Privacy policy
Last updated 25 July 2026
VQFA is a hobby virtual airline — we're not a real airline or employer, but we still collect some personal data to run the staff structure, support tickets, and applications on this site, so this page covers what we collect, why, and what rights you have over it.
What we collect
- Your Discord ID and username, whenever you sign in — this is how we recognise you, and we never see or store your Discord password.
- If you apply for a staff position: the name and answers you submit on the application form.
- If you're appointed staff: your name, role, department, and a record of role/status changes over time.
- If you open a support ticket: the ticket content and any replies, so staff can help and so there's a record if you need to refer back to it.
- If you're staff and something needs formally recording (an internal note or a disciplinary action): who it concerns, what happened, and who recorded it. This is only ever visible to relevant leadership, never to the wider membership.
- If you're staff: an availability status you set yourself, any leave you request (dates and reason), and — if it applies — a probation end date. If you leave the airline, an exit interview may be recorded (your stated reason and any feedback), visible only to senior leadership, the same as disciplinary records.
- If you're invited to an internal meeting or training session, whether you attended is recorded against your name.
- If you're an Executive or Director: your name, position, and Discord profile picture are shown publicly on our Team page — not just internally. Your Discord avatar is pulled directly from Discord each time you sign in, and loading that page means a visitor's browser requests the image straight from Discord's own servers.
Why, and on what basis
We process this to run the airline: to let you sign in, to review applications, to provide support, and to keep an accurate account of staff appointments and conduct.
How long we keep it
- Session data (keeping you signed in) ends when you log out or your session expires.
- Support tickets are kept so there's a history if you need to refer back to a past issue.
- Appointment and disciplinary records don't have a delete option in the everyday staff dashboard — that's deliberate, so day-to-day access can't casually remove entries from what's meant to be an accountable, auditable log. If you'd like a record like this erased, contact us and we'll action it manually — it just isn't self-service from within the normal interface.
Who else sees it
- Discord Inc. — signing in and our bot's DM notifications rely on Discord's own platform, which has its own separate privacy policy governing how it handles your account. Loading our Team page also causes a visitor's browser to request Executive/Director profile pictures directly from Discord's servers.
- Our hosting provider — stores the database this site runs on.
- We don't sell your data, and we don't use it for advertising — there isn't any on this site.
- Data may be processed outside the UK (Discord's infrastructure is US-based), with the safeguards Discord itself provides as a data processor.
Cookies
We use one cookie — to keep you signed in. It's strictly necessary for the site to function and isn't used for tracking, analytics, or advertising.
Your rights
Under UK GDPR you can ask to see what we hold on you, ask us to correct anything inaccurate, ask us to restrict or object to certain processing, ask for a copy of your data, and ask us to erase it. Erasure of appointment or disciplinary records isn't something you can trigger yourself from the site — it takes a manual request to us — but we will action a genuine request.
If you're unhappy with how we've handled a request, you can complain to the Information Commissioner's Office, the UK's data protection regulator.
Changes to this policy
We may update this page as the site changes. Significant changes will be announced through our Discord server.
To exercise any of the above, or ask us anything about your data, open a support ticket.