Privacy Policy — SkySpot SA
Version: 4.0
Effective date: 23 July 2026
Canonical legal pages:
- Privacy Policy: https://skyspot.co.za/legal/privacy-policy
- Terms of Service: https://skyspot.co.za/legal/terms-of-service
1. Who we are
SkySpot SA (“SkySpot”, “we”, “us”, or “our”) is operated by David Graeme Middleton. For purposes of the Protection of Personal Information Act 4 of 2013 (“POPIA”), David Graeme Middleton, operating as SkySpot SA, is the responsible party for the processing described in this policy.
SkySpot is a community service for South African radio-control, first-person-view, and drone pilots. This policy explains what personal information we process, why we process it, how it is shared and retained, and the choices and rights available to you.
2. Information we process
2.1 Account and consent information
We process information needed to create and administer an account, including:
- Firebase user identifier;
- email address and email-verification state;
- display name, username, province, and pilot type;
- sign-in provider and account status;
- an 18-or-over age attestation; and
- the Privacy Policy and Terms version identifiers accepted at signup or re-consent, acceptance time, consent source, and, where available, app version and platform.
We do not ask for a date of birth as part of the current age-attestation flow.
Fields marked as required in the signup flow, the 18-or-over attestation, and acceptance of the then-current Privacy Policy and Terms are mandatory to create an account. If you do not provide them, SkySpot cannot complete account creation. Optional profile fields, social links, custom photos, phone verification, notification permissions, and device permissions are voluntary, although the related feature may be unavailable if you do not provide them.
2.2 Profile, community, and trust information
Depending on the features you use, we process:
- profile visibility, biography, optional social links, avatar selection, and optional custom profile photo;
- flying-spot, field, comment, check-in, field-edit, field-photo, WhatsApp-group, vendor, review, NOTAM, and other community submissions;
- hearts, follows, vouches, ratings, trust counters and badges;
- points, XP, levels, streaks, monthly activity, badges, and related history; and
- reports, moderation outcomes, notifications, and safety or abuse-prevention records.
2.3 Supported photo and media flows
Current normal-user media flows include:
- photos uploaded with an initial point-of-interest (flying-spot) submission;
- photos later added to or removed from an approved point of interest by its submitter through the owner edit flow;
- field photos submitted through a moderation workflow; and
- optional custom profile photos for eligible accounts.
Normal-user vendor-image and WhatsApp-group-cover upload flows are not currently supported. Existing media for those features may remain readable or administratively managed.
Photo metadata may include the related record identifier, uploader identifier, storage path, submission status, category, caption, and moderation data. You must not upload media that you do not have the right to submit.
2.4 Optional phone verification
Phone verification is optional and uses Firebase Authentication. The full phone number is held in Firebase Authentication rather than in the public SkySpot user document. SkySpot stores limited verification information, including verification state and the last four digits in an owner/admin-restricted contact record.
SkySpot also maintains server-only derived state needed to make phone verification, phone changes, recovery, and administrative reset converge safely across Firebase Authentication and Firestore. That server-only state is not exposed to ordinary clients and does not publish the full phone number.
The seller Number Check feature lets an eligible, current, non-banned user submit a number they already possess and receive only a match or non-match result against a phone-verified profile. SkySpot does not return the verified number. Syntactically valid eligible checks consume a per-buyer, per-profile, per-day quota whether the result is a match or non-match. Sensitive phone actions require recent authentication.
2.5 Location information
SkySpot requests device location permission only for location-dependent features. Location may be used to centre maps, show nearby places or conditions, support check-ins, and assist with a submission you initiate. You can revoke device permission in operating-system settings, although some features will then be unavailable.
Community records can also contain locations that users deliberately submit, such as flying spots, fields, check-ins, and NOTAMs. SkySpot does not claim to provide passive background-location tracking or a general location-history service.
2.6 Device, operational, and support information
We may process push-notification tokens, app and platform version, operational security data, and limited technical information needed to deliver and protect the service. Device details or diagnostics may also be processed when you deliberately include them in a bug report or support request. SkySpot does not currently claim to operate a general third-party advertising or passive behavioural-analytics system.
