Version 1.8 · Effective 5 October 2026
Your passport is never shown to anyone but us.
You verify your identity with your passport within 30 days of joining, because one passport backs one account — that is what keeps TJ-Aero a network of real, verified professionals. It is checked by hand by our verification staff (never by AI), never appears on your profile or to other members — and the copy is deleted as soon as you are verified.
PRIVACY NOTICE
Raffles Online Platforms ("we") operates TJ-Aero. This notice explains what personal data the platform
holds about you, why, who else sees it, how long we keep it, and what you can require of
us. It is written to describe what the software actually does.
Controller: Raffles Online Platforms, 4/27 Galkanda Road, Aniwatte, Kandy, Sri Lanka. Data protection contact — for questions, requests and complaints about your data: contact@tj-aero.com.
1. WHAT WE COLLECT
1.1 Identity and account. Your name, email address and password (stored only as a hash,
never in readable form) are needed to open an account. Within 30 days of joining you verify
your identity with your passport: its number, expiry date and, if you give it, issuing
country, and a copy of its photo page. The passport number is stored encrypted, and the copy
is deleted once your identity has been verified (section 3). Registration records the date
you accepted the Terms and took the Oath, together with the IP address and browser you used
at that moment.
1.2 Professional profile. Your role, job title, employer or business name, base airport,
city and country, biography, phone number, LinkedIn address, years of experience, flight
hours, type ratings, licences and issuing authorities, certificates, endorsements, work
authorisations, availability and rates, a profile photograph and cover image, and an
uploaded CV if you provide one. Where you set a base city, we store its approximate latitude
and longitude so that radius searches work. If you upload a medical certificate, that is
health information — see section 3A.
1.3 What you write and do here. Posts, comments, questions and answers, reviews,
endorsements, marketplace listings, flight requests, offers, airport and country
contributions, private messages and their attachments, support tickets and help-desk
conversations, travel journals and photo albums (Memories), route plans and any route
reports you choose to share, and your connections with other members. We log activity such
as searches you run and tools you use, with the IP address of the request, so that the site
can show you what you looked at and so we can investigate abuse.
1.4 Technical. Session records including IP address and browser user-agent; the time you were
last active on the site, which our staff can see; your interface preferences (language,
theme, sound). Cookies are covered in section 9. Each time you sign in we also record the kind
of device (computer, phone or tablet), its operating system, the browser and its version, and
whether you used the TJ-Aero app — not your IP address. We use this to understand which devices
members use so we can build and test the site for them, and you can see your own recent
sign-ins in Account settings, which also helps you spot a sign-in that was not you.
1.5 Payment. If you subscribe, payment is taken by an external payment provider. Card
numbers are entered on the provider's systems and never reach ours. We store the fact and
status of your subscription, not your card details.
1.6 Connected accounts. If you connect a third-party flight-operations account, we store
the access token you provide, encrypted, so the integration can run. You can disconnect it
at any time.
1.7 Two-factor sign-in. If you switch it on, we store the secret your authenticator app
uses, encrypted, and your one-use recovery codes, hashed.
2. WHY WE HOLD IT, AND ON WHAT BASIS
2.1 To provide the service you asked for — your account, profile, messages, listings and
tools. This is necessary to perform our contract with you.
2.2 To verify that members are who they say they are. This is the point of the platform:
professionals here rely on one another's word, and the value of an answer depends on
knowing who gave it. This is our legitimate interest, and yours.
2.3 To keep the network safe — preventing impersonation, duplicate accounts and evasion of
a ban, and investigating abuse reports. Legitimate interest.
2.4 To send you service messages: verification, password resets, notifications you have
turned on, and administrative notices. Contract and legitimate interest.
2.5 To send you news and announcement emails — only if you asked for them (the optional tick
box when you register, or the switch in Account Settings), or, where the law allows, as an
existing member about features of the platform similar to those you use. Every such email
carries an unsubscribe link, and you can switch them off in Account Settings. An unsubscribe
is final: we never add you back without your asking. Unsubscribing does not stop service
messages.
2.6 To meet legal obligations, and to establish or defend legal claims.
3. YOUR PASSPORT, SPECIFICALLY
TJ-Aero is a network of verified members. You do not need your passport to register: your
account opens straight away, unverified, and you have 30 days to verify your identity by
sending your passport — its number, its expiry date and a copy of its photo page. Only
passports are accepted, because a passport always carries an expiry date and because one
kind of document keeps one person to one account. One passport backs one account: this is
how we stop a removed member returning under a new name, and how a member's claimed identity
can be checked. Every passport is checked by hand by a member of our verification staff; no
automated system or artificial intelligence decides whether you are verified.
