The fine print, minus the fog
Privacy
Plain language, on purpose. Short version: we collect what you give us, we use it to run the crew, and we don't sell it.
Last updated: 7 September 2026
Who's responsible for your data
Not Your Parents' Tour is a trading name of Alpaca Kit Technologies, a company incorporated in Hong Kong with its registered office at Unit 1603, 16/F, The L. Plaza, 367–375 Queen's Road Central, Sheung Wan, Hong Kong. That company is the data controller for everything described here, and hello@notyourparentstour.com reaches a human at it.
What we collect
When you join the waitlist or contact us, we collect what you type into the form: your name, email, home city, age band, trip interest, whether you're coming solo, and anything you add in the notes — plus a phone number if you choose to give one.
If you create an account, you can sign in with Google or with an email and password. With Google, Google tells us your name, email address and profile picture, and that's what we store — we never see your Google password, and the permission we ask for only identifies you (no access to your Gmail, contacts, calendar or Drive). With a password, it's handled by our authentication provider — we never see it.
If you book a trip, we also store your booking: the departure, the number of travelers, your contact name and phone, any requests you make of us, what you've paid and what's still owed — and, so we can defend the booking if your bank ever queries it, the moment you accepted our terms, which version you accepted, and the IP address it came from.
Payments
Card payments are processed by Stripe. Your card number, expiry and security code go straight to Stripe from your browser — they never touch our servers and we never store them. What we get back is the outcome, the amount, and a reference we can use to find the payment again.
Stripe is an independent controller of the payment data it handles, under its own privacy policy at stripe.com/privacy. It uses that data to process the payment, meet financial-crime obligations, and detect fraud — which includes device and behavioural signals collected on our checkout page.
Stripe emails you a card receipt for each payment; we send the booking confirmation separately.
Who else sees it
Only the people and services needed to run the thing: hosting and cookieless site analytics (Vercel — page views, referrer, coarse location and device class, plus which step of the booking flow you reached and how many travelers you were booking for, with no cookie and no cross-site tracking), product analytics (PostHog — described under Advertising and measurement below, and only with your permission), a secured cloud database and authentication provider (Supabase), sign-in (Google, if you choose it), payment processing (Stripe), and transactional email (Resend). Each gets only what its job requires. Google is an independent controller of what it does on its own side when you sign in, under its policy at policies.google.com/privacy.
Trips are delivered with licensed local operating partners in mainland China. If you book, we share with them only what's needed to run your trip — typically your name, and where a supplier requires it for rail, hotel or entry bookings, passport details you provide us for that purpose. We don't send them your payment details.
That means some of your data is handled in mainland China, and some of it in the United States and Europe where our providers run. We don't sell your data. The one thing that goes to an advertising platform is described under Advertising and measurement below — and only when your settings allow it.
How long we keep it
Waitlist and contact entries: until you ask us to delete them, or until they're clearly stale. Booking and payment records: we keep them for seven years after the trip, because tax and accounting rules in Hong Kong require it and because a card dispute can arrive long after you get home. Deleting your account doesn't erase a completed booking's financial record — nothing lets us do that.
Cookies
The boring ones are always there: a cookie that remembers your language choice (English or 中文), one that remembers whether you prefer the light or dark background, session cookies if you log in, and cookies Stripe sets on the checkout page to spot fraud. Vercel's site analytics set no cookie at all. The rest exist only while you allow the measurement described under Advertising and measurement below: PostHog's cookie, which holds the random id that ties your page views together, and Meta's two (_fbp and _fbc) for the pixel — plus our own small cookie that remembers your answer for a year, and which stays either way. One thing that isn't a cookie: if you arrive from a link that says where it came from (a campaign tag, a friend's referral link, or the site that sent you), your browser keeps that note in its own local storage for up to 90 days and attaches it to a form you choose to submit — so we know which channel brought you, on your device, with no third-party script and nothing sent anywhere until you do. Clear your browser storage and it's gone.
Advertising and measurement
Two different things live under this heading, and one switch controls both. The first is product analytics: we use PostHog to see how the site itself is working — which pages people read, where they get stuck, and how far they get in the booking flow. PostHog receives the pages you visit, the clicks and form steps on them, your browser and device, and a rough location worked out from your IP address, tied together by a random id stored in your browser rather than by your name. When you submit the waitlist or contact form it also receives a one-way hash of your email address, the same for your phone number if you gave one, and Meta's own cookie identifiers — passed through PostHog only so that signup can be reported to Meta as an ad conversion, described next. A hash cannot be turned back into your address; it is a matching key, and it is the only form in which your contact details reach either company. We never send it passport details, dates of birth, health information or payment details. PostHog also records a replay of your session — the pages, clicks and scrolling, so we can see where people get stuck — with password and payment fields masked out so their contents are never captured. Those requests leave your browser addressed to core.notyourparentstour.com, which is our own subdomain forwarding them to PostHog — it looks first-party in your network tab because the domain is ours, but PostHog is who receives the data, which is why it is named here. PostHog handles it only as our processor, on our instructions, on servers in the United States, under its policy at posthog.com/privacy — it does not get to use it for anything of its own.
The second is advertising. We run ads on Meta (Facebook and Instagram) to find the people these trips are for, and we want to know whether an ad actually brought someone here — not who you are. To measure that we can use Meta's pixel and its server-side Conversions API. When they run, Meta receives the pages you visit on this site, the standard events that happen on them (viewing a trip, joining the waitlist, starting checkout, paying a deposit — with the amount), your IP address and browser details, Meta's own cookie identifiers, and — when you give us an email address or phone number — a one-way hash of it so Meta can match the event to an account you already hold. We never send passport details, health information, dates of birth or payment details, and we never upload contact lists.
Whether either of them runs depends on where you are. In the European Economic Area, the United Kingdom, Switzerland and Quebec nothing loads until you say yes on the banner. Everywhere else they run by default and you can turn them off at any time with the “Do Not Sell or Share My Personal Information” link in the footer; if your browser sends a Global Privacy Control signal we treat that as a no, automatically. One answer covers both, and it is stored in a cookie for a year.
For California residents: sharing a visit with Meta for advertising counts as “sharing” personal information under the CPRA. We do not sell personal information, and the footer link above is how you opt out of sharing. We do not knowingly share the personal information of anyone under 16.
Meta is an independent controller of the data it receives, under its own policy at facebook.com/privacy/policy and its data-processing terms for measurement. What it does with that data on its own side — including building advertising audiences — is governed by your Meta settings, not ours.
Your data, your call
Want to see what we have on you, fix it, or have it deleted? Email hello@notyourparentstour.com and a human will handle it. If you're unhappy with how we've handled a request, you can complain to the Hong Kong Privacy Commissioner for Personal Data.
Changes
If we change how we handle your data in a way that matters, we'll update this page and the date at the top of it. The promise that won't change: we collect the minimum, and we don't sell it.
Questions about any of this? Email hello@notyourparentstour.com or see the terms and the cancellation policy.