Privacy Policy

Last updated: [DATE] · Location notice version 2026-10-07b · For US visitors

Starter template: not legal advice. This page was drafted to describe what this website's code actually collects. It has not been reviewed by a lawyer, and publishing it does not by itself make the site compliant with the CCPA/CPRA, GDPR, UK GDPR, ePrivacy rules or any other law. Have counsel review it, fill in every [bracketed] item, and remove this box before launch.

Who we are

This website, rivercardcruiseline.com, is operated by [River Card Cruise Line legal entity name], [postal address] ("River Card", "we", "us"). Questions or requests: [privacy@rivercardcruiseline.com].

Who this site is for

This website and its services are intended for visitors in the United States and its territories (Puerto Rico, Guam, the US Virgin Islands, American Samoa and the Northern Mariana Islands). We use the country Cloudflare associates with your IP address to decide this. Requests from other countries, from unknown locations and from the Tor network are shown a "US visitors only" page instead of the site. For those refused requests we keep only a daily count per country. We do not store their IP address, browser details or anything else. A VPN or proxy can make a US visitor look like they are elsewhere, and the reverse.

What we collect on every visit

When you load a page, our server (a Cloudflare Worker) records:

We skip logging for obvious automated traffic (search-engine crawlers, scripts) and for requests for images, fonts and styles. We also label visits that look automated (for example, ones coming from cloud-hosting or internet-scanner networks, or with browser details that don't add up), using the network and device details above. The label is only used to separate real visitors from bots in our own statistics.

Pre-registration: only if you sign up

If you fill in the pre-registration form, we collect your name and email address to send you launch updates about River Card Cruise Line, such as when booking opens. We store them with the time you signed up, your IP address, your session ID, the page-view ID and your browser's user-agent string (to link the sign-up to the visit details above and to prevent abuse). We don't ask for anything else, and we don't take payment. To be removed from the list, email [privacy@rivercardcruiseline.com]. [Describe how launch emails will be sent, e.g. the email provider used, and the unsubscribe link each email will carry.]

Precise location: only if you choose to share it

When you open the home page we show a short card offering to find your best airports. Neither the card nor the page asks your browser for your location by itself. Only when you tap "Share my location" on the card, or "Use my precise location" further down the page, does your browser show its own permission prompt, and nothing is collected if you decline. If you allow it, we save:

We also record which button you used (the arrival card, the in-page button, or an automatic update, described next), so we can see how location is being shared.

Later visits. When you share, your browser stores a small note (rc_location_consent, the notice version you agreed to) in its local storage on your device. If you come back on the same browser, the note still matches the current notice, and your browser still allows this site to use your location, the page updates your saved location automatically without asking again, and the location section tells you it did. If we change the notice, we ask again. Tapping "Not now" on the card stores rc_arrival_snooze_until so the card stays hidden for 7 days. These local-storage entries are not sent to our server.

You can tap "Stop saving my location" at any time on that page. The map keeps working, nothing further is sent, and the automatic update on later visits is switched off (the rc_location_consent note is deleted). Typing a city or airport instead of sharing your location sends nothing beyond the normal visit log.

Why we use it

PurposeData[Legal basis (EU/UK) — confirm with counsel]
Send launch updates to people who pre-registeredName, email addressYour consent, which you can withdraw
Suggest nearby airports and help plan your trip to Fort LauderdalePrecise location, device detailsYour consent, which you can withdraw
Understand how the site is used and improve itVisit log, device details[Legitimate interests / consent]
Keep the site secure and prevent abuse (e.g. rate limiting)IP address, visit logLegitimate interests

[State whether you sell or "share" (for cross-context behavioural advertising) personal information, and whether you use it for any other purpose such as marketing. The website code itself does not send this data to advertisers.]

How long we keep it

Visit records and saved locations are deleted automatically after 90 days by a daily job. Pre-registrations (name and email) are kept until you ask us to remove them or we stop sending launch updates [confirm your rule]. CSV exports an administrator downloads are kept only as long as needed for the purpose above [describe your rule]. [Check: Cloudflare D1 "Time Travel" point-in-time recovery may keep deleted rows recoverable for up to 30 days.]

Who can see it

Cloudflare operates globally, so data may be processed outside your country. [Describe transfer safeguards, e.g. Cloudflare's Data Processing Addendum / Standard Contractual Clauses.]

Your rights

California residents (CCPA/CPRA)

You may have the right to know what personal information we collect and how we use it; to access, correct and delete it; to opt out of its "sale" or "sharing"; and to limit our use of sensitive personal information, which includes precise geolocation. We will not discriminate against you for using these rights. You may use an authorised agent.

EU, EEA and UK residents (GDPR / UK GDPR)

[The site is limited to US visitors. Ask counsel whether this section is still needed, e.g. for EU/UK residents travelling in the US.] You may have the right to access, correct or erase your data, restrict or object to its use, receive it in a portable format, and withdraw consent at any time (this does not affect earlier processing). You can also complain to your local data protection authority. [EU/UK representative, if required.]

How to make a request

Email [privacy@rivercardcruiseline.com]. Unless you pre-registered (then we can look you up by email), we don't know your name, so we can usually only find your records from details such as the IP address you used, the approximate date and time of your visit, and your browser. We may need to verify a request before acting on it. [Add response times and any toll-free number required for your business.]

Your choices

Children

This site is not directed to children under 13 [or 16 in some regions], and we do not knowingly collect their data.

Security

Data is sent over HTTPS, stored in Cloudflare D1, and the admin page requires a secret token. No system is perfectly secure.

Changes

We will update this page and its date when our practices change. When the location notice changes, its version number changes too, and each saved location records the version that was shown.