Privacy Policy
Effective date and last updated:
Horse Layover ("we," "us," or "our") provides a directory of horse-friendly overnight stops and route-planning tools at horselayover.com. This policy explains how we collect, use, disclose, and retain personal information when you use our website, create an account, submit a listing, or communicate with us.
You can browse listings and plan a route without an account. We do not sell personal information or share it for cross-context behavioral advertising. Questions and privacy requests can be sent to hello@horselayover.com.
Information we collect
The following categories describe information collected during the preceding 12 months and our current practices. We collect information directly from you, automatically from your browser or device, from our authentication provider, and from property operators, listing contributors, and publicly available business or property sources. Not every category is collected from every visitor.
- Identifiers and customer-record information
- Names, email addresses, phone numbers, postal addresses, account identifiers, and related profile and contact information. We receive these when you create or update an account, send a listing request, or contact us. We use them to authenticate you, manage accounts, respond, and maintain listings. Authentication, hosting, database, and email providers process the information needed for those tasks.
- Commercial and professional information
- Property or business names, your role as a property contact, listing inquiries, descriptions, amenities, pricing information, and communications about our services. We use this information to review, publish, correct, and support listings. Hosting, database, and email providers process it; approved listing details are public. Horse Layover does not process lodging bookings or collect payment-card details.
- Internet or other electronic network activity
- IP addresses, browser and device information, cookie or session identifiers, pages and links visited, referring pages, timestamps, searches and filters, listing interactions, performance measurements, and error or security events. Our infrastructure and analytics providers process these to deliver, secure, measure, and improve the site. A search URL may contain the location or words you entered.
- Geolocation information
- Places, addresses, and coordinates you enter or select for searches, listings, and route endpoints, and approximate location derived by providers from an IP address. Location input can identify a home or another precise place. Mapbox receives search text and route coordinates to provide maps, suggestions, and directions. Listing coordinates are stored by our hosting and database providers and can be public.
- Visual information
- Account profile images and listing photos you or a contributor provide. We use authentication providers for profile images and storage and hosting providers for listing images. Approved listing photos are publicly accessible. We do not use photos for facial recognition or biometric identification.
- Sensitive personal information
- Depending on the sign-in method, our authentication provider processes login credentials or access tokens. Precise location information, when it relates to you, may also be sensitive personal information under California law. We use this information only as needed to provide requested account, mapping, and listing services, maintain security, and for other purposes permitted by California law, not to infer sensitive characteristics about you.
These categories overlap. We do not ask for Social Security numbers, government ID documents, financial-account credentials, health records, biometric identifiers, or information about protected characteristics. Avoid including unnecessary sensitive information in messages, listing descriptions, or photos.
How we use and disclose information
During the preceding 12 months, we have disclosed the categories above to providers for the business purposes described with each category: operating and securing the service, managing accounts, answering communications, reviewing and publishing listings, providing maps and routes, and measuring traffic and performance. Providers and their functions are described below.
Public listings. Published listings may show a property's name, address, precise map location, contact name, phone number, email address, website, photos, pricing, and description. Visitors, search engines, and other parties can access or copy this information. Submit only information you are authorized to provide for publication. Email us to request a correction or removal; account deletion alone does not remove a listing. We cannot directly erase copies held independently by other websites.
Listing requests and email. Our listing-request form prepares a message in your own email application. We receive the message and any photos you attach only when you send it. Your email provider and ours process those communications. Do not assume a submitter's contact details will remain private if they are included as public listing contact information.
We may disclose information when reasonably necessary to comply with law or legal process, protect people and the service, investigate misuse, or establish or defend legal claims. If the service is involved in a merger, acquisition, or asset transfer, information may be disclosed to advisers and a successor subject to appropriate confidentiality protections and applicable law. We may also disclose information at your direction.
No sale or cross-context advertising. We do not sell personal information for money or other valuable consideration, or share it for cross-context behavioral advertising as those terms are defined by California law. We have not done so during the preceding 12 months. This applies to every category above and to all users, including users under 16. We do not offer a financial incentive in exchange for personal information.
Service providers and Google sign-in
Clerk: authentication and account management
We use Clerk as our authentication and account-management processor. Clerk processes account information, sign-in credentials or tokens, authentication sessions, and related device and security information to provide these services on our behalf. We keep a synchronized profile containing your account ID, name, email address, display name, profile image URL, and account timestamps.
See Clerk's Privacy Policy and Data Processing Addendum. Clerk's processing of customer data is governed by its agreements with us; its privacy policy also explains its own separate practices. Contact Horse Layover about your account data and privacy rights rather than assuming that a request to Clerk deletes all information we hold.
