Privacy
Your information, handled with care
12 Hours Ahead exists to plan trips, not to trade in data. This page says plainly what we collect, why we collect it, and the choices you always have. Effective August 7, 2026.
What we collect
- Trip inquiries. When you write to us through the inquiry form, we receive what you send: your name, email address, and your message.
- The newsletter. If you subscribe, your email address, and nothing else. Every issue carries an unsubscribe link that works immediately.
- Client accounts. If we plan travel for you, we hold your email address, your name, and the details of your trips: flights, hotels, reservations, and the notes you choose to leave on an itinerary. Signing in uses a one-time email link or a passkey; we never store a password.
- Cookies and measurement. One essential session cookie keeps you signed in to your itineraries. We also set a cookie on our public pages recording how you first reached us: the link, ad, or site you came from. It holds no name and no email; we use it to know which of the places we write and advertise actually bring people here. The only things in it we ever pass to an advertiser are the click identifier from an ad you arrived through and the time of that click, which is needed to format it (see below). Site traffic is measured with cookieless analytics that identify no one. Our public pages (the homepage, the Dispatch, the journeys, and the rest of the open site) also carry the Meta advertising pixel, which sets a cookie and tells Meta that a visit happened, so we can tell whether an ad was worth running. That visit is reported twice, once by your browser and once by our server, and counted once; we mention it because a tracker blocker stops the first and not the second. What Meta receives is the page address, your IP address and browser, its own advertising cookies, and (if you arrived from one of its ads) the click identifier from that link and when you clicked it; never your name or your email. It is deliberately absent from every signed-in page: your lounge, your itineraries, and everything behind them load no advertising code and report nothing about you. If your browser sends a Global Privacy Control signal, we send Meta nothing at all, neither half.
- What your browser remembers. If we've shown you an invitation to get in touch (the small window that appears on the homepage or a journey), your browser keeps three notes to itself. One records that you were asked on that particular page, so we don't ask again there for a month. Another records which version of the message you saw, because we try more than one wording and want to know which one people find useful. The third is a random label for the browser itself, with nothing inside it: no name, no email address, not even a guess at one. That lets us tell one person's visits apart from another's without knowing who either of them is. All three stay in your browser and are erased when you clear your site data. If you do give us your address, that is remembered too, and we stop asking you anywhere. What reaches us is a count of how many people were offered a version and how many replied, plus a note when the window was offered and a note if you replied to it, each carrying that random label, the time, which version you saw, and whether you were reading on a phone or a computer. Those notes carry nothing else, and we keep them for a little over a year. If you give us your address anywhere on the site (that window, a newsletter box, or the form on our welcome page), we also keep that random label beside it, on our side. It is the one place the label sits next to anything about you, and there is a single reason for it: without it we can count how many people got in touch, but not whether the window had anything to do with it. Some people are deliberately shown no window at all, so that we can find out whether interrupting anyone is worth doing; if we only kept the label when the window itself collected an address, that group would be unmeasurable and the question unanswerable. We remove the label from your record after that same year, because past that point it answers nothing. GrowthBook, the service that helps us read whether one wording works better than another, can see the label, the dates, and how far things got: never your address, never your name, never one word of anything you have told us. If your browser sends a Global Privacy Control signal we keep neither the second note nor the third; the note of the offer arrives with no label on it at all (so it still counts, and it points to nobody), and if you reply, no note of the reply is kept and nothing is stored beside your address.
- If that window asks a question and you type your own answer. Some versions of it offer a "something else" box instead of the choices. What you type there reaches us when you send it, whether or not you go on to give us your address. That is the point of asking, and previously we only ever saw it from people who did. It is stored on its own: the sentence and which question it answered, with no label, no address, and nothing tying it to you or to your other visits, so we can read what people are telling us without knowing who said it. We keep those for a little over a year. Nothing else you do in that window is written down this way: the choices you tap are only ever counted, never recorded one by one.
How we use it
To design and deliver your trips, to send you the itineraries and updates you've asked for, to answer your inquiries, and (only if you subscribed) to send the newsletter. That's the list.
Who we share it with
Only who the work requires: the airlines, hotels, and suppliers who fulfil your bookings; Fora Travel, our host agency, for booking and commission processing; and the infrastructure that runs this site (cloud hosting and email delivery providers acting on our instructions). Meta receives the visit data described above, and only that, from public pages only, never from your itineraries, and never your name, your email, or anything about your trips. GrowthBook, which helps us tell whether one wording of the invitation works better than another, reads only the notes described above and how far things went afterwards (never your address or your name), and reads them from our own database rather than from your browser; it runs no code on any page of this site. We do not sell your information.
How it's protected
Your itineraries live behind server-side access checks on every request: no public links, no guessable URLs. Data is encrypted in transit and at rest, and trip documents are stored privately and served only to the travellers they belong to.
Retention and deletion
We keep trip records while you're a client so your travel history can serve your next trip. Ask us to delete your information and we genuinely delete it: the trip records, the documents, and the account, not a "deactivation." Email hello@12hoursahead.com and we'll confirm when it's done.
Your choices
You can ask what we hold about you, ask us to correct it, ask us to delete it, or unsubscribe from the newsletter at any time. Depending on where you live, some of these are also legal rights; we honour them for everyone regardless. This site isn't directed to children under 13, and we don't knowingly collect their information.
Changes
If this policy changes, the new version appears here with a new effective date. Questions: hello@12hoursahead.com.