Privacy policy
The short version
We hold the little we need to let you sign in and be recognised. We record what people do with the service, because that is how we find out whether it works. You decide whether we may also watch how you use your browser. We do not sell anything about you to anyone. You can ask us to delete all of it and we will.
How you sign in
Two ways: a six-digit code we email you, or a passkey held by your device. There is no password. Verifying a phone number is optional and does not create a third way in — a number never signs anyone in.
What we hold
If you joined the waitlist: your email address, whether you said you ride or travel, the language you were reading in, and when you signed up and confirmed.
If you have an account: your email address, and your name and profile picture if you added them. Your phone number, if you chose to verify one. If you set up a passkey, the public half of it, what kind of authenticator holds it, and the technical details the standard needs — never the private half, which never leaves your device. The language you use. When you accepted the terms and when you last confirmed the safety notice.
Whenever anyone visits: that a page was viewed, and roughly where in the world from. If something breaks in your browser, the error itself, where in our code it came from, and the page you were on. Everyone is counted. By default nobody is identified: no cookie, and no identifier carried from one visit to the next. We cannot tell one anonymous visitor from another.
We do not collect location while you are riding. We have no way to. Nothing here follows you around other websites.
Why we hold it
Almost all of it is what the service cannot run without. The one exception is marked.
- Your email address — to sign you in, and to write to you when something needs your attention.
- Your passkey — so your device can sign you in instead of a code.
- Your phone number — so your profile can show that a real number was verified. It is never a way to sign in, and nothing depends on it.
- Your name and picture — so the other person knows who they are meeting.
- Your language — so we write to you in it.
- The dates you agreed — so we can prove you saw the safety notice and the terms, and so we know to ask again when the terms change.
- The waitlist — to write to you once when we launch.
- What people do with the service — to know whether it works and what to fix next.
- How you use your browser — only if you said yes.
In legal terms: everything above is what we need to perform our contract with you, which is to provide the service you asked us for. The one exception is watching how you use your browser. That rests on your consent alone, and it stops when you withdraw it.
What we measure, and what you decide
Two different things, worth telling apart.
What people do with the service, we always record. Today that is which pages were viewed, roughly where in the world from, that somebody tried to join the waitlist, which role they picked and whether it worked, and each step of verifying a phone number — that a code was asked for, whether it went out or could not be sent, and whether the verification finished. It is also what tells us when something breaks in your browser: we are sent the error and the page it happened on, because otherwise the only way we hear about it is if you take the trouble to tell us. As the product grows it will also be the other steps people complete in it, such as confirming an email address. Without it we would be guessing at whether anything we build helps anyone. Knowing that the service works is part of running it, so this is not something we ask permission for.
How you use your browser, we ask about. Saying yes lets us recognise your browser on your next visit, so we can tell a returning visitor from a new one, and lets us keep the occasional recording of a session.
That leaves three states you can be in:
- Before you answer. Your visit is counted anonymously, and we store nothing on your device for it.
- If you say no. The same, and we do not ask again unless you clear this site’s data from your browser. You do not drop out of our numbers, declining takes nothing away from you, and the service behaves exactly as it did before.
- If you say yes. We may then keep a small identifier on your device, recognise your browser between visits, and record the occasional session.
Three things are true in every state. No email address, no phone number and no name ever reaches our analytics provider. If we ever tell it who someone is, we tell it an opaque id: a string of characters that means nothing on its own. Recordings are a small sample, mostly of sessions where something broke, and whatever you type into a field is masked out before the recording leaves your browser.
The banner is up on this site and on the blog. The app does not ask yet, so everyone there is in the first state until it does. We also count how many people answer it and which way, and how many never see it at all — some browser extensions hide it, and we would rather know than assume.
Who else sees it
We use other companies to run the service. They see only what they need to do their job, and none of them may use it for anything else.
- Cloudflare — hosting and the database. Everything lives here. It also runs the check that a person, not a script, is filling in the waitlist form or the sign-in screen: that check sees the network address you connect from and what your browser is, and answers yes or no about that one request.
- Resend — sends our email. Sees your address and the message.
- Prelude — sends and checks the code when you verify a phone number. Sees your number, the network address you connect from, which browser you use, and which language you read in; it needs those to tell a real person from an attack. It generates and checks the code itself, so we never see the one you are sent.
- PostHog — our analytics and error reports, hosted in the EU. Sees which pages were viewed, that somebody tried to join the waitlist, which role they picked and whether it worked, each step of verifying a phone number — that a code was asked for, whether it went out, whether it finished, and which attempt each of those was, along with the dialling code of that number and the country the request came from, never the number itself — and what went wrong. If we ever tell it who someone is, it is told an opaque id and nothing else — never your email address, your phone number or your name.
We do not sell your data. We do not share it for advertising. We will hand something over if the law genuinely requires it, and not otherwise.
Where it lives
On Cloudflare’s network, with the database in the European Union. Email passes through Resend and analytics through PostHog’s EU hosting.
How long we keep it
Your account data stays until you delete your account, and then it goes.
Waitlist entries stay until we launch and write to you, or until you ask us to remove you — whichever comes first.
What you can ask for
Ask us for a copy of what we hold, ask us to correct it, or ask us to delete it. Write to hello@backpackwith.me and we will do it. You do not need to give a reason.
Deleting means both places: our own database, and our analytics provider.
If you are in the EU or UK, these are rights you have under law, not favours. You can also complain to your national data protection authority if we handle this badly.
Cookies
Five things run in your browser: four cookies, and one check that stores nothing. None of them are for advertising.
- A sign-in cookie, so you stay signed in. It goes when you sign out. Necessary.
- A language cookie, remembering which language you chose. Necessary.
- A cookie holding your answer to the banner, whichever way you answered, with a copy in your browser’s local storage. It is what stops us asking again, so saying no writes it too — a refusal we could not remember would be a refusal we kept overriding. It holds what you chose, when, and a random id for this browser that means nothing on its own. No one else receives it, and nothing on our side reads it. It stays until you clear this site’s data. Necessary.
- An analytics cookie, only once you have said yes, so we can recognise your browser on your next visit. This is the one the banner asks about, and the only one you get a say over.
- The bot challenge — Cloudflare’s check that a person, not a script, is filling in the waitlist form or the sign-in screen. We measured what it leaves on your device: nothing. It is necessary rather than a choice — without it, nobody could join the waitlist or sign in at all.
Changes
If we change this policy we will update the date at the top. If a change is significant, we will tell you rather than hoping you check.