Skip to main content
Privacy

Privacy notice

This notice describes the live Pier service on withpier.com. Email-code accounts, profiles, settings, saved products, game progress sync, and Watch monitoring for supported listings are available. Watch email alerts are sent only when an eligible rule matches and your account settings allow them.

Last updated 17 August 2026

Who this notice covers

This notice covers people who browse withpier.com, search for activities, open an approved supplier link, use a Pier account, save products, create or manage a Watch, receive a Watch alert, sync game progress, or contact Pier.

Pier is operated by Mint Labs. Privacy requests can be sent to hello@withpier.com.

Browsing, search, and supplier-link information

Search conditions can include a destination or product, travel date, adult count, child ages, category, language, and display currency. A chosen supplier creates an opaque handoff record with the product, provider, destination address, return path, locale, and support reference. It expires after 30 minutes. Opening or retrying the link records the click reference, event type, and event time for safe retry limits and failure investigation.

For popularity rankings, Pier keeps random one-use search and click IDs with resolved supplier, destination, product, page source, and time. These records prevent duplicate counts and do not contain search words, travel date, traveler ages, account, email address, or IP address. Supplier booking outcomes can be retained without traveler contact, payment, voucher, or trip-time details.

The necessary NEXT_LOCALE cookie keeps a language choice for up to one year. It is not used for advertising. Cloudflare and Vercel can process ordinary request and security data such as IP address, browser or device information, page, and time. A contact email contains what you choose to send.

If you choose Accept all, Pier uses Google Analytics to understand visits and improve the site. Google receives page addresses and titles, referrers, interaction events, approximate location, browser and device information, and cookie-based client and session identifiers. Pier does not send your account email, account ID, or text entered in search fields to Google Analytics. Analytics and consent-preference cookies last up to six months, and user-level and event-level Analytics data is configured for two-month retention. Google may process this information outside your country. You can reject or change your choice at any time through Cookie settings. Google Analytics does not load before you accept, and advertising features remain off.

  • Pier does not request payment card details.
  • Optional analytics cookies are used only after you accept them, and advertising cookies are not enabled.
  • Pier does not sell personal information.

Approximate location recommendations

When you select Day trips, Pier may use the approximate city supplied with your network request to prepare a location-based search. Pier does not ask for precise device location or store this inferred city for this feature.

Account, profile, saved product, and game information

A Pier account stores an account ID, name, email address, email verification state, optional image, and timestamps. Sessions can store a token, expiry, IP address, and browser or device description. Security records store a hashed email one-time code rather than the readable code.

Your profile stores a display name, Pier character choice, and whether you allow a future public completion display. Settings can store purchase country, display currency, time zone, locale, meaningful-change email preference, daily digest choice, and quiet hours. The public-completion choice does not create a public directory today.

A saved product stores its slug, locale, title, destination label, image details, and saved time. It does not save a price. You can remove it individually or through account deletion.

A Watch can store the supported product and provider references, selected visit conditions, provider scope, alert rules, status, current result, and check history. It does not store an account password or payment details.

Daily games can sync validated resume data and completion summaries. Air Traffic sync stores campaign version, completed stage IDs and fingerprints, best score, stars, safe landings, and completion time; it does not upload routes, positions, frames, pointer paths, or audio state. Browser-only game data can remain on the device after account deletion until you reset the game or clear browser storage.

Trip planner sharing is available only to signed-in accounts. Pier stores the recipient's normalized email address, invitation generation and expiry, invitation and delivery state, acceptance time, and the recipient account ID after acceptance. The read-only shared view contains the share ID, trip title, destination, dates, update time, the owner's display name when available, and activity, stay, and place items with title, duration, placement, booked state, and safe view links when available. It omits notes, descriptions, traveler details, raw provider identifiers, Watches, and internal records.

Email-code sign-in and security check

Pier signs users in with a six-digit email one-time code sent through Cloudflare Email Service. A code is valid for 10 minutes, allows three attempts, is replaced when resent, and is stored as a hash. Turnstile checks the request before Pier sends a code.

Pier does not ask you to create a password.

Why information is used

Pier uses search and handoff information to return comparisons and open the chosen supplier safely. Popularity records support rankings and prevent duplicate counts. Account information signs you in, restores your profile and settings, saves chosen products, syncs valid game progress, runs supported Watch checks and matching alerts, protects the service, and answers requests.

Pier uses Trip planner sharing information only to create, deliver, accept, list, and revoke signed-in shares, enforce recipient and sending limits, and show the safe read-only trip view to an accepted recipient.

Services that process information

Cloudflare supports the API, account database, email-code and eligible Watch-alert delivery, Turnstile, rate limiting, security, and operational logs. Vercel hosts the public web app. Google provides optional Analytics after consent. Approved activity providers receive the product and conditions needed for an eligible Watch check and receive information when you open their sites; Pier does not add your account email or account ID to those requests. Your email provider and Pier's mailbox provider process messages you send.

These service providers can process information outside your country. Pier does not give contact details to a supplier merely because you searched.

For Trip planner sharing, Cloudflare stores the share records, applies invitation and rate limits, and sends the transactional invitation through Cloudflare Email Service. The recipient's email provider receives the invitation, but the email does not contain the shared trip items.

