Visit Saipan
Privacy
What this site knows about you, in the order you would find out.
Effective 19 August 2026
This is a draft prepared for review. It describes how visit-saipan.com handles personal data and is written to be checked against what the site actually does.
1. Who we are
visit-saipan.com is a trip planner for Saipan, in the Commonwealth of the Northern Mariana Islands. It is operated by Justin Tan, at JP Center, 2nd Floor, Garapan, Saipan 96950, Northern Mariana Islands — ATTN: Judy Mendieta.
For anything about your personal data, write to justin@visit-saipan.com. Our privacy officer is Justin Tan — justin@visit-saipan.com. We have not appointed a Korean domestic representative or a representative in the European Union, so write to us directly.
We sell nothing and take no bookings. There is no account to create, no password to remember, and nothing to pay for. That is why this policy is shorter than you might expect.
2. Your trip is in the link
This site has no accounts, so a trip has to live somewhere. It lives in the web address. Every answer you give — how many adults, how many children and how old they are, how many nights, how you want to spend, which hotel and which restaurants you picked, which month you are going — is spelled out in the address bar.
A link reading /plan/family_a2_k7-9_island_n4 means two adults, children aged seven and nine, an island trip, four nights. That design is why the plan survives being forwarded on KakaoTalk, opened on a different phone, or escaped from Instagram’s in-app browser into Safari. It is also a real disclosure, and you should know exactly how far it reaches.
- Anyone holding the link can read the whole party from it. There is no password on a trip.
- It is in your browser history, and in the history of everyone you send it to.
- It is in our hosting provider’s access logs, like every web address ever requested from any site.
- When you paste it into KakaoTalk, Instagram or a message, that service fetches the page to build a preview — so it sees the address too.
- If you allow advertising pixels, the address of the page you are on is part of what those pixels report. This is the strongest reason the pixels are off until you say otherwise.
We never ask for a child’s name or date of birth. There is no field for either, anywhere in this product. An age is the least we can ask and still refuse to put a fourteen-year-old on a scuba dive or send a toddler to a beach with a current.
If that is more than you want in a link, plan with adults only. The itinerary still works; the prices will not carry child fares, and some age warnings will not appear.
We do not publish trip links anywhere, and nothing on this site links to yours. A search engine can only reach one if somebody posts it in public.
3. What we collect
Nothing at all, until you do one of three things: save a trip, ask us to email it to you, or agree to advertising. Browsing the site, answering the four questions and reading a whole itinerary collect nothing.
- Your trip answers
- Party size, children’s ages, seniors, certified divers, trip length, budget, chosen hotel and restaurants, travel month or date. Held in the link; stored on our database only if you save or share.
- Your email address
- Only if you type one in, and only to send you the trip you asked for — or, separately and only if you tick the box, occasional offers.
- Whether you agreed to marketing, and when
- Stored as its own record, with a timestamp, so the answer to “did they agree” is evidence rather than someone’s memory.
- Your language and currency preference
- A cookie, so prices are in the unit you asked for on the first byte of the page rather than after a flash of the wrong one.
- A token that finds your saved trip again
- Kept in your browser’s local storage, not sent to advertisers. It identifies the trip, not you.
- Ordinary server logs
- Our hosting provider records the address requested, the time, the browser type and the IP address, as every web server does. We do not use them to build a profile.
We never ask for your name, your phone number, your passport, your flight booking or a payment card. Nothing in this product can take a payment.
4. Why we have it
- To build and price your trip
- Your answers are what the itinerary is made from. This happens in your browser and on our server as you use the site.
- To keep a trip and hand it back
- You asked us to save it or to email it. That is the whole purpose, and we treat it as the thing you asked for rather than as permission for anything else.
- To send you offers
- Only with a separate, explicit tick that is never pre-ticked, and only until you tell us to stop.
- To measure and advertise
- Only with your consent, and nothing loads before you give it. See the next section.
Where the law of your country asks us to name a basis for each of those: the first two are us doing the thing you asked us to do, and the last two happen only because you said yes and stop when you say no. We do not claim a “legitimate interest” in advertising to you; that is what the switches are for.
6. Email, and how to stop it
There are exactly two kinds of email from us, and they are not versions of each other.
- Your itinerary
- The trip you asked us to send you, with a link to it. It carries no advertising, because a message that carries advertising is an advertisement.
- Offers
- Only if you ticked the separate box. The subject line begins with (광고), the sender is named in the message, and every one carries a link that takes you off the list.
That link needs no password and no account. One tap and you are off, on every trip your address is attached to, not just the one the message was about. Nothing is asked of you beyond following it.
Every two years we send one message that sells nothing: it tells you the date you agreed, that you are still on the list, and how to come off. Korean law asks for that check and it is a fair one — a permission given two years ago and never mentioned since is not really a permission.
Saying no to offers costs you nothing at all. Every part of this site works identically, and we will never withhold a feature, a price or an itinerary because you left the box unticked.
You can also write to justin@visit-saipan.com and we will do it by hand.
8. How long we keep it
- A saved trip
- For as long as it is useful to you, and deleted on request. A trip nobody has opened for a long time is a candidate for deletion, not an asset.
- An email address with no marketing consent
- Kept while the trip it belongs to is kept, then deleted with it.
- An email address with marketing consent
- Kept until you unsubscribe, and the record of the unsubscribe is kept after that — because the only way to be sure we never mail you again is to remember that you said not to.
- Server logs
- For the period our hosting provider keeps them, which is short.
When a period ends, or when you ask, the record is deleted from the database rather than hidden, and it goes from our backups as those roll over. Nothing is printed, exported to a spreadsheet or kept on anybody’s laptop, so there is no second copy to go and find.
9. Your rights, and how to use them
Depending on where you live, you may have the right to see what we hold about you, to have it corrected, to have it deleted, to have us stop or limit what we do with it, to take it elsewhere in a portable form, and to withdraw a consent you gave without that costing you anything.
Write to justin@visit-saipan.com and say what you want done. We do not have a form, we will not ask you to create an account, and we will not charge you.
One honest limit: we identify a saved trip by the link and the address it was sent to, and nothing else. If you ask us to delete a trip, tell us the link or the address — otherwise we genuinely cannot find it, and we would rather say so than guess and delete somebody else’s holiday.
If you are in Korea and are not satisfied with our answer, you can complain to the Personal Information Protection Commission. If you are in the European Union or the United Kingdom, you can complain to your national supervisory authority.
10. Children
This site is built for the adult planning a family holiday, not for children. It has no account, no profile, no messaging and nothing to buy, and we do not knowingly collect personal data directly from a child.
The one thing we hold about a child is an age, given by the adult who is planning the trip, and used to decide what the itinerary may contain — a dive has a minimum age, a beach has a current, a resort has a kids’ club. It is in the link, as described above. If a child is old enough to be sending links themselves, they should know that.
If you believe a child has given us personal data, write to justin@visit-saipan.com and we will delete it.
11. Security
The database refuses every request that does not come from our own server, and your browser holds no key to it. Saved trips are reachable only through an unguessable identifier, and the one that lets you edit a trip is separate from the one that lets somebody read it.
That is a real design and not a guarantee. A link is only as private as the people it has been sent to, and no system is unbreakable. If something goes wrong we will say so.
12. Changes
When this policy changes, the date at the top changes with it. If a change means we would be doing something new with data we already hold — a new advertising partner, a new purpose — we will ask again rather than assume the old answer covers it.