We just launched! We need YOU to help us become helpful to student pilots. Please , review your current or past CFIs, schools, and write DPE gouges! You can add your CFI or flight school if they are missing. Our site is, and always will be, completely free.
Privacy Policy
Last Updated: August 24, 2026
Effective Date: August 24, 2026
RateMyCFI and RateMyDPE are operated by Smiths Group, LLC ("Smiths Group," "RateMyCFI," "RateMyDPE," "we," "us," or "our").
This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you access or use RateMyCFIs.com, related pages, services, communications, and features, and any other service that links to this Privacy Policy (collectively, the "Site").
RateMyCFI and RateMyDPE may share account, authentication, directory, moderation, verification, storage, security, and administrative systems.
By using the Site, you acknowledge that you have read and understood this Privacy Policy.
1. Who We Are
Business name: Smiths Group, LLC
Websites: RateMyCFIs.com
Email: contact@ratemycfis.com
Mailing address: 4539 N 22nd St, Ste R, Phoenix, AZ 85016
Telephone: 602-888-3014
2. Scope of This Privacy Policy
This Privacy Policy applies to information processed through the Site.
It does not govern the independent privacy practices of:
- Flight instructors;
- Flight schools;
- Designated Pilot Examiners;
- Check Airmen;
- Advertisers;
- Government agencies;
- Linked websites; or
- Other third parties.
The appearance of a person or organization on the Site does not mean that person or organization is affiliated with Smiths Group.
3. Categories of Information We Collect
We may collect information you provide directly, information generated through your use of the Site, information obtained from public records, and information received from third parties.
3.1 Account Information
When you create or manage an account, we may collect:
- Email address;
- Password or authentication credentials;
- Display name;
- Optional biography and profile photograph;
- Optional aviation certificates or ratings you identify;
- Email-verification status;
- Account creation, update, login, and security information; and
- Other information you choose to add to your account.
Passwords are stored in hashed form rather than as readable plaintext.
3.2 Reviews and Ratings
When you review a flight instructor or flight school, we may collect:
- Numeric ratings and written comments;
- Certificate or rating being pursued;
- Part 61 or Part 141 training status;
- Aircraft type, airport, and training date;
- Whether you would train with the subject again;
- Your selected display name;
- Submission, edit, and deletion information;
- Moderation status, votes, reports, and confidence signals; and
- Other information you include.
Published reviews may be pseudonymous to readers but remain associated with account and security information in our internal systems unless later disassociated.
3.3 Checkride and Examiner Reports
When you submit a report about a Designated Pilot Examiner, Check Airman, or other listed examiner, we may collect:
- Certificate or rating sought and whether the test was initial or additional;
- Outcome, including passed, not passed, or discontinued;
- Examiner fee, oral duration, and flight duration;
- Aircraft, date, and location information;
- Ratings concerning fairness, professionalism, and communication;
- Written comments, display name, votes, reports, and moderation information; and
- Other information you include.
We may aggregate this information to calculate pass rates, discontinuance rates, median fees, average ratings, sample sizes, and similar statistics.
3.4 Votes, Reports, and Community Activity
We may collect information about helpful and unhelpful votes, content reports, dispute reasons, correction requests, confidence signals, moderation decisions, account restrictions, appeals, and communications with moderators.
3.5 Profile Creation Requests
When you request creation of a profile, we may collect the proposed subject's name, airport, location, school affiliation, certificate or designation information, website or contact information, supporting information, your account information, public-record comparison results, and review notes.
3.6 Profile Claim Information
When you request to claim a profile, we may collect your name, account, verified email address, claimed profile, position or role, professional contact information, public-record information, verification communications, review notes, and claim decision history.
3.7 Certificate Verification Images
A flight instructor claiming a profile may be asked to upload an image of a flight instructor certificate with a handwritten one-time verification code.
The claimant is instructed to redact information not needed for verification, which may include a signature, residential address, date of birth, certificate number, and other unnecessary personal information.
