NIRO Privacy Policy
This notice covers NIRO's public corporate and hardware sites, including niroaerial.com and the NNIRO landing page at nniro.com. NIRO's apps and consumer services have separate, product-specific notices linked below so their disclosures match what each product actually does.
Last updated: July 22, 2026
What this notice covers
This notice is published by NIRO Corp and applies to the public hardware pages and forms at niroaerial.com, dronepair.com, and dronesatellite.vercel.app, plus the NNIRO corporate landing page at nniro.com and www.nniro.com. These sites do not create a NIRO user account, take a payment, or include advertising scripts. NIRO Aerial, DronePair, and Drone Satellite include the optional, disabled-by-default first-party aggregate analytics control described below. The NNIRO landing page does not run application JavaScript or send application analytics events.
Following a link to another NIRO product takes you to that product's service and its own privacy notice.
Information you choose to send
If you submit a Drone Satellite pre-launch form, we receive the name, email address, product interest, and optional use case you enter. If you submit the DronePair briefing form, we receive your name, optional organization, email address, inquiry type, and use-case message. We store the validated request in NIRO's protected lead system so the team can respond and manage the resulting business conversation. You can instead email us directly.
The form rejects invalid fields and hidden-field bot submissions before storage. It does not collect payment-card information.
Technical information and abuse prevention
Like ordinary hosted websites, our hosting provider processes request information needed to deliver and secure the site, such as an IP address, requested URL, timestamp, and browser-supplied headers, under its own service practices.
For these public forms, the server creates product-specific salted, one-way hashes of the submitting network address and normalized email address solely to rate-limit automated abuse. The network-address window is 10 minutes and the email window is one hour. The raw network address is not stored with the lead.
Aggregate usage analytics
These sites include a privacy-minimal, first-party usage analytics client. This release ships with a compile-time off switch, so it sends no analytics request at all; the description below is how it behaves once a later reviewed release turns it on, disclosed here and in the store privacy labels.
When enabled, usage analytics is on by default and disclosed — there is no separate pop-up asking permission first — except in the EU/UK, where it stays off until you agree. You can turn it off (or back on) any time from the Analytics settings control, stored only in that product's local storage. Global Privacy Control or Do Not Track always keeps analytics off, everywhere, even if the browser previously turned it on.
When on, the only permitted fields are a random one-time event UUID, a fixed funnel event and category, the surface (web, iOS, or Android), a major.minor release, a coarse device family and OS, and a coarse country the server derives from the connection (never the address); an app error may add a bounded, address- and email-stripped crash report. The hardware-site funnels are limited to a page view, form start, a broad product-interest category, and an aggregate submit outcome.
An analytics event body never contains a page address, referrer, raw browser string, name, email, organization, message, use case, precise location, form value, payment detail, or an account, installation, session, advertising, or other stable identifier. Analytics failures are silent and do not change whether a form succeeds. It is not used for advertising and does no cross-app tracking. Ordinary hosting request data remains covered by the technical-information paragraph above.
Service providers
- Vercel hosts the website and NIRO API and processes ordinary web requests.
- Supabase provides NIRO's protected database for validated lead records and short-lived rate-limit counters. The browser never receives its server credential.
- FormSubmit may send NIRO a best-effort inbox notification after the request is safely stored. Notification delivery is not the system of record and does not determine whether the form shows success.
- Your email provider and NIRO's email provider process messages when you contact us directly or when we reply.
We may also disclose information when required by law or when reasonably necessary to protect people, NIRO, or the service. The current site source does not include advertising networks or data-broker integrations, and NIRO does not sell website inquiry data.
Cookies, local storage, and external resources
The audited NIRO hardware-form sources do not set application cookies or stable local-storage identifiers. On the three sites that present an analytics choice, each product stores only its own choice (allow or deny) locally; that choice is never placed in an analytics event. NIRO Aerial, DronePair, Drone Satellite, and NNIRO use local/system font fallbacks and do not load remote web fonts. Hosting infrastructure may still use request-level security controls under the provider's own practices.
Retention and requests
The protected lead-system copy receives a database-enforced delete-after time of 90 days after submission, and a daily retention job removes records once that time is due. Expired rate-limit counters are removed by the same retention path. If the inquiry becomes an active business conversation, messages you or NIRO send through email may remain in the relevant mailboxes as needed to answer it, manage that relationship, resolve a dispute, or meet a legal obligation.
You may ask to access, correct, or delete information you submitted, subject to identity verification and any information NIRO must keep for legal or dispute purposes. Email jesse@niroaerial.com with enough detail to identify the request. Rights available to you may also depend on where you live.
Children
These corporate and hardware-information sites are not directed to children, and their forms are intended for adults making a product or business inquiry. If you believe a child sent personal information through a site, contact us so we can review the request.
Security
The site uses HTTPS, origin checks, input validation, request-size limits, bot filtering, and short-lived rate limits for the public form. No internet service can guarantee perfect security.
Product-specific privacy notices
These notices describe the data flows of the corresponding product and control for that product:
- PicPlots Privacy Policy
- GAIC Privacy Policy
- SkyWrite / SmokeMSG Privacy Notice
- DeNiro Card Privacy Policy
Changes and contact
We will revise this page when the website's practices change and update the date at the top. We do not promise a notice method that the current site does not implement.
For privacy questions or requests about these NIRO hardware sites, email jesse@niroaerial.com.
See also: Terms of Service.