Until your identity is verified you can use the platform and post — on walls, in the
community, experiences and answers — but you cannot suggest changes to aerodrome, country or
routing information or take part in community votes, confirmations, reviews and endorsements, and
what you post is not added to aerodrome or country cards or other information members rely
on as fact. Other members can see that your identity is not yet verified. This is a safety
measure: members plan real flights with this information and rely on knowing who they are
dealing with. Once you are verified, you have full access, and your earlier experiences may
then be reviewed by staff for the cards like any verified member's. If 30 days pass without
your passport, the site asks you to verify before you continue; you can still contact us,
download your data or delete your account. This is a rule applied to every account in the
same way, and it lifts as soon as you send your passport.
We treat this as the most sensitive data we hold. The copy is kept on private storage that no
web address reaches: there is no public link to it, and it never appears on your profile or
anywhere other members can see. It can be opened only through a route that first checks the
viewer holds the identity-verification permission. Full administrators hold every permission
and so can open it; support staff hold only the permissions they have been granted, and
without that one they cannot. When your passport expires, the account is automatically
restricted until you send your renewed passport.
The copy is kept only until your identity has been verified. As soon as staff verify it, the
copy is deleted; we keep the passport number (encrypted), its issuing country if given, its
expiry date, and a record of who verified it and when. If staff cannot verify a passport,
the copy is deleted and you are told why so you can send it again. The copy is never
included in our backups and is shown to staff without being stored in their browser, so once
it is deleted no copy of it remains. When you renew your passport you send a new copy, which
is deleted in the same way once it has been checked.
You are not obliged to give it — but TJ-Aero is a verified-identity network, so an account
that is not verified stays restricted as described above.
3A. HEALTH INFORMATION (MEDICAL CERTIFICATES)
A medical certificate (for example a Class 1 medical) is health information, which the law
treats as a special category of personal data. Uploading one is optional, and we hold it
only with your explicit consent, given by a separate tick box when you upload it. It is used
only to verify it and to show its validity on your profile. Other members see its title and
verified status at most — never the document, whatever your visibility or sharing settings.
Only you and staff verifying it can open it. You can withdraw your consent at any time by
deleting it.
4. WHAT OTHER MEMBERS CAN SEE
4.1 Public to signed-in members, if your profile is set to public: your name, role, job
title, employer, base airport, city and country, biography, experience, credentials,
photographs, whether your identity has been verified, and anything you post publicly —
posts, answers, reviews, listings and contributions. Your listings show your name and declared role so that others can judge what
you are offering.
4.2 Never shown to other members: your email address, password, passport details, the copy
of your passport, payment status, connected-account tokens, IP addresses, and your private
messages.
4.3 You control whether your profile appears in the public directory, and you can change
that at any time in your profile settings.
5. AUTOMATED AND AI FEATURES
We do not train AI on your data, and nothing you do on TJ-Aero is used to train AI by us or
by anyone else. Every AI feature uses one provider, Anthropic, whose commercial terms do not
allow it to train its models on what we send. Our AI Policy lists every place AI is used,
what is sent and what is never sent: https://tj-aero.com/ai-policy
Some features send text to an external AI provider to generate a summary, a briefing, a
support answer, or to research public information — about an airport, a ground handler or a
company, including the business contact details those organisations publish. Emails sent to
our aerodrome-intelligence address are read by the AI provider to draft notes about
airports, which our staff review before anything is published; if you write to that address,
your message is processed that way. What is sent is the content of the request or the
message. Do not put personal details about yourself or anyone else into those fields if you
would not want them processed by that provider.
AI output is assistance, not authority. No decision with a legal or similarly significant
effect on you is made by automated means.
6. WHO ELSE PROCESSES IT
We do not sell your personal data, and we do not share it for anyone else's marketing.
We use service providers who process data on our instructions: Hostinger (hosting — our
database and uploaded files); Anthropic (the AI features in section 5); Mailjet and
Mailchimp (announcement and newsletter email); our own mail server at Hostinger (service
email); PayPal and PayHere (payments, if you subscribe); and Jitsi (8x8) for video meetings,
when you use them.
Announcement and newsletter mail is sent through a specialist marketing-email provider, and
for that purpose your name, email address and role are held in their system as well as ours.
Service mail is deliberately not sent that way: your verification and password-reset messages
go out on our own mail server, so that a problem at the marketing provider can never stop you
getting back into your account.
Unsubscribing is honoured in both systems. Whether you click the link in one of our emails or
the one in a campaign, the opt-out is recorded on both sides.
Pages with maps load the map tiles from OpenStreetMap: your browser contacts OpenStreetMap
directly, so it receives your IP address. Everything else on our pages — including the map
software and the fonts — is served from our own server.
We also read public aviation and weather data from aviation authorities and data providers
(for example NOAA and the Iowa Environmental Mesonet for historic weather, and NOTAM,
schedule and airport-data services). Those requests carry the airport or route being looked
at; they do not carry your identity.
We will disclose data where the law requires it, or to establish, exercise or defend legal
claims.
7. WHERE IT IS HELD
We are based in Sri Lanka, and our providers operate in several countries, so your data is
transferred and stored outside your own country, and outside Sri Lanka. We transfer it
because it is necessary to provide the service you asked for, and we rely on the contractual
safeguards in our agreements with those providers (section 6). Where the law of your
country, or Sri Lanka's Data Protection Authority, requires particular safeguards for such
transfers, we apply them.
