Legal

    Privacy Policy

    Effective date: August 24, 2026 · Last updated: August 24, 2026

    Independent product notice: SupaPark is not affiliated with, endorsed by, or sponsored by The Walt Disney Company or Walt Disney World Resort.

    1. Who We Are

    This Privacy Policy explains how SupaPark LLC ("SupaPark," "we," "us," or "our") collects, uses, shares, and protects personal information when you use the SupaPark website, iOS app, and related services (the "Service"). SupaPark is a park-planning tool for Walt Disney World guests.

    SupaPark LLC is a subsidiary of Sean Ventures LLC, its parent company. SupaPark LLC operates the Service and is the controller of the personal information described in this policy. Sean Ventures LLC is the merchant of record for purchases and is the controller of the payment and billing records that arise from them — which is why a SupaPark charge appears on your card or bank statement as "SEAN VENTURES LLC" rather than as SupaPark. Both are United States companies, both are covered by this policy, and a privacy request sent to either one reaches both.

    SupaPark is an independent product and is not affiliated with, endorsed by, or sponsored by The Walt Disney Company or Walt Disney World Resort. We never receive personal data from Disney, and we never send your personal data to Disney.

    2. Information We Collect

    We collect the following categories of information:

    • Account information: your email address, display name, and authentication identifiers, managed through our backend provider, Supabase. If you use Sign in with Apple, we receive the identifier Apple provides and, if you choose Hide My Email, only Apple's private relay address — we never receive your real address in that case.
    • Party and family profiles: names or nicknames and height you choose to enter for the people in your party, used to work out which rides each person can ride. If you enter a child's details, please read Section 11 (Children's Privacy).
    • Location: see Section 3 for a full explanation of what we collect, when, and what we keep.
    • Device and notification data: when you enable push notifications we store a push token, the device platform, a device identifier, and the app version, so we can deliver alerts you asked for and stop sending to devices that no longer exist.
    • Planning data: saved plans, trips, alerts, watch targets, preferences, and the outcomes of recommendations we showed you.
    • Payment information: when you buy a Silver or Gold plan on our website, payment is processed by Stripe on behalf of Sean Ventures LLC as merchant of record, and appears on your statement as "SEAN VENTURES LLC". We receive your plan, entitlement status, billing period, and a payment reference. We never see or store your full card number. Stripe collects your billing address to calculate sales tax. If you subscribe inside the iOS app instead, the purchase is made through your Apple ID and Apple is the merchant: we never receive your payment details at all, only the fact that a subscription is active, its plan, and its renewal date.
    • Usage analytics: product events such as pages viewed, features used, and approximate device/browser information. Our analytics are self-hosted on our own infrastructure.
    • Support and feedback: messages you send to support, and — if you use the in-app feedback widget — the message, the page you were on, your app version and user agent, and a screenshot of your own screen that the widget captures when you submit it.

    3. Location Data

    Location is the most sensitive thing we handle, so we describe it precisely.

    WHAT WE COLLECT. With your permission, we collect your device's precise location while you use the Service. If you additionally grant "Always" permission on iOS, we may also collect location while the app is in the background so that proximity features keep working when your phone is in your pocket — which is the only way a "you are standing next to this ride" tip can reach you at the moment it is useful.

    WHY. Location is used to detect which park you are in, to order rides and restaurants by how close they are to you, to power the park map, and to send proximity tips and alerts about things near you.

    WHAT WE KEEP. We store only your most recent position — latitude, longitude, accuracy, and the park it maps to — and each new reading overwrites the previous one. We do not build or retain a location history, we do not track where you go over time, and we do not store location once you delete your account.

    YOUR CONTROL. You can refuse location permission entirely and still use the Service; proximity features simply will not run. You can change or revoke permission at any time in iOS Settings > Privacy & Security > Location Services > SupaPark, or in your browser's site settings on the web. Revoking it stops collection immediately.

    WE DO NOT SELL LOCATION. We do not sell your location data, share it with data brokers or advertisers, or use it for advertising.

    4. Push Notifications and Alerts

    If you enable alerts, we send push notifications through Apple Push Notification service (APNs) on iOS, web push in browsers, email, and — on plans that include it — SMS through Twilio. Notifications are sent only for the watches and alerts you set up.

    You can turn notifications off at any time in the app's alert settings, in iOS Settings > Notifications, or by using the unsubscribe link in any alert email. Turning them off does not delete your account or your saved plans.

    5. Merlin and AI Features

    Merlin, our in-app assistant, generates its answers using a third-party large language model accessed through a gateway we operate.

    When you use Merlin, or when Merlin greets you or suggests something, we send it a limited context: your first name, the park you are in, current crowd and weather conditions, the shortest waits at that moment, and a summary of your saved watches and trips. If you type a question, your question is sent too. We do not send your email address, payment details, or precise coordinates to the model.

    Our AI processor receives this solely to generate your response, and we do not use your Merlin conversations to build advertising profiles or to train our own models. Do not type information into Merlin that you would not want processed by a third party.

