Back
Legal

Privacy policy

Last updated 2 August 2026

The short version: ParkPlanner stores the trip you plan and, if you make an account, your email address. There are no ad trackers, your phone's location never leaves your device, and we never sell your data. We use Google Analytics to count visits, but only if you agree when asked — say no and nothing is loaded. You can delete everything from the Account screen.

Who we are

ParkPlanner is a theme-park trip planner run by an individual, not a company. For anything in this policy — including a request to see or delete your data — email admin@parkplanner.net. We are the data controller for the information described below.

What we store

You can plan a whole trip without giving us a name, an email address or a password. The first time you save anything, we create a record for you and set one cookie so the same browser finds it again.

  • A session cookie (pl_sid) — set by the server, HttpOnly, and valid for up to 400 days. Only a SHA-256 hash of its value is stored on our side, so a copy of the database hands out no live sessions.
  • Your trip — its name and dates, the hotel name and location you type in, which park you are doing each day, your arrival and departure times, notes, and the attractions on your list along with their status and timings.
  • A display name— “Guest” until you change it. It is shown to anyone you share a trip with.
  • If you create an account — your email address. If you sign in with Google or Facebook, we also store the account identifier that provider gives us, plus the email address and name on it.
  • Sign-in codes — when you ask for an email code we store the address, a hash of the code, and the IP address that asked for it. The IP is there to stop someone hammering the sign-in with guesses; we do not use it for anything else.

Analytics

We use Google Analytics to count visits and see which pages get used. It is off until you say yes: the first time you visit, a bar at the top of the screen asks, and nothing is sent to Google unless you tap Allow. Nothing is blocked while you decide, and declining does not limit any part of the app.

  • If you say no— the Google script is never loaded. Not loaded and switched off, but never fetched at all, so no request reaches Google and no cookie is set.
  • If you say yes — Google sets its own cookies (_ga and _ga_*, up to two years) and receives the pages you view, a randomly generated device identifier, your approximate location derived from your IP address, and your browser and device type. It does not receive your trip, your email address or your name.
  • Either waywe record your answer in your browser's local storage — not a cookie, so asking the question does not itself store anything on your device. Clearing site data makes the bar reappear.

Advertising features and Google Signals are turned off on our Analytics property, so your activity is not added to a cross-site advertising profile and we run no remarketing.

What we don't do

  • No tracking pixels and no advertising networks. Beyond the analytics described above, nothing on these pages reports your browsing anywhere.
  • Your location stays on your device. When you tap to sort attractions by what is nearest, the browser hands your coordinates to the page and they are used there and then. They are never sent to our server and never stored.
  • We do not sell or share your personal information — in the ordinary sense or in the specific senses those words carry under California law.

Your browser also keeps a few interface preferences (the park you last looked at, whether you dismissed a prompt) in its own session storage. That never reaches us and disappears when you close the tab. Your analytics answer is the one thing kept for longer, so we do not have to ask again.

Who else sees it

  • People you share a trip with. A share link lets whoever holds it join the trip — or a single day of it — as a viewer or an editor. Everyone on a trip sees its contents and the display names of the other members. You can revoke a link at any time; revoking it does not remove someone who has already joined.
  • Cloudflare hosts the app and stores its database.
  • Resend delivers sign-in emails, and receives the address the code is going to.
  • Google Analytics, only if you agreed to it, and only the browsing information listed above. Google acts as our processor and applies its own privacy policy to what it receives.
  • Google or Facebook, only if you choose to sign in with them. They tell us your account identifier, email address and name; what they record about the sign-in is governed by their own policies.

Wait times, park hours and weather come from ThemeParks.wiki, Queue-Times and Open-Meteo. Those are fetched by a scheduled job on our server, never by your browser, so no information about you is sent to them.

Some links in the guides are affiliate links. Following one may pass a code identifying ParkPlanner — not you — to the retailer, who then applies their own privacy policy.

Why we're allowed to (UK and EU)

Under the UK GDPR and the EU GDPR our lawful bases are:

  • Performance of a contract — storing your trip, your account and your share links is the service you asked for.
  • Legitimate interests — keeping sign-in secure and preventing abuse, which is why a code request records an IP address.
  • Consent— using your device location, which only happens after you tap for it and grant the browser permission; and analytics, which only happens after you tap Allow. Withdraw location permission in your browser or phone settings, and analytics consent by clearing this site's data, which makes the bar ask again.

How long we keep it

Trips and account details are kept until you delete them. Sessions expire after 400 days, or immediately when you sign out. Sign-in codes stop working after 10 minutes but the row recording the attempt is removed when you sign out or delete your account.

Deleting your account removes your user record, your sessions, your connected sign-in providers, your share links, and any trip nobody else is on. A trip you share with other people is left intact for them, and ownership passes to another member.

Analytics data sits with Google rather than with us, on a 14-month retention setting. Deleting your account does not reach it, because nothing in it identifies you to us.

Your rights

If you are in the UK or the EU you have the right to access your data, correct it, have it erased, restrict or object to how we use it, and receive a copy in a portable form. Most of that is self-service on the Account screen — change your name or email, or delete the account outright. For anything else, email admin@parkplanner.net and we will respond within one month. You can also complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.

If you are in California, you have the right to know what personal information we collect and why, to request its deletion or correction, and not to be treated differently for exercising those rights. The categories we collect are identifiers (email address, account identifiers, IP address, and an analytics device identifier if you allowed analytics) and internet activity covering your own trip content and, with your agreement, which pages you viewed. We do not sell or share personal information, and we do not use it for cross-context behavioural advertising. Use the same address above to make a request.

Where your data is

The app runs on Cloudflare's network and our providers are based in the United States, so your data is processed outside the UK and EEA. Those transfers rely on the UK Addendum and the EU Standard Contractual Clauses in each provider's terms.

Children

ParkPlanner is not aimed at children under 13 and we do not knowingly collect their data. If you believe a child has given us information, email admin@parkplanner.net and we will delete it.

Changes

If this policy changes, the date at the top changes with it. Material changes will be flagged in the app rather than made quietly.