Certificate images:
- Are used only to evaluate the applicable profile claim;
- Are not displayed publicly or placed on a profile;
- Are not shared with other users;
- Are stored separately from public profile images;
- Are re-encoded to remove available embedded metadata, including EXIF and GPS metadata;
- Use opaque filenames that do not intentionally contain personal information;
- Are accessible only to authorized administrators;
- May have administrative access recorded in an access log;
- Cannot ordinarily be retrieved by the uploader after submission;
- Are deleted when the claim is decided;
- Are deleted if the associated account is deleted while the claim is pending; and
- Are deleted no later than seven days after submission.
3.8 Public Profile Information
We may collect information about flight instructors, flight schools, and examiners from FAA databases, other government records, publicly available professional or business information, user submissions, profile requests, claimants, profile subjects, school websites, professional directories, and other lawful sources.
This information may include names, instructor credentials, examiner designations, school names, business types, airports, general locations, professional affiliations, public business contact information, profile photographs, biographies, services offered, and activity status.
A profile may exist even if the person or organization did not request, approve, claim, or know about it.
3.9 Communications
We collect information you send to us, including support requests, privacy requests, profile disputes, copyright notices, legal communications, safety concerns, reports, feedback, emails, attachments, and other correspondence.
3.10 Information Collected Automatically
When you use the Site, we and our service providers may automatically collect:
- IP address, browser, device type, operating system, and language;
- Approximate location derived from IP address;
- Referring and exit pages, URLs visited, searches, and interactions;
- Date, time, session duration, and authentication events;
- Error, diagnostic, and performance information;
- Cookie, local-storage, advertising, or similar identifiers;
- Device, network, fraud, and abuse signals; and
- Other interaction information.
3.11 Donations
The Site is free to use. If you choose to make a voluntary donation, the payment is processed by Stripe, Inc. You are taken to Stripe's own checkout page to complete it.
We do not collect, receive, or store your payment card number, card expiry, security code, or bank account details. That information is entered on Stripe's page, transmitted to Stripe, and held by Stripe under Stripe's own privacy policy. It never reaches our servers.
We also do not store a record of who donated. We do not save the donor's name, email address, billing address, or donation history to our database, and a donation is not linked to any Site account, review, profile, or other activity. Moderators are not told who has donated.
When you are returned to the Site after donating, we ask Stripe whether that particular checkout completed, so that we can display an accurate confirmation message. We use the answer to render that page and do not retain it.
Stripe independently collects and retains information necessary to process the payment, prevent fraud, and meet its own legal and financial-record obligations. This may include your name, email address, billing address, payment method details, device and network information, and transaction history. Stripe acts as an independent controller of that information. See Stripe's privacy policy at stripe.com/privacy.
We can see, within Stripe's own dashboard, the transaction records associated with our Stripe account, including donor names and email addresses that Stripe collects. We use this only to reconcile donations, answer donor enquiries, issue refunds, and cancel recurring donations. We do not use it for marketing, and we do not import it into the Site.
If you email us about a donation, that correspondence is handled as described in Section 3.9.
4. Information We Ask Users Not to Submit
Do not submit unnecessary sensitive information through public reviews, comments, reports, or profile fields.
In particular, do not publish or submit another person's:
- Home address, personal telephone number, or personal email address;
- Certificate number or government identifier;
- Financial information, password, or login credentials;
- Medical information;
- Student or confidential training records; or
- Other sensitive personal information.
This restriction does not apply when information is specifically requested through an appropriate private process. We may redact or remove prohibited information.
5. How We Use Information
We may use information to:
- Create, maintain, authenticate, and secure accounts;
- Operate RateMyCFI and RateMyDPE;
- Publish reviews, ratings, reports, replies, and profile information;
- Calculate ratings, pass rates, fee statistics, and other aggregated information;
- Create, maintain, correct, merge, and mark profiles inactive;
- Process profile creation and claim requests;
- Review certificate images and verify profile claims;
- Operate votes, reports, confidence labels, and moderation systems;
- Detect fraudulent reviews, votes, reports, claims, accounts, brigading, and coordinated manipulation;
- Resolve disputes, corrections, support requests, and privacy requests;
- Send transactional and security-related communications;
- Protect Site infrastructure and investigate unlawful conduct;
- Enforce our Terms and Conditions and protect legal rights;
- Comply with legal obligations and valid legal process;
- Improve Site performance, accessibility, usability, and features;
- Conduct analytics and internal reporting;
- Display, measure, and improve advertising;
- Provide personalized or contextual advertising where permitted;
- Promote the Site and public User Content as authorized by our Terms and Conditions;
- Facilitate a merger, financing, acquisition, sale, or reorganization; and
- Carry out other purposes disclosed when information is collected.
