1. Introduction
Anywhere.Vegas is a Las Vegas trip-planning site. This policy explains what information we handle when you use our public pages, browse Explore and venue pages, use our recommendation tools, chat with Concierge or Plan My Vegas Day, create temporary or saved itineraries, manage a profile, sign in, or interact with editorial and administrative tools where applicable.
Some Anywhere.Vegas features rely on your browser’s local storage, and some rely on third-party infrastructure providers such as our hosting and database platforms. Where that matters, we call it out below.
2. Information You Provide
You may choose to provide information when you use certain features:
- Email address and authentication credentials when you create an account or sign in.
- Google account information if you choose Google as your sign-in method.
- Profile details you enter (display name, hotel or area anchor, planning preferences).
- Itinerary content you create, edit, or save.
- Favorites you mark on venues.
- Recent searches generated as you use the planner.
- Free-text requests you type into Concierge, Help Me Decide, or Plan My Vegas Day.
- Media uploads submitted by authorized editorial or administrative users.
- Messages you send using the contact options listed in the Legal & Trust Center.
Most features are optional. Some — such as saving items to a persistent account — require you to sign in. Contact is currently handled through email destinations listed in the Legal & Trust Center; there is no public contact form at this time.
3. Information Collected Automatically
When you use Anywhere.Vegas, some information is handled automatically:
- Authentication session information when you are signed in.
- Temporary itineraries and planning drafts kept in your browser’s local storage.
- Recent searches stored on your device for convenience.
- Local analytics events and outbound click events kept in bounded browser buffers.
- Functional interface preferences (for example the sidebar state cookie).
- Browser, device, and network information that our hosting and security providers process to route requests, prevent abuse, and operate the service.
- IP addresses processed by infrastructure providers for routing, security, diagnostics, and fraud prevention. Anywhere.Vegas does not use application-level IP geolocation to personalize recommendations.
- Error and diagnostic information generated by standard platform tooling.
Anywhere.Vegas does not run third-party advertising pixels or marketing trackers in the audited application code.
4. Browser Storage
Several features use your browser’s local storage instead of our servers. Categories currently include temporary itineraries, a saved-itinerary flag, favorites, recent searches, local analytics buffers, click-event buffers, an authentication session entry managed by our auth library, and interface preferences.
Because this data lives in your browser:
- It generally stays on the device and browser where it was created.
- It usually does not synchronize to your other devices.
- It may be removed when you clear browser data or site data.
- It may be unavailable in private-browsing or incognito modes.
- It may be lost if storage is blocked, quota-limited, or reset.
We do not currently back these browser-local items up to a server-side account store.
5. Temporary & Saved Itineraries
Itineraries you build without explicitly saving are held on your device as temporary itineraries. They:
- Are retained for up to 30 days after the last meaningful update.
- Are not extended by passive viewing.
- Have their expiration period refreshed by meaningful edits.
- Are removed the next time the relevant storage is read after they expire.
- Can be cleared at any time in the Profile Privacy Controls.
If you deliberately mark an itinerary as saved, the saved flag is kept on that device until you remove it or clear browser storage.
6. Favorites & Recent Searches
- Favorites remain in your browser’s local storage until you remove them or clear that storage.
- Recent searches are retained for no more than 30 days.
- Recent searches are capped at 20 entries.
- You can clear supported local privacy data through the Profile Privacy Controls.
These features exist for convenience. Favorites are not currently tied to a persistent server-side account list.
7. Location Information
Anywhere.Vegas asks your browser for precise location only when you start a feature that needs it — for example, a “near me” request. You control whether your browser grants that permission, and denying it does not prevent you from using the rest of the site.
- You can instead select a hotel, venue, landmark, neighborhood, or area manually.
- Precise coordinates are held only in the active browser session, currently for up to approximately 30 minutes.
- Precise coordinates are not intentionally retained long-term in application storage.
- An explicit venue or area selection may override an older cached location context.
- Anywhere.Vegas does not use application-level IP geolocation to personalize recommendations.
Infrastructure providers may still process IP addresses for ordinary routing, hosting, security, and diagnostics. Anywhere.Vegas does not perform background location tracking.
8. Recommendation & AI Processing
Some features let you submit free-text requests to recommendation and planning tools. Those requests are sent through validated server-side functions rather than directly from your browser to an AI provider. The current architecture:
- Validates and length-limits your request before processing.
- Does not expose AI-provider credentials to the browser.
- Does not store your complete prompt text in local analytics buffers.
- Records only minimal derived metadata (for example the length of a request) where applicable.
- Treats request text as transient unless you deliberately keep the resulting content in an itinerary.
9. How Information Is Used
We use the information described above to:
- Provide requested features and pages.
- Authenticate users and protect accounts.
- Generate recommendations and planning content.
- Hold your temporary planning information between sessions on the same device.
- Remember planner preferences and recent searches locally.
- Improve usability of features and interface flows.
- Support location-based recommendations when you grant permission.
- Measure local feature activity in a device-local buffer.
- Distinguish affiliate, booking, and ordinary outbound clicks.
- Operate, secure, and troubleshoot the service, and prevent misuse.
- Manage authorized administrative and editorial media.
We do not use this information for third-party advertising personalization.
