Privacy Policy
Last updated 12 September 2026
1. About this policy
Seasoned.info is a database and review platform for people who work a full season at a ski or snowboard resort — living and working there, not visiting as a tourist. We hold information on roughly 400 resorts, and we publish reviews written by seasonal workers about those resorts and about the employers who hire them.
This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what you can do about it. We are based in British Columbia, Canada, so the laws that apply to us first are the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (BC PIPA). Because we publish to, and collect information from, users in the UK and the EEA, this policy is also written to meet our obligations under Articles 13 and 14 of the UK GDPR and the EU GDPR.
If anything here is unclear, email support@seasoned.info and we will explain it in plain terms.
2. Who we are — the data controller
The controller of your personal data is:
- Operator: Daniel Stephenson
- Company status: Seasoned.info is currently operated by an individual sole proprietor based in British Columbia, Canada. It is not an incorporated company, so there is no company registration number.
- Address: 5307 Victoria Drive #1290, Vancouver, BC V5P 3V6, Canada
- Contact for data protection matters: support@seasoned.info
We have not appointed a Data Protection Officer. Our processing does not consist of large-scale monitoring or large-scale processing of special category data, so we do not consider one to be required. Data protection questions are handled directly by the operator at the address above.
"We", "us" and "our" in this policy mean Daniel Stephenson operating Seasoned.info.
3. The personal data we collect
3.1 Data you give us directly
| Category | What it includes |
|---|---|
| Account data | Your email address and a securely hashed password. We never see or store your password in readable form. |
| Profile data | Your screen name, your bio, and your avatar image — all optional except the screen name, and all chosen by you. |
| Review content | Reviews you write about resorts and employers, including what you say about pay, rent, hours, accommodation and working conditions. Reviews are published publicly under your screen name unless you mark the review anonymous, in which case we publish the content with no screen name, no avatar and no nationality attached to it. |
| Photos | Images you upload and attach to reviews, together with any caption or comment. Photos may contain images of identifiable people. |
| Comments | Comments you leave on photos. |
| Data corrections | Suggested corrections you submit to resort or employer records. |
| AI chat messages | Messages you type into our AI chat assistant. These are stored in our database and linked to your account. |
| Support correspondence | Anything you send to support@seasoned.info, including complaints and takedown notices. |
| Newsletter subscription | Your email address, if you choose to subscribe. |
3.2 Data we generate or collect automatically
| Category | What it includes |
|---|---|
| Rate-limiting identifiers | We derive a one-way hash from your IP address to limit abusive request volumes and prevent spam. We do not store raw IP addresses for this purpose beyond the moment of hashing. |
| Server and security logs | Our hosting provider records request metadata (including IP address, timestamp, user agent, and requested path) for security and reliability. |
| Authentication session data | A session token stored in a cookie so you stay logged in. See section 9. |
| Moderation records | Records of moderation decisions taken on your content, including AI moderation outputs, and records of any warnings, suspensions or bans. |
3.3 Data about other people
Reviews and photos you submit may contain personal data about other people — for example, an employer's staff, other seasonal workers, or people visible in a photo. Our Acceptable Use and Content Policy forbids naming individual colleagues or managers, and requires you to have a lawful basis for uploading images of identifiable people. If you supply personal data about someone else, you are responsible for doing so lawfully. Where we receive personal data about a person indirectly in this way, this policy is our Article 14 notice and we will provide it on request to any individual who contacts us.
3.4 Special category data
We do not ask for special category data (health, race, religion, sexual orientation, trade union membership, political opinions, biometric or genetic data). Please do not put it into a review. If it appears in user content, we rely on Article 9(2)(e) UK/EU GDPR where the individual has manifestly made the data public, and otherwise we will remove it.
4. Why we use your data, and our lawful basis
Under PIPEDA and BC PIPA we may only collect, use and disclose personal information for purposes a reasonable person would consider appropriate, and generally with your knowledge and consent. Under the UK and EU GDPR we must also have a lawful basis under Article 6. The table below sets out each purpose and the GDPR basis that applies; for users in Canada, the same list is our statement of the purposes for which we collect and use your information, and using the service with knowledge of this policy is the basis on which we rely.