8. HOW LONG WE KEEP IT
8.1 Account and profile data: for as long as your account exists.
8.2 Private messages and their attachments: kept for as long as your account exists, unless you
choose an auto-delete window in your settings. You may set your messages to be automatically and
permanently deleted after 3 months, 6 months or 1 year; a message is only auto-deleted once both
participants in the conversation have chosen a window, and then after the longer of the two.
8.3 Activity logs (searches and tools used, with the request's IP address) and sign-in device
records (section 1.4): 12 months, then deleted automatically. Session records expire when you sign out or after two hours without
activity.
8.4 Backups: we take a backup every day and keep the most recent twenty, so data you delete
may persist in a backup for about three weeks until that backup is replaced.
8.5 Signed agreement records: kept while your account exists and for six years after you
delete it, as evidence of what was agreed. When the account is deleted, any passport number
in the record is removed and replaced by a one-way fingerprint — it can confirm that a
passport was used before, but the number cannot be recovered from it.
8.5A Registrations we refuse: any passport copy is deleted when the registration is refused,
and the rest of the account is deleted twelve months later. A passport copy we cannot verify
is deleted when we decline it.
8.6 After you close your account: see section 10.
9. COOKIES
We use cookies that are necessary for the site to work: one that keeps you signed in, and
one that protects forms against cross-site request forgery. Your browser also keeps some
things on your own device — your display preferences, and unsent drafts and uploads so work
isn't lost if a page closes; these stay on your device until you submit them. We do not use
advertising or analytics cookies and we do not track you across other websites.
10. YOUR RIGHTS
Depending on where you live, you may have the right to obtain a copy of your data, to have
inaccurate data corrected or completed, to have data deleted, to withdraw your consent, to
restrict or object to processing, to ask for a review of a decision made by automated means
(we make none with legal or similarly significant effect), to receive your data in a
portable form, and to complain to a data protection authority. In Sri Lanka that is the Data
Protection Authority of Sri Lanka (www.dpa.gov.lk); elsewhere, your local authority.
YOUR RIGHT TO OBJECT. Where we rely on our legitimate interests (section 2), you may object
at any time, on grounds relating to your situation, and we will stop unless we have
compelling legitimate grounds or need the data for legal claims. You may object to marketing
at any time, for any reason, and we will stop — use the unsubscribe link or the switch in
Account Settings.
You can exercise several of these yourself: download a copy of your data (a machine-readable
file with the files you uploaded) from Account Settings, edit your profile at any time,
remove your own posts and listings, take your profile out of the public directory, switch
news emails on or off, and delete your account from your profile settings.
Deleting your account permanently removes your account, profile, listings, posts, journals
and photos, the files you uploaded (including your CV, certificates, photos and videos —
removed at once, and in any case within three days), your activity log and your help-desk
conversations, and your address from our mailing lists and our email providers' lists.
Private messages you exchanged stay with the other people in those conversations, because
they are theirs too: your messages and their attachments remain readable to them, shown as
from a "Deleted member", with your name and profile removed. They are deleted when the other
people delete their accounts too, or when the conversation's auto-delete setting removes
them. Contributions you made to the shared aviation reference data — corrections to an
airport card, a confirmed route, a reported fee — remain, because other members' operational
decisions rely on them, but they are no longer linked to your name. The signed agreement
record is kept as described in 8.5.
For anything you cannot do yourself, write to contact@tj-aero.com. We respond within one month; if a
request is complex we may extend that by up to two further months, and we will tell you
within the first month if we do. If we refuse a request, we will tell you why and how you
can appeal to the Data Protection Authority.
11. SECURITY
Passwords are stored hashed. Passport numbers, connected-account tokens and two-factor
secrets are stored encrypted. Our staff can see your account as you see it only if you allow
it: you switch on support access in Account Settings, for 24 hours, and can switch it off at any
time. A support view is read-only, lasts at most 30 minutes, never opens your messages, notes,
Copilot chats, identity or certificate documents, billing or applications, and is recorded with
its reason in Account Settings, where you can see every one. Access to passport data is limited to staff performing
verification, and staff accounts can be required to use two-factor sign-in. You can switch
on two-factor sign-in for your own account in Account Settings. No system is perfectly
secure, and we do not claim otherwise; if a breach affects your data and the law requires us
to tell you, we will.
12. CHILDREN
The platform is for aviation professionals and is not intended for anyone under 18. We do
not knowingly hold data about children.
13. CHANGES
We will update this notice when our practices change, and change the version and date
above. Where a change materially affects you, we will tell you rather than rely on you
noticing.
Version 1.8 · Effective 5 October 2026
Raffles Online Platforms
Raffles Online Platforms 4/27 Galkanda Road Aniwatte Kandy Sri Lanka
contact@tj-aero.com · +94 77 2920 111