Privacy Policy

1. Who is responsible for your data

LocalPilot hosts operator websites and processes bookings on their behalf. When you book, both LocalPilot and the operator receive your booking details. LocalPilot is responsible for the platform, guest accounts, and the emails we send. The operator is responsible for how they use your details to deliver the trip and for any marketing they choose to send.

2. What we collect

3. How we use it

To take and confirm bookings, send codes and confirmations, remind you about upcoming trips, help operators run their business, prevent fraud, support you, and improve the product. We do not sell personal information.

4. Email

Transactional email (sign-in codes, confirmations, day-before reminders, receipts) is sent through Resend and is required to use the service. Operators can send marketing campaigns to their past guests through LocalPilot. Every marketing email includes an unsubscribe link; using it stops marketing from that operator immediately. Unsubscribing does not stop transactional email about a booking you hold.

5. Cookies

We use cookies to keep you signed in, to remember your booking while you check out, and to keep the site secure. Analytics cookies and identifiers, described next, help us understand how the product is used. You can clear or block cookies in your browser; sign-in and checkout will not work without the essential ones.

6. Analytics, session replay, and error monitoring

We use Amplitude for product analytics and session replay. Analytics records which pages and features are used. Session replay reconstructs how a page was used (clicks, scrolls, and navigation) so we can fix confusing flows. Text you type into form fields is masked before it leaves your browser, and payment fields are never captured because they are rendered by Stripe. We use Sentry for error monitoring; when something breaks, Sentry receives a technical report that can include the page, browser, and the account or booking involved. Both providers process this data on our behalf under their own security commitments.

7. Who we share it with

8. Retention

Booking and payment records are kept for as long as the operator’s account is active and for seven years afterward to meet tax and accounting obligations. Guest accounts stay open until you ask us to close them. Analytics and session replay data are retained for up to twelve months; error reports for up to ninety days. Marketing suppression lists are kept so that an unsubscribe continues to be honored.

9. Your choices and requests

You can ask to see, correct, or delete the personal information we hold about you, or to stop analytics processing, by emailing hello@joinlocalpilot.com. We answer within thirty days. We may keep records we are legally required to retain, and we will tell you if that applies. Residents of states with privacy laws (such as California) have the rights those laws provide, and we honor them without discrimination.

10. Children

The service is not directed to children under 13 and we do not knowingly collect their personal information. Guests under 18 must be booked by an adult.

11. Security

Data is encrypted in transit, access to production systems is limited to staff who need it, and payment data never touches our servers. No system is perfectly secure; if a breach affects you we will notify you as the law requires.

12. Governing law and changes

This policy is governed by the laws of the State of [STATE] (placeholder to be completed before publication) and applicable US federal law. We may update it; the effective date at the top will change, and we will email account holders about material changes.