1. Introduction
Anywhere.Vegas uses cookies and similar browser technologies to operate the website, support authentication, remember interface settings, preserve planning information, retain recent searches and favorites, support temporary itineraries, measure limited feature interactions locally, and distinguish booking, affiliate, and ordinary website clicks locally.
Some of these technologies are traditional cookies. Others are not. Several of the categories described below store information entirely within your browser and are never transmitted to Anywhere.Vegas servers. We use the term “browser storage” when referring to those; we use “cookie” only for actual cookies.
3. Similar Browser Technologies
Several Anywhere.Vegas features do not use cookies at all. They use other browser mechanisms:
- localStorage — a per-origin store where information can remain in the browser until it is removed by application logic, cleared by the visitor, reset by the browser, or removed by our retention cleanup.
- sessionStorage — a per-tab store that ordinarily lasts only for the current browser tab or session. Third-party libraries loaded by the site may use sessionStorage internally; Anywhere.Vegas application code does not rely on it for its own features.
- In-memory application state — information held temporarily in the running page, such as precise location coordinates, which is not written to persistent browser storage.
- Authentication storage — our authentication provider may use cookies and browser storage to keep your signed-in session active. Specific token names and formats are intentionally not published here.
localStorage is not technically a cookie, even though it is often discussed alongside cookies. We describe both because both matter for privacy.
4. Current Technology Categories
The categories that currently apply to Anywhere.Vegas are:
- Strictly Necessary and Security
- Functional and Preference
- Planning and Convenience Storage
- Local Measurement and Diagnostics
- Affiliate and Booking Click Storage
- Third-Party Services and External Links
We do not currently operate an “Advertising Cookies” category. No third-party advertising pixels or cross-site behavioral advertising cookies were identified in the audited application code. See section 11.
5. Strictly Necessary & Security Technologies
These technologies are required to operate the site, keep you signed in, deliver requests, and defend against abuse. Examples include:
- Authenticating account holders and maintaining signed-in sessions.
- Routing requests and delivering pages.
- Preserving essential navigation state during a session.
- Fraud prevention and infrastructure security handled by our providers.
The identifiable application-controlled cookie in this category is:
- sidebar_state — first-party functional cookie remembering whether the collapsible interface sidebar is open or closed. Persistent, approximately 7 days. Not essential for public content; if it is missing, the sidebar simply opens in its default state.
Authentication session information is managed by our authentication provider using its own cookies and browser storage. We do not publish the token or storage-key names to avoid weakening account security. The duration of these authentication credentials is governed by the provider’s configuration rather than by a fixed period set in this policy.
6. Functional & Preference Technologies
Functional storage remembers interface preferences that make the site easier to use. Currently identified functional storage:
- The sidebar_state cookie described in section 5.
- A local profile record used to remember planner preferences you enter in your profile.
We do not currently use browser storage to remember a dark-mode preference, a language setting, or a persistent accessibility preference. If we add those preferences later, this policy will be updated.
Disabling or clearing functional storage may reset your interface preferences but should not, on its own, prevent access to public content.
7. Planning & Convenience Storage
Several planning features rely on your browser’s local storage rather than a server account:
- Temporary itineraries and planning drafts.
- A local “saved” flag on itineraries you deliberately keep.
- Favorited venues.
- Recent free-text planner searches.
- Recent venue and planning context used to keep planner results consistent between screens.
- Manually selected hotel, venue, or area anchors, where verified.
Verified retention behavior:
- Temporary itineraries: retained for up to 30 days after the last meaningful update, then removed the next time storage is read.
- Recent searches: retained for up to 30 days, capped at 20 entries.
- Favorites: kept until you remove them or clear browser storage.
- Locally marked saved itineraries: kept until you remove them or clear browser storage.
Planning storage:
- Generally remains on the same browser and device where it was created.
- Does not currently provide guaranteed cross-device synchronization.
- Can be cleared through the Profile Privacy Controls where supported.
- May disappear if browser storage is cleared, blocked, or unavailable.
8. Location Technology
Anywhere.Vegas asks your browser for precise location only after you start a feature that needs it — for example, a “near me” request. Your browser controls whether that permission is granted.
- Precise browser location is never requested silently in the background.
- Precise coordinates are held in application memory for a limited operational session, currently up to approximately 30 minutes.
- Precise coordinates are not intentionally written to persistent localStorage or a user database.
- You can use manual anchor selections (a hotel, venue, landmark, neighborhood, or area) instead of granting location permission.
- Anywhere.Vegas does not currently use application-level IP geolocation to personalize recommendations.
Hosting and security providers may still process IP addresses as part of normal service operation. In-memory coordinates are not a cookie.
9. Local Analytics & Diagnostics
The audited application code keeps limited interaction events in a bounded browser-local buffer:
- Analytics events are capped at the most recent 500 entries.
- Event information may include feature names, route information, venue identifiers, interaction types, and request-length metadata.
- Complete free-text recommendation prompts are not stored in the local analytics buffer.
- The audited application code does not transmit these buffers to Google Analytics, Meta Pixel, or another third-party advertising analytics service.
Hosting and security providers may still generate their own infrastructure logs as part of ordinary service operation; those are separate from this in-browser buffer.
10. Affiliate, Booking & Website Click Storage
To distinguish between affiliate links, booking links, and ordinary venue website links, Anywhere.Vegas may record outbound click events in a browser-local buffer:
- Click events are capped at the most recent 500 entries.