10. Affiliate & Booking Links
Anywhere.Vegas links to hotels, restaurants, shows, attractions, tours, ticket providers, reservation platforms, and other third-party services. Some links may be affiliate links, and third parties may receive referral information when you follow them.
Third-party websites operate under their own privacy policies and terms, which we do not control. For details, see the Affiliate Disclosure.
11. Local Analytics & Click Information
The audited application code keeps analytics and outbound click events in bounded browser-local buffers:
- Analytics events are limited to the most recent 500 entries.
- Click events are limited to the most recent 500 entries.
- These buffers are not currently transmitted to Google Analytics, Meta Pixel, or another third-party advertising analytics service.
- Raw free-text prompts are not stored in analytics.
- Event information may include categories, feature interactions, venue identifiers, CTA types, and request-length metadata.
This implementation may change over time. If we materially change the analytics behavior — for example, by introducing a third-party analytics processor — we will update this policy. We do not treat the current absence of third-party analytics as a permanent guarantee.
13. Third-Party Service Providers
Anywhere.Vegas relies on a limited set of infrastructure and service providers:
- Lovable Cloud (Supabase) for authentication, database, and storage.
- Cloudflare for hosting, routing, content delivery, and security.
- Google for optional OAuth sign-in, only when you choose Google as a sign-in method.
- External booking and affiliate providers when you choose to visit their websites through outbound links.
- Social media platforms reached through outbound footer links.
- A future AI gateway or model provider, only when that processing is activated. Until then, treat that processing as conditional rather than active.
We do not publish sensitive infrastructure identifiers such as project IDs, environment variable names, storage bucket internals, database schema details, or service credentials.
14. Data Retention
- Temporary itineraries: up to 30 days after the last meaningful update.
- Saved local itineraries: until you remove them or clear browser storage.
- Recent searches: 30 days, capped at 20 entries.
- Favorites: until you remove them or clear browser storage.
- Local analytics: most recent 500 buffered events.
- Local click events: most recent 500 buffered events.
- Precise location: in-memory only, up to approximately 30 minutes per session.
- Free-text recommendation requests: transient; not intentionally retained in analytics or the application database.
- Authentication and provider-managed records: retained according to operational needs and provider configuration.
- Authorized administrative media: retained until removed or managed through editorial workflows.
Where an infrastructure provider controls the retention of logs or platform records, retention may be governed by that provider’s settings and contractual terms rather than by Anywhere.Vegas.
15. User Privacy Controls
The Profile Privacy Controls let you clear supported local categories, including:
- Temporary itineraries.
- Recent searches.
- Locally stored favorites where supported.
- Cached location information.
- Local analytics events.
- Click-event buffers.
16. Account & Data Deletion Limitations
A complete self-service account deletion workflow is not yet available. Today:
- You can clear supported locally stored data through the Privacy Controls.
- You can contact us with account or privacy questions using the channels below.
- Deletion of provider-hosted account information may require manual handling.
- Certain information may need to be retained for security, legal, fraud-prevention, operational, or recordkeeping purposes where applicable.
We do not commit to a specific deletion timeline at this time. When a formal deletion workflow is available, this policy will be updated.
17. Data Security
Anywhere.Vegas uses reasonable technical and organizational practices, including:
- HTTPS for site traffic.
- Authentication controls on account-bound features.
- Server-side input validation for planning and recommendation functions.
- Role-based administrative access for editorial tooling.
- Row Level Security on user-linked database tables where implemented.
- Restricted administrative routes.
- No AI-provider credentials in the browser bundle.
- Bounded local analytics storage.
- Limited in-memory retention of precise location.
- Controlled media administration.
No internet service or storage system can guarantee absolute security. Anywhere.Vegas does not claim perfect security, zero breach risk, or any formal security certification, and does not publish detailed security configurations that could create risk.
18. Children's Privacy
Anywhere.Vegas is intended for a general audience and is not directed to children who are not legally permitted to provide personal information without parental or guardian consent. We do not knowingly collect personal information from such children without appropriate authorization.
If you believe a child has provided personal information through Anywhere.Vegas, please use the contact channels below and we will take reasonable steps to review the situation.
19. Nevada, U.S. & International Visitors
Anywhere.Vegas is operated from Nevada, United States. Visitors from other states or countries may be subject to different privacy laws. This policy is not intended to satisfy every global privacy regime, and additional jurisdiction-specific notices may be added where legally required.
20. External Links
Anywhere.Vegas links to third-party websites and services. Their privacy practices are separate from ours, and we recommend reviewing each provider’s policy before using it. Anywhere.Vegas is not responsible for third-party privacy practices, and following an outbound link may share normal referral or request information with that third party.
21. Policy Changes
We may update this Privacy Policy as application features change, data practices change, providers change, legal requirements evolve, AI functionality becomes active, server-side account storage is introduced, or analytics systems change. The “Last Updated” date will be revised when material changes are published. We do not currently promise individual email notification for every change.
22. Contact
You can contact Anywhere.Vegas about privacy questions, correction requests, deletion requests, access questions, or concerns about location or browser-stored information using the channels below. Contact fulfillment is currently handled manually.
Privacy contacts
Use the Legal & Trust contact form to reach the right team. Select the closest category and we’ll route your message internally.
General Legal
General questions about our policies, terms, or Legal & Trust Center.
Open contact formPrivacy
Privacy questions, data access requests, and deletion requests.
Open contact form
