Privacy Policy
What we collect when you use Visiting Niagara Falls, why we collect it, who else sees it, and how to get it removed. Written to be read, not skimmed past.
Who we are
Visiting Niagara Falls ("we", "us", "our") is an online travel agency for a single destination. We list tours, attraction tickets and passes at Niagara Falls on both the New York and Ontario sides, and we are the data controller for the personal information described in this policy.
This policy covers visitingniagarafalls.com and nothing else. It does not cover the operators who run the experiences, the booking platform that completes your purchase, or any other site we link to; each of those has its own privacy policy.
This policy sits alongside our Terms of Service, which set out our role as your booking agent, our Cookie Policy, and our Accessibility Statement.
Questions, or want to exercise a right below? Email info@visitingniagarafalls.com or use our contact page.
The short version
We do not run advertising trackers, we do not sell your personal information, and we do not take payment on this site. Most of what we store lives in your own browser, not on our servers.
- You can browse the whole site without giving us anything.
- Your wishlist and saved trip plan are stored in your browser, not in an account.
- You only give us your details if you contact us or subscribe.
- When you book, you are handed to our booking partner, who takes the payment.
What we collect
Information you give us
- Contact form, your name, email address, phone number if you add one, and whatever you write in the message.
- Newsletter, your first name, email address, and the travel interest you optionally pick.
- Trip planner, the dates, group make-up and interests you enter to generate an itinerary.
Information collected automatically
Like any website, our hosting provider records technical information when a page is requested: your IP address, browser and device type, the page you asked for, the page that referred you, and the date and time. These logs exist to keep the site running and secure.
Information stored on your device
We use one analytics tool, Microsoft Clarity, which sets two first-party cookies (_clck and _clsk) and records your visit as anonymous pointer movement, clicks and scrolling so we can see which parts of a page people actually use. We use no cookies for advertising or profiling, and we sell nothing. What Clarity sets, and how to refuse it, is in the Cookie Policy. We also use your browser’s local storage for two things, both of which stay on your device and are never sent to us.
| Name | What it holds | How long it lasts |
|---|---|---|
vnf_wishlist | The tours and attractions you have saved with the heart icon | Until you clear it or clear your browser data |
vnf_tripplan | The itinerary the trip planner last generated for you | Until you clear it or clear your browser data |
You can remove both at any time by clearing site data for this domain in your browser settings. Nothing else on the site depends on them.
How we use it
- To answer you. If you send a message, we use your details to reply and to follow up on that enquiry.
- To send what you asked for. If you subscribe, we use your email for the guide and subscriber offers, and nothing else.
- To show accurate prices. Live prices and availability are fetched from our booking partner when you open a listing, and converted into your currency.
- To keep the site working. Server logs help us find faults, block abuse and understand load.
We do not build advertising profiles, and we do not make automated decisions that produce legal or similarly significant effects.
Legal bases (UK and EU visitors)
Where the UK GDPR or EU GDPR applies, we rely on:
- Consent, for marketing email. You give it by subscribing and can withdraw it at any time.
- Legitimate interests, for answering enquiries, keeping the site secure, and preventing abuse. We have considered your rights and do not think these uses override them.
- Legal obligation, where we must keep records or respond to a lawful request.
Who we share it with
We do not sell personal information and we do not share it for cross-context behavioural advertising. We do rely on a small number of service providers, and your browser contacts some of them directly when it loads a page:
| Provider | What it does | What it can see |
|---|---|---|
| Vercel | Hosts the site and runs our booking endpoints | Request logs, including IP address |
| Viator (Tripadvisor) | Our booking partner: live prices, availability, and checkout | Your booking details, entered on their checkout |
| Cloudinary, Unsplash | Serve the photography | IP address and browser, as with any image request |
| Google Fonts, jsDelivr | Serve the typefaces and flag icons | IP address and browser |
| Frankfurter | Provides exchange rates for currency conversion | Nothing about you; we call it from our server |
We may also disclose information where the law requires it, to protect our rights or someone's safety, or to a buyer if the business is ever sold, in which case this policy travels with it.
When you book
We do not take payment on this site. Selecting an experience hands you to our booking partner's secure checkout, where you enter your traveller and payment details. Your card details never reach our servers.
From that point the operator running the experience and the booking platform handling the transaction are responsible for your booking data under their own privacy policies. We receive enough to help you if something goes wrong, and we will take an issue up with the operator on your behalf.
International transfers
We operate across the United States and Canada, and our providers may process data in either country or elsewhere. Where data covered by the UK or EU GDPR leaves that jurisdiction, we rely on the transfer mechanisms our providers put in place, such as the European Commission's Standard Contractual Clauses or an adequacy decision.
How long we keep it
- Enquiries, kept while we deal with them and for up to 24 months afterwards, so we have context if you come back.
- Newsletter, kept until you unsubscribe, then removed from the active list.
- Server logs, kept for a short period by our host for security and diagnostics.
- Wishlist and trip plan, kept in your browser until you clear them. We hold no copy.
Security
The site is served over HTTPS, payment is handled entirely by our booking partner, and access to any enquiry we hold is limited to the people who need it. No method of transmission or storage is completely secure, so we cannot promise absolute security, but we do not hold card data and we keep what we do hold to a minimum.
Your rights
UK and EU (GDPR)
You have the right to access your data, correct it, delete it, restrict or object to how we use it, receive it in a portable form, and withdraw consent at any time. You may also complain to your supervisory authority, in the UK, the Information Commissioner's Office.
California (CCPA/CPRA)
You have the right to know what we collect and why, to have it deleted, to correct it, and to opt out of sale or sharing. We do not sell or share personal information, and we do not use sensitive personal information for inferring characteristics, so there is nothing to opt out of. We will not discriminate against you for exercising any right.
Canada (PIPEDA) and anti-spam (CASL)
You may ask what personal information we hold, request a correction, and withdraw consent. Marketing email is only sent to people who asked for it, every message carries an unsubscribe link and our identity, and unsubscribes are actioned promptly.
Making a request
Email info@visitingniagarafalls.com. We will respond within the time your law allows, 30 days under the GDPR, 45 days under the CPRA, and we may ask you to confirm your identity first. Requests are free unless they are excessive or repetitive.
Children
This site is meant for adults booking travel. We do not knowingly collect personal information from children under 13 (or under 16 in the UK and EU). If you believe a child has given us information, contact us and we will delete it.
Do Not Track and Global Privacy Control
We run no cross-site tracking, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. Clarity is the one thing those signals are aimed at; block it with your browser settings or a tracker blocker, as described in the Cookie Policy.
Changes to this policy
Microsoft Clarity was added on 21 August 2026 and this page was updated the same day. If we add advertising, profiling, or any new way of using your data, we will update this page and change the date at the top before the change takes effect. Material changes will be flagged on the site.
Contact us
Visiting Niagara Falls
Email: info@visitingniagarafalls.com
Or use the contact form.
If you are contacting us about a specific booking, include the confirmation reference so we can find it quickly.