Privacy Policy
Last updated: 11 September 2026
This is a deliberately small privacy policy, because hikes.guide deliberately collects almost nothing. There are no accounts and no advertising. We set one cookie of our own, and only if you answer the Instagram question; and if you subscribe to the Fell Report we ask for an email address, which MailerLite hold to send it. To understand how the site is used we run privacy-friendly, cookieless analytics (Plausible) that collect no personal data — no cookies, no persistent identifiers, and nothing that can identify you (see Analytics). The exceptions are optional and there are two: if you choose to load Instagram photos on some pages, or to load an embedded Strava activity on one page, those companies set their own cookies — and only then, and only if you ask for it by clicking. This page explains exactly what does and doesn't happen with your data.
What data we collect
Almost none. You don't need to create an account or give us any personal information to use the Website. We don't ask for your name or your location. The one thing we do ask for is an email address, if and only if you subscribe to the Fell Report; we don't sell or share personal data with anyone for marketing.
Cookies
hikes.guide sets one cookie of its own, hg_consent_instagram, and only when you answer the Instagram consent question. It records your answer (granted or denied) so you are not asked again, lasts 180 days, is mirrored in your browser’s local storage, identifies nothing and is sent to no one. There are no advertising networks and nothing that places a persistent identifier on your device for our purposes. Our analytics (Plausible) is deliberately cookieless and stores no personal data (see Analytics below). The only other cookies on the site come from Instagram, if you allow that content, as described below.
Because the only non-essential cookies are opt-in, you'll only see a cookie-consent prompt on pages that actually offer Instagram photos, and only until you've made a choice. You can change or withdraw that choice at any time using the "Cookie settings" link in the footer.
Analytics
We use Plausible Analytics (opens in new tab) to understand how the site is used — which pages people read, roughly where visitors arrive from, and whether the changes we make actually help. We chose it specifically because it is privacy-friendly by design:
- No cookies and no persistent identifiers — the analytics script stores nothing on, and reads nothing from, your device.
- No personal data retained. According to Plausible's data policy (opens in new tab), visitor counts are derived from a daily-rotating salted hash that is discarded within 24 hours; your IP address is never stored and cannot be recovered from it.
- No cross-site or cross-device tracking, no advertising, and no data sold or shared with anyone.
- Only aggregate statistics are produced — never a profile of you as an individual.
- Data is collected and processed within the EU.
Because Plausible sets no cookies and stores no personal data about you, it needs no consent banner under PECR or the UK GDPR; to the extent any minimal processing applies, our lawful basis is our legitimate interest in understanding and improving the site. The full detail is in Plausible's data policy (opens in new tab).
Embedded content from Instagram
Some pages — for example our Most Instagrammable Viewpoints guide — can display photographs hosted on Instagram, shown as an "Editor's favourite photo". These embeds are provided by Instagram, part of Meta Platforms, Inc.
We do not load any Instagram content until you allow it — either by choosing "Allow Instagram content" in our consent banner, or by clicking an individual "View on Instagram" card. Until then, nothing is requested from Instagram and no Instagram cookies are set.
When you do allow it, Instagram/Meta may set cookies on your device and receive your IP address, browser and device information, and the page you are viewing, in order to render the post and for Meta's own purposes. This processing is carried out by Meta as an independent controller under Meta's Privacy Policy (opens in new tab). Meta is based in the United States, so allowing this content may involve a transfer of your data outside the UK/EEA.
You can withdraw consent at any time via "Cookie settings" in the footer; this stops further Instagram content from loading (any embed already loaded on the page you're looking at may remain until you refresh).
| Category | Set when | Purpose | Controller | More |
|---|---|---|---|---|
| Embedded social media (Instagram/Meta) | You accept the banner, or click a card to load it | Display Instagram posts | Meta Platforms, Inc. | Meta's policy (opens in new tab) |
Apart from this opt-in embedded content, the rest of the site sets no cookies, as described above.
Embedded activity from Strava
One page — The perfect Wainwright round — offers an embedded map of a public Strava activity, so you can see the record holder’s actual line beside our computed one. Strava is operated by Strava, Inc.
Nothing loads from Strava unless you click it. The page shows a plain placeholder with a button; until you press it, your browser makes no request to Strava, sends them no IP address, and receives no cookies. There is no auto-loading and no pre-connecting, and ignoring the placeholder is not consent.
If you do click, your browser contacts strava-embeds.com to fetch the