- Recorded fields may include a venue identifier, CTA type, and destination category or normalized destination information.
- The click buffer is not intended to contain full authentication tokens, raw prompts, or precise GPS coordinates.
- Once you follow an external link, the destination site’s own tracking may apply. Certain affiliate or booking providers may separately collect data after the visitor arrives.
Not every booking link is an affiliate link. For details on how affiliate relationships work, see the Affiliate Disclosure.
11. Current Absence of Advertising Trackers
At the time this policy was last updated, the audited Anywhere.Vegas application code did not include:
- Google Analytics.
- Meta Pixel.
- Advertising networks or remarketing pixels.
- Cross-site behavioral advertising cookies.
- Third-party marketing tag managers.
This statement describes application code only. Hosting and security providers may perform their own measurement and security logging as part of delivering the service. We do not treat the current absence of third-party advertising trackers as a permanent guarantee; this policy will be revised before adding materially different marketing or advertising technologies.
12. Authentication Providers
Anywhere.Vegas uses a managed authentication provider to sign users in and maintain authenticated sessions. That provider may use cookies, localStorage, or session technologies to:
- Keep you signed in.
- Refresh authenticated sessions.
- Protect account access.
- Support optional Google OAuth sign-in.
If you choose Google as your sign-in method, Google may set its own cookies and use its own technologies during the sign-in flow. Google’s own practices are governed by its policies, not this one.
We do not publish authentication token names, storage-key names, storage formats, or provider project identifiers here.
13. Infrastructure Providers
Anywhere.Vegas relies on a limited set of infrastructure providers that may use cookies or process technical request data for content delivery, load balancing, fraud prevention, abuse detection, authentication, service availability, diagnostics, and security. Verified providers include:
- Cloudflare — hosting, routing, edge delivery, and security.
- Lovable Cloud (Supabase) — database, authentication, and storage.
- Google — used only when a visitor selects Google OAuth sign-in.
Specific infrastructure-cookie names and durations are governed by each provider’s own configuration and are not asserted in this policy. These providers are not used to run Anywhere.Vegas advertising.
14. External Websites
When you follow a link from Anywhere.Vegas to a booking platform, a reservation site, a ticket provider, a venue website, a social media service, or an affiliate partner, those external websites may set their own cookies and use their own tracking technologies.
External technologies are governed by the third party’s own policies and controls. Anywhere.Vegas cannot remove cookies set by another website and does not control what those sites collect after you arrive.
15. Managing Cookies & Browser Storage
You can manage cookies and browser storage using several tools:
- Your browser’s cookie controls and site-data controls.
- Clearing site data for anywhere.vegas.
- Blocking browser storage for a specific site.
- Using private-browsing or incognito windows.
- Signing out to end the authenticated session.
- The Profile Privacy Controls for supported categories.
The Profile Privacy Controls can currently clear:
- Temporary itineraries.
- Recent searches.
- Favorites, where supported.
- Cached location information.
- Local analytics events.
- Click-event buffers.
Clearing at the browser level may also:
- Sign you out.
- Remove saved preferences.
- Delete temporary itineraries.
- Remove favorites.
- Reset interface state.
Browser-level clearing does not delete information that is held independently by our infrastructure or authentication providers, which is governed by their own policies.
16. Essential Technology Limitations
Some technologies are required for signing in, account security, maintaining authenticated sessions, protecting the website, and preserving certain actions during a session. If you block all cookies or all browser storage for Anywhere.Vegas, some features may:
- Fail to work.
- Reset between page loads.
- Prevent you from signing in.
You are still free to browse public content without granting these technologies, subject to those limitations. We do not claim that every form of browser storage is legally required.
17. Consent & Current Cookie Banner Status
Anywhere.Vegas does not currently operate a full cookie-consent banner or a consent-management platform.
- Currently verified application storage is primarily functional, planning-related, or local measurement storage.
- No audited third-party advertising pixels are currently active.
- Additional consent controls may be introduced before activating technologies that would require them.
18. Retention Summary
- Temporary itineraries: up to 30 days after the last meaningful update.
- Recent searches: up to 30 days, maximum 20 entries.
- Favorites: until you remove them or browser storage is cleared.
- Locally marked saved itinerary state: until you remove it or browser storage is cleared.
- Local analytics events: capped at 500 entries.
- Local click events: capped at 500 entries.
- Precise location: retained in application memory for up to approximately 30 minutes.
- Authentication storage: governed by session and provider configuration.
- sidebar_state functional cookie: approximately 7 days.
Durations for cookies set by third-party providers are governed by those providers and are not restated here.
19. Policy Changes
We may update this Cookie Policy when Anywhere.Vegas adds or changes analytics providers, advertising technologies, consent-management tools, cloud-synchronized itineraries, authentication providers, AI services, affiliate integrations, personalization, cookies, or browser-storage behavior.
The “Last Updated” date at the top of this page will be revised whenever material changes are published. Individual notice of updates is not guaranteed unless and until a notification system exists.
20. Contact
Questions about cookies, browser storage, authentication storage, local privacy controls, or clearing your data are welcome. Contact routing for the Legal & Trust Center is listed below; specific email addresses will appear once each channel is provisioned. See the Privacy Policy for broader information about personal data practices.
Cookie & privacy contact channels
Use the Legal & Trust contact form to reach the right team. Select the closest category and we’ll route your message internally.
General Legal
General questions about our policies, terms, or Legal & Trust Center.
Open contact formPrivacy
Privacy questions, data access requests, and deletion requests.
Open contact form