6. Public Information and Visibility
The Site is a public directory and review platform. Publicly displayed information may include display names, reviews, ratings, written comments, training details, checkride outcomes, examiner fees and durations, profile-owner replies, profile photographs, biographies, credentials, locations, business contact information, confidence labels, aggregated ratings, pass rates, median fees, sample sizes, and other professional or community information.
Public information may be viewed by anyone, indexed by search engines, copied, screen-captured, reposted, quoted, archived, shared through social media, or retained by third parties outside our control.
We cannot guarantee that information will disappear from search engines, third-party archives, screenshots, or copies after it is deleted or changed on the Site.
7. Pseudonymous Reviews and Reviewer Identification
A user may select a display name different from the user's legal name. Reviews may therefore appear pseudonymous to readers, but they are not necessarily anonymous to Smiths Group.
Internally, a submission may be associated with account email, account identifier, login information, IP address, timestamps, security records, device or network signals, moderation history, and related communications.
We do not publicly disclose internal reviewer information merely because a profile subject disagrees with a review. We may preserve or disclose relevant information when reasonably necessary to comply with legal process, investigate fraud or threats, enforce our Terms, protect rights or safety, establish or defend legal claims, or obtain legal advice.
We do not guarantee that we will be legally permitted to notify a user before making a disclosure.
8. Cookies and Similar Technologies
We and our service providers may use cookies, pixels, web beacons, tags, local storage, session storage, software development kits, advertising identifiers, IP addresses, and similar technologies.
These technologies may be used to keep users signed in, remember settings, operate features, maintain security, prevent fraud, measure traffic, diagnose errors, understand activity, store consent choices, limit repeated advertisements, measure advertising, and select contextual or personalized advertisements where permitted.
Some cookies are necessary for the Site to function. Others may be optional and subject to your choices or consent where required by law. Blocking necessary cookies may prevent certain features from functioning.
9. Advertising and Google Services
We may use Google AdSense, Google Ads, Google Ad Manager, Google Analytics, or other Google advertising and measurement products.
Google and other advertising vendors may use cookies, web beacons, IP addresses, device identifiers, browser information, approximate location, prior visits to this Site or other websites and apps, advertising interactions, and similar information to serve, personalize, limit, measure, and report on advertisements.
Advertisements may be contextual, personalized, or selected using a combination of these methods. Even when personalized advertising is disabled, providers may continue using cookies or similar technologies for frequency capping, fraud prevention, security, aggregated reporting, measurement, and contextual advertising.
We will not intentionally provide Google with passwords, certificate images, or information that directly identifies a user for advertising personalization.
Where required by law, we will request consent before enabling nonessential advertising cookies or personalized advertising. Opting out of personalized advertising does not necessarily prevent all advertising.
10. Analytics and Performance Monitoring
We may use analytics and performance tools to understand Site use and improve reliability. These tools may collect page visits, interaction events, referring pages, device and browser information, approximate location, IP address, session information, performance data, error messages, and diagnostics.
We use Vercel Analytics to count page views and measure performance. It sets no cookies and builds no profile of you: visits are counted using a value derived from the incoming request that is discarded daily, so it cannot follow you between sites or between days.
We may use error-monitoring services such as Sentry and configure them to reduce unnecessary personal-information collection where reasonably possible. We may also use Google Analytics or similar services in the future.
11. How We Disclose Information
11.1 Public Display
We disclose information intended for public display, including reviews, ratings, display names, checkride reports, profile information, profile-owner replies, aggregated statistics, and other public content.