4.1 Performance of a contract (Art. 6(1)(b))
Used where processing is necessary to give you the service you signed up for.
- Creating and maintaining your account.
- Authenticating you when you log in and keeping you logged in.
- Displaying your profile and publishing your reviews, photos and comments as you asked us to.
- Operating the AI chat assistant when you use it.
- Sending you transactional email — account confirmation, password resets, security notices, and notifications about your own content.
4.2 Legitimate interests (Art. 6(1)(f))
Used where we have a genuine business need that does not override your rights. We carry out and keep a written balancing assessment for each of the purposes below, and we review them when the service changes. You can ask us for a summary of any of them.
- Publishing reviews for the benefit of other seasonal workers. Our interest: running an information service of real public value to a workforce with very little reliable pay and conditions data. Your interest: control over how your words appear. We mitigate by letting you write under a screen name, publish anonymously, edit your reviews, and delete them.
- Moderating content — human review supported by AI — to keep the platform lawful, accurate and safe.
- Preventing fraud, spam and abuse, including rate limiting using hashed IP identifiers.
- Security and reliability of the site, including server logs.
- Handling complaints and notice-and-takedown requests, including contacting a reviewer about content that has been challenged.
- Understanding and improving the service — for example by looking at which resorts lack coverage. We do not use analytics or advertising cookies for this.
- Defending legal claims, including defamation claims arising from reviews.
You can object to any legitimate-interests processing — see section 10.
4.3 Consent (Art. 6(1)(a))
Used only where we ask you to opt in.
- Newsletter and marketing email. You subscribe deliberately, and every message contains an unsubscribe link. You can withdraw consent at any time and it is as easy to withdraw as it was to give.
- Optional profile content such as an avatar or bio, where you choose to make additional information public.
4.4 Legal obligation (Art. 6(1)(c))
- Responding to lawful requests from courts, regulators or law enforcement.
- Meeting our obligations as a hosting provider when we receive a valid notice about unlawful content.
4.5 Publishing pay, rent and conditions data
When you tell us what you were paid, what your rent was, and how many hours you worked, that becomes part of a published review — attributed to your screen name, or to nobody at all if you marked it anonymous. That is your personal data as well as commercial information about the employer. We publish it under legitimate interests, on the basis that it is your own first-hand experience, that you chose to publish it, and that the information is of clear value to other workers making decisions about their season. You can remove it at any time.
5. AI processing of your content
We use AI in three ways, and you should know about all of them.
- AI chat assistant. When you send a message to the assistant, your message (and relevant context) is transmitted to OpenRouter, which routes it to a model provider — currently Anthropic (Claude) and Perplexity. Your messages and the assistant's replies are stored in our database and linked to your account.
- Moderation of photo comments. Comments are screened by an AI model to flag abusive, discriminatory or otherwise policy-breaching content for human attention.
- Sanity-checking data corrections. When you submit a correction to a resort or employer record, an AI model assesses whether it looks plausible before a human reviews it.
No solely automated decisions with legal or similarly significant effects. AI flags content; a human makes the final call on removals, suspensions and bans. If you believe an automated step has affected you unfairly, email support@seasoned.info and a person will review it. You have the right under Article 22 not to be subject to a decision based solely on automated processing.
We do not permit our sub-processors to train their models on your content. We select AI providers on terms that exclude training on the inputs we send them, and we re-check those terms when we change provider.
Do not put anything into the AI assistant that you would not want stored.
Error reporting. The site contains an integration with Sentry, an error-tracking service, which is currently switched off — no error data leaves the site. If we turn it on, it would receive technical details of crashes, which can include your IP address and the page you were on. We will add it to the table in section 6 and update the date at the top of this policy before enabling it, not after.
6. Who we share your data with
We do not sell your personal data. We never have and we will not.