Google sign-in, when available
If we offer Google sign-in and you choose it, Google provides Clerk and us with the account identifier and basic profile information authorized in that flow, such as your name, email address, and profile picture. We use this information to create or connect your account and authenticate you. Google sign-in is optional and this description does not mean it is already available or was used during the preceding 12 months.
We do not receive your Google password. We do not request access to Gmail messages, Google Drive files, contacts, or calendars for sign-in. Google processes your interaction under Google's Privacy Policy. You can manage the connection in your Google Account connections. Disconnecting Google does not by itself delete your Horse Layover account, and deleting your Horse Layover account does not delete your Google account.
Maps, infrastructure, and analytics
- Mapbox receives location searches, selected coordinates, and technical request information to supply maps, geocoding, and directions. See Mapbox's privacy information.
- Vercel hosts the website and provides usage analytics and performance monitoring. See Vercel's Privacy Notice.
- Microsoft Azure stores and delivers listing photographs. Database and hosting providers store listings and synchronized account profiles. See Microsoft's Privacy Statement.
- Google Analytics, when configured, measures visits and interactions with the public site. See how Google uses information from sites that use its services.
- Email service providers deliver and store listing requests, attachments, support messages, and privacy-request correspondence.
We use providers for the specific functions described here, not to sell your information or run cross-site advertising. Providers may also process technical or service-use information under their own notices. Their linked notices do not replace our responsibility for the personal information we collect and disclose.
Cookies, analytics, and browser signals
Authentication uses cookies or similar technologies to recognize sessions and keep accounts secure. Google Analytics may use cookies and identifiers to measure visits. Analytics can include page visits, referral information, listing views, searches, selected filters, contact-link clicks, and performance information. We do not intentionally send contact-form message contents, sign-in credentials, or entered route addresses to Google Analytics; our custom page-view reporting removes query strings. This does not prevent request URLs or technical metadata from reaching hosting, mapping, or authentication providers.
Browser local storage remembers appearance and optional feature preferences. Public place-map data is cached for up to seven days before it is treated as expired; expired entries are removed when the cache is next read. Preferences remain until changed or cleared. We do not store Mapbox route geometry or location suggestions in this cache.
You can clear site data or block cookies in your browser, although doing so may affect sign-in and preferences. Google offers a Google Analytics opt-out browser add-on for supported browsers. That add-on does not stop all site logging, mapping requests, or other providers' processing. We do not currently offer an in-app analytics consent or opt-out control.
Do Not Track and Global Privacy Control. Our site does not currently change its behavior automatically in response to a browser Do Not Track signal or a Global Privacy Control signal. Our no-sale and no-cross-context-sharing policy applies whether or not you send a signal; there is no sale or sharing to opt out of under that policy. These signals do not currently disable analytics, essential services, or authentication. Third-party services may collect information about your activity over time and across websites according to their own settings and notices; browser controls and this disclosure are not a substitute for any opt-out mechanism required by law.
Retention and account deletion
We retain personal information for the time reasonably necessary for the purposes described in this policy, taking into account the information's sensitivity, the service you request, security needs, unresolved disputes, and legal obligations. We use the following criteria rather than promising a single deletion period for all systems:
- Account identifiers and profile information: for the life of the account and as needed to complete an account-deletion request, resolve account issues, and meet applicable legal or security requirements.
- Listing, business-contact, location, and photo information: while needed to review or maintain an accurate directory listing, handle corrections or removal requests, and resolve related issues. An active listing may remain published after its contributor deletes an account.
- Messages and attachments: while needed to respond to the inquiry, administer a listing or request, document the correspondence, and address legal or operational needs.
- Network activity, analytics, and security information: for the configured provider retention periods and as needed to measure service performance, investigate incidents, and prevent abuse. These periods depend on the service and the purpose; account deletion does not automatically clear provider logs or analytics.
- Authentication secrets and tokens: for session, account-recovery, and security purposes under the authentication provider's applicable lifecycle and retention practices.
- Route inputs and browser storage: route calculations run in your browser, and we do not save Mapbox Directions responses to our application database. Route and search URLs can remain in browser history, copied links, or provider request logs. Public-place cache data expires after seven days; preferences remain until changed or cleared.
- Privacy-request records: where the CCPA applies, we retain a record of the request and our response for at least 24 months to demonstrate compliance, not for unrelated marketing.
Copies may remain in backups or caches until overwritten, deleted, or expired under their applicable lifecycle. A cached copy is not a promise of a specific source-data retention period. We will handle deletion requests and any permitted exceptions under applicable law, including restrictions on information retained solely for compliance or recovery.