How long information is kept

Supplier handoff records expire after 30 minutes. One-use popularity records, daily totals, and relevant supplier booking-state records are kept for up to 180 days. The NEXT_LOCALE cookie lasts up to one year. Contact messages and provider security logs follow the periods needed or configured for those systems.

An email one-time code stops working after 10 minutes. A session lasts 30 days and can refresh daily while used. Account identity, profile, settings, saved products, game completion summaries, and Air Traffic progress remain until you remove or reset them where offered, or delete the account. Daily-game resume data expires 30 days after the last server-accepted update.

While a Watch is active, Pier keeps its supported check results and history. After a Watch ends, its history is designed to be removed after 90 days. Watch email delivery or digest rows are designed to be removed after 30 days.

A pending Trip planner sharing invitation and token expire after 7 days, but the share record is not deleted automatically. The expired pending share, including recipient email and status, remains until the owner removes it, the board or owner account is deleted, or a later explicit retention policy applies. Deleting an account that merely has the invited email before acceptance does not remove the pending share. Accepted read-only access remains until the owner revokes it or the board, recipient account, or owner account is deleted. Pier removes hashed recipient-email send-rate evidence during the first 15-minute cleanup after it becomes 48 hours old. Revoking a share or deleting the recipient account does not erase it sooner; deleting the owner account does.

Emails and stopping Watch email

Pier sends an email one-time code only when sign-in is requested. Necessary account or security messages are not a marketing subscription.

When an eligible Watch rule matches, Pier can send an immediate meaningful-change email or include the event in an optional daily digest, according to your account settings. Each Watch email contains a signed unsubscribe link. The link stops future Watch email for that account; it does not delete the account or saved data.

A Trip planner sharing invitation is a transactional email requested by the signed-in owner, not a marketing subscription. It identifies the owner and trip and links the recipient to sign in or accept; it does not subscribe the recipient to Watch email.

Your choices, requests, and account deletion

Depending on where you live, you may have rights to ask for access, correction, deletion, restriction, portability, or objection, and to complain to an authority. Use Contact and include the email connected to the request. Pier may ask for enough information to verify the request without asking for unnecessary documents.

Account deletion requires a recent sign-in and removes Pier account-owned profile, settings, saved products, synced game data, and Watch rows. Browser-only game data can remain on the device. Supplier records, email mailboxes, security records without a user link, logs, and backups follow their own retention and legal requirements, so Pier does not promise that every record disappears immediately.

The owner can revoke Trip planner sharing at any time. A pending share is removed when the owner revokes it, deletes the board, or deletes the owner account; deleting an account with the invited email before acceptance does not remove it. After acceptance, deleting either linked account also removes the share and ends access. Hashed send-rate evidence is removed by the scheduled retention cleanup, or sooner when the owner account is deleted.

Security, children, and changes

Pier uses safeguards suited to the service, but no online service can promise absolute security. Public travel pages can be browsed without an account. Pier accounts are for people aged 18 or older. Pier does not ask for a date of birth or identity document solely to verify this age rule. If Pier learns that an account holder is under 18, the account and related Pier-owned data may be deleted; a parent or guardian can contact Pier at hello@withpier.com. Pier will update this notice when processing changes and show a new date.

Accounts and Google sign-in

Email-code sign-in processes the email address, verification result, account and session identifiers, and the profile and preferences you choose to save. Verification codes are hashed and short-lived. Necessary secure cookies keep the session active and are not used for advertising.

Pier shows the Google option only while its live sign-in capability is enabled. When you continue with Google, Google sends Pier a stable Google account identifier, verified email, and basic name and profile details. Pier creates a separate Google-based account and does not automatically merge it with an email-code account. Pier requests online sign-in access only and does not request Gmail, Drive, Calendar, or other Google service data. Pier encrypts Google access and refresh tokens and does not retain the Google ID token.

Cloudflare processes account, session, security, and email-code delivery data. When Google is connected or used, Google processes sign-in and revocation requests under Google's terms. If a Pier account holds a stored Google access or refresh token when deletion starts, Pier asks Google to revoke each token within a bounded timeout and keeps an opaque, token-free confirmation record. If Google does not return the exact success response, deletion stops with Pier records unchanged. Because a lost response can leave the outcome unknown, Pier asks you to reconnect Google for a fresh token before deleting again; it never sends the same uncertain token automatically. After every current token version is confirmed, Pier atomically removes its sessions, sign-in links, encrypted provider-token records, profile, preferences, saved products, and account-synced game data. This does not delete your Google account or supplier records controlled outside Pier.

Creator Journeys, YouTube, and Gemini

A Creator Journey can show a thumbnail supplied by YouTube. The youtube-nocookie.com player and playback connection load only after you choose to play the video; YouTube and Google can then receive ordinary request, device, page, and playback information under their own terms and privacy policy.

For editorial preparation, Pier sends the public YouTube URL to Google Gemini. Pier stores bounded observations, moments, activity-search intents, review state, and generated proposals, not a raw transcript. The published article is independently organized, does not claim creator affiliation, and can contain marked affiliate links to activity providers.

Privacy contact

Email hello@withpier.com or choose Privacy request on the Contact page. State whether the request concerns your account, saved products, game progress, email, or another use. Do not send a password, one-time code, or full payment card number.