1. Who we are
This Privacy Policy explains how Never Roam Alone ("we," "us," or "the site") handles information when you visit neverroamalone.com and use its features. Never Roam Alone is an independently operated personal travel blog and trip-planning website. For privacy questions, you can reach the site owner using the contact details in Section 14.
2. Information we collect
We've designed the site to collect as little personal information as possible. You do not need to create an account to use it — including to post in the community forum.
Information you give us
If you contact us by email, we receive whatever you choose to include in that message (such as your name and email address). When you use the trip-planning tools, you may type in details like a departure airport, a destination, or travel dates. This information is used to fetch results for you and is not tied to your identity.
If you create a profile (optional)
If you choose to create a free account (with an email and password, an emailed sign-in link, or Google), we store your email address, your display name, and your notification preference in our account database (hosted by Supabase). You may also choose to add optional profile details — a short bio, your home city and country, your travel style, an age or age range, favorite/bucket-list destinations, travel stories, social media links (website, Instagram, Facebook, X/Twitter, TikTok, YouTube), and up to 10 travel photos with captions (photos are stored with our database host, Supabase). All of these are optional, editable, and deletable on your profile page. If you sign in with Google, we receive your email address and name from Google; we never see your Google password.
Public profile page (off by default): your profile page has a "public profile" switch. If — and only if — you turn it on, your display name, bio, home city and country, travel style, age (if added), travel stories and answers, travel photos, and any social links you added become visible to anyone on a public profile page (for example, when someone clicks your initials in the community forum). Your email address and settings are never shown publicly. You can turn the switch off again at any time and the page immediately becomes private.
Private messages (on by default): signed-in Roamers can send each other private messages. A conversation is only visible to the two people in it — message text is stored in our account database (hosted by Supabase) so both of you can read the conversation later, and a "you have a new message" email may be sent to you (through Resend; the sender never sees your email address) at most once per sender per 24 hours. On your profile page you can switch these alert emails off, or switch private messages off entirely, at any time — new messages to you stop instantly — and you can block individual Roamers from a conversation.
Community forum posts
Questions and replies you post on Ask A Roamer are public — anyone can read them, along with the name shown on them. If you post while signed in, the post is linked to your account; if you post signed out, it's saved without any account link under the name you type (or "Anonymous Roamer"). Please don't include personal details you wouldn't want public in the body of a post.
Reply notification emails
If you have an account, asked your question while signed in, and left "Email me when someone replies" switched on, we send you an email when your question gets a reply (delivered through Resend, our email provider). The email contains your question title and a preview of the reply. You can switch these emails off at any time using the checkbox on the Ask A Roamer page.
Information collected automatically
- Basic technical data: Like most websites, our hosting provider automatically logs standard request information such as your IP address, browser type, device type, referring page, and the date and time of your visit. This is used for security and to keep the site running reliably.
- Preferences stored in your browser: Your chosen language and the state of the trip-planning forms are saved locally on your own device (see Section 3). This data stays on your device and is not transmitted to us.
Information we do not collect
We do not knowingly collect sensitive personal information, we do not build advertising profiles, and we do not sell or rent personal information to anyone.
3. Cookies & local storage
Never Roam Alone does not use any analytics trackers. The one exception to an otherwise cookie-free site is our travel partner Travelpayouts, whose script can place affiliate cookies so that bookings made through our partner links can be credited to this site. This script only runs if you click "Accept" on the cookie banner. If you decline, it never loads and the site works exactly the same. You can change your choice at any time using the small cookie button in the corner of every page.
Everything we save in your browser is strictly functional — it exists only so the site works and remembers your own choices. The complete list of what we store in your browser's local storage:
nra_lang— the display language you selected.nra_choose_state_v2— what you entered in the destination-finder tools, so your choices survive a page refresh.nra_forum_v2— forum questions and replies you post while the shared database is unavailable (guest mode); these stay on your device only.nra_forum_votes_v1/nra_forum_votes_remote_v1— which forum posts you've given a thumbs up or down, so you can't vote twice.nra_actcounts_v2_…— a short-lived cache of activity counts for the Activities tool, so repeat searches load faster.sb-…-auth-token— your sign-in session token, created only if you sign in to an account (set by Supabase). Signing out removes it.nra_cookie_consent— whether you accepted or declined partner cookies, so we don't ask you again on every page.
Apart from the sign-in token (which is sent to our account provider to keep you signed in), this information never leaves your device and is not used to track you. You can clear it at any time through your browser settings, though doing so will reset your saved preferences and sign you out.
Shared links: if you use the "Share itinerary" button on the destination finder, the link it creates contains your search settings (such as your starting city, travel dates, trip length and budget) so that whoever opens it sees the same results. Only share such links with people you're happy to see those details. Your passport selection is never included in a shared link.
4. How we use information
We use the limited information described above to:
- Display the interactive map, blog posts, city pages, photos, and trip-planning results;
- Remember your language and tool preferences for a smoother experience;
- Respond to messages you send us;
- Keep the site secure, diagnose technical problems, and prevent abuse;
- Understand, in aggregate, how the site is performing so we can improve it.