11.2 Service Providers
We may disclose information to vendors that provide hosting, content delivery, database services, file storage, email delivery, authentication, payment processing, security, error monitoring, analytics, advertising, moderation, support, legal services, and other business operations.
Current or anticipated providers may include Vercel, Neon or another database provider, Vercel Blob or another storage provider, Resend or another email provider, Sentry or another error-monitoring provider, Stripe or another payment processor, Google, and other infrastructure or professional-service providers.
11.3 Advertising and Analytics Partners
Advertising and analytics partners may collect or receive information through cookies, pixels, web beacons, IP addresses, and similar technologies. Depending on applicable law, disclosures for cross-context behavioral or targeted advertising may be treated as a sale, sharing, or targeted-advertising disclosure even though we do not receive money specifically in exchange for personal information.
11.4 Legal Compliance and Protection
We may disclose information when reasonably necessary to comply with law or legal process, respond to government requests, enforce agreements, investigate violations, detect or prevent fraud, protect security or safety, address emergencies, establish or defend legal claims, or obtain legal advice.
11.5 Business Transactions
We may disclose or transfer information in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, change of control, due diligence process, or similar transaction.
11.6 With Your Consent or Direction
We may disclose information with your consent or at your direction.
12. Sale, Sharing, and Targeted Advertising
We do not sell personal information in the ordinary sense of exchanging personal information directly for money.
However, advertising cookies, pixels, and identifiers may be treated as a sale, sharing for cross-context behavioral advertising, or processing for targeted advertising under some state laws.
Where applicable, we may provide a "Do Not Sell or Share My Personal Information" link, targeted-advertising opt-out, cookie-consent interface, recognition of supported browser-based opt-out signals, or other legally required controls.
We do not knowingly sell or share the personal information of users under 16 without legally required authorization.
13. Sensitive Personal Information
The Site may process limited sensitive information for verification, security, legal, or safety purposes, including privately submitted certificate images, account credentials, safety-request information, identity-verification details, and information included in legal or harassment complaints.
We do not use certificate images for advertising, marketing, public profiling, public display, ad personalization, or training unrelated artificial-intelligence models.
14. Automated Processing and Integrity Systems
We may use automated rules, risk signals, and algorithms to compare profile requests against public records, detect duplicate profiles, spam, coordinated reviews or voting, suspicious login activity, fraud, and abuse; apply confidence labels; exclude content from aggregate ratings; prioritize moderation; and enforce rate limits.
These systems may use account history, email-verification status, IP address, device or network signals, submission timing, voting patterns, similarity between submissions, public-record matches, reports, and moderator decisions. We may also conduct manual review.
15. Data Retention
We retain information for periods reasonably necessary to operate the Site, maintain accounts and public content, process claims, prevent fraud, maintain security, resolve disputes, enforce agreements, maintain audit trails, comply with law, and establish or defend legal claims.
15.1 Account Information
Account information is generally retained while an account remains active. When an account is deleted, we delete or deidentify account information as described below, subject to limited legal, security, fraud-prevention, and backup retention.
15.2 Reviews and Checkride Reports
Published reviews and reports may remain available until the user deletes the individual submission while the account is active, we remove it, it violates policy, a legal obligation requires removal, or we otherwise discontinue retention.
If a user deletes an account without first deleting published reviews or reports, those submissions may be retained and permanently disassociated from the account.
15.3 Certificate Images
Certificate images are deleted when the claim is decided, when the associated account is deleted while the claim remains pending, or no later than seven days after submission, whichever occurs first.
15.4 Claims, Moderation, and Security Records
We may retain limited claim, moderation, policy, fraud, restriction, security, legal-request, report, and dispute records for as long as reasonably necessary to protect the Site, maintain auditability, enforce agreements, or comply with law.
15.5 Donation Records
We retain no donation records of our own. Because donations are not written to our database, there is nothing about a donation for us to delete on request, and deleting your Site account does not affect any donation.
