Cookie notice

We use cookie-free analytics by default. Optional cookies help us recognize returning visits and measure marketing performance. Learn more in our Privacy Policy.

Privacy Policy

Learn how your data is protected and handled when using Holiday Optimizer

Last updated: August 25, 2026

👋 Overview

Holiday Optimizer runs primarily in your browser. This policy explains what data is processed, where it lives, and which third-party services are involved.

I'm an indie developer based in Ontario, Canada. This is a side project, but I'm committed to following common-sense privacy practices (like those in PIPEDA and GDPR) to keep your data safe and be transparent about how things work.

🔒 Data Usage and Storage

Here's what happens to your data:

  • Plans, preferences, and custom time-off data (company days, pre-booked days, and custom holidays) are stored in your browser's local storage
  • Your selected country, state, region, and weekend preferences are stored locally
  • Consent for enhanced tracking, Pinterest measurement, and partner services is stored locally and can be withdrawn by clearing browser storage
  • Holiday calculations run locally using the bundled date-holidays library
  • No holiday requests or country codes are sent to external APIs
  • The planner does not request or store your name or email unless you purchase the export

Only what's needed to run the app is processed.

🗂️ Calendar Files & Retention

When you start the optional calendar export, break data is sent to a private AWS Lambda function that creates the ICS file and stores it in a private S3 bucket under a random token. Files and download links expire after a short retention window (typically about 48 hours). To validate the export, a temporary file is generated before checkout, but the download link is only issued after payment is confirmed. The contents of your plan are used only to build the file and are not stored in a database.

💳 Payments & Polar

Payments are processed by Polar, which collects the billing information required to complete the transaction (email, payment method, and billing address where required). The download link is provided on the thanks page after checkout, and the service does not send it by email. Polar retains its copy of the data under their policies—see Polar's Privacy Policy for details. If you want Polar customer data deleted, contact support at support@waqarbinkalim.com and the maintainer can delete the Polar Customer object when possible, or contact Polar support directly. Polar may retain certain records for legal or compliance reasons.

📊 Analytics & Marketing Measurement

This site uses a two-tier analytics approach to balance useful insights with minimal data collection.

Basic analytics (no consent required)

PostHog Analytics (US region) loads automatically with memory-only persistence. This means no cookies are set, no data is written to local storage or session storage, and each page load is treated as a new anonymous visit with no cross-session tracking. IP addresses are processed by PostHog to infer coarse location (country/region) but are discarded after enrichment and not stored in event data. No person profiles are created, and Do Not Track is respected—if your browser sends a DNT signal, no events are captured at all. Session recording is disabled.

Events captured include page views, page leaves, clicks and form submissions (input values are never collected), dead clicks, web performance metrics (Core Web Vitals), JavaScript errors, and anonymized usage patterns. URL query strings, hash fragments, and plan details are stripped from analytics events before they are sent. To measure whether AI assistants help people discover the site, an analytics event may record a recognized assistant name, the landing-page path, and the referring hostname.

Enhanced tracking (consent required)

If you accept enhanced tracking via the consent banner, PostHog persistence upgrades from memory-only to local storage, enabling returning-visitor identification and session continuity. PostHog stores a random identifier in local storage to distinguish visits.

With consent, the Pinterest Tag may also load to measure visits, whether a plan was successfully generated, and attribution from Pinterest, and to support Pinterest audience reporting. The plan-generated event contains no dates, locations, PTO totals, or other plan details. Pinterest may receive a public page URL, referring origin, IP address, browser or device information, and cookie or similar identifiers. The tag is not loaded on URLs containing planner, checkout, or shared-calendar parameters. Enhanced Match is disabled: names, email addresses, and PTO-plan contents are not sent to Pinterest.

You can withdraw consent at any time by clearing your browser storage. Declining or ignoring the banner keeps basic anonymous analytics active with no device storage.

Pinterest's domain-verification metadata and public RSS feed do not themselves set tracking cookies. For details about Pinterest's handling of tag data and cookies, review its Privacy Policy and Pinterest Tag cookie documentation.

For more information about PostHog's data practices, please refer to  PostHog's Privacy Policy.

The site is hosted on Amazon Web Services (S3 and CloudFront). AWS may process IP addresses as part of content delivery. For more information, seeAWS's Privacy Notice.

🤝 Affiliate Partners

This site participates in affiliate programs, including Travelpayouts. Affiliate partners may use cookies or scripts to track referrals and measure conversions. This data is used to attribute purchases and calculate commissions.

For details on how Travelpayouts handles data, see their Privacy Policy.

🖼️ Blog Images

Blog images are self-hosted on the same infrastructure as this site (AWS S3/CloudFront). No requests are sent to third-party image services when you browse travel guides.

Original photos are sourced from Unsplash and used under the Unsplash License.

🔄 Updates

This privacy policy may be updated occasionally to reflect changes in how data is handled. Any updates will be reflected in the “Last updated” date at the top of this page. Users are encouraged to review this policy periodically.