Privacy Policy
Last updated 30 August 2026
This policy describes what the SnapDestinations website actually does, checked against its own source code and its real network behaviour. It is deliberately specific: where we cannot establish something from the implementation, we say so instead of using vague wording.
1. Scope of this policy
This policy covers the SnapDestinations website only. SnapDestinations is an independent, non-commercial project under active development. Full operator identification details (legal name and postal address) are not yet published here; they will be added to this page and to the contact page before the site is presented as a commercial service.
2. What SnapDestinations receives
- Technical request data. Like any website, pages are delivered over HTTP, so our hosting provider necessarily processes the request, including your IP address and user agent, in order to serve the page and protect the site from abuse. We do not have an analytics pipeline attached to this and we do not build profiles from it.
- Email you choose to send us. If you email the address in section 12, we receive your address and whatever you write.
3. What SnapDestinations does not collect
- No user accounts, logins, profiles or user-generated content
- No advertising, no advertising identifiers and no ad-serving code, dormant or active
- No affiliate links, commission tracking or referral tagging
- No contact form, newsletter signup or email list
- No browser geolocation request, and no IP-based location lookup
- No sale or sharing of personal data for marketing
3a. What we do measure
We use Google Analytics 4 through the Google tag (gtag.js) to see aggregate traffic, page views and navigation paths. Google receives your IP address, browser information, the pages you visit and the site you came from. We use this only to understand how the site is used as a whole; we do not use it to identify individuals or build personal profiles. You can read how Google processes this data in Google's privacy policy.
4. Destination searches and the trip form
Destination search, the free-text trip brief and the recommendation logic all run inside your browser against data that was bundled into the site when it was built. What you type is not sent to a search service, not logged by us and not transmitted to any third party. The place identity index — built offline from Wikidata, with an offline GeoNames cross-check — is a static file shipped with the site; using it causes no request to Wikidata or GeoNames.
A destination name in a URL, such as a shared link containing a query, appears in ordinary hosting request logs like any other URL. If that matters to you, use the form on the page rather than sharing the URL.
5. Cookies
SnapDestinations sets no cookies of its own — no session cookie, no preference cookie and no consent cookie. One third-party cookie can appear in your browser without our involvement: Wikimedia's image servers may set their own cookie (currently observed as WMF-Uniq) on the upload.wikimedia.org domain when a destination photograph loads. It is set by Wikimedia, is readable only by Wikimedia, and we neither read it nor receive anything from it. Because there are no non-essential cookies under our control, we do not operate a cookie banner, and a separate cookie policy would tell you nothing this section does not.
6. Storage in your own browser
To make the product usable, a small amount of information is stored locally on your device. It never leaves your browser and is never transmitted to us:
- Trip preferences (localStorage key
snapdestinations.trip-brief.v1): the origin text, month, trip length, travelling companion, budget band and priorities you last selected. Persists until you clear it. - Recently viewed destinations (localStorage key
snapdestinations.recent-destinations.v1): up to six destination identifiers. Persists until you clear it. - Scroll position (sessionStorage key
tsr-scroll-restoration-v1_3): written by our routing library so the page returns to where you were. Discarded when you close the tab.
You can clear these at any time with your browser's site-data controls, and the Reset button on the trip form clears the two preference keys. If storage is blocked, the site works normally without it.
7. Third parties your browser contacts
Three third parties receive a request when you use SnapDestinations, and each one necessarily sees your IP address and user agent as a consequence of serving the file:
- Google Fonts (
fonts.googleapis.com,fonts.gstatic.com): serves the two typefaces the site uses. - Google Analytics / Google tag (
googletagmanager.com,google-analytics.com): loads the gtag.js library and sends page-view events when you navigate. Google processes this under its own terms. - Wikimedia Commons (
upload.wikimedia.org): serves the licensed destination photographs, which are loaded from Wikimedia rather than copied onto our own hosting so that attribution stays tied to the original file.
There is nothing else: no maps, no video players, no social widgets, no comment system, no consent platform, no error-monitoring service in the published site, and no advertising or affiliate network. Weather statistics and geographic data are processed offline and baked into the site at build time, so your browser makes no request to those data providers.
8. Hosting and technical logs
The site is served by our hosting platform, which processes requests on our behalf and may retain ordinary technical logs. The provider's retention periods, server locations and internal security measures are set by that provider and are not something we can state precisely here, so we do not make claims about them. We do not export, enrich or analyse those logs.
9. Legal bases, retention and sharing
Where the GDPR applies, our legal basis for processing technical request data is legitimate interest (Article 6(1)(f)) in delivering and protecting the website; for email correspondence it is legitimate interest in replying to you, or your consent where you volunteer additional information. We hold no database of visitors, so there is nothing to retain beyond hosting logs kept by our provider and email we have received, which we delete once the matter is closed. We do not share personal data with anyone for their own purposes, and we do not transfer any visitor database internationally, because we do not have one. Requests to Google Fonts and Wikimedia may be served from infrastructure outside the EEA; that is inherent to loading those files.
10. Your rights
If you are in the EEA or the UK you have rights of access, rectification, erasure, restriction, objection and portability, and you may complain to your supervisory authority (in Norway, Datatilsynet). In practice the only personal data we hold about you is email you have sent us: write to the address below and we will act on it. We cannot answer an access request about browsing that we never recorded.
11. Children, security, external links and changes
SnapDestinations is a general-audience information site, is not directed at children, and collects no personal data from anyone beyond the analytics and technical data described above. Pages are served over HTTPS; because we operate no accounts and no database, there is no stored personal data to breach on our side. Pages link to external sites — official transport operators, statistics agencies, licence texts — and those sites have their own privacy practices, which we do not control. If SnapDestinations adds advertising or any other new processing, this page will be updated before that goes live, together with any consent mechanism the law requires.
12. Contact
Privacy questions can be sent to snapdestinationsplus@gmail.com. See the contact page for what to expect when you write.