3. Public profiles and user discovery
Current +10 pilot search, leaderboards, and Hall of Fame surfaces use a server-owned, sanitised projection for eligible public, completed, non-banned profiles. During the bounded Phase-A compatibility period for supported +9 clients, a signed-in user can still issue legacy list queries against the full users collection. Those records can contain profile, community, trust, and account-state information beyond the projection, including biography, social links, membership information, notification preferences, phone-verification status, moderation state, and denormalised legal-version timestamps. They do not contain the Firebase Authentication email or full phone number, or the separate private contact and consent-subcollection records. Phase B is intended to remove authenticated full-user listing only after +10 adoption is separately evidenced and authorised.
The +10 projection exposes only the supported public discovery information:
- searchable username;
- display name;
- avatar URL, if any;
- level;
- lifetime points;
- monthly points; and
- verified flight-session count.
A private, incomplete, or banned profile is not eligible for the ordinary +10 projection.
Some approved community content, such as places, comments, photos, field information, or public trust signals, can be visible to other users or, where the feature is designed to be public, without sign-in. Visibility depends on the feature and moderation state.
4. Why we process personal information
We process personal information to:
- create, authenticate, secure, and administer accounts;
- provide maps, weather, community, discovery, trust, notification, and safety features;
- display public profiles and community content according to the feature and profile-visibility setting;
- operate optional phone verification and Number Check;
- moderate content, investigate reports, enforce rules, prevent abuse, and maintain service integrity;
- keep consent and operational records;
- respond to support, privacy, safety, and legal requests;
- comply with legal obligations; and
- improve the service using appropriately limited or de-identified information.
Depending on the processing, the justification may include consent, performance of the agreement with you, compliance with law, or a legitimate interest that does not unjustifiably interfere with your privacy. Optional permissions or features can have their own consent or control. Withdrawing optional consent does not affect processing already lawfully carried out and may make the relevant feature unavailable.
5. Reports, moderation, bans, and urgent matters
Ordinary in-app reports can include your user identifier, the target type and identifier, a reason, optional notes, and a timestamp. Reports are not visible to ordinary users and are used for moderation, safety, abuse prevention, and enforcement.
Banned users cannot submit ordinary in-app reports through the normal reporting paths. A banned user, or anyone unable to use the normal reporting flow, may send an urgent safety, legal, privacy, or abuse matter to support@skyspot.co.za. That support route is not a promise of emergency response. Contact the appropriate emergency service or public authority where immediate assistance is required.
Moderation may result in content being hidden, restored, rejected, removed, or referred for further review. Limited audit records may be retained where reasonably necessary for safety, abuse prevention, dispute handling, or legal compliance.
6. Sharing and service providers
We do not sell personal information and do not currently share it with third-party advertisers.
We use service providers and infrastructure including:
- Google Firebase for Authentication, Firestore, Cloud Functions, Cloud Storage, App Check, and Cloud Messaging;
- Google Maps Platform for mapping services;
- Open-Meteo for weather information; and
- OpenAIP and other authorised aviation-data sources for airspace or related information.
Providers process information according to their functions, contractual terms, and applicable law. We may also disclose information where required or authorised by law, to protect rights or safety, to investigate abuse, or in connection with a properly governed business transfer.
7. Storage locations and cross-border processing
SkySpot’s primary Firestore database is configured in africa-south1 (Johannesburg). Cloud Functions currently run in europe-west1 (Belgium). Firebase Authentication, Cloud Messaging, Google Maps, and other provider services may use infrastructure in more than one country.
The level of legal protection varies by provider and destination, and some recipient countries may not provide privacy legislation equivalent to POPIA. In those cases, SkySpot will transfer personal information only where another POPIA section 72 basis applies, such as binding corporate rules or a binding agreement that provides adequate protection, consent where valid, performance of an applicable contract, or another legally permitted ground. You may request provider-specific transfer information at support@skyspot.co.za.
8. Security
We use measures designed to protect personal information, including encrypted network transport, Firebase Authentication, App Check where configured, security rules, server-side validation, user-scoped media paths, role and authority controls, and restricted server-only records. No service can guarantee absolute security.
If there are reasonable grounds to believe that an unauthorised person has accessed or acquired personal information, we will investigate and provide notifications required by POPIA, subject to any lawful delay or direction.
9. Retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, or as required or authorised by law. Current product behaviour includes the following distinctions:
| Category | Current approach |
|---|---|
| Active account, profile, consent, and private account records | Retained while needed to provide and administer the account, then handled through the account-deletion process |
| Vouches | Retained while both related records remain in the active trust system; vouches given and received are deleted when the relevant account is deleted |
| Uploaded media | Removed as part of account deletion, subject to retry where cross-service work is incomplete |
| Useful community records | May be retained in anonymised form where applicable so that shared community information remains useful |
| Reports and moderation records | Deleted, anonymised, or retained in limited form according to the record and the continuing safety, abuse-prevention, dispute, or legal purpose |
| Banned-account safety record | A limited record may be retained for ban enforcement and abuse prevention |
| De-identified information | May be retained where it cannot reasonably be linked back to the data subject |
Backup, cache, provider, and legal-preservation cycles may not complete at the same instant as the live account-deletion flow.
10. Account deletion
You can request permanent account deletion from Account Settings in the app. The app requires an online connection, a deliberate confirmation, and recent reauthentication.
Account deletion currently distinguishes between data that is deleted and useful community records that are retained in anonymised form where applicable:
- your account profile, private subcollections, authentication account, push-token record, follows, check-ins, reports made by you, number-check quota records, field edits, and other personal or relational records in the deletion cascade are deleted;
- vouches you have given and vouches you have received are deleted;
- affected surviving users’ current seller/buyer vouch counts, current rating, and trust badges are recomputed from the vouches that remain;
- previously awarded points and XP, monthly history, level, point-event history, and unrelated badges are not reversed by that surviving-user trust recomputation;
- media you uploaded through supported flows is removed;
- useful community records such as approved places or other shared contributions may be retained with the account identifier and username replaced by deletion markers where applicable; and
- your username reservation is released, so another person may be able to use that username in future.
Deletion is a multi-step operation across Firestore, Cloud Storage, and Firebase Authentication. Those services do not provide one atomic transaction covering the whole operation. A storage, network, or service failure can therefore leave the request incomplete. The app does not treat an error, malformed response, or missing confirmation as successful deletion. It keeps or restores an actionable recovery state so that you can retry deletion or sign out locally. The server-side steps are designed to converge safely when retried, including when a previous attempt already removed part of the account.
If an account is banned when deletion is requested, SkySpot may retain a limited ban-enforcement record. Depending on the available data, this can include the account identifier, prior username, ban reason and timing, responsible moderation reference, deletion time, and a server-derived non-plain phone-reuse marker if the account had phone-verification data. It is not intended to retain the full phone number, email, profile content, or ordinary private account data.
11. Your POPIA rights
Subject to POPIA and any lawful limitations, you may ask us to:
- confirm whether we hold personal information about you and provide access to it;
- correct or update inaccurate, irrelevant, excessive, out-of-date, incomplete, misleading, or unlawfully obtained information;
- delete or destroy information that we are no longer authorised to retain;
- object to processing in circumstances recognised by POPIA; or
- stop optional processing after consent is withdrawn.
Contact support@skyspot.co.za. We may need to verify your identity and may ask for enough information to locate the relevant record. We will explain any lawful reason for refusing or limiting a request.
You may lodge a POPIA complaint through the Information Regulator’s official channels:
- Complaints email: POPIAComplaints@inforegulator.org.za
- General enquiries: enquiries@inforegulator.org.za
- Telephone: 010 023 5200
- Toll-free: 0800 017 160
- Website: https://inforegulator.org.za
12. Children
SkySpot is intended only for people aged 18 or older. Signup requires a self-attestation that the user is at least 18. SkySpot does not currently operate a verified-parental-consent pathway.
If you believe a person under 18 has created an account or provided personal information, contact support@skyspot.co.za. We will investigate and take appropriate action, which may include removing the account and its personal information.
13. Communications and direct marketing
Operational notifications may be used to provide requested features, account notices, moderation results, security information, or material service updates. Optional notification permissions can be changed in the app or device settings.
SkySpot does not currently claim to send third-party advertising. If direct marketing is introduced, it must be implemented and described in accordance with POPIA and other applicable South African law, including consent and opt-out requirements where applicable.
14. Changes to this policy
We may revise this policy. A successor must have a version identifier and effective date approved before publication. Where a material revision requires renewed acceptance, the app records the legal version identifiers accepted during re-consent. Historical acceptance identifiers are operational records; they do not make an unpublished draft effective.
15. Contact and Information Officer
Responsible Party: David Graeme Middleton, operating as SkySpot SA
Information Officer: David Graeme Middleton
Physical and correspondence address: 8 Hely Street, Ndabeni, Cape Town, 7405
Telephone: +27 72 446 1882
Support and privacy email: support@skyspot.co.za
SkySpot SA — South Africa’s RC, FPV and drone pilot community