Privacy policy

Effective 26 September 2026. The short version: no advertising, no third-party analytics or tracking cookies, no stored IP addresses, self-hosted fonts, and anonymous usage statistics. An account is optional — the map works fully without one — and when you do create one, we keep only what the planner needs and you can delete it yourself at any time.

Who runs this site

Month to Go (monthtogo.com) is run by an independent traveller. For anything in this policy, contact [email protected] — that address is the controller contact for the purposes of the EU and UK GDPR.

What is recorded

When you use the site, it stores small anonymous event records in a database we run ourselves (Cloudflare D1). Each record can contain: a timestamp; the event type (page visit, start city chosen, country picked in Quick budget, nights or travellers adjusted, month clicked, view switched, share button used); your country only, as estimated by our host from your connection; a coarse device class (mobile, tablet or desktop) and operating-system family (such as Windows, iOS or Android); a random session code that groups one visit’s clicks and is discarded when you leave; and, where relevant, the city, country, month, nights and traveller count you selected, plus how you arrived (a link tag such as “reddit”, the referring site’s hostname, or the platform of a shared link) and which platform you shared to.

What is never collected

In the usage statistics: no tracking cookies; no identifying localStorage; no names or email addresses; no stored IP addresses; no precise location; no device fingerprinting; no advertising or third-party analytics scripts; no cross-site tracking of any kind. The random session code is generated fresh on every visit and cannot be linked back to you. Two small conveniences are kept on your device only and never sent anywhere: your chosen display currency, and — on the owner-only logbook page — the owner’s access key, which that page forgets after 30 minutes of inactivity. If your browser sends the “Do Not Track” or Global Privacy Control signal, the site sends no statistics events at all, and automated browsers that identify themselves as such are ignored too.

The nearest-city suggestion

On the opening screen the site suggests the start city nearest to you. To do this it asks our host (Cloudflare) for the approximate location it derives from your connection at that moment; the answer is used once, inside your browser, to pre-select a city, and is not stored by us. You can pick any other city from the list.

The contact form

If you send us a message through the contact form, we keep what you wrote — the subject, the category you chose and the message text, together with the country your message came from — and it may also be delivered to our email inbox. The form has no name or email field, so a message is anonymous unless you choose to include contact details in the text. We use messages only to read and act on your feedback, and you can ask us to delete one at [email protected].

If you create an account

Accounts exist only to power the planner, your map and collaboration. When you sign up we store: your email address; an optional display name; your chosen home city; and either a salted password hash (PBKDF2-SHA256, 100,000 rounds — we never see or store the password itself) or, if you continue with Google or Apple, the identifier and email address they give us. Email sign-ups receive one verification email from [email protected]; the link in it works once and expires after 24 hours. Signing in sets one cookie (mtg_sess) — HttpOnly, Secure, and strictly necessary, which is why it needs no consent banner. It keeps you signed in for up to 30 days.

Your plans — destinations, months, nights, travellers and the notes you write — and your map marks are stored against your account and shown only to you, to contributors you invite, and to anyone you hand a read-only share link (the link is the key: keep it to people you trust, and you can switch it off at any time). If you invite a contributor we store the email address you enter so the plan can appear in their planner; they will see the plan’s content, and you will see whether they have joined. Account data is never used for advertising, never sold, and never mixed into the public statistics.

Sign-in providers. If you use “Continue with Google” or “Continue with Apple”, those providers process your sign-in under their own privacy policies; we receive only your identifier, email and name — never your contacts or anything else.

Deleting your account is self-serve on the account page and immediate: it removes your account, sessions, plans, trips, notes, map marks and contributor entries. Plans shared with you belong to their owners and remain theirs.

Cookies and device storage

This site sets no advertising, analytics or third-party cookies of any kind, which is why you see no cookie banner: under the EU ePrivacy rules and the UK PECR, consent is only required for storage that is not strictly necessary for a service you asked for, and everything below is exactly that.

The complete list: mtg_sess — set only when you sign in; HttpOnly, Secure and SameSite; keeps you signed in for up to 30 days; deleted when you sign out or delete your account. mtg_oauth — a ten-minute, HttpOnly security token set only while a Google or Apple sign-in is in flight, to protect against cross-site request forgery. In your browser’s own storage, never sent to us: your chosen display currency; a per-tab note that you dismissed the sign-in suggestion; and, on the owner-only logbook page, the owner’s access key, forgotten after 30 minutes of inactivity, plus an optional “don’t count my visits” switch that simply stops this browser sending statistics. That is everything — there is nothing to accept or refuse.

Fonts and third-party requests

Every font on the site is served from monthtogo.com itself. Loading a page here makes no request to Google Fonts or any other third-party server, so no outside company sees your IP address just because you visited. The only third parties involved at all are the ones listed under “Processors” below, each doing a specific job for us.

Processors we use

Cloudflare hosts the site and its database and delivers pages worldwide; while doing so it processes connection data (including IP addresses) as our infrastructure provider. Resend sends our account-verification emails from [email protected]; for that one purpose it processes the email address you registered with and the message content. If you sign in with Google or Apple, they handle that sign-in under their own policies and pass us only your identifier, email and name. We have no other processors, no advertising partners and no data brokers.

How long things are kept

Sign-in sessions expire after at most 30 days. Email-verification links die after 24 hours and after first use. The security log used for rate-limiting (a hashed key and a timestamp) is pruned after roughly a day. Your account, plans, notes, expenses and map marks are kept until you delete them — deletion is immediate and permanent. Contact-form messages are kept until dealt with; anonymous, aggregate statistics may be kept indefinitely.

Legal bases and international visitors

The statistics we keep are anonymous and are not used to identify anyone. To the extent that serving the website involves transient processing of personal data (for example, your IP address while our host delivers pages and estimates your country), that processing rests on legitimate interest (GDPR Art. 6(1)(f)) in operating, securing and improving the site, and the data is not retained by us. Account data is processed to provide the service you asked for (Art. 6(1)(b)) and kept until you delete it. The same standard applies to every visitor worldwide — EU, UK, US and everywhere else. For California residents (CCPA/CPRA): we do not sell personal information, do not “share” it for cross-context behavioural advertising, honour the Global Privacy Control signal, and will never discriminate against you for exercising a privacy right. Requests: [email protected].

Where the data lives

The site and its database are hosted on Cloudflare’s global network, which acts as our infrastructure provider and processes traffic to deliver the site. Aggregated, anonymous statistics may be kept indefinitely. If you email us, we keep the email only as long as needed to deal with it.

Your rights

If you are in the EEA, UK or a jurisdiction with similar rules, you have rights of access, rectification, erasure, restriction, objection and portability over personal data, and the right to complain to your supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk). Because the usage statistics are anonymous, we cannot single out records belonging to you. For your account, the data is yours to read on the pages themselves, to download as a single JSON file with the “Download my data” button in account settings (data portability), and to erase with the delete button; for anything else involving personal data (such as emails you have sent us), write to [email protected] and we will act on it.

Children

The site is a general-audience travel-planning tool and does not knowingly collect personal data from children.

Changes

If this policy changes, the new version will be posted here with a new effective date.

Account