Privacy policy.
What we collect, what we don’t, and how to ask us to forget.
What we collect
When you submit a listing, claim a place, create an account, or sign up for the newsletter, we ask for your name and email. If you’re a proprietor, we also collect business details (address, hours, photos, the kind of thing that goes on a public listing).
We log basic analytics events — which pages get viewed, which outbound links get clicked, which forms get submitted — so we can tell what’s useful and what to fix.
Aggregate analytics run by default (US audience), and you can turn them off any time via the Cookieslink in the footer. Meta’s Pixel and Conversions API — which we can use to measure advertising performance on Facebook and Instagram — are off by default and not enabled by the analytics setting.
Forms are protected by routine spam mitigations (rate limits, honeypots). We don’t sell personal information to anyone.
Booking requests
When you request a stay, table, or activity through the site or app, we collect the details of the request — dates, party size, pets, your name if you provide one, and any note you write — and share them with the property or business so they can respond. The proprietor sees your account email so they can reach you directly; that’s the point of the request.
We keep the booking record — the request, the quoted price, the cancellation policy shown to you, the version of the Guest Terms you accepted and when, the host’s decision, and any messages exchanged on the booking — as evidence of what both sides agreed to, for as long as the account and reasonable dispute windows require. Payment happens directly between you and the proprietor; we do not collect or store your payment card details for bookings.
Booking-related email (request notices, confirmations, messages) is sent through our email provider like the rest of our transactional mail. Booking details are never used for advertising and never sold.
Third-party services
Running a directory at this scale takes a small constellation of vendors. We pick ones with credible privacy postures and pass them only the data they need:
- Supabase — authentication and the primary database for listings, claims, and user accounts.
- Vercel — hosting and the platform analytics that count requests by region.
- Firecrawl— extracts public business information from proprietor websites we’re indexing.
- Google Gemini and Anthropic Claude APIs — assist with editorial cleanup of submitted copy. We don’t train models on your data.
- Mapbox, MapTiler, and OpenStreetMap — render the maps you see on listing and region pages.
- Google Analytics 4 — pageview and event metrics with IP anonymization. Used to understand which pages are useful, which forms get submitted, and which ads convert.
- Meta (Facebook / Instagram) — the Meta Pixel and Conversions API receive page views and conversion events (signup, claim, purchase) so we can measure ad performance and target visitors with relevant ads. Email addresses are hashed (SHA-256) before transmission. Currently off by default.
- Stripe — payment processing for the Mercantile. Stripe receives card details directly; we never see them.
- Resend — transactional and newsletter email delivery.
Cookies & tracking
We use two categories of cookies:
- Essential— required to keep you signed in, remember small preferences (region filter, dismissed banners), your shopping bag, and enforce security. These are always on; without them the site doesn’t function.
- Analytics (on by default)— Google Analytics 4 with IP anonymization, used to understand which pages readers find useful. Because our visitors are almost entirely in the United States, aggregate analytics run by default and we don’t interrupt you with a consent pop-up. You can turn analytics off any time via the Cookies link in the footer, and we remember that choice on your device.
- Advertising (off by default) — the Meta Pixel for ad measurement and retargeting stays off unless we re-enable it in the future; it is not turned on by the analytics control above.
Analytics uses Google Consent Mode v2, granted by default and downgraded to denied the moment you opt out via the footer control, which blocks user-level analytics storage at the source. The Meta Pixel initializes in revoke state and stays there.
We don’t sell personal information. Hashed identifiers (email, phone) are sent to Meta only when you complete a conversion event after consent is granted, and only so that ad performance can be measured.
If something about how we handle data isn’t clear, email hello@adirondackregion.com and we’ll get back to you.
Advertising & ad measurement
Aggregate Google Analytics runs by default so we can see which pages readers find useful. Meta’s Pixel and Conversions API — used to make paid advertising on Facebook and Instagram accountable — are off by default. Were we to turn advertising measurement on, it would work like this:
- Page views — Meta and Google would receive that you visited a page.
- Sign-ups, leads, purchases — events fire with a hashed (SHA-256) version of your email address so the ad platforms can match the conversion to the click that brought you here.
- Server-side mirror— for purchases and other key events, we send the same event from our server via Meta’s Conversions API and Google’s Measurement Protocol. This is more reliable than browser pixels alone (which iOS and ad blockers often suppress) but doesn’t add data we weren’t already collecting.
You can turn analytics off at any time via the Cookies link in the footer. Opting out blocks Google Analytics user-level storage at the source; the Meta Pixel stays off regardless.
Data retention & your rights
Account and listing data lives in our database for as long as the account is active. Newsletter subscribers can unsubscribe with one click from any email; the address is then dropped from the active list and retained only in suppression records.
You can ask us to export your data, correct it, or delete it entirely. For accounts, the cleanest path is the portal at /my. For anything more involved, write to hello@adirondackregion.com and we’ll handle it within ten business days.
Contact
Questions, deletion requests, or concerns: write to hello@adirondackregion.com. A real person reads it.