Stripe retains its own transaction records under its own retention practices and its legal and financial-record obligations. Requests to access or delete information Stripe holds about you should be directed to Stripe, though we will help where we can.
15.6 Backups
Deleted information may remain temporarily in encrypted, restricted, or disaster-recovery backups until overwritten through normal retention cycles.
16. Account Deletion
Users may delete their accounts using available account tools or by contacting us. Before deleting an account, users should separately delete reviews or checkride reports they do not want retained.
When you delete your account:
- Your email address, password hash, account display name, profile photograph, and biography are deleted or disassociated from the active account;
- Published reviews and checkride reports may be retained but permanently disassociated from your account;
- Your display name may be removed from retained submissions;
- Votes and reports may be deleted;
- Pending claims may be canceled;
- Claimed profiles may be released and returned to unclaimed status;
- Claimant-added photographs, biographies, credentials, and contact information may be removed;
- Pending certificate-verification images are deleted; and
- Limited security, fraud-prevention, legal, and transactional records may be retained where necessary and permitted by law.
Deleting an account does not necessarily remove public-record information, profiles created independently, disassociated reviews or reports, third-party archives, search-engine caches, screenshots, independently submitted information, or records we are legally required to retain.
17. Profile Correction and Removal Requests
A person or organization shown on the Site may ask us to correct inaccurate factual profile information, merge a duplicate, address misidentification, mark a profile inactive, review a safety concern, or consider removal where permitted under our Terms and Conditions.
A profile is not automatically deleted because it is unclaimed, contains negative reviews, includes disputed opinions, may affect a business, or is unwanted by the subject.
Correction, merge, misidentification, inactive-profile, and removal requests may be sent to removals@ratemycfis.com from an address we can reply to. Please include a link to the profile and which category applies.
Safety-related requests involving stalking, domestic violence, or similar risks may be handled confidentially and with reduced documentation requirements where appropriate.
18. Your Privacy Rights
Depending on where you live and subject to legal exceptions, you may have rights to:
- Know whether we process your personal information;
- Access, obtain a copy of, correct, or delete certain information;
- Restrict or object to certain processing;
- Withdraw consent where processing is based on consent;
- Request portability;
- Opt out of targeted advertising, sale, or sharing;
- Limit certain uses of sensitive information;
- Opt out of certain profiling or automated decisions;
- Appeal a denied request; and
- Not receive unlawful discriminatory treatment for exercising privacy rights.
These rights are not absolute. We may retain information where permitted or required to exercise free-speech rights, preserve lawful public content, provide services, detect security incidents, prevent fraud, comply with law, establish or defend legal claims, or protect users and the public.
19. California Privacy Rights
California residents may have rights under the California Consumer Privacy Act, as amended, subject to applicable thresholds and exceptions. These may include rights to know, access, correct, delete, opt out of sale or sharing, limit certain uses of sensitive information, use an authorized agent, and receive equal service when exercising privacy rights.
If advertising cookies or similar technologies constitute sharing for cross-context behavioral advertising, California residents may opt out through the mechanism we make available when that activity is enabled and legally applicable.
20. Other U.S. State Privacy Rights
Residents of other U.S. states may have similar rights concerning access, correction, deletion, portability, targeted advertising, sale, profiling, sensitive-data processing, and appeals.
Where required, we will recognize legally valid opt-out preference signals, such as Global Privacy Control, for the browser or device from which the signal is sent.
21. European Economic Area, United Kingdom, and Similar Jurisdictions
The Site primarily concerns United States flight training and is operated from the United States.
If the GDPR, UK GDPR, or a similar law applies, we may process personal information based on:
- Performance of a contract, including operating accounts and requested Site features;
- Our legitimate interests in operating a public professional directory, publishing genuine experiences, moderating content, preventing fraud, maintaining security, correcting information, protecting legal rights, improving the Site, and supporting advertising-funded operations;
- Your consent for nonessential cookies, personalized advertising, optional information, and certain communications;
- Compliance with legal obligations;
- Establishing, exercising, or defending legal claims; or
- Protecting vital interests in an emergency.
Where applicable, you may complain to your local data-protection authority.
