Privacy
Privacy
The short version: no cookies, no tracking scripts, nothing about you sold or shared. We count visits to our own pages, and we email hotels about their day passes. That is the whole of it.
Last updated 6 September 2026.
When you browse this site
We count what happens on our own pages — which page was opened, what was searched for, which link out to a hotel was clicked — so we know which listings are worth keeping current. It is measured by our own server, not by an analytics company.
There is no tracking script, no advertising network and no third party watching you here. Nothing is stored in your browser: no cookies, no local storage, no identifier of any kind. Your visit is counted under a one-way keyed hash of your IP address, your browser’s user-agent string and today’s date, worked out on our server and never sent back to you. It cannot be reversed into an address, it does not name you, and it changes at midnight, so nothing follows you from one day to the next — or to any other site. Those counts are kept for 13 months and then deleted.
The one cookie this site can set belongs to the private operator console, and only after somebody signs in to it with a password.
Hotels and their contact details
JuaPass is a directory of hotel day passes, and it is built by asking hotels. We record a hotel’s business contact address where the hotel publishes it — on its own website, or in a public business listing — and we write to it to ask whether the hotel sells day access and on what terms. Those are business addresses for business questions, never anyone’s personal account.
A hotel’s reply is stored against that conversation and read for the facts a listing needs: the price, the hours, what is included. That reading is automated — the text is passed to Anthropic’s API to have the day-pass details extracted from it — and a person reviews the result before anything is published. We publish only what a hotel actually told us, or what its own website states, with the date we checked it.
If you would rather we did not write again, say so in a reply, or use the unsubscribe button your mail client shows beside our messages — every email we send carries the header that puts it there. Either way the address goes on a suppression list, and nothing in this pipeline may write to a suppressed address again.
Email we send
Outreach is sent from one Gmail account we own, dedicated to this pipeline and used for nothing else. Our software signs in to that account through Google’s API with permission to send mail as it, and reads that account’s own inbox for the replies hotels send back.
That access is used for exactly that and nothing more. We do not read any other mailbox, we do not share or sell what is in ours, we do not use it for advertising, and we do not use it to train or improve any generalised AI model. Nobody outside this project has access to that account.
Where it is kept
Listings, conversations and visit counts live in a Postgres database hosted by Supabase in the EU. The website runs on Vercel and the pipeline runs on Railway. Those three, Google for the mailbox, and Anthropic for the automated reading described above, are the only companies that handle any of it.
Asking us anything
Reply to any email you have had from us — to ask what we hold about a hotel, to have it corrected, or to have it deleted. Every one of our emails is a working address that a person reads, and we answer.