Flightpath

Privacy policy

Last updated 7 September 2026

Flightpath is a work management tool built by MKRST for MKRST and its client businesses in Australia. This page explains what we collect, why, and how to reach us about it.

Who we are

Flightpath is operated by MKRST (Australia). If you have any questions about this policy or your data, email casey@mkrst.co.

What we store

Flightpath is an invitation-only workspace tool. We store:

  • Account details — your name and email address.
  • The business data you or your team enter into a workspace — leads, contacts, clients, jobs, documents and any files you upload.
  • Integration tokens — for example, the access token Google issues when you connect your Google Calendar (see below).

Our database and file storage are hosted on Supabase, in Australia where available. Our application is hosted on Vercel, running out of its Sydney (syd1) region.

Google user data

Flightpath can connect to your Google Calendar, but only if you choose to turn that on. When you connect it, Google asks you to grant these scopes:

  • https://www.googleapis.com/auth/calendar.events — to read and create events on your calendar.
  • openid and email — to confirm which Google account you connected.

We use this access only to:

  • Show your Google Calendar events inside Flightpath.
  • Create calendar events when you book an appointment.

The tokens Google issues are stored in our database, encrypted at rest by our hosting provider, and used only for the calendar features described above. We do not sell Google user data. We do not use it for advertising. We do not share it with third parties, except where needed to provide the feature itself (for example, our hosting and database providers). No one at MKRST reads it, except when you ask us for support and give us permission, or where we reasonably need to for security reasons.

Flightpath's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Google Calendar at any time from Settings → Integrations → Disconnect. Disconnecting deletes the tokens we stored for your account.

Other services we use

Flightpath relies on a small number of other providers:

  • Vercel — hosts the application.
  • Supabase — our database and file storage.
  • Resend — sends and receives email on our behalf (for example, team invites and inbound lead emails).
  • Google Maps (Places) — used server-side to look up addresses when you type a location, for example for a calendar event.

Each of these providers only sees the data needed to do its job for us, and none of them are permitted to use it for their own purposes.

How long we keep data

We keep your workspace's data for as long as the workspace exists. If you want your account or your workspace's data deleted, email casey@mkrst.co and we will action it.

Security

Traffic to Flightpath is encrypted in transit (TLS). Each organisation's data is isolated at the database level, so one workspace cannot read another's. Secrets such as OAuth client credentials are encrypted at rest.

Changes to this policy

We may update this policy as the product changes. We'll update the “last updated” date above when we do. If you have any questions, email casey@mkrst.co.

MKRST · casey@mkrst.co