Legal

Privacy

Enjoy Vancouver Island is a free directory for Vancouver Island. You can use almost all of it without an account and without telling us who you are. This page says exactly what is recorded when you do use it.

Last updated 21 September 2026.

The short version

  • No advertising, no ad networks, no cross-site tracking pixels, and nothing sold or shared for marketing.
  • No cookie banner, because we set no cookies you could meaningfully decline — the only cookie is the one that keeps you signed in, and it only exists if you sign in. The things we do store live in your browser’s local storage, listed below.
  • We do record every page view and click, with a random session id, your IP address and your browser’s user-agent string. That is how we know which pages are worth keeping.
  • Card numbers never reach us. Payments go through Stripe.
  • Anything you want removed: email hello@enjoyvancouverisland.com and say so.

What we record when you browse

Every page view, every tap on a venue, event or link, every search, and every swipe in Discover is written to one table, analytics_events. A row holds:

  • A session id.A random value generated in your browser and kept in that browser’s local storage, plus a second random id for the current visit. Neither is derived from anything about you, and neither follows you to another site.
  • What you looked at — the page, and the id of the venue or event, if it was one. For a search, the words you typed and how many results came back.
  • Where you came from — the referring URL and any utm_* parameters on it.
  • Your IP address and user-agent string, recorded with the event. The user-agent is what lets us tell crawler traffic from human traffic — about six visits in seven here are bots, and reporting is useless without that split.
  • Your user id, but only if you are signed in.

We use this in aggregate: which pages earn visits, which searches return nothing, which venues get clicks. Business owners who have claimed a venue see the counts for that venue alone — never a visitor’s identity, IP or session id.

Hosting-level performance data (page load timings) comes from Vercel Analytics and Speed Insights, which are cookieless and do not build a per-person profile.

What happens to a question you ask the AI

The site’s home page, and every venue page, answer questions. When you send one:

  • Your question is sent to Anthropic’s Claude API, which writes the answer. Along with it we send the site’s own instructions and the results of the lookups the model asks for — real venues, events and weather from this database and from the Open-Meteo forecast service.
  • The question is also recorded as a search event, as described above, so we can see what people ask for and do not find.
  • If you are signed in, the conversation is saved to your account so you can come back to it, and a small profile of what you have favourited and clicked is used to make answers more relevant. Signed out, nothing about the conversation is tied to you beyond the session id.
  • We do not use your questions for anything else, and we do not train a model on them.

The model can be wrong. Treat an answer about hours, prices or conditions as a starting point, not a guarantee — see the terms.

If you make an account

Accounts are optional and only unlock saving. Sign-up stores your email address and a password hash through Supabase Auth; we never see the password itself. With an account we also store:

  • The venues and events you favourite, and the trips you build.
  • Your saved AI conversations.
  • Reviews, check-ins and photos you choose to post. These are public — that is the point of posting them — and a check-in you make from the button that asks for your location stores the coordinates your browser reports.

Signed out, favourites and preferences stay in your browser’s local storage and are never sent to us. Signing in merges them into your account.

Settings has a button that clears everything this browser has stored. To have the account itself and its rows deleted, email hello@enjoyvancouverisland.com from the address on the account.

What this site keeps in your browser

None of this is sent to us unless the page says so above, and clearing your browser data removes all of it.

  • evi_vid — the random visitor id that goes on analytics events, and evi_visit, the per-visit one.
  • evi_favorites — what you have saved while signed out, and evi_fav_synced, a marker that it has been merged into your account.
  • evi_home_convo_v1 — the conversation in progress on the home page, so a reload does not lose it.
  • vi-directory-preferences— your settings, including a location you volunteered with the “near me” button. That location stays in your browser.
  • evi_nearby_seen and a cached forecast per set of coordinates — so the same thing is not fetched twice.
  • Mapbox’s own mapbox.* entries, on pages with a map.

Email we send, and how to stop it

  • The weekend digest. Double opt-in: we store the address you type and which page you typed it on, send one confirmation email, and add you to the list only if you click the link in it. Every digest carries an unsubscribe link.
  • Invitations to claim a business listing.Sent to the contact address a business already publishes, about that business’s own page. Every one carries a one-click unsubscribe link and a postal address, and the address is added to a permanent do-not-contact list the moment you use it. You can also just reply with “unsubscribe”.
  • Transactional mail — confirmations, booking receipts, password resets. These follow what you asked us to do and have no opt-out beyond not doing it.

Email is delivered by Resend, which handles the sending and the bounce records.

Payments

Paid plans and ticket or booking purchases run through Stripe Checkout, and money owed to a business runs through Stripe Connect. Your card details go from your browser to Stripe and never touch this site — we receive the outcome: which plan or item, the amount, the email you gave Stripe, and an identifier for the payment.

Stripe processes that under its own privacy policy, as an independent controller.

Who else touches the data

  • Supabase — the database and sign-in.
  • Vercel — hosting, plus cookieless performance analytics.
  • Anthropic — the model that writes AI answers.
  • Stripe — payments and payouts.
  • Resend — outgoing email.
  • Sentry — error reports, and session replay (see below).
  • Mapbox— the map itself. The map library sends Mapbox its own usage events and keeps an identifier for them in your browser’s storage. It only loads on pages with a map.
  • Google Places — venue photographs. Your browser requests those images from this site, not from Google, so Google does not see your visit.
  • Open-Meteo — forecasts, requested by town, never by you.

Data is stored on infrastructure in Canada and the United States. Nobody buys this data from us, because we do not sell it.

Session replay

The site uses Sentry, which does two things. It records an error report whenever something breaks — the URL you were on, your browser, and the failure itself. And it records a session replay: a reconstruction of what happened on screen, built from the page’s structure and your clicks, scrolls and typing, played back like a video.

  • It runs on roughly one visit in ten, chosen at random, and on any visit where an error occurs.
  • It is configured to capture the page’s visible text and images rather than masking them, and to attach your IP address to the report.
  • We use it for one purpose: working out what actually went wrong when a page fails, which is otherwise guesswork on a site nobody staffs full time.

If you would rather not be recorded, most browsers’ “do not track” and script-blocking extensions stop it, and you can email hello@enjoyvancouverisland.com to have any replay associated with your account or a session id deleted.

How long we keep it

Honestly: there is no automatic deletion schedule for analytics events today, so they are kept for as long as the site runs. Account data lives until the account is deleted. Newsletter addresses live until you unsubscribe; an unsubscribed outreach address is kept deliberately, precisely so we never contact it again.

If you want rows tied to your account, your email address or a specific session id removed, email hello@enjoyvancouverisland.com and we will do it.

Your rights

Under Canadian federal privacy law (PIPEDA) and, where it applies to you, the GDPR, you can ask what we hold about you, ask for a copy, ask for corrections, and ask for deletion. One address handles all of it: hello@enjoyvancouverisland.com. You will get a human reply, and we will not ask you to create an account to make the request.

This site is not directed at children and we do not knowingly collect anything from them.

Changes

When what the site does changes, this page changes with it and the date at the top moves. There is no version history to consult; the date is the version.

The other document is Terms of use.