22. How to Exercise Privacy Rights
To submit a privacy request, email contact@ratemycfis.com with the subject line Privacy Request.
Please describe the right you wish to exercise, the account or profile involved, the email address associated with your account if any, your state or country of residence, and information reasonably necessary to locate relevant records.
We may verify your identity using access to an account email, information associated with the account, information already maintained by us, a signed declaration, or another reasonable method.
If we deny a request and applicable law grants an appeal right, you may appeal by replying to our decision with the subject line Privacy Appeal.
23. Advertising and Cookie Choices
Depending on your location and enabled services, you may manage advertising and cookies through a cookie-consent banner, privacy settings page, "Do Not Sell or Share My Personal Information" link, targeted-advertising opt-out, Google advertising settings, industry opt-out tools, Global Privacy Control, browser controls, device settings, or other provider mechanisms.
Clearing cookies, using another browser, or changing devices may require you to renew your choices. Some opt-outs apply only to the browser or device where the choice is made.
24. Email Communications
We may send transactional or service-related emails concerning email verification, password resets, account security, reviews, reports, moderation, profile claims, disputes, privacy requests, policy changes, legal notices, and other Site operations.
You generally cannot opt out of communications necessary to operate or secure an active account. Optional marketing emails will include an unsubscribe mechanism where required by law.
25. Data Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These may include password hashing, access controls, private object storage, separation of public and private files, authentication requirements, sensitive-access logging, metadata removal, transport encryption, restricted administrator privileges, monitoring, backups, vendor controls, and incident-response procedures.
No method of transmission, storage, or security is completely secure. We cannot guarantee absolute security or that unauthorized access, interception, copying of public information, or vulnerabilities will never occur.
26. Data Breach Notification
If a security incident affects personal information, we will investigate and provide legally required notices to affected individuals, regulators, or others within the time required by applicable law.
27. International Data Transfers
The Site is operated in the United States. Information may be transferred to, stored in, or processed in the United States and other countries where our service providers operate.
Where required, we may use lawful transfer mechanisms such as standard contractual clauses, data-processing agreements, adequacy decisions, contractual safeguards, or other approved mechanisms.
28. Children's Privacy
The Site is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Users must be at least 13 to create an account or submit content. A user under the age of legal majority may use the Site only with the permission and supervision of a parent or legal guardian, as described in our Terms and Conditions.
We do not knowingly use information from users known to be under 13 for personalized advertising. If we learn that we collected personal information from a child under 13 without legally sufficient authorization, we will take reasonable steps to delete it.
A parent or guardian who believes a child under 13 provided personal information may contact contact@ratemycfis.com.
29. Third-Party Links, Embeds, and Services
The Site may link to or integrate third-party websites, social-media platforms, maps, videos, advertising, analytics, aviation databases, government records, tools, and services.
Third parties may collect information directly from you and apply their own privacy policies. We are not responsible for third-party privacy, security, content, or business practices.
30. Do Not Track
Some browsers provide a "Do Not Track" setting. There is no universally accepted standard governing all responses to Do Not Track signals, so the Site may not respond to traditional Do Not Track signals in all circumstances.
Where required by law, we may recognize supported opt-out preference signals, such as Global Privacy Control, for applicable sale, sharing, or targeted-advertising opt-outs.
31. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date.
For material changes, we may provide notice through the Site, email, an account notification, a banner, or another reasonable method. If a change requires consent under applicable law, we will request consent as required.
32. Contact Us
Questions, privacy requests, and complaints may be directed to:
Smiths Group, LLC
Mailing address: 4539 N 22nd St, Ste R, Phoenix, AZ 85016
Email: contact@ratemycfis.com
Telephone: 602-888-3014
For faster processing, use the subject line Privacy Request.
Some matters reach us faster at a dedicated address:
- Privacy questions, requests, and complaints: contact@ratemycfis.com
- Profile corrections, misidentification, and removal requests: removals@ratemycfis.com
- Copyright and DMCA notices, including counter-notifications: digitalrights@smithsgroup.net (ATTN: Digital Rights Office)