Privacy Notice
Waterlogged collects very little. This page says exactly what, why and where.
Version 2026-08-28-live-sender
Who is responsible
Waterlogged River Cruise Watch Ltd., PO Box 100, Kelowna, BC V1P 1S5, Canada, is responsible for the personal information described here. Privacy contact: privacy@rivercruisewatch.com.
Person accountable for personal information (Quebec Law 25 s.3.1): Privacy Officer, reachable at privacy@rivercruisewatch.com.
Information collected and why
- Watch request. If you submit an email address, Waterlogged stores the address, sailing identifier, request time, source and the consent sentence shown at submission. The only purpose is to send the daily email requested for that sailing. Registering on a served sailing's page means Waterlogged sends the Daily River Log Watch — the morning email for that one sailing — each morning until the morning after the sailing ends. Stopping is one reply (“stop”) or a deletion request, and the address is deleted no later than the retention period stated below either way. A request recorded for a sailing this site does not serve sends nothing until that sailing is served.
- A note left on the contact page. If you send a note from the form on Contact us, Waterlogged stores what you wrote, the time you wrote it, the consent sentence shown at submission, and your email address if you chose to give one — that field is optional and nothing else about you is collected. The only purpose is so a person can read it and answer if we are able to. Nothing here sends mail, so leaving a note does not put a reply in motion and the page says so. A note left without an address holds no personal information at all, and cannot afterwards be traced back to you in order to be deleted on request — there is nothing in it that is yours.
- A sailing request. If you send the form on Add your sailing, Waterlogged stores what you typed into it — the cruise line, the ship, the ports, the departure date and anything you added in the last box — together with the time you sent it, the consent sentence shown at submission, and your email address. That address is required on this form, and the reason is that a request nobody can come back to you about cannot be finished. It is kept in the same place, under the same rule and for the same period as a note left on the contact page. Nothing here sends mail, so sending the form does not put a reply in motion and the page says so.
-
Visit counts. Waterlogged counts how busy it is. Nine things are counted
for each day: how many times each page was opened, which sailing pages were looked at,
which cruise line a page was about, which
site a reader arrived from, which country readers were in, how often the share button was
used, the name of a visiting program where the visitor is one, two running totals used to
check that the counting itself is right, and roughly how many
different readers there were. Each count is split three ways: people,
automated visitors, and pages fetched before anybody had decided to open them.
- The site a reader arrived from is kept as the domain only — never the full web address, because a search result can hold what somebody typed and a domain cannot.
- The cruise line is worked out from the address of the page itself and matched against the list of cruise lines this site holds. It says which cruise line a page was about, and that is all it says. It is not a note about you: it does not say which cruise line you have booked, nothing about you is read or kept in order to work it out, and a page that is not about a cruise line — the front page, a river page, the questions page — is counted under no cruise line at all.
- Pages fetched before anybody opened them are counted on their own and are kept out of the reading figures. A search engine will sometimes fetch a page in advance, through its own network, in case the person looking at the results decides to click; that fetch is made by a machine, and it says so in the request. Waterlogged reads only that statement. It does not use your network address, and it does not treat a country as evidence of anything: somebody genuinely reading this site from Singapore is a reader, and is counted as one.
- Two totals exist to check that counting, and only that. One is how many requests said they were an advance fetch. The other is how many were counted as people while showing the pattern that first made this visible — a Google referral resolved to Singapore. They are two numbers a day, they are compared with each other on the operator's page so that a wrong count can be seen rather than believed, and neither of them decides anything about any request. Nothing about you is kept to produce either.
- The name of a visiting program is recorded for automated visitors only — search engine crawlers and the like — and never for a person. Programs of that kind identify themselves in the request, and what is kept is the short name a program calls itself by, with its version removed. Nothing of the kind is kept about a person's browser. The name is not asked for and not stored where the visitor is a reader: there is no column for it and nothing that could put one there. It is kept so that a burst of automated traffic can be told apart from readers, and named, rather than counted as an unexplained number.
- The country is a two-letter country code and nothing finer. It is worked out by the content network the site is served through, before the request reaches us, so Waterlogged never reads or keeps your network address in order to produce it. There is no region and no city.
- The number of different readers is an estimate, and it is made without keeping anything about you. Your network address is turned into a one-way code using a key that changes every day. The code marks a spot in a fixed block of ticks, and is then thrown away. At the end of the day only the estimate remains. Because the key changes at midnight, the same reader on two days cannot be matched up, and a code cannot be turned back into an address. A reader is not a person: everyone sharing one office or ship connection counts as one, and a phone that changes network counts as two.
- Some pages have a share button at the top and another at the foot. We count how often the share button was used and, when somebody uses it, which way they chose to share — the phone's own sharing panel, copying the link, Facebook or email — and which of the page's two share buttons they pressed. That is the whole of it. The count does not record who you are, where you sent the page, or whether anybody opened it afterwards. Only presses of our own button are counted, so a web address you copy out of the bar at the top of your browser is not counted at all.
- None of these counts holds a name, an email address, a network address, a cookie, a session, a browser user-agent line or a time finer than the day. They say how busy a page was. They do not say who read it.
- Request and security logs. The web server may record standard technical data such as the time, the requested path, the IP address, the browser's user-agent line and any error, to run the service and keep it secure. A submitted email address is not deliberately written to these logs.
- Limiting form abuse. The forms a stranger can submit are rate-limited by network address. That address is held in the server's memory for a short time to count the submissions, and it is not written to a file. It is read in memory for one other purpose — to make the one-way code described above — and in neither case is the address itself kept.
- No cookies. Waterlogged sets no cookies. There is no account, no sign-in and no session, so there is nothing for a cookie to remember.
This release uses no advertising tracker and no third-party analytics pixel. Counting how often the share button is used is done by Waterlogged's own server, and pressing a share button sends nothing about your visit to anybody else. Waterlogged does not sell personal information and does not use a watch request for marketing.
Consent and email rules
Submitting the unchecked watch form is an affirmative request for the identified operational message. It is not consent to a newsletter or promotion. Any future alert sender must identify Waterlogged, include a working stop method, record consent, and honour withdrawal. Promotional content requires a separate consent and is outside this pilot.
Retention and deletion
Watch requests are deleted automatically 180 days after the scheduled sailing, or sooner on a verified request. This is not a promise waiting on a scheduled job: the store applies the rule on every write, so an expired address is removed the next time the file is touched, on any host, whether or not a maintenance task was ever configured. Malformed or unrecognised records are quarantined for operator review rather than guessed at, and the repository includes a tested removal/purge function plus an operating runbook. A periodic purge is still scheduled on the production host so that a store nobody is writing to is cleared as well.
A note left on the contact page, or a sailing request sent from Add your sailing, is deleted automatically 180 days after it was sent, or sooner on a verified request where there is an address to verify. This rests on the same mechanism as the watch list rather than on a scheduled job: the store applies the rule on every write. A sailing request always has an address on it, so unlike an anonymous note there is always something to verify a deletion against.
Visit counts hold nothing to delete. They are totals per day, with no address, cookie or identifier in them, so there is no row in that file that belongs to any one reader.
Where this site runs, and how long technical logs are kept
Waterlogged runs on Amazon Web Services in the US West (Oregon) region, and that is where personal information sits: the application on Amazon ECS, the stored watch and sailing requests on an Amazon EFS file system attached to it, and the site itself served through Amazon CloudFront, which holds cached pages at edge locations worldwide but holds no personal information. Domain names resolve through Amazon Route 53. Nothing is processed in another company's data centre, and no analytics or advertising service receives anything from this site.
Server logs are kept for 90 days and then deleted automatically. They record the ordinary technical facts a web server records — the page requested, the time, the response and a truncated network address — and they are not joined to a watch request. Build logs, which contain no reader data at all, are currently kept indefinitely.
Backups are kept for 35 days. The stored requests are backed up daily and each backup is deleted 35 days later, so a deletion you ask for today can persist in a backup for up to 35 days before it ages out. Backups are held in the same Oregon region. There is no cross-border transfer of personal information beyond your own connection reaching Oregon.
Email that Waterlogged sends is sent through Amazon Simple Email Service in the same region.
Access, correction, deletion and complaints
You may ask whether Waterlogged holds a watch request for you. You may ask to see it, to have it corrected, or to have it deleted, and you may withdraw it at any time. We will check who you are before we show or remove any personal information. Waterlogged will record and answer privacy complaints, and if the law stops us completing a request we will say why.
How to ask, and what happens. Send the address you used to the privacy contact below, with the word "delete" in the subject.
- Watch requests are removed in full from every sailing, or from a single sailing if that is what you ask for. Nothing is kept about you afterwards.
We aim to confirm in writing within 30 days, which is the outer limit set by Quebec's Law 25 and by comparable rules elsewhere. A request that cannot be completed gets a written reason and a route to complain — to us first, and then to the privacy regulator where you live.
Send requests to privacy@rivercruisewatch.com.
Service providers, location and incidents
The watch store is a server file and is not sent to an analytics provider. To deliver the Daily River Log Watch, the address on a registration is used to send that email through Zoho's mail systems (Canadian data centre), which deliver the message as a service provider; nothing else about you is shared with them. Every further processor, storage location and cross-border transfer must be inventoried, contractually controlled and added here before it touches the data flow. Access is limited to operators who need it, and backups containing watch requests must follow the same deletion and security rules.
Suspected loss or unauthorised access must be contained, documented and assessed under the applicable breach-notification rules. This notice will be updated when the host, the mailer or another service provider changes the actual data flow.