Home / Privacy

Privacy Policy

Privacy policy

You do not need an account to use the ski planner. Optional usage analytics is on by default. You can turn it off with Reject analytics or Privacy settings. The planner still works either way. Newsletter signup and any AI text we send to answer a request you make are separate from that passive analytics.

Last updated: September 18, 2026

The short version

WhereToSkiNext.com does not require an account and does not collect a name or payment details to rank mountains. We do not sell your personal information. Optional usage analytics runs unless you reject it. If you subscribe to the newsletter, your email goes to Beehiiv, our email platform. If a page asks Anthropic to write recommendation copy for you, we send the mountain and trip facts needed to produce that text. That requested processing is not the same as the background analytics described below.

This page describes how the current site works. It is not legal advice, and it does not claim that this opt-out design meets every jurisdiction's consent rules.

Analytics choices

Analytics starts automatically when this browser has no valid rejection saved. The banner does not wait for Accept analytics before tracking can begin. Ignoring the notice, scrolling past it, or tapping Hide does not turn analytics off. Tracking continues until you reject it. Hide only removes the notice for this tab. Privacy settings, next to the Privacy Policy link in the footer, brings the notice back so you can change your choice. Reject analytics turns off future optional analytics from this browser, including our first-party usage events and the Google Analytics load that our consent code controls.

Your choice is stored in this browser as wtsn_consent_v1 for 183 days from the moment you accept or reject. After those 183 days, the saved choice expires. Analytics turns back on automatically, and the banner shows again until you accept, reject, or hide it for that visit. Clearing this site's browser storage removes the saved choice, which has the same effect: analytics is treated as allowed until you reject it again.

If this browser cannot save the choice (for example, blocked storage or some private modes), the choice still applies for that page load in memory. Reload or open a new visit and there is no saved rejection, so analytics is allowed again and the banner returns.

A choice applies to that browser on that device. It does not automatically follow you to your phone, another browser, or another computer.

What we collect and why

The ski planner does not use an account. Email is collected only if you subscribe. Optional analytics uses random identifiers created in your browser. Those identifiers are not your name, but they can link activity across visits in that browser. They do not make the records fully anonymous.

DataHow it's usedWhere it's stored
Email address (if you subscribe) Used to send the weekly newsletter. Collected only if you sign up. Beehiiv, our email platform. Unsubscribe with the link in any email.
Start point (ZIP, city, GPS, or an IP estimate) Used to rank mountains by drive and conditions. Precise device location is read only if you tap Use my location. A start point you set is saved in this browser. An IP estimate is used to rank for that visit and is not written to that saved-location key. See Location below.
Saved planner settings Restores pass, trip distance, and priority choices on a later visit. This browser only. Resetting filters changes those settings. It does not clear analytics identifiers or your privacy choice.
Cached weather Avoids repeat forecast fetches during a session. This browser's session storage. It goes away when you close the tab.
Optional usage analytics (unless you reject it) Helps us see how the planner is used. This can include filter and ski-date choices, the recommendation shown and related result information, mountain detail opens, compare-my-mountain events and recommendation feedback, sponsor clicks, and ordinary outbound clicks to a mountain website or tickets page. A click is not a purchase and not proof you skied there. Crowd-forecast check-ins are optional. If you dismiss that prompt, nothing is sent for that answer. Our analytics database (Supabase), tied to random browser identifiers, not to your email. Google Analytics also receives page, device, referral, and similar traffic data when that tag is allowed to load.

We do not collect your name, payment information, or account passwords. There are no accounts on this site.

Random browser identifiers

When analytics is allowed, the site can create a persistent browser ID (wtsn_client_id) and a shorter visit ID. The same browser ID can be sent with later events from this browser, so filter changes, recommendations, and clicks can be joined without knowing who you are. If storage is blocked, an ID may exist only in memory for that visit.

Location

Using a start point to rank mountains is how the planner works. That is separate from storing a coarse origin label in analytics, and separate from sending coordinates to a routing service.

When you visit, we may estimate city and region from your IP address through our host (Vercel) so we can rank without asking you to type a ZIP. That estimate is approximate. The geo function returns it to your browser and does not insert it into our analytics tables. Hosting infrastructure can still see request metadata, including IP addresses used for routing, rate limits, and platform logs. We have not verified those providers' log retention.

If you set a start point yourself, we save the label and coordinates in this browser for about 180 days so you do not have to re-enter it. We only read precise GPS from your device if you tap Use my location. Drive-time requests send your coordinates and resort coordinates from your browser to OSRM. We do not proxy those routing requests through our analytics database. When analytics is on, a coarse origin such as "Boston, MA", a ZIP, or "GPS" can be stored with usage events. That is not a street address, and it is not the same as storing live GPS coordinates in analytics.

If you create a share link, your current planner settings, including approximate coordinates and the location label, are encoded in the URL. Anyone with that link can see those settings. Clear the location field first if you do not want that in the link.

Third-party services the app contacts

When you use WhereToSkiNext.com, your browser or our servers make requests to the services below. We do not control their privacy practices. Links to their policies are included where we have them. We do not promise how long those providers keep what they receive.

ServicePurposeData sent
Vercel
vercel.com/legal/privacy-policy
Hosts the site and API routes, including the IP-based location estimate Ordinary request data for any internet host, which can include IP address, URL, and browser headers. Our geo route reads Vercel's location headers to return an approximate US city and coordinates to your browser.
Open-Meteo
open-meteo.com
Live weather forecasts for ski areas Latitude and longitude of ski areas (not your start point). The homepage forecast often goes through our /api/forecast proxy using resort coordinates from our catalog. Some mountain pages still request Open-Meteo from the browser.
Open-Meteo Archive
open-meteo.com
Recent historical snowfall for ski areas Latitude and longitude of ski areas (not your start point)
Project OSRM
project-osrm.org
Road drive times from your start point to mountains Your coordinates and resort coordinates, from your browser, used to compute a route. No account is sent.
Zippopotam.us
zippopotam.us
Converts a US ZIP to coordinates The ZIP code you type
OpenStreetMap Nominatim
nominatim.org
Converts a city or address search to coordinates The location text you type
Beehiiv
beehiiv.com/privacy
Newsletter delivery The email address you submit when you subscribe. Beehiiv handles storage, delivery, and unsubscribe.
Anthropic
anthropic.com/privacy
Writes recommendation copy when you use that feature Structured mountain and trip facts needed to produce the writeup, sent because you asked the planner for a recommendation. That is not optional analytics retention. We do not currently write AI query text into our analytics database. Current pages do not send a free-text assistant chat into analytics.
Supabase
supabase.com/privacy
Our first-party analytics database Usage events described above, including random browser identifiers and coarse origin labels when analytics is allowed. This is where WTSN stores those events. Google Tag Manager is not that database.
Google Analytics
policies.google.com
The analytics service for page-level traffic when analytics is allowed Standard analytics data such as pages visited, browser and device type, approximate region, and referrer. When analytics is allowed, Google Tag Manager has loaded Google Analytics as G-VK2Q3TTFEW. Custom events we put on the page can be forwarded if that tag is configured to do so. We have not inventoried every other tag inside the container, and we did not capture a production network trace.
Google Tag Manager
policies.google.com
Loads analytics tags. It is tag management, not our event database The container we load is GTM-MCCDNQGB. Our consent code grants analytics storage unless you have rejected, and it keeps ads storage denied. This container has loaded G-VK2Q3TTFEW. Other tags, if any, were not fully inventoried.
Google Fonts
developers.google.com
Loads typefaces used on the site Your IP address and browser info are sent to Google when the font files load. Font loading is not turned off by Reject analytics.

Drive-time calls to OSRM go from your browser to OSRM. Newsletter signup is a request you make. AI writeups are a request you make by using the planner's recommendation copy. Optional analytics is the background tracking you can reject.

Cookies and browser storage

Analytics uses cookies and similar browser storage. localStorage is not outside tracking controls. Reject analytics is meant to stop optional analytics even when some of it lives in localStorage rather than a cookie.

Storage that supports the planner

KeyTypeWhat it stores
wtsn_location_v1localStorageStart point you set (ZIP, city, or Use my location), including coordinates, for about 180 days. IP estimates are not saved here.
ski-saved-originlocalStorageOlder saved-location key. Migrated into wtsn_location_v1 when present.
ski-planner-weightslocalStorageYour snow, size, value, and crowd priority settings
ski-pass-preflocalStorageYour selected pass preference
ski-hero-prefslocalStorageYour selected pass filter and trip-distance setting
wtsn-comparelocalStorageA short-lived compare-my-mountain session (about 4 hours)
ski-wx-cache-v8sessionStorageCached weather for this tab
ski-hist-cache-v1sessionStorageCached historical snowfall for this tab

Reject analytics leaves these planner keys in place. Resetting filters in the app also leaves analytics identifiers and wtsn_consent_v1 in place.

Storage that remembers your privacy choice

KeyTypeWhat it stores
wtsn_consent_v1localStorageJSON with status (accepted or rejected), ts (when you chose), and version (currently 1). Valid for 183 days. Saving this choice does not create an analytics ID by itself.

Optional analytics cookies and identifiers

KeyTypeWhat it stores
wtsn_client_idlocalStorageA random browser ID and an expiry. Lifetime is 90 days and slides forward while analytics is allowed and the ID is used.
wtsn_visit_idlocalStorageA visit ID refreshed after 30 minutes idle, while analytics is allowed
wtsn_rec_handoff_maplocalStorageShort-lived recommendation context so a mountain-page click can stay tied to the pick, for 10 minutes
wtsn_rec_handoffsessionStorageThe same handoff for the current tab, for 10 minutes
wsn_sessionsessionStorageOlder session-ID fallback used if durable storage is unavailable
wtsn-rec-feedback-v1sessionStorageIn-tab state for "does this pick feel right?" feedback
wtsn_feedback_v1localStoragePending crowd-forecast check-ins for later visits (mountain, ski day, what we predicted)
Google Analytics cookiescookiesWhen analytics is allowed, Google Analytics may set first-party cookies. Names commonly start with _ga. Our reject path also tries to expire cookies starting with _gid, _gat, _gcl_, _dc_gtm_, __utm, and AMP_TOKEN if they are present on this site. We have not confirmed every Google cookie from a live production network capture.

You can clear site data for wheretoskinext.com in your browser. That removes planner settings, the privacy choice, and analytics identifiers stored here.

What rejection does, and what it does not

Reject analytics stores a rejection, stops future optional analytics from this browser, and removes the supported analytics keys listed above from this site's localStorage and sessionStorage. It also tries to expire the Google cookie prefixes listed above on this site. If Google Tag Manager had already started on that page, the tab reloads so those tags are not left running.

Rejection does not delete usage records already stored in our database or at Google. It cannot recall a request that already left the browser. It cannot guarantee removal of cookies Google sets on Google's own domains. It does not clear your saved ski preferences, weather cache, or compare session.

How long records are kept

Three clocks are easy to mix up. They are not the same.

Proposed approach for review, not yet built: keep first-party analytics event rows for 24 months from created_at, then delete them. That covers two ski seasons of product work without treating the 183-day banner choice as a database deletion timer. Google Analytics retention would still need an explicit setting in Google's admin, which we have not verified here. Newsletter addresses stay with Beehiiv until you unsubscribe or we delete them there.

Children's privacy

WhereToSkiNext.com is aimed at adults planning ski days. It is not directed at children under 13. If you believe a child has submitted information, email us at the address below.

Questions, access, and deletion

Email trip@wheretoskinext.com for privacy questions or to ask us to delete what we can find. If you subscribed, we can work from that email to remove the Beehiiv subscription. Optional analytics rows are keyed to random browser identifiers, not to your email, so an email address alone may not let us identify every matching record. We will not ask you for extra identity data solely to search those tables. Clearing this site's storage in your browser is the reliable way to drop the local identifiers and the saved privacy choice.

Changes to this policy

If we change how we handle data in a material way, we will update the Last updated date at the top of this page.

September 18, 2026: Clarified that hiding or ignoring the analytics notice does not opt out. Tracking stays on until you reject it. The notice is a compact card so it does not cover planner controls.

September 16, 2026: Rewrote this policy to match the current opt-out analytics banner. Analytics runs unless you reject it. Added Privacy settings, expiry, identifiers, rejection cleanup, and the current retention status.

June 2026: Added the crowd-forecast check, which can ask on a later visit whether a mountain we recommended felt quiet or packed. It is optional and, when sent, is stored with a random identifier rather than your name.

Questions about this policy?
Reach us at trip@wheretoskinext.com