Resources · Privacy
Privacy, plainly.
Last updated · July 25, 2026 · plain-English edition
SkyWrite is a small operation and this site begins with an availability request. Approved customers may later receive a personalized Stripe Checkout link. Here is what happens with your information.
What we collect, and only when you send it
- Booking & contact forms. When you submit an availability request or a message, the details in the form (name, email, phone, country, event ZIP, event date, preferred show window, event location or venue, occasion, selected package, sky message, smoke-color preference, and any notes) are validated and stored in NIRO's protected lead system. We use them to reply and decide whether the proposed location and show can be served — that's it. The same transaction also creates a retryable operator-notification job.
- Optional current location. SkyWrite does not request device location on page or app launch. If you are already at the event location and tap Use my current location, the device shows one SkyWrite-branded permission prompt. On iOS the native helper requests low-accuracy location and rounds the coordinates to one decimal place before they ever enter JavaScript; the web/Android helper applies the same rounding before putting the broad point in the visible event-location field. You can edit or remove it, and it is transmitted only if you choose to send the request.
- Approved reservation payments. The public website and mobile request form do not collect card information. If operations approves a request, NIRO may send a personalized link to Stripe's hosted Checkout. Stripe processes the card or payment method; NIRO receives the booking reference, package, amount, payment status, billing/contact details, and provider identifiers needed for receipts, accounting, refunds, disputes, and support. NIRO does not receive or store your full card number or security code.
Things that happen by virtue of being a website
- Hosting and storage. The site and NIRO API run on Vercel, which may keep standard server logs (IP address, request time) to operate the service. Supabase provides NIRO's protected lead database; the browser never receives its server credential. Each lead receives a database-enforced delete-after time of 90 days, and a daily retention path removes records once due.
- Abuse prevention. When you send a form, the server converts the request IP address and normalized email into product-specific salted, one-way hashes. Only those hashes are used for atomic short-lived rate-limit counters (including a 10-minute network window and one-hour email window) and bounded daily caps (20 requests per network, 50 for this product, plus a high portfolio backstop). The raw IP address is not stored with the lead.
- Operator notification. The storage transaction also writes a durable delivery job. NIRO's pinned, send-only Google Workspace webhook notifies the business inbox only after storage succeeds; provider failures are retried by the authenticated retention job with bounded backoff. A notification failure never erases the stored request or makes the app encourage a duplicate submission.
- Payment processor. Stripe processes an approved payment only when you open the personalized Checkout link. Stripe's handling of payment information is described in Stripe's privacy policy.
Aggregate usage analytics
SkyWrite includes a privacy-minimal, first-party usage analytics client. This release collects usage analytics as described below, on the website and in the iOS and Android apps, disclosed here and in the store privacy labels.
Usage analytics is on by default and disclosed — there is no separate pop-up asking permission first — except in the EU/UK, where it stays off until you agree. You can turn it off (or back on) any time from Analytics settings on this device. Global Privacy Control or Do Not Track always keeps analytics off, everywhere, even if this device previously turned it on.
The only permitted fields are: a random one-time event UUID; a fixed funnel event and category; the surface (web, iOS, or Android); the app's major.minor release; a coarse device family and OS (e.g. “iPhone”, “ios17”); and a coarse country the server derives from your connection (never your address). If the app hits an error it may send a bounded crash report (error type and a truncated, address- and email-stripped message and stack), at most three per session. SkyWrite's fixed funnel covers app open, booking start and step, package category, current-location-helper outcome, booking review, and aggregate submit outcome.
How long analytics is kept. Crash reports are assigned a 90-day delete-after time. Aggregate usage counts are retained for up to 13 months. Neither is tied to you: there is no account, installation, session, or advertising identifier in any analytics or crash record.
An analytics event body never contains the page address, referrer, raw browser string, contact details, sky message, form values, event location or coordinates, payment details, or an account, installation, session, advertising, or other stable identifier. Analytics failures are silent and never change a booking or contact-form result. It is not used for advertising and does no cross-app tracking. Ordinary hosting request data remains covered by the hosting paragraph above.
Adults and underage inquiries
SkyWrite's availability and contact forms are intended for adults who are at least 18 years old (or the age of legal majority where they live) and are arranging a show or making a business inquiry. Children and other underage users should not submit the forms or provide personal information. If you believe an underage person submitted personal information, email jesse@niroaerial.com so we can investigate and delete information we control where required, subject to identity verification and any legal retention obligation.
What we don't do
- No advertising trackers, no tracking pixels, no third-party ad networks.
- No cross-app tracking, and a browser privacy signal (GPC or Do Not Track) always turns analytics off regardless of any saved choice.
- We do not sell or rent your information to anyone.
- No marketing lists — we email you about your inquiry or booking, nothing else, unless you ask.
- No background location, continuous location, location history, or location-based advertising. The one-time current-location helper is used only to prepare an event availability request.
Your choices
You can change the product-local analytics choice at any time with Analytics settings. Want your inquiry details deleted sooner, or have any question about your data? Email jesse@niroaerial.com and we'll sort it out. The central lead copy is assigned a 90-day delete-after time and removed by the daily retention path once due; later email correspondence may remain as needed for the active conversation or a legal obligation.
This page is a plain-English summary of how the site actually works today, written to be honest rather than exhaustive. If we change how the site handles data, this page changes with it.