Privacy
We collect very little, because there is very little worth collecting about someone booking a holiday that does not exist.
Last updated August 2026
The short version
- You can use the whole product without an account.
- Your trips are stored in your browser first, and only in the cloud if you sign in.
- We never collect payment card details. There is no payment form and no payment processor.
- We do not sell data.
- The site carries Google Analytics and Google AdSense. Both are governed by the consent message, and neither stores anything until you answer it.
Anonymous ID
On your first visit the site generates a random UUID and stores it in your browser under tnh:anonymousId. It lets us attach your trips to your browser so they can later be merged into an account, and to de-duplicate them.
It is random. It is not derived from your device, browser, screen, fonts, IP address or anything else — we do not fingerprint. Clearing your site data destroys it, and a new one is generated next time.
Local storage
These keys are written to your browser:
tnh:anonymousId— the random id abovetnh:booking— the booking you are part-way throughtnh:trips— completed fake trips and unlocked achievementstnh:settings— currency, theme and departure airporttnh:syncQueue— writes that failed and should be retriedtnh:referral— a referral code, if you arrived through one
Clearing your browser data for this site removes all of it. Beyond this first-party storage, the only cookies are those Google sets once you accept the consent message, and the session cookie Supabase needs if you choose to sign in.
If you create an account
Signing in stores, in our Supabase database:
- Your email address, held by Supabase Auth so you can sign back in
- A display name and avatar URL, if your sign-in provider supplied them
- Your fake trips, passport stamps and achievements
- A referral code, so friends can be attributed to you
Your email is never exposed through any public page or API. Shared passports show only a display name and aggregate counts, and only if you explicitly make your passport public.
Cookies and consent
Consent is handled by Google’s Consent Management Platform — one message, shown where the law requires it. We deliberately do not run a second cookie banner of our own: two banners would mean answering the same question twice and keeping two records of the answer.
- Strictly necessary. The browser storage listed above — your booking, your trips, your settings. This is first-party storage on your own device, it is what makes the product work at all, and it is not covered by the consent message because without it there is no product.
- Advertising and analytics. Governed by your answer to the consent message.
We implement Google Consent Mode v2. Every advertising and analytics signal is set to denied before any Google code runs, and is only raised once you agree — so Analytics sends cookieless pings and AdSense withholds advertising storage until then. Our own product analytics reads the same answer.
You can change your decision at any time using the Privacy choices link in the footer.
Advertising
This site is free and costs money to run, so it may show a small number of ads through Google AdSense. Where they appear, they are labelled “Advertisement”.
Ads never appear inside the booking flow, the payment sequence, the confirmation or the journey. Those screens are the product, and an advert in the middle of a fake checkout would make a joke look like a scam. Subject to your consent, Google may use cookies to personalise and measure ads; you can review your options at Google My Ad Center.
Product analytics
When a database is configured, we record a small set of named product events — for example booking_started, cabin_selected, trip_completed — along with your anonymous id and a few properties such as the destination slug or cabin chosen.
In our own database we do not store IP addresses, user agents, referrer URLs, page URLs, scroll depth, mouse movement or session recordings. The purpose is narrow: understanding where the booking flow loses people.
The same events are also sent to Google Analytics once you have consented, where Google applies its own collection and retention rules. IP anonymisation is enabled. If you decline, Analytics runs without storage and sends no identifiers.
Deleting your data
Local data: clear site data in your browser, or use the button on the account page.
Account data: the account page has a delete option. It removes your profile, trips, stamps, achievements, referrals and analytics events, and then deletes the auth user itself. It is immediate and cannot be undone.
Children
This site is not directed at children and we do not knowingly collect data from them. It is a joke about overspending, which requires having money to overspend.
Contact
Built by Sunnysoft. Privacy questions can go there.