PRIVACY POLICY
Effective date: 2026-09-26
VariFlight ("we", "us") operates the VariFlight AI Open Platform (ai.variflight.com, the "Platform"), providing aviation and travel data services to developers and businesses over the MCP protocol. We take your personal information seriously and protect it in accordance with the Personal Information Protection Law of the PRC and, for users in the European Union, the General Data Protection Regulation (GDPR). This policy explains what we collect, how we use and protect it, and the rights you have. By using the Platform you acknowledge that you have read and understood this policy.
Account information: registration requires a username, email address and password (stored hashed); a phone number and company name are optional. We use this to create and manage your account, send activation and security emails, and provide support.
API usage records: to enable usage-based billing, statistics and service assurance, we log the endpoint name, timestamp, billed amount and request identifier of each call. For troubleshooting and billing disputes we also log the source IP address, request parameters (such as flight numbers, airport or city codes and dates) and the returned results; these detailed records are deleted automatically after 30 days.
Transaction information: when you top up, we record the order amount, payment channel and the channel transaction reference. Payment itself is processed by licensed payment institutions such as Alipay or Stripe — we do not collect or store your card number, payment account credentials or other sensitive payment data.
Communications: when you contact us by email or WeChat, we keep the correspondence to follow up on your request.
We will seek your separate consent before using your personal information for any purpose beyond those stated above.
You can connect the Platform to MCP-compatible AI clients such as Claude through OAuth. When you authorize a client, you sign in to the Platform and approve access; we then issue the client an access token and a refresh token linked to your account, and its calls are billed to your account.
For calls made through an AI client, we receive only the request parameters the client sends to run a tool. We do not receive your conversations with the AI assistant or any other content. The parameters we receive are logged and retained as described under API usage records above.
You can revoke access at any time by disconnecting the Platform in the AI client. Access tokens expire after 1 hour and refresh tokens after 30 days.
The Platform uses no tracking, advertising or third-party analytics cookies. We only keep the following service-related items in your browser's local storage:
"Strictly necessary" items are required to provide the service (such as keeping you signed in) and, under the EU ePrivacy Directive, do not require consent; "Preference" items only remember your interface choices. You can clear them at any time via your browser settings — you will then need to sign in and set your preferences again. Should we ever introduce analytics cookies, we will ask for your consent before using them.
| Item | Purpose | Category |
|---|---|---|
| token | Session credential that keeps you signed in | Strictly necessary |
| user-language | Remembers your interface language | Preference |
| user-theme | Remembers your light/dark theme choice | Preference |
| console-sidebar-collapsed | Remembers the console sidebar state | Preference |
| cookie-notice-ack | Records that you have seen our storage notice | Strictly necessary |
Your personal information is stored by default on servers located in the People's Republic of China. We apply transport encryption (HTTPS/TLS), salted password hashing, API-key permission isolation, least-privilege access control and operational auditing to protect it.
We retain personal information only as long as necessary for the purposes described here: account data until you delete your account; transaction and billing records for the period required by finance and tax regulations; usage logs for billing reconciliation, after which they are deleted or anonymized.
In the event of a personal-information security incident, we will notify you of the basic facts, the possible impact and the measures we have taken, as required by law.
We do not sell your personal information. We share necessary information only: (1) with payment institutions such as Alipay and Stripe, limited to the order amount and order reference, to complete a payment; (2) with your explicit consent; (3) where required by law, legal proceedings, or requests from competent authorities; (4) in aggregated, anonymized form that cannot identify any individual, for statistical analysis.
In the event of a merger, acquisition or asset transfer, we will require the successor to remain bound by this policy or to obtain your consent anew.
You can access and correct your account information, manage API keys, and review transactions and usage in the console. You may also contact us using the details at the end of this policy to request access, correction, supplementation or deletion of your personal information, or to close your account.
We will respond within 30 days of verifying your identity. After account deletion we will delete or anonymize your personal information, except where laws and regulations require otherwise.
The Platform is intended for developers and business users and is not directed at minors under 18. Minors must obtain prior written consent from a parent or guardian before using the Platform. If we learn that we have collected a minor's personal information without such consent, we will delete it as soon as practicable.
If you are located in the European Economic Area, our legal bases for processing are: performance of our contract with you (account and billing), your consent (withdrawable at any time without affecting prior processing), and our legitimate interests (service security and fraud prevention).
Because our servers are located in China, your personal information is transferred to China. We safeguard such transfers with measures including the Standard Contractual Clauses (SCCs) under the GDPR.
In addition to the rights above, you have the GDPR rights to data portability, restriction of processing and objection to processing, and the right to lodge a complaint with your local data protection authority.
We may revise this policy from time to time. Updated versions will be published on this page with a new effective date. For material changes we will notify you prominently on the site or by email, and where renewed consent is required, we will process the relevant data only after obtaining it.
For any questions, comments or requests regarding this policy or your personal information, please contact:
Email: mcp@variflight.com (Data & Privacy Protection)
Address (China): Building E, High-tech Innovation Valley Industrial Park, No. 1856 Wenqu Road, High-tech District, Hefei, Anhui, China
Address (Singapore): 1 Raffles Place, #02-209, Singapore 048616