DRAFT TEMPLATE — REQUIRES LEGAL REVIEW before launch.
Privacy Policy
Last updated: TODO: date
This policy explains what Holocene (“Holocene”, “we”, “us”) collects, why, who we share it with, and the choices you have. We’ve tried to keep it short and plain.
Contact: TODO: contact email
Data controller: TODO: legal entity name and address
What we collect
When you join the waitlist
- Your email address
- Your home city or airport, stored as a city code (for example NYC or LON)
- How you describe yourself (for example employed, remote worker, student). You choose this from a list.
- The trip or creative project you keep putting off, if you choose to tell us. This is optional free text.
- Campaign information from the link you arrived on (UTM parameters)
- The referral code of the person who invited you, if any, and your own referral code
We use this to send you the flight alerts and updates you asked for, to count sign-ups toward unlocking your airport, to run the referral rewards, and to understand which channels people find us through.
Your sign-up only counts once you confirm your email (double opt-in).
When you sign up for the workshop or enter the Leap Grant
- Workshop: your email address.
- Leap Grant: your name, email, home airport, the link to your video, and the trip you describe. See the Leap Grant Official Rules for how entries are used.
When you become a member
- Your membership and payment are handled by Circle, our community platform, and its payment processor. We do not receive or store your full card number.
- We keep a record of whether your email has an active membership, so we can send member alerts and let you into the member library.
- Whatever you post in the community is visible to other members.
Automatically
- Basic technical data needed to serve the site and keep it secure, such as IP address and browser type. We use IP addresses to limit abuse of our forms.
- Aggregate, cookieless page statistics through Cloudflare Web Analytics. This does not use cookies and does not build a profile of you.
We do not knowingly collect data from anyone under 18.
The public map
Our home page shows a map with dots for cities where people have joined the waitlist. The map shows city-level totals only. It never shows names, email addresses, or anything that identifies an individual.
TODO: confirm minimum count per city before a dot is shown.
Cookies and browser storage
We keep this minimal.
- One login cookie, for members only. When you log in to the member library with an email link, we set a single signed, HttpOnly cookie that keeps you logged in for 30 days. It is strictly necessary for the library to work.
- Local storage for bookmarks. If you bookmark places or mark them as “been”, that list is saved in your own browser (localStorage). It stays on your device and is not sent to us.
- Bot protection. Our forms use Cloudflare Turnstile to tell people from bots. Turnstile may process technical signals from your browser to do this.
- We do not use advertising cookies or cross-site tracking cookies.
Who we share data with
We do not sell your personal data. We use these service providers to run Holocene:
- Cloudflare: hosting, database, security, Turnstile bot protection and Web Analytics.
- Kit (kit.com): email delivery, subscriber list, tags and sequences.
- Circle (circle.so): community, live coaching calls, membership checkout and billing, together with its payment processor (Stripe).
- Airtable: stores our curated content (accommodations, restaurants, experiences, destinations) only. We do not put your personal data in Airtable.
- Travelpayouts: flight price data and affiliate links. When you click a flight link you go to a third-party site, which may set its own cookies and has its own privacy policy.
- TODO: confirm automation provider (Zapier or Make), which passes membership status from Circle to Kit.
Some of these providers are based in the United States or process data there. TODO: confirm international transfer mechanism (for example Standard Contractual Clauses or the Data Privacy Framework).
We may also disclose data if the law requires it, or to protect our rights or the safety of others.
Affiliate disclosure
Some links on Holocene, including flight links in deal alerts and on deal pages, are affiliate links. If you book through one, we may earn a commission at no extra cost to you. This does not change which deals we show you. We pick deals on price.
Legal bases (EEA and UK)
- Consent: sending you emails you signed up for. You can withdraw consent at any time.
- Contract: providing your membership.
- Legitimate interests: keeping the site secure, preventing referral fraud, and understanding how the site is used in aggregate.
- Legal obligation: tax and accounting records.
How long we keep data
- Waitlist and subscriber data: until you unsubscribe or ask us to delete it. TODO: confirm retention period after unsubscribe.
- Membership records: for the length of your membership, and afterwards as long as tax and accounting law requires.
- Leap Grant entries: TODO: retention period.
- Security logs: TODO: retention period.
Your rights
Wherever you live, you can unsubscribe from any email using the link at the bottom, and you can ask us to delete your data by writing to TODO: contact email.
EEA and UK (GDPR and UK GDPR)
You have the right to:
- access the personal data we hold about you
- correct it
- delete it
- restrict or object to our use of it
- receive it in a portable format
- withdraw consent at any time
- complain to your data protection authority (in the UK, the Information Commissioner’s Office)
California (CCPA/CPRA)
You have the right to:
- know what personal information we collect, use and disclose
- delete it
- correct it
- opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined in California law.
- not be discriminated against for using these rights
To use any of these rights, email TODO: contact email. We will reply within the time the law requires. We may need to confirm your identity first.
Security
We limit the data we collect, keep API keys and secrets out of our code, and use signed cookies and bot protection. No system is perfectly secure. If we learn of a breach affecting your data, we will tell you as the law requires.
Changes
If we change this policy in a way that matters, we will update the date above and tell subscribers by email.
Contact
TODO: contact email
TODO: legal entity name and postal address