1. Overview & Service Scope

click.holiday (“we,” “our,” or “the Platform”) operates as an editorial travel wire aggregator, curating global travel dispatches, regional trends, and destination ideas from across the web. Our service provides concise editorial summaries alongside direct backlinks to original publishers and travel operators.

This Privacy Policy applies to all interactions with the click.holiday website (https://click.holiday), our RSS feeds, API endpoints, email dispatches (“The Weekly Wire”), and editorial submission channels. By using our service, you acknowledge the data practices described in this document.

2. Direct Information Collection

We collect personal information only when you explicitly and voluntarily provide it to us through the following channels:

  • Newsletter Subscriptions (“The Weekly Wire”): When you subscribe to our weekly editorial digest, we collect your email address. We enforce a strict double opt-in protocol: a confirmation link is sent to your email and you are only added to active dispatches after you confirm.
  • Contact & Editorial Inquiries: When submitting story tips, corrections, advertising requests, or general inquiries via our contact form or direct email, we collect your name, email address, topic selection, and the contents of your message.

We do not collect sensitive personal data such as payment card details, passport numbers, government IDs, biometric data, or precise geolocation coordinates.

3. Automated Analytics & Telemetry

To understand aggregated readership patterns and maintain wire reliability, we collect non-identifying technical information when you navigate the platform:

  • First-Party Server-Side Telemetry: Our Hono backend API collects minimal server-side event logs (such as request timestamps, requested slug, HTTP status codes, and aggregate read completion rates). These logs do not store raw IP addresses or track individuals across sessions.
  • Google Analytics 4 (GA4): We utilize GA4 to measure aggregate pageviews, referrer domains, device categories, and general country-level distribution. We have enabled IP anonymization (IP masking), disabled Google Signals advertising identifiers, and turned off data sharing with third-party ad networks.
  • HTTP Referrer & User-Agent Data: Standard browser headers are parsed solely to ensure responsive layout compatibility and detect malicious automated scrapers.

4. Anti-Spam & Bot Protection (Cloudflare Turnstile)

To safeguard our submission endpoints and forms from automated credential abuse, spam bots, and Distributed Denial of Service (DDoS) attacks, we employ Cloudflare Turnstile.

Cloudflare Turnstile validates human visitors using non-interactive, privacy-preserving cryptographic challenges. Unlike legacy CAPTCHAs, Turnstile does not harvest biometric information, analyze your personal browsing history, or drop persistent ad-tracking cookies. Turnstile verification tokens are validated server-side on our Hono backend and discarded immediately after validation.

5. Cookies & Local Storage

We believe in minimal client-side storage footprint:

  • Strictly Essential Cookies: Ephemeral session headers and CSRF security tokens necessary for the secure transmission of form submissions.
  • Local Storage: Browser local storage may be used to store UI preferences (such as dismissal state for notification banners and client-side cache keys) to enhance page load performance. No personal tracking data is written to local storage.
  • Zero Cross-Site Ad Cookies: We do not deploy third-party retargeting pixels, behavioral tracking beacons, or cross-domain ad cookies.
  • Global Privacy Control & DNT: We honor browser-level Do Not Track (DNT) and Global Privacy Control (GPC) headers.

6. Third-Party Infrastructure & Processors

To deliver a fast, reliable, and secure travel wire, we partner with reputable infrastructure and service providers who comply with stringent privacy and security standards:

  • Buttondown: Newsletter delivery, double opt-in subscriber database, and one-click unsubscription processing. Buttondown adheres to strict privacy standards and GDPR-compliant Data Processing Addenda (DPA).
  • Cloudflare, Inc.: Global Content Delivery Network (CDN), DNS routing, SSL/TLS encryption termination, and Turnstile bot protection.
  • Google Analytics (Google LLC): Aggregated traffic reporting with IP masking and ad personalization disabled.
  • Neon (Serverless Postgres) & Google Cloud Run: Encrypted database storage and container compute environments hosting our backend API, operating within SOC 2 and ISO 27001 certified facilities.

7. Your Privacy Rights (GDPR & CCPA / CPRA)

Regardless of your geographic location, click.holiday affords you comprehensive data protection rights:

  • Right to Access & Portability: You may request a copy of the personal data we hold about you in a structured, machine-readable format.
  • Right to Rectification: You may ask us to correct inaccurate, incomplete, or outdated personal information.
  • Right to Erasure (“Right to be Forgotten”): You may request that we permanently delete your email address, contact records, and any associated correspondence from our active systems.
  • Right to Withdraw Consent: You may withdraw your newsletter consent at any time by clicking the “Unsubscribe” link found in the footer of every email we send, or by emailing us directly.
  • California Consumer Privacy Act (CCPA / CPRA): We do not sell or share your personal information for monetary or cross-context behavioral advertising consideration. You have the right to equal service and non-discrimination when exercising your privacy rights.

To exercise any of these rights, email us at privacy@click.holiday. We will verify and complete your request within 30 days free of charge.

8. Data Retention & Security Standards

We adhere to data minimization principles and do not retain data longer than necessary:

  • Newsletter Subscriber Records: Retained only while your subscription remains active. If you unsubscribe, your email is suppressed from mailings and purged according to data retention schedules.
  • Contact Inquiries: Messages sent via the contact form are retained for up to 90 days to resolve your enquiry, after which they are archived or securely deleted.
  • Security Architecture: All communication between your browser and our servers is encrypted using modern TLS (HTTPS) with HSTS enforcement. Data at rest is encrypted using industry-standard AES-256 encryption.

9. Children’s Privacy

click.holiday is a general audience editorial wire intended for individuals aged 16 and older. We do not knowingly solicit or collect personal information from children under 16 years of age. If we learn that personal data of a minor has been submitted without verifiable parental consent, we will promptly delete that information.

10. Data Protection Officer & Contact Information

If you have questions, feedback, or concerns regarding this Privacy Policy, our data handling practices, or wish to exercise your statutory rights, please contact our Data Protection Officer:

Data Protection Office

click.holiday Data Protection & Privacy Team
Privacy Inquiries & Erasure: privacy@click.holiday
General Inquiries: contact@click.holiday
Response Time: Within one working day (statutory requests within 30 days)

We periodically review and update this policy to reflect platform updates and evolving regulatory standards. Changes take effect upon posting to this URL.