Legal
Privacy policy
Last updated: July 25, 2026
ParkBound Apps LLC (“ParkBound,” “we,” “us”) builds theme-park companion apps and this website. This policy explains what we collect, how we use it, and the choices you have. We keep data collection minimal and never sell your personal information.
Data we collect
- Account data. When you create an account we store your email address and authentication details through our auth provider, plus a display name and any profile details you add, including an optional profile photo or banner. User-selected profile images are sanitized and held for automated or manual moderation before publication.
- Content you create. Your collection, park history, trip plans (itineraries, flights, dining), blog comments, game progress, achievements, and other entries you save in the app. ParkBound pass purchase details, visit notes, discount logs, and collected magnets are saved to your ParkBound account and cached on your device for offline use. Race and reminder entries and dietary restrictions or allergy selections remain on your device unless you choose to share an export. Android cloud backup and device transfer are disabled for this app data.
- Subscription status. If you subscribe to ParkBound+, the purchase is processed by the app store you subscribe on. We use RevenueCat to manage subscription status and receive transaction identifiers — never your full payment details.
- Push tokens. If you turn on notifications in the mobile app, we store a device push token to deliver them. Turning notifications off in your device settings stops delivery.
- Usage and interaction data. ParkBound records aggregate blog view counts and, for signed-in users, an account-linked record of which ParkBound app and platform was used, first and last use, and an open count. That limited presence record supports cross-app operations and aggregate adoption reporting, is visible only to authorized staff, and is deleted after 180 days without another use or when the account is deleted. ParkBound Collections sends its presence and other optional account-linked product analytics only when you opt in; withdrawing that choice deletes the optional analytics history. If you accept website analytics, we also collect masked page views, clicks, pointer movement, and scroll depth to build aggregate interaction heatmaps. We disable session recordings and mask page text, inputs, and element attributes. Ad partners may separately process ad impressions and interactions as described below.
- Device and log data. Standard technical data your device sends when you use the service, such as IP address, browser type, and error logs, used for security and reliability.
- Giveaway data. When you enter a ParkBound giveaway, we store the email address needed to record the entry, prevent duplicates, conduct the drawing, and contact a potential winner. A standalone web entry does not add you to a marketing list.
- Calendar data. If you choose Add to Calendar on Android, ParkBound reads the available calendar list to select a writable calendar and writes the trip titles, dates, and notes you confirm. It does not read unrelated event contents or send calendar contents to ParkBound servers; your selected calendar provider may sync the new events.
How we use it
- Provide, maintain, and sync your account and collection across devices.
- Operate features you use, such as trip planning and comments.
- Understand aggregate usage so we can improve the product.
- Keep the service secure and prevent abuse.
- Communicate with you about your account and important service changes.
- Administer giveaways, enforce entry limits, draw a winner, and deliver the prize.
- Personalize ParkBound Collections recommendations using collection and activity signals.
- Personalize ParkBound Pulse articles using your follows, wishlist, favorites, upcoming trips, and whether an article connects to your collection.
Third parties
We share data only with service providers that help us run ParkBound, under their respective terms:
- Supabase — hosts our database and handles account authentication and storage.
- Vercel Analytics — provides privacy-friendly, cookieless usage analytics when you accept analytics.
- PostHog — builds aggregate website interaction heatmaps from masked click, pointer, and scroll data after you accept analytics. Session recording is disabled.
- RevenueCat — manages ParkBound+ subscription status across platforms.
- AWS Rekognition — moderates user-selected images for safety.
- Google Gemini — processes images when you initiate an AI scan and, when you choose Build my trip, processes your planning request and the trip details needed to prepare a draft itinerary, budget, and packing list. When relevant, those details can include saved bookings and your annual-pass destination, tier, validity dates, and selected add-ons; purchase price and passholder activity logs are not sent.
- Google Maps Platform and Google Search — provide place and current travel information used in trip drafts. ParkBound shows supporting sources with the draft when they are available.
- Open-Meteo — provides destination geocoding and forecast data used for weather-aware trip and packing suggestions.
- Apple APNs and StoreKit — deliver notifications and process purchases.
- Google Firebase and Google Play Billing — provide Android push delivery, installations needed for that delivery, and purchase processing. Optional Firebase analytics/crash collection stays off until an eligible user opts in where offered.
- Meta App Events — optional Collections analytics only after an eligible user opts in.
- Google AdSense and Google AdMob — serve ads to free-tier users on the website and in our apps (see Advertising below).
We are not affiliated with, endorsed by, or sponsored by The Walt Disney Company or any theme-park operator.
Advertising
- Free accounts may see ads on this website (served by Google AdSense) and in the ParkBound apps (served by Google AdMob). ParkBound+ subscribers do not see ads.
- The ParkBound Collections website makes no AdSense or optional marketing-vendor request unless the visitor has opted in and a signed-in, age-eligible account is confirmed.
- Where offered, Google’s consent choices determine whether ad personalization is allowed. On iOS, Apple’s App Tracking Transparency choice separately controls whether an app may permit cross-company tracking and access the advertising identifier.
- When the applicable choices permit it, Google may use cookies or device identifiers to select and measure ads under Google’s partner policy. If a choice does not authorize the requested processing, Google may use an eligible limited or non-personalized mode, or the apps make no ad request. Free accounts may still see ads where an eligible mode is available.
- Google’s mobile ads SDK may process device identifiers, ad interactions, diagnostics, IP-derived coarse location, and advertising data. The apps obtain any required regional consent before requesting ads and request Apple tracking permission before cross-company tracking; unresolved consent disables ad requests.
Age protections
ParkBound requires a one-time 13+ age-band selection before starting accounts, online content, ads, analytics, notifications, or other network features. ParkBound Collections offers a local-only Explorer Mode for users under 13. Users aged 13–15 in configured guardian-consent regions remain in Explorer Mode unless and until ParkBound offers an independently verified parent or guardian consent channel. We store an age band, not a birth date or exact age.
Your rights
You can delete your account or create a personal-data export from the app’s settings. Collections exports combine the shared server record with documented device-local preferences and scan drafts; the iOS export also includes pending offline operations. To ask us to access, correct, or delete data, email support@parkboundapps.com. You can accept or decline analytics and ads from the consent banner, and change that choice at any time — . Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; contact us to exercise them.
Retention and deletion
Account records and private content are retained while your account remains active and are removed through the in-app deletion flow. Public catalog contributions that other collectors rely on may be retained only in de-identified form with account attribution removed. Moderation and security records are retained only while needed to investigate abuse, meet legal obligations, or protect the service. Temporary export files are replaced on the next export and cleared during account sign-out or deletion; the operating system may also clear temporary storage. Standalone giveaway email addresses are deleted within 30 days after a winner is confirmed, unless we must retain a limited record for fraud prevention, tax, legal, or recordkeeping obligations. Account-linked app and platform presence rows are deleted after 180 days without another recorded use.
Contact
Questions about privacy? Email support@parkboundapps.com.
See also our Terms of Service.