Cookie Policy

This site uses one analytics tool, Microsoft Clarity, and stores a little data for the wishlist and trip planner. No advertising, no profiling, nothing sold. Here is exactly what is set, what it records, and how to refuse it.

Last updated: 21 August 2026

The short version

One analytics tool, no advertising. We use Microsoft Clarity to see how pages are actually used, which sections people read, where they get stuck. It sets two cookies and records your session as anonymous pointer movement, clicks and scrolling. We run no advertising pixels, no profiling, and we sell nothing.

Most travel sites load a dozen third-party trackers before you have read a word. We have one, and this page names it. There is still no list of advertising partners at the bottom, because there are no advertising partners.

Until 21 August 2026 this site set no cookies at all and this page said so. That changed when Clarity was added, and this page changed on the same day.

Two things are worth knowing all the same. We store a small amount of data in your browser to make the wishlist and trip planner work, explained below, and never sent to us. And when you go on to book, you leave this site for our booking partner's checkout, which does use cookies of its own.

This page covers visitingniagarafalls.com. For everything else we do with data, see the Privacy Policy.

What cookies actually are

A cookie is a small file a website asks your browser to keep and hand back on your next request. That is genuinely useful for keeping you logged in or holding a basket together. It is also the mechanism behind most tracking on the web: a cookie set by an advertiser and read across thousands of sites is how a pair of boots follows you around the internet for a fortnight.

Cookies are not the only way to store things in a browser. Local storage, session storage and cache storage do a similar job through different mechanisms, and a policy that only mentions cookies can be technically true while telling you very little. So this page covers all of it. In the UK and EU, the rules on "storing information on a user's device", PECR and the ePrivacy Directive, apply to local storage exactly as they do to cookies, and we have written this page to that standard rather than the narrower one.

Cookies we set

None, in any category. Set out the way a cookie policy normally sets it out:

CategoryWhat it would normally doWhat we use
Strictly necessarySessions, logins, baskets, security tokensNone, the site has no accounts and no basket
PreferencesRemember language, currency or region choicesNone, currency follows your browser each visit
AnalyticsMeasure visits, pages, journeys and drop-offMicrosoft Clarity, _clck and _clsk, first-party, set on every page
AdvertisingRetargeting, conversion pixels, audience buildingNone, we run no advertising tags
Social mediaEmbedded feeds, like and share buttonsNone, our social links are plain links

You can check this yourself in about a minute. Open your browser's developer tools on any page of this site, go to the Application or Storage tab, and look at the cookie list for this domain. It is empty.

What we store instead

Two features need to remember something between pages, and both use your browser's local storage. This data stays on your device and is never transmitted to us, we have no copy of your wishlist and no copy of your trip plan.

NameTypeWhat it holdsHow long it lasts
vnf_wishlistLocal storageThe tours and attractions you have saved with the heart iconUntil you clear it
vnf_tripplanLocal storageThe itinerary the trip planner last generated for youUntil you clear it

Both are created only when you use the feature. Browse the site without touching the heart icon or the trip planner and nothing is written to your device at all.

Under the UK and EU rules these fall within the exemption for storage that is strictly necessary to provide a service the user has explicitly requested, you asked for a wishlist by saving to it, which is why they do not require a consent prompt. They are also why the two features are device-bound: your wishlist does not follow you to your phone, because there is no account for it to follow you through.

Third parties your browser contacts

Loading any web page means your browser fetching files from wherever they live, and each of those requests reveals your IP address and browser to that host. That is true of every site on the internet, and it is worth being straight about which hosts are involved here:

HostWhat it servesCookies
VercelThe site itself and our booking endpointsNone set
Cloudinary, UnsplashPhotographyNone set on our pages
Google FontsThe typefacesNone set
jsDelivrThe country flag icons on listings and filtersNone set
Microsoft ClarityAnalytics: session replay and heatmaps_clck (1 year), _clsk (1 day)

All but the last are static asset hosts: they hand over an image, a font or a stylesheet and nothing else. Clarity is the one third-party script we embed. There is no tag manager, no chat widget, no social feed and no maps iframe, the map links on our attraction pages are ordinary links that open in a new tab, so nothing is loaded from Google until you choose to click one.

To be precise about the basis for that third column: it reflects what these hosts are, asset CDNs that answer with a file and no Set-Cookie header, rather than a continuous audit of every response they send. We do not control a third party's behaviour, and theirs is governed by their own policies rather than ours. What we can control is how many of them there are, and we keep that number small deliberately. If you ever observe a cookie from any of them on our pages, tell us and we will correct this page.

When you go to book

We do not take payment on this site. Choosing an experience hands you to our booking partner's secure checkout to enter your traveller and payment details.

That checkout is not covered by this policy. Like any payment flow, it uses its own cookies for the session, fraud prevention and its own analytics. From the moment you arrive there, their cookie policy and privacy policy apply.

Nothing you do on their checkout writes anything back to this site, and we receive no cookie from them. What happens to your booking data at that point is set out in the Privacy Policy, and the split of responsibility between us and the operator is in the Terms of Service.

Consent, and what you can refuse

Clarity is analytics, which is not strictly necessary storage. There is no consent banner on the site yet, so it currently loads for everyone. If you would rather it did not run, any of these stops it, and none of them break the site:

  • Block cookies for this domain in your browser settings, or use a private window.
  • Use any tracker-blocking extension, Clarity is on the standard blocklists.
  • Opt out for every Clarity-using site at clarity.microsoft.com/terms.

The wishlist and trip planner storage is separate and stays either way. It falls under the strictly-necessary exemption, because it exists only to deliver a feature you actively asked for and never leaves your browser.

We neither sell nor share personal information for cross-context behavioural advertising, so there is nothing to opt out of under the CCPA or CPRA.

Clearing and blocking storage

Everything on your device is yours to remove, and you do not need our permission or a preference centre to do it. Clearing site data for this domain deletes the wishlist and trip plan; nothing else on the site depends on them, and every page keeps working normally.

BrowserWhere to look
ChromeSettings › Privacy and security › Third-party cookies, or Site settings › View permissions and data stored across sites
SafariSettings › Privacy › Manage Website Data (macOS), or Settings › Safari › Advanced › Website Data (iOS)
FirefoxSettings › Privacy & Security › Cookies and Site Data › Manage Data
EdgeSettings › Cookies and site permissions › Manage and delete cookies and site data

Browsing in a private or incognito window discards everything when you close it. Blocking storage for this site entirely is fine too, the wishlist and trip planner simply stop remembering between pages, and the rest of the site is unaffected.

Do Not Track and Global Privacy Control

We run no cross-site tracking, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We honour those signals by default, in the only way that really counts: by not doing the thing they are designed to disable.

If this changes again

Microsoft Clarity was added on 21 August 2026 and this page was rewritten the same day to say so. Everything above describes what the site does today.

If we add advertising, profiling, or anything that shares data with a partner for their own purposes, we will update this page and the date at the top before it goes live. We will not quietly start doing something and update a policy page afterwards.

Contact us

Visiting Niagara Falls
Email: info@visitingniagarafalls.com
Or use the contact form.

If you have found something on this site storing data we have not listed here, we want to know. Tell us what you saw and where, and we will investigate and correct this page.