Yarn

Privacy Policy

You can browse Yarn Excursions without creating an account. If you choose to sign in, we use Clerk to manage authentication and Supabase to store the account record needed for reviews, saved listings, claims, owner tools, and photo moderation.

The app may load third-party services for maps, images, or external links. When you click a Google Maps, Apple Maps, shop, tourism, or transportation link, that third party may receive information under its own privacy policy.

If you submit a review or listing photo, we store the content, moderation status, and the account that submitted it. Approved reviews and photos may appear publicly; pending and rejected content is not shown in public guide content.

If you request a Port Day Pack, we store the email address, port, selected berth, optional sailing, page and campaign source, the exact promise shown, guide version, account link when signed in, and whether you separately opted into marketing. The public guide does not require an account, and the pack email is transactional. The optional marketing box is unchecked by default.

To limit automated or repeated pack requests, we create keyed, one-way hashes from the normalized email address and, when our trusted hosting proxy supplies it, the network address. The 15-minute quota uses those pseudonymous values; the raw network address and the secret operation token are not stored in the guide request record. We also remove query parameters, fragments, and embedded credentials from the referring page before storing it.

Resend processes Yarn Excursions email. We record its message ID and provider events when available, including acceptance, delivery, delay, bounce, complaint, failure, suppression, open, and link click. Provider acceptance is not treated as proof of mailbox delivery. We also record when a valid pack URL is served so support can determine whether the value exchange occurred.

If you save a listing or cruise, request a business claim, or submit an owner response, we store the information needed to provide that feature, review the request, and show the result in your account or owner tools. Claim evidence and moderation notes are used for site operations and are not published as guide content.

If you click a paid product before Stripe Checkout is enabled, the site opens a contact option instead of collecting payment details. Payment card data should only be entered through Stripe once checkout is available.

We store limited product analytics, such as meaningful guide or listing views, outbound clicks, saves, guide requests, and pack responses. These records can include a random browser session ID, referring page, and destination URL; they are operational product data, not a promise of traffic or sales. We do not place IP addresses or full browser user-agent strings in notification emails.

Clerk provides authentication, Supabase provides application data storage, Resend provides email delivery, Stripe provides checkout when enabled, and hosting/infrastructure providers process the technical data needed to run the service. Their own terms and privacy policies also apply. We keep operational, consent, and delivery records only as long as reasonably needed for the feature, support, abuse prevention, accounting, or legal obligations.

If you want an account, guide request, saved trip, business listing, schedule, photo, credit, or consent record corrected or removed, contact curtis@curtisduggan.com. You can unsubscribe from marketing with the link in those emails; doing so does not remove transactional support records. Last updated July 29, 2026.