means you accept the revised policy.

16How to contact us

For any privacy question, or to exercise any of your rights, contact the data controller at privacy@statusrunner.app. You can also write to us at [TODO: registered / business address]. We aim to respond to all privacy requests within one month.

# TODO — complete before you publish

Every placeholder in this draft, collected in one place. Fill each one in (or remove the surrounding sentence if it doesn't apply) before this policy goes live.

  • Controller identity — legal entity name and ABN (if a business), or your full legal name (if a sole trader).
  • Privacy contact email — e.g. privacy@statusrunner.app (used in several places).
  • Registered / business address — a postal or business address; a PO box is common for individuals.
  • "Last updated" date — the date you publish this version.
  • Application Insights log retention — confirm your configured period (default is 90 days).
  • Deletion timeframe — how long after a deletion request you actually delete data (e.g. 30 days); make it match your implementation.
  • In-app account deletion — required by Apple (5.1.1(v)) and Google Play. If not built yet, don't claim it exists; describe email-based deletion until it ships.
  • Children / age-gating — confirm whether an age gate is required for your store age rating, and add one if needed.
  • Legal review — EU/UK representative — check whether Article 27 requires you to appoint an EU (and separate UK) representative, and add details if so.
  • Legal review — Australian Privacy Act — confirm your obligations under the Privacy Act 1988 / Australian Privacy Principles.
  • Legal review — Legitimate Interests Assessment — consider documenting an LIA for device details and IP-address processing.
  • Legal review — transfer mechanism — confirm SCCs / EU–US Data Privacy Framework (and the UK equivalent) match the Azure regions you use.
  • Overall legal review — have a qualified privacy lawyer review the whole policy before publishing.

StatusRunner Privacy Policy · Version 1.0 · Last updated [TODO: publication date]. This AI-drafted document is not legal advice; please have it reviewed by a qualified privacy lawyer before publishing.

↑ Back to top