1. Introduction
Welcome to Powder Finder ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our ski resort powder tracking application.
2. Information We Collect
2.1 OAuth Authentication Data
When you sign in using Google or GitHub OAuth, we collect:
- Email address - Used as your primary identifier
- Name - Displayed in your profile
- Avatar/Profile picture URL - Displayed in the application
- Provider user ID - To link your OAuth account
- Email verification status - From your OAuth provider
2.2 Session and Security Data
For security and authentication purposes, we collect:
- IP address - To track sessions and detect suspicious activity
- Browser user agent - To identify your device type
- Login timestamps - To track account activity
- Session tokens - Stored as hashed values (SHA256)
2.3 User Preferences
To personalize your experience, we store:
- Favorite ski resorts - Your saved resort list
- Unit preferences - Metric vs. Imperial measurements
- Notification preferences - Email and powder alert settings
2.4 Automatically Collected Data
We automatically collect:
- Browser localStorage data - Unit preferences, map position, UI state (stored locally on your device)
- API usage metrics - For performance monitoring and cost management
3. How We Use Your Information
We use your information to:
- Authenticate your account and maintain your session
- Display personalized resort information and powder predictions
- Remember your preferences (units, favorites)
- Send email notifications if you opt in
- Detect and prevent fraudulent activity or unauthorized access
- Improve our services and fix technical issues
- Comply with legal obligations
4. Cookies and Tracking Technologies
Essential Cookies Only
We only use essential cookies required for authentication and security. We do not use analytics, advertising, or tracking cookies.
4.1 Session Cookie
- Name:
session_token
- Purpose: Maintains your logged-in session
- Duration: 7 days
- Security: HttpOnly, Secure (HTTPS), SameSite=Lax
4.2 CSRF Protection Cookie
- Name:
csrftoken
- Purpose: Protects against Cross-Site Request Forgery attacks
- Duration: 1 hour
- Security: HttpOnly, Secure (HTTPS), SameSite=Strict
4.3 OAuth State Cookie
- Purpose: Temporary validation during Google/GitHub login
- Duration: 15 minutes (automatically deleted after login)
- Security: Single-use token, expires quickly
4.4 Local Storage
We use your browser's local storage (not cookies) to remember non-sensitive preferences:
- Unit system preference (metric/imperial)
- Map position and zoom level
- Recently viewed resorts
- UI filter and sort preferences
This data is stored locally on your device and is not transmitted to our servers.
5. Third-Party Services
5.1 OAuth Providers
We use third-party OAuth services for authentication:
- Google OAuth - Managed by Google LLC
- GitHub OAuth - Managed by GitHub, Inc.
When you sign in with these providers, you are subject to their privacy policies:
5.2 Weather Data
We use OpenWeather API to provide weather and snow condition data. No personal information is shared with OpenWeather.
5.3 AI Services
We use OpenAI API to generate powder predictions. We do not share any personal user data with OpenAI - only anonymized resort weather data.
6. Data Security
We implement industry-standard security measures to protect your data:
- Encryption: All data transmitted over HTTPS (TLS 1.3)
- Token Hashing: Session tokens are hashed with SHA256 before storage
- HttpOnly Cookies: Prevents JavaScript access to authentication tokens
- CSRF Protection: All state-changing operations require CSRF validation
- Rate Limiting: Protects against brute-force attacks
- Account Lockout: Automatic lockout after 5 failed login attempts
- Session Management: Maximum 5 concurrent sessions per user
7. Data Retention
We retain your data as follows:
- Account data: Until you delete your account
- Session data: 7 days or until logout
- OAuth state tokens: 15 minutes (single-use)
- Login logs: 90 days for security purposes
- Expired sessions: Automatically cleaned up daily
8. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update incorrect or incomplete data
- Deletion: Request deletion of your account and data
- Export: Receive your data in a portable format
- Opt-Out: Disable email notifications at any time
- Revoke Access: Disconnect OAuth providers from your account
To exercise these rights, contact us at: privacy@powderfinder.bigmac-attack.com
9. Children's Privacy
Powder Finder is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
10. International Users
Our services are hosted in the United States. If you access Powder Finder from outside the U.S., your data may be transferred to and stored in the U.S. By using our services, you consent to this transfer.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date
- Sending an email notification (if you have email notifications enabled)
Your continued use of Powder Finder after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
← Back to Dashboard