What we collect, why, and what we never do with it.
FIDS is operated by Antifragile Technologies, based in Dubai, United Arab Emirates. This policy covers the FIDS website (fids.ae), the console (app.fids.ae) and the flight boards it displays. For anything in it, write to [email protected].
To run your account we hold your email address and a hashed password — the password is stored only as a scrypt hash, so a database read never yields it. To keep you signed in we set a session cookie. To run your screens we hold the screens you create and their settings, and any hotel logo you upload for a board. A paired display holds only an anonymous device token in a cookie — never your account — and reports a periodic heartbeat so your dashboard can show whether the screen is online.
We do not collect anything about the guests who look at a board. A board has no camera, no analytics and no advertising; it only reads flight and weather data and shows it.
The flights on a board come from a third-party aviation data provider, reached through an API gateway. The weather comes from a third-party weather data provider. A board requests this data by airport in order to display it; it sends nothing about you or your guests to either of them.
If you switch on drive times, a screen can show how long it takes to reach each terminal from your building in current traffic. To do that we send Google two things: an identifier for the address you chose, and identifiers for the destinations you chose. Nothing else goes with it — not your account, not your screen, and nothing at all about the guests standing in front of the board. Google returns a number of minutes and we show it.
We store the identifiers Google gives us for the places you pick, so a screen can ask again without searching each time, and we keep the answer for a few minutes so several screens in one building share a single lookup. Address search in the console is also powered by Google, which is credited there. Leave the feature off and nothing is ever sent to Google at all.
A few services process data on our behalf so the product can work: SendGrid delivers the one-time codes and password-reset links you ask for by email; Cloudflare Turnstile runs the “are you human” check on the sign-in, sign-up and reset forms; and Cloudflare sits in front of the site to serve and protect it; and Google provides the address search and the drive times described above, when you switch that on. Each sees only what it needs for that job — for example, Turnstile and Cloudflare see the network request, and SendGrid sees the address a code is sent to. We do not use third-party analytics or advertising networks.
Short-lived security records are deleted as soon as they expire — one-time email codes, password-reset tokens and pairing requests all live minutes, not longer, and are swept automatically. Your account, screens and their settings are kept for as long as your account exists. Ask us to delete your account and we remove your account data; a paired display’s token dies with the screen it belonged to.
You can ask us to show you the data we hold about you, correct it, or delete it — email [email protected] and we will act on the request. You can change your email and password yourself from your profile at any time.
We don’t sell your data, we don’t track guests, and we don’t show advertising of any kind. Email is used to run your account and to send the codes and links you ask for — nothing else.
We’ll update this policy as the product grows — for example, when billing launches — and the “last updated” date above will change with it. This policy is governed by the laws of the United Arab Emirates and the Emirate of Dubai. Questions: [email protected].