Privacy Policy

What we collect when you use Visiting Niagara Falls, why we collect it, who else sees it, and how to get it removed. Written to be read, not skimmed past.

Last updated: 21 August 2026

Who we are

Visiting Niagara Falls ("we", "us", "our") is an online travel agency for a single destination. We list tours, attraction tickets and passes at Niagara Falls on both the New York and Ontario sides, and we are the data controller for the personal information described in this policy.

This policy covers visitingniagarafalls.com and nothing else. It does not cover the operators who run the experiences, the booking platform that completes your purchase, or any other site we link to; each of those has its own privacy policy.

This policy sits alongside our Terms of Service, which set out our role as your booking agent, our Cookie Policy, and our Accessibility Statement.

Questions, or want to exercise a right below? Email info@visitingniagarafalls.com or use our contact page.

The short version

We do not run advertising trackers, we do not sell your personal information, and we do not take payment on this site. Most of what we store lives in your own browser, not on our servers.

  • You can browse the whole site without giving us anything.
  • Your wishlist and saved trip plan are stored in your browser, not in an account.
  • You only give us your details if you contact us or subscribe.
  • When you book, you are handed to our booking partner, who takes the payment.

What we collect

Information you give us

  • Contact form, your name, email address, phone number if you add one, and whatever you write in the message.
  • Newsletter, your first name, email address, and the travel interest you optionally pick.
  • Trip planner, the dates, group make-up and interests you enter to generate an itinerary.

Information collected automatically

Like any website, our hosting provider records technical information when a page is requested: your IP address, browser and device type, the page you asked for, the page that referred you, and the date and time. These logs exist to keep the site running and secure.

Information stored on your device

We use one analytics tool, Microsoft Clarity, which sets two first-party cookies (_clck and _clsk) and records your visit as anonymous pointer movement, clicks and scrolling so we can see which parts of a page people actually use. We use no cookies for advertising or profiling, and we sell nothing. What Clarity sets, and how to refuse it, is in the Cookie Policy. We also use your browser’s local storage for two things, both of which stay on your device and are never sent to us.

NameWhat it holdsHow long it lasts
vnf_wishlistThe tours and attractions you have saved with the heart iconUntil you clear it or clear your browser data
vnf_tripplanThe itinerary the trip planner last generated for youUntil you clear it or clear your browser data

You can remove both at any time by clearing site data for this domain in your browser settings. Nothing else on the site depends on them.

How we use it

  • To answer you. If you send a message, we use your details to reply and to follow up on that enquiry.
  • To send what you asked for. If you subscribe, we use your email for the guide and subscriber offers, and nothing else.
  • To show accurate prices. Live prices and availability are fetched from our booking partner when you open a listing, and converted into your currency.
  • To keep the site working. Server logs help us find faults, block abuse and understand load.

We do not build advertising profiles, and we do not make automated decisions that produce legal or similarly significant effects.

Where the UK GDPR or EU GDPR applies, we rely on:

  • Consent, for marketing email. You give it by subscribing and can withdraw it at any time.
  • Legitimate interests, for answering enquiries, keeping the site secure, and preventing abuse. We have considered your rights and do not think these uses override them.
  • Legal obligation, where we must keep records or respond to a lawful request.

Who we share it with

We do not sell personal information and we do not share it for cross-context behavioural advertising. We do rely on a small number of service providers, and your browser contacts some of them directly when it loads a page:

ProviderWhat it doesWhat it can see
VercelHosts the site and runs our booking endpointsRequest logs, including IP address
Viator (Tripadvisor)Our booking partner: live prices, availability, and checkoutYour booking details, entered on their checkout
Cloudinary, UnsplashServe the photographyIP address and browser, as with any image request
Google Fonts, jsDelivrServe the typefaces and flag iconsIP address and browser
FrankfurterProvides exchange rates for currency conversionNothing about you; we call it from our server

We may also disclose information where the law requires it, to protect our rights or someone's safety, or to a buyer if the business is ever sold, in which case this policy travels with it.

When you book

We do not take payment on this site. Selecting an experience hands you to our booking partner's secure checkout, where you enter your traveller and payment details. Your card details never reach our servers.

From that point the operator running the experience and the booking platform handling the transaction are responsible for your booking data under their own privacy policies. We receive enough to help you if something goes wrong, and we will take an issue up with the operator on your behalf.

International transfers

We operate across the United States and Canada, and our providers may process data in either country or elsewhere. Where data covered by the UK or EU GDPR leaves that jurisdiction, we rely on the transfer mechanisms our providers put in place, such as the European Commission's Standard Contractual Clauses or an adequacy decision.

How long we keep it

  • Enquiries, kept while we deal with them and for up to 24 months afterwards, so we have context if you come back.
  • Newsletter, kept until you unsubscribe, then removed from the active list.
  • Server logs, kept for a short period by our host for security and diagnostics.
  • Wishlist and trip plan, kept in your browser until you clear them. We hold no copy.

Security

The site is served over HTTPS, payment is handled entirely by our booking partner, and access to any enquiry we hold is limited to the people who need it. No method of transmission or storage is completely secure, so we cannot promise absolute security, but we do not hold card data and we keep what we do hold to a minimum.

Your rights

UK and EU (GDPR)

You have the right to access your data, correct it, delete it, restrict or object to how we use it, receive it in a portable form, and withdraw consent at any time. You may also complain to your supervisory authority, in the UK, the Information Commissioner's Office.

California (CCPA/CPRA)

You have the right to know what we collect and why, to have it deleted, to correct it, and to opt out of sale or sharing. We do not sell or share personal information, and we do not use sensitive personal information for inferring characteristics, so there is nothing to opt out of. We will not discriminate against you for exercising any right.

Canada (PIPEDA) and anti-spam (CASL)

You may ask what personal information we hold, request a correction, and withdraw consent. Marketing email is only sent to people who asked for it, every message carries an unsubscribe link and our identity, and unsubscribes are actioned promptly.

Making a request

Email info@visitingniagarafalls.com. We will respond within the time your law allows, 30 days under the GDPR, 45 days under the CPRA, and we may ask you to confirm your identity first. Requests are free unless they are excessive or repetitive.

Children

This site is meant for adults booking travel. We do not knowingly collect personal information from children under 13 (or under 16 in the UK and EU). If you believe a child has given us information, contact us and we will delete it.

Do Not Track and Global Privacy Control

We run no cross-site tracking, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. Clarity is the one thing those signals are aimed at; block it with your browser settings or a tracker blocker, as described in the Cookie Policy.

Changes to this policy

Microsoft Clarity was added on 21 August 2026 and this page was updated the same day. If we add advertising, profiling, or any new way of using your data, we will update this page and change the date at the top before the change takes effect. Material changes will be flagged on the site.

Contact us

Visiting Niagara Falls
Email: info@visitingniagarafalls.com
Or use the contact form.

If you are contacting us about a specific booking, include the confirmation reference so we can find it quickly.