5. Third-party services
To provide its features, the site relies on a small set of reputable third-party services. When you use the relevant feature, your browser or our servers may exchange limited data (such as your search terms or IP address) with these providers, each of which has its own privacy policy:
- Travelpayouts — our affiliate partner network. With your consent (see Section 3), its script may turn some travel mentions into partner links and set cookies to credit bookings to this site. Privacy policy
- Netlify — website hosting and serverless functions. Privacy policy
- Supabase — hosts our account database (profiles) and the shared community forum posts, and handles sign-in. Privacy policy
- Resend — sends account emails (confirmations, password resets) and reply-notification emails. Privacy policy
- Google (sign-in only) — if you choose "Sign in with Google," Google confirms your identity to us. Privacy policy
- MapLibre / CARTO basemaps — the interactive 3-D globe and map tiles. CARTO privacy policy
- Unsplash — destination and landmark photography. Privacy policy
- Picsum — placeholder photography on some pages.
- SerpApi (Google Travel results) — live flight search results for the trip-planning tools. Legal & privacy
- OpenStreetMap Overpass API — live venue counts for the Activities tool, provided by community-run servers. OSM Foundation privacy policy
- Transitous — public-transport route lookups for train and bus results. Project site
- ExchangeRate-API (open.er-api.com) — live currency conversion rates on city pages.
- OurAirports / OpenFlights / Passport Index datasets — open airport, route, and visa datasets loaded from GitHub-based content servers (jsDelivr and GitHub Pages).
- jsDelivr & unpkg — content-delivery networks that serve some of the site's code libraries.
- MyMemory — on-the-fly translation of long-form articles. Privacy policy
Affiliate disclosure: some links on this site are affiliate links provided through Travelpayouts. If you book a flight, stay, or activity through one of them, we may earn a small commission at no extra cost to you. This is how we keep the site free, and it never affects which destinations or recommendations we write about.
The site's display font is hosted on our own server, so no font request is sent to Google when you load a page.
We share only what each service needs to do its job, and we keep the keys for these services on our server rather than in your browser. We are not responsible for the privacy practices of these third parties; we encourage you to review their policies.
6. How we share information
We do not sell, rent, or trade your personal information. We only share information in these limited situations: with the service providers listed above so they can perform their function; when required by law, legal process, or a valid government request; to protect the rights, safety, or property of the site, its visitors, or the public; or in connection with a transfer of the site to a new owner, in which case this policy would continue to apply.
7. Your privacy rights (GDPR & CCPA/CPRA)
Depending on where you live, you may have rights over your personal information. If you never created an account, in most cases we hold nothing that identifies you.
Delete your account yourself: if you have a profile, you can delete it at any time from your profile page. Deleting your account permanently removes your email, profile details, and sign-in credentials, and makes any forum posts you made anonymous.
If you are in the European Economic Area or the UK (GDPR)
You have the right to access, correct, delete, or restrict the use of your personal data, to object to certain processing, and to data portability. Where we process data, we rely on legitimate interests (running and securing the site) and your consent (where applicable). You also have the right to lodge a complaint with your local data protection authority.
If you are in California (CCPA/CPRA) or a similar U.S. state
You have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information as those terms are defined under California law, and we will not discriminate against you for exercising your rights.
To exercise any of these rights, contact us using the details in Section 14. We will respond within the time required by applicable law and may need to verify your request.
8. Data retention
We keep server logs only as long as needed for security and troubleshooting, after which they are deleted or anonymized. Email correspondence is kept as long as needed to address your request. Preferences stored in your browser remain until you clear them. Account and profile information is kept until you delete your account (or ask us to); public forum posts remain after account deletion but are made anonymous.
9. Security
The site is served over encrypted HTTPS connections, and access keys for third-party services are stored securely on the server rather than exposed in the browser. While no method of transmission over the internet is ever completely secure, we take reasonable measures to protect the limited information we handle.
10. Children's privacy
Never Roam Alone is intended for a general audience and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
11. International visitors
The site is operated from the United States and uses service providers that may process data in other countries. If you visit from outside the United States, you understand that your information may be transferred to, stored in, and processed in countries whose data protection laws may differ from those in your country.
12. Do Not Track & Global Privacy Control
Because we do not track visitors across third-party websites, we do not behave differently in response to a browser "Do Not Track" signal. Where required by law, we treat a recognized Global Privacy Control (GPC) signal as a valid opt-out of any "sale" or "sharing" of personal information.
13. Changes to this policy
We may update this Privacy Policy from time to time as the site evolves or as the law changes. When we do, we'll revise the "Last updated" date at the top of this page. Significant changes may be highlighted on the site. Your continued use of the site after an update means you accept the revised policy.
14. Contact us
If you have questions about this Privacy Policy or how your information is handled, please get in touch:
- Email: jcwolinsky@gmail.com
- Website: neverroamalone.com