Deleting an account is not the same as deleting every record
You can delete your account through Account / Manage account / Security / Delete account. See our account-deletion instructions. Deleting the Clerk-managed account triggers removal of our synchronized account profile. It does not automatically delete published listings, listing contact information, photographs, emails, administrative records, analytics, or backups.
To request deletion of other personal information, email hello@horselayover.com. Please identify the account, listing, or correspondence involved. We will assess the request, arrange deletion where required, and explain any applicable exception. Clearing browser storage or disconnecting Google is not a substitute for this request.
Your California privacy rights
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), gives California residents the rights below when the law applies to a business and the information involved. Some information and requests are subject to legal exceptions. You may contact us about your information regardless of whether these laws apply to your particular request.
- Know and access: request the categories and specific pieces of personal information we hold about you, the categories of sources, the purposes for collection and disclosure, and the categories of recipients. Where required, we provide a portable, readily usable copy.
- Delete: request deletion of personal information, subject to exceptions such as meeting legal obligations, protecting security, and exercising or defending legal claims.
- Correct: request correction of inaccurate personal information, taking into account its nature and why it is used. Account settings also let you update supported profile fields; email us about listing corrections.
- Opt out of sale or sharing: direct a business to stop selling your information or sharing it for cross-context behavioral advertising. Horse Layover does neither, as explained above.
- Limit sensitive-information use: limit uses and disclosures beyond those permitted by the CCPA. We use sensitive information only for the permitted purposes described in this policy and not to infer characteristics about you, so we do not offer a separate limitation control for such additional uses.
- No discrimination or retaliation: we will not discriminate or retaliate against you for exercising an applicable privacy right. Deleting information necessary for an account or feature may prevent us from providing that account or feature; this is not a penalty for exercising your rights.
We do not use automated decisionmaking to make credit, employment, housing, insurance, or similarly significant decisions about you. Our route and listing tools help you find information, not determine your eligibility for those services.
How to make a privacy request
Email hello@horselayover.com and describe what you would like to access, correct, or delete. "Privacy request" is a helpful subject line, but is not required. Include the email address associated with your account or correspondence and any relevant listing URL so we can locate the information. You may request all information we are required to provide, including information older than 12 months where applicable. You do not need to create an account.
Verification and authorized agents
To protect your information, we may verify control of the relevant email address or account and match details already in our records before granting access, correction, or deletion. If needed, we will request only additional information reasonably necessary to verify and process the request. We use verification information for that purpose and applicable security or compliance requirements, not for marketing. Never send your password. If we cannot verify a request or must deny part of it, we will explain why.
You may designate an authorized agent to contact us at the same email address. We may request signed permission, verify your identity directly, and ask you to confirm the agent's authority, as permitted by law. We will recognize a valid power of attorney and applicable exceptions to these verification steps.
Response timing and cost
For CCPA requests to know, delete, or correct, we will acknowledge receipt within 10 business days and respond within 45 calendar days of receipt. If a permitted extension is reasonably necessary, we will explain it within the initial period; the total will not exceed 90 calendar days. These deadlines run from receipt, not from completion of verification. Requests are ordinarily free. If the law permits a fee or refusal for a manifestly unfounded or excessive request, we will explain the basis before charging.
If a sale/sharing opt-out or sensitive-information limitation obligation becomes applicable, the applicable deadline is as soon as feasibly possible and no later than 15 business days, not the 45-day access-request period. We will provide any legally required controls before beginning such practices.
California residents may also contact us about disclosures for third parties' own direct marketing under California's "Shine the Light" law. We do not disclose personal information for that purpose. If you have a concern about our response, reply to us or submit a complaint to the California Privacy Protection Agency.
Children, security, and other websites
Our service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided personal information, contact us so we can investigate and take appropriate deletion steps. Our no-sale and no-sharing policy also applies to information about people under 16.
We use reasonable administrative and technical safeguards, including access controls for account and administrative functions. No website, transmission, or storage system can be guaranteed completely secure. Please do not send passwords, government identification numbers, or financial-account credentials by email.
Our service is focused on the United States. Providers may process information in the United States and other countries where they operate. Property websites, mapping services you open, and other external links have their own privacy practices. Contacting or booking with a property is a separate interaction with that operator.
Changes and contact information
We will update this policy when our practices change and review it at least annually. We will revise the date above and notify you of material changes through a prominent website notice or, when appropriate, an email to your account address before the changes take effect. If a new use requires consent or another notice under applicable law, we will obtain that consent or provide that notice.
For privacy questions, requests, listing corrections, or an accessible alternative format of this policy, contact Horse Layover at hello@horselayover.com.