    6. How We Use Information

    We use personal information to:

    • Provide and operate the Service, including accounts, plans, alerts, and the notifications you request;
    • Determine which rides members of your party can ride, using the heights you enter;
    • Process subscription payments and manage billing through Stripe;
    • Personalize recommendations, rankings, and proximity tips based on your stated preferences and location;
    • Generate assistant responses as described in Section 5;
    • Monitor, debug, and improve reliability, accuracy, and product quality;
    • Communicate with you about your account, service changes, and — with your consent where required — product updates;
    • Detect, investigate, and prevent abuse, fraud, and security incidents, and comply with legal obligations.

    7. Tracking and Advertising

    We do not track you across other companies' apps or websites, we do not embed third-party advertising or ad-tech SDKs, and we do not sell or share your personal information for cross-context behavioral advertising. Because we do not track you across apps and websites, we do not ask for App Tracking Transparency permission.

    Our product analytics run on infrastructure we host ourselves. Session replay, where enabled, masks form inputs and rendered page text, and analytics are disabled on administrator routes.

    8. Legal Bases

    Where the GDPR or UK GDPR applies, we rely on: performance of a contract (operating your account and delivering features you request); consent (location, push notifications, marketing email, and analytics where consent is required — withdrawable at any time); legitimate interests (security, debugging, and improving the Service); and legal obligation (tax, accounting, and responding to lawful requests).

    9. How We Share Information

    We do not sell your personal information. We share it only with processors who provide the Service on our behalf, each limited to what their function requires:

    • Stripe — payment processing, billing, and tax calculation, for Sean Ventures LLC as merchant of record;
    • Apple — Sign in with Apple, App Store purchases, and delivery of push notifications via APNs;
    • Twilio — SMS alerts, where you enable them;
    • Our AI provider — assistant responses, as described in Section 5;
    • Our email and support systems — transactional email and support conversations;
    • Supabase — the database and authentication layer, running on infrastructure we control.
    • We may also disclose information if required by law, to enforce our Terms, or to protect the rights, safety, and security of our users or the public.

    10. Data Retention and Deletion

    We keep account and planning data for as long as your account is active. Location is kept only as the single most recent position and is overwritten by each new reading. Operational time-series data is pruned on a rolling schedule. Records we must keep for tax and accounting — such as payment records — are retained for the period the law requires, even after account deletion.

    YOU CAN DELETE YOUR ACCOUNT FROM INSIDE THE APP. On iOS, go to Settings > Account > Delete Account; on the web, go to your Account page. Deletion removes your account, profile, party profiles, saved plans, alerts, stored location, and entitlements. It cannot be undone. You can also email [email protected] and we will process the request.

    Deleting the app from your device does not delete your account — use the in-app deletion above, or write to us.

    11. Children's Privacy

    The Service is intended for adults planning a trip. It is not directed to children under 13, and we do not knowingly create accounts for them.

    SupaPark does let a parent or guardian add the people in their party — including children — as profiles containing a name or nickname and a height, so we can tell you which rides each person meets the requirements for. Only an adult account holder can add these, they are visible only to that account, they are never used for advertising or profiling, and they are deleted when the profile or account is deleted. Please use a first name or nickname rather than a full legal name.

    If you believe a child has provided us personal information directly, contact [email protected] and we will delete it.

    12. Security

    We protect data in transit with TLS and restrict access to production systems to authorized personnel. Database access is governed by row-level security so that one account cannot read another's data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

    13. Your Rights and Choices

    Depending on where you live, you may have the right to access, correct, delete, or export your personal information; to object to or restrict certain processing; to withdraw consent; and not to be discriminated against for exercising these rights. Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have these rights, as do residents of the EEA and UK.

    You can exercise most of these directly in the app — edit your profile, change alert settings, revoke location permission, or delete your account. For anything else, email [email protected]. We will respond within the time the applicable law requires. If you are in the EEA or UK you also have the right to complain to your local supervisory authority.

    14. Cookies

    We use cookies and similar local storage to keep you signed in, remember your preferences, and measure product usage. We do not use advertising cookies. See our Cookie Policy for detail and controls.

    15. International Transfers

    We operate from the United States, and our processors may handle data in the United States and elsewhere. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

    16. Changes to This Policy

    We may update this policy as the Service changes. We will revise the effective date above and, for material changes, give notice in the app or by email before the change takes effect.

    17. Contact Us

    For privacy questions or to exercise your rights, contact [email protected]. For general support, contact [email protected]. For billing questions, including a charge you do not recognize on your statement, contact [email protected] — charges appear as "SEAN VENTURES LLC".

    Data controllers: SupaPark LLC (the Service) and its parent company Sean Ventures LLC (payment and billing records), both United States companies. A request sent to either address reaches both.

    Merlin

    Beta

    How can I help with your Disney day?

    Ask me anything about rides, restaurants, planning, or just say "What should I do?"