This Privacy Policy describes how skyRoute66 ("SR66", ""we," "us," or "our") collects, uses, and protects information in connection with our skyRoute66 MCP (Model Context Protocol) Server Demo (the "Service").

Data Controller: skyRoute66, Los Angeles, California, United States.

For questions about this policy or your data, contact us at Email: webmaster@skyroute66.com.

1. Information We Collect

We use a third-party OAuth provider for authentication (see 7. Third-Party OAuth Provider below). When you authenticate through this provider, we receive and store the following information:

  • Name — as provided by your OAuth provider
  • Email address — as provided by your OAuth provider

We do not collect passwords or other authentication credentials directly. Authentication is handled entirely by the OAuth provider; we never see or store your OAuth provider password.

If you make a payment through the Service, we use Stripe as our payment processor. Stripe collects and processes payment information (such as card details and billing address) directly — we do not receive or store your full payment card details on our own systems. We may receive limited transaction information from Stripe (such as payment status, amount, and a payment reference ID) to confirm and manage your purchase. (see 8. Third-Party Payment Processor below)

2. How We Use Your Information and Our Legal Basis

The name and email address we receive are used solely to:

  • Establish and maintain your authenticated session with the Service
  • Identify your session for the duration it is active
  • Ensure only authorized users can access the Service

For users in the EU/EEA and UK, our legal basis for this processing is performance of a contract (Article 6(1)(b) GDPR) — we need this information to provide the Service you've requested — and, where applicable, our legitimate interest (Article 6(1)(f) GDPR) in maintaining the security and integrity of the Service.

We do not use your information for:

  • Marketing, advertising, or promotional communications
  • Selling, renting, or otherwise disclosing your information to third parties for commercial purposes
  • Profiling or analytics unrelated to session management

3. Data Retention and Deletion

Session data, including your name and email address, is retained only for as long as necessary to maintain your active session, and in any event no longer than 24 Hours after your session ends. This data is deleted periodically as part of routine session cleanup. We do not maintain long-term records of your personal information beyond what is required for session management.

4. Data Sharing

We do not sell your personal information. We do not share your name or email address with third parties, except:

  • With the OAuth provider itself, as part of the authentication process (see 7. Third-Party OAuth Provider below)
  • With Stripe, as part of processing payments (see 8. Third-Party Payment Processor below)
  • Where required by law, regulation, or valid legal process

5. Data Security

We take reasonable technical measures to protect the information we temporarily store, including limiting access to session data and deleting it on a periodic basis as described above. However, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.

6. Your Rights

Depending on your jurisdiction, you may have rights regarding your personal data. If you are located in the EU/EEA or UK, these rights include:

  • Access — request confirmation of, and access to, the personal data we hold about you
  • Rectification — request correction of inaccurate or incomplete data
  • Erasure — request deletion of your information
  • Restriction — request that we limit how we process your data in certain circumstances
  • Data portability — request a copy of your data in a structured, commonly used, machine-readable format
  • Objection — object to processing based on our legitimate interests
  • Withdraw consent — revoke authentication access at any time (e.g., by revoking OAuth permissions through your provider)
  • Lodge a complaint — file a complaint with your local data protection supervisory authority if you believe your rights have been violated

To exercise these rights, please contact us at Email: webmaster@skyroute66.com.

7. Third-Party OAuth Provider

Authentication is provided by GitHub or Google. Your use of that provider's login service is also subject to that provider's own privacy policies. We encourage you to review it separately:

GitHub Privacy Policies

Google Privacy Policies

8. Third-Party Payment Processor

Payments made through the Service are processed by Stripe, Inc. We do not store your full payment card information on our own servers. Your payment details are collected and processed directly by Stripe in accordance with Stripe's own privacy policy and security standards. We encourage you to review Stripe's Privacy Policy separately.

In addition, this server is a demo and does not process actual payments. You may use test cards numbers provided by Stripes instead of your real payment information.

 →  Stripe's Test Card Numbers

9. International Data Transfers

Our service providers — GitHub, Google, and Stripe — may process and store your information in the United States or other countries outside the EU/EEA and UK. Where this occurs, we rely on appropriate safeguards recognized under GDPR, such as Standard Contractual Clauses (SCCs) or the providers' own certified transfer mechanisms, to ensure your data receives an adequate level of protection. You can find further detail in each provider's own privacy policy, linked above.

10. Cookies and Similar Technologies

The Service uses a cookie to keep track of authorized client software during your session. This cookie is encrypted and is strictly necessary for the Service to function — it does not require your consent under the ePrivacy Directive / applicable cookie laws, as it is used solely for authentication and not for tracking, advertising, or analytics purposes. We do not use any non-essential cookies.

11. Children's Privacy

The Service is not directed to individuals under the age of 13 (or the relevant age of digital consent in your jurisdiction), and we do not knowingly collect information from children. For users in the EU/EEA, the relevant age of digital consent is 16, unless the laws of your EU member state specify a lower age (as low as 13).

12. EU Representative

skyRoute66 does not have an establishment in the EU/EEA. We have not designated an EU representative under Article 27 GDPR, as we rely on the exemption available under Article 27(2): our processing of personal data in connection with the Service is occasional, does not involve large-scale processing of special categories of data (such as health or biometric data) or criminal conviction data, and is unlikely to result in a risk to the rights and freedoms of individuals, taking into account the nature, context, scope, and purpose of the processing described in this Policy.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be reflected by an updated Last Updated date at the top of this page.

14. Contact Us

If you have questions about this Privacy Policy or how your information is handled, please contact us at:

Email: webmaster@skyroute66.com