Gatsby Files Chicago
Privacy Policy
What this site collects when you plan a night out, why, where it lives, and how to get rid of it. Written from the code that runs the site, in plain English.
Effective
Who we are
Gatsby Files is a Chicago date planner at gatsby-files.vercel.app, run by Gatsby Files, the site operator. For anything in this policy, email shawn14@gmail.com.
This policy covers this website and its API. It does not cover the restaurants, Google Maps, Ticketmaster, or booking sites we link to. Once you leave, their policies apply.
The short version
- You can use the whole planner without an account. Signed out, your saved plans and notes live in cookies in your own browser.
- If you sign in with Google, we keep your email address and profile picture so the signed-in header can show your account. We do not store your Google account id, and we never store Google tokens.
- There are no analytics, advertising, or tracking scripts on this site. We do not sell your data.
- Signed-in data is stored in a Redis database (Upstash, provisioned through Vercel) and kept until you ask us to delete it.
What we collect, and why
Signed out. Your saved plans (up to six), the restaurants and events you save (ids only), your been-there list, taste notes you type, your plan mode and who the plan is for. All of it is stored in cookies in your browser and read by our server to build your plan. Nothing about a signed-out visitor is written to our database, apart from household sharing and Decide together, described below. Taps on booking, ticket, or map links are not recorded while you are signed out.
Signing in with Google. We ask Google for the openid, email and profile scopes. Google returns a signed identity token containing your email address, whether Google has verified it, your Google account id, your name, and your profile picture. We require the address to be verified, keep the email address and profile picture for your signed-in avatar, and discard the name and account id when the request finishes. The tokens Google issues are used for that one request and are not stored. Google’s side of sign-in is covered by Google’s privacy policy.
Your profile, once signed in. A record keyed by your email address that holds:
- your Google profile picture URL, used only for the signed-in avatar;
- when it was created and when you last used it;
- ratings from 1 to 5 by restaurant or event;
- the restaurants and events you saved, and your been-there list (up to 500 entries: type, id, name, date);
- saved plans (up to 30: plan id, date, mode, title, the event and dinner names, ids and time, neighborhood);
- activity signals (up to 200): when you tap a booking, website, ticket, maps, calendar, save, done or skip action, we record which action, the restaurant, event or plan it was on, its category, neighborhood and cuisine, and the time;
- taste notes (up to 50, each up to 500 characters, with an optional link).
When you first sign in, anything already in your signed-out cookies is merged into the profile so you do not lose it. We use the profile to rank plans for you (skip places you have been, lean toward what you save and open), to show the counts on your Account page, and to draw your personal map on Saved. A tap on a booking link is treated as interest, not proof you went.
Decide together. When you share a decision link, we store the options (restaurant and event facts from our own catalog), the date and mode, and the votes. Each person who opens the link gets an anonymous random id in a cookie so a vote counts once. It is not connected to any account or email. A voter may type a display name of up to 24 characters, which is shown to the other people on that link. Decisions are deleted after 60 days. Creating and voting are rate limited by IP address: a counter keyed by your IP is kept in the database for up to one hour and then expires. We keep no other record of IP addresses ourselves.
Household sharing. If you enter a household code, the notes, saved plans and been-there history for that code are stored under it in the database for up to one year, and anyone who enters the same code sees them. Treat the code like a shared password.
Your location. Only if you tap to use it on the home page. Your browser then sends your coordinates, rounded to five decimal places, with that plan request so distances are measured from where you are. They are used for that response and not stored.
Editors. A few trusted people sign in with Google to maintain the catalog. Their email addresses are kept in an editor list and on an audit trail of catalog edits and Great Pick endorsements. Great Picks are shown to everyone with a display name or as “Gatsby editor”, never an email address.
Logs. Our own log lines record errors and the reason a sign-in failed. They do not contain your email address or tokens. Vercel, which hosts the site, keeps standard request logs under its own policy.
Cookies
We use cookies, all set by this site and none by advertisers. They are sent only over HTTPS in production, with SameSite set to Lax except the editor session, which is Strict. Blocking or clearing them signs you out and forgets signed-out saves. The planner keeps working either way.
| Cookie | What it holds | Who can read it | Lifetime |
|---|---|---|---|
| gf_who | Your email address plus a signed verified flag. This is your sign-in. | Server only | 180 days. Cleared when you sign out. |
| gf_google_oauth_state | Random anti-forgery tokens for a Google sign-in in progress (up to three attempts at once). | Server only | 15 minutes. Cleared when sign-in completes. |
| gf_picks | Up to six saved plans, while signed out. | Server only | 1 year |
| gf_saved | Ids of restaurants and events you saved, while signed out. | Server only | 1 year |
| gf_done | Your been-there list, while signed out. | Server only | 1 year |
| gf_taste | Taste notes you typed, while signed out. | Server only | 1 year |
| gf_mode | Your plan mode: date night, fancy, casual day or fun. | Server and page scripts | 1 year |
| gf_sports | Whether to include sporting events in suggested plans. Off unless you turn it on. | Server and page scripts | 1 year |
| gf_plan_who | Who the plan is for. | Server and page scripts | 1 year |
| gf_household | Your six-character household code, if you use sharing. | Server and page scripts | 1 year |
| gf_decide_voter | An anonymous random id so a Decide together vote counts once. Not linked to your account or email. | Server only | 1 year |
| gf_admin | A signed editor session after the admin password. Editors only. | Server only | 30 days |
Where it is stored, and for how long
- Hosting: Vercel runs the site and its API.
- Database: a Redis database from Upstash, provisioned through Vercel (Vercel KV or Upstash Redis). Profiles are kept with no automatic expiry, until you ask us to delete yours. Decisions expire after 60 days, household data after one year, IP rate-limit counters after one hour.
- Your browser: the cookies above, for the lifetimes listed.
- The catalog of restaurants and events is public information stored in our code, not personal data.
Third parties
Services that see something when you use the site, and what they see.
- Google handles sign-in, only when you choose it.
- Vercel hosts the site and processes every request. Vercel privacy policy.
- Upstash stores the database described above. Upstash privacy policy.
- Google Fonts. Every page loads its typefaces from fonts.googleapis.com and fonts.gstatic.com, so your browser sends Google a font request with your IP address and browser details. Google Fonts privacy FAQ.
- unpkg serves the map stylesheet (Leaflet CSS), which your browser fetches from unpkg.com on every page.
- OpenStreetMap. On pages with a map (the plan map on the home page and Your Chicago on Saved), map tiles come straight from tile.openstreetmap.org, so the OpenStreetMap Foundation sees your IP address and the map area you view. OSMF privacy policy. Map data © OpenStreetMap contributors.
- Restaurant photos. Where an editor has approved a photo, your browser loads it from the restaurant’s own website or the approved source, without sending a referrer.
- National Weather Service. When you share your location, our server uses your rounded coordinates to request the forecast for that area from api.weather.gov. We do not store those coordinates.
- Ticketmaster, venue calendars, City of Chicago open data, Eater, Michelin. Sources of the event and restaurant catalog. Our scripts fetch listing data. Your browser loads event photos from the image hosts supplied by these sources, which receive your IP address and browser details. Ticket and table links go to Ticketmaster, the venue’s website, Google Maps, OpenTable, Tock or Resy, and their policies apply once you are there.
- Google Places. Used by editors to look up a place when adding it to the catalog. A visitor’s page load never calls Google Places.
Your choices
- Use it signed out. Everything works without an account.
- Sign out from the Account page. That clears the sign-in cookie; your profile stays until you ask us to delete it.
- Edit what you have saved: unsave restaurants, remove plans, delete notes and ratings from Saved, Notes, and the home page.
- Delete or export everything. There is no self-service delete button yet. Email shawn14@gmail.com from the Google address you signed in with and we will delete your profile record, or send you a copy of it, within 30 days.
- Cookies can be cleared or blocked in your browser at any time.
- Location is only used when you tap for it, and you can deny it in your browser.
Children
Gatsby Files is not directed at children under 13, or under 16 where that is the local age of digital consent, and we do not knowingly collect data from them. If you believe a child has signed in, email us and we will delete the record.
Security
Sign-in and editor cookies are signed with a server secret and cannot be forged or edited in the browser. Data travels over HTTPS. Secrets live in the hosting environment, not in code. No system is perfectly secure, and we cannot promise otherwise.
Changes
When this policy changes, the new version appears at this address with a new effective date. The current version is always at /privacy. Our Terms of Service cover the rest.