M Maytabi
Log in

Maytabi — Privacy Policy

Effective date: 28 June 2026.

1. Who we are

Maytabi ("we", "us") is a travel-coordination service for motorsport teams. The service is provided by Maytabi, operated by its founder. For any privacy matter, contact us at [email protected]. For the personal data of a team's crew/travellers, the team (our customer) is the data controller and Maytabi is the data processor acting on the team's documented instructions (see our Data Processing Agreement). For account and billing data, Maytabi is the controller.

2. What data we process

We do not sell personal data and do not use it for advertising.

3. How sensitive data is protected

An honest note on data location

Our application database (Cloudflare Workers KV) is globally replicated and cannot be restricted to a single region. We therefore protect sensitive personal data by encrypting it at rest (above) so that, wherever the bytes are replicated, the sensitive fields are unreadable without the key, which is held only within our EU-processed application. We do not claim that all data physically resides only on EU servers. Customers with strict data-residency requirements should contact us to discuss options.

4. Why we process it (legal bases)

5. Who we share it with (sub-processors)

We use a small number of processors. Each receives only what it needs:

ProcessorPurposeWhat it receives
CloudflareHosting, database (KV), file storage (R2, EU jurisdiction)All stored data — sensitive fields encrypted
LetsFGFlight availability (search)Route + date only — no personal data
AeroDataBoxFlight schedule lookup (flight numbers)Route + date + flight numbers — no personal data
ResendTransactional email (password reset, nudges)Email address only

A current sub-processor list is available on request. We impose data-protection terms on every processor.

6. International transfers

Where a processor operates outside the EEA, transfers are covered by an adequacy decision or the EU Standard Contractual Clauses. The processors that receive flight queries (LetsFG, AeroDataBox) receive only route and date — no personal data.

7. Retention

We retain personal data only for as long as the team's account is active and the data is needed to provide the service. When a team or a traveller is deleted, we erase all associated records and files — database records, uploaded confirmation files, and accounts — and retain nothing thereafter, save minimal audit logs required by law. Customers can request export or erasure at any time (section 9).

8. Your rights

Subject to applicable law, individuals have the right to access, rectify, erase, restrict, object to processing, and to data portability. Because the team is the controller of crew data, traveller requests are normally directed to the team; Maytabi provides the team the tools to fulfil them:

9. How to exercise rights / contact us

Email [email protected]. Team owners can self-serve export and erasure from the back office. You may also lodge a complaint with your local supervisory authority.

10. Security & breach

We apply encryption-at-rest for sensitive fields, role-based access control, audited admin actions, and the no-AI processing described above (no personal data is sent to any AI). In the event of a personal-data breach we will notify affected controllers/authorities as required by law.

11. Changes

This policy may be updated as the service evolves; we will post material changes here and, where appropriate, notify account holders.