We use third-party services to operate the platform. Each is bound by a data processing agreement requiring them to process your data only on our instructions and to apply protections comparable to our own. These are the ones that actually receive personal data:
| Service | What it does | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage | Your account, profile, reviews, photos and session |
| Cloudflare | Hosting, content delivery, object storage | Every request you make to the site, including your IP address |
| Resend | Transactional email | Your email address and the contents of emails we send you |
| MapTiler | Map tiles | Your IP address, when you load a page containing a map |
| OpenRouter | Routes AI requests to model providers | Your chat messages and the context we send with them |
| Anthropic, Perplexity | The AI models themselves, via OpenRouter | As above |
We name them rather than describing them by category because you cannot meaningfully assess "a mapping service" — you can look up MapTiler. If we add or change a provider that receives personal data, this table changes with it.
Services that receive no personal data are not listed: exchange-rate and image sources are queried by us, not by you, and never see anything about you.
We may also disclose personal data:
- to professional advisers (lawyers, accountants) where necessary;
- to law enforcement, regulators or courts where legally required;
- to a person who has made a valid notice-and-takedown complaint, only where we are legally obliged to disclose or where a court orders it — we do not routinely hand over reviewer identities;
- to a buyer, if the platform is ever sold or transferred, subject to the same protections.
7. International transfers
We operate from Canada and our sub-processors are based in, or process data in, the United States and the European Union. Personal information handled outside Canada is subject to the laws of the country where it is held, and may be accessible to the courts and law enforcement of that country. Under BC PIPA and PIPEDA we remain accountable for your information when it is processed by a service provider on our behalf, and we require contractual protections comparable to our own.
When personal data leaves the UK or EEA we rely on:
- the UK International Data Transfer Addendum to the EU Standard Contractual Clauses for transfers from the UK;
- the EU Standard Contractual Clauses (2021/914) for transfers from the EEA;
- the UK–US Data Bridge / EU–US Data Privacy Framework where the recipient is certified;
- the European Commission's adequacy decision covering commercial organisations in Canada subject to PIPEDA, for transfers to us.
We document a transfer risk assessment for each sub-processor that receives personal data outside the UK or EEA, and we review it when we add or change a provider.
You can request a copy of the safeguards in place by emailing support@seasoned.info.
8. How long we keep things
We keep personal information only as long as we need it for the purposes set out in this policy, or as long as the law requires. These are the periods we work to.
| Data | Retention | Notes |
|---|---|---|
| Account and profile data | For as long as your account is open, then 30 days after you delete it | The 30-day window lets you recover an account deleted in error |
| Published reviews | Indefinitely while published; anonymised rather than deleted if you close your account, unless you ask us to remove them | See note below |
| Photos attached to reviews | Same as the review they belong to | |
| Photo comments | Same as the photo | |
| AI chat messages | Up to 12 months from the date of the message | Deleted sooner if you ask us to |
| Hashed IP rate-limiting identifiers | 30 days | |
| Server and security logs | Up to 90 days | Held by our hosting and database providers; shorter where their default retention is shorter |
| Moderation records and enforcement decisions | 3 years from the decision | Needed to apply repeat-offender rules consistently |
| Notice-and-takedown correspondence and evidence | 6 years | Kept so that we can deal with any later claim about the content or about how we handled the complaint |
| Newsletter subscription | Until you unsubscribe, then 12 months to honour the suppression list | |
| Support correspondence | 3 years |
What "anonymous" actually does. Marking a review anonymous removes your screen name, your avatar and your nationality from the published review, and severs the link back to your public profile. The words themselves are still published, and a small season community may still recognise a detailed account — anonymity is not a guarantee that nobody can guess who wrote it. We still hold the link internally so that you can edit or delete the review, and so we can respond to a legal complaint about it.
A note on reviews after account deletion. If you delete your account, we would prefer to keep your reviews and detach them from your identity — replacing your screen name with "Former member" and severing the link to your account. This preserves the value of the database for other workers. You can instead ask us to delete your reviews outright, and we will, unless we need to retain a copy because the review is the subject of a live legal complaint.
9. Cookies
We do not use analytics, advertising or tracking cookies. There is no consent banner because none is required.
The only cookies we set are strictly necessary authentication cookies placed by Supabase Auth. They store your login session so you do not have to sign in on every page. Without them you could not use an account at all.
Under PECR (UK) and the ePrivacy Directive (EU), cookies that are strictly necessary to provide a service the user has explicitly requested are exempt from the consent requirement. Our auth cookies fall squarely within that exemption.
| Cookie | Purpose | Lifetime |
|---|---|---|
Supabase auth session cookies (sb-*) | Keep you signed in; protect against session hijacking | The session and refresh token lifetimes configured in Supabase — typically hours for the session and up to a few weeks for the refresh token. Logging out clears them. |
Our hosting provider may also set a short-lived security cookie to tell legitimate visitors apart from automated traffic. That is also strictly necessary.
If we ever add analytics or any non-essential cookie, we will implement a proper consent mechanism first and update this policy.
10. Your rights
Wherever you live, we will give you the rights below. They are free to exercise, and we will respond within 30 days, extendable for complex requests (we will tell you if we need longer).
Under PIPEDA and BC PIPA you have the right to access the personal information we hold about you, to be told how it has been used and who it has been disclosed to, to ask us to correct it if it is wrong, and to withdraw consent (subject to legal or contractual limits). If you are in the EEA or the UK, the EU GDPR or UK GDPR also gives you the rights set out below, and you may complain to your local supervisory authority — see section 11.
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected. You can edit your own profile and reviews directly in your account.
- Erasure ("right to be forgotten") — have your data deleted. You can delete your account from your settings. Note that this right is not absolute: we may retain data where we need it to establish, exercise or defend legal claims, or where publication is protected by the freedom of expression exemption.
- Restriction — ask us to stop using your data while a dispute about it is resolved. In practice we will usually un-publish the content in question while we look into it.
- Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller. This applies to data processed on the basis of consent or contract.
- Objection — object to processing based on legitimate interests, including publication of a review. Tell us why, and we will stop unless we have compelling legitimate grounds that override your rights.
- Withdraw consent — at any time, for anything we do on the basis of consent (e.g. the newsletter). Withdrawal does not affect processing carried out before you withdrew.
- Rights around automated decision-making — see section 5.
How to exercise them. Use the tools in your account settings where they exist, or email support@seasoned.info with "Data request" in the subject line. We may ask you to verify your identity — usually by asking you to send the request from the email address on the account.
11. Complaining to a regulator
If you are unhappy with how we have handled your data, please tell us first — we would rather fix it.
You also have the right to complain to a regulator:
- Canada (federal, under PIPEDA): the Office of the Privacy Commissioner of Canada (OPC). https://www.priv.gc.ca/
- British Columbia (under BC PIPA): the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC). https://www.oipc.bc.ca/
- UK and EU/EEA: if you are in the UK or the EEA, you may complain to the data protection authority in your country of residence, place of work, or where the issue occurred.
12. Children
Seasoned.info is for people aged 16 and over. Season work is adult employment and our content is not designed for children. We do not knowingly collect data from anyone under 16. If we learn that an account belongs to someone under 16, we will delete it.
If you believe a child has an account, email support@seasoned.info.
13. How we protect your data
- Passwords are hashed by Supabase Auth; we never store them in readable form.
- All traffic is encrypted in transit with TLS.
- Data at rest is encrypted by Supabase and Cloudflare R2.
- Access to production data is limited to the operator and protected by multi-factor authentication.
- Row-level security policies restrict what any given account can read or write.
- Rate limiting and bot protection guard against automated abuse.
- We keep sub-processors under written data processing agreements.
No system is perfectly secure. We maintain a written incident response and breach notification procedure, and we review our security configuration periodically. If a breach of security safeguards occurs that creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and to the Office of the Information and Privacy Commissioner for British Columbia as required, notify affected individuals, and keep a record of the breach. Where the breach affects users in the UK or the EEA, we will also notify the relevant supervisory authority within 72 hours and tell you directly where the risk to you is high.
14. Changes to this policy
We will update this policy when the service changes. When we do:
- we will update the "last updated" date at the top;
- for material changes — a new purpose, a new lawful basis, a new category of sharing — we will email registered users and give at least 14 days' notice before the change takes effect;
- for minor clarifications we will simply publish the new version.
Previous versions are available on request.
15. Contact
Postal address:
5307 Victoria Drive #1290 Vancouver, BC V5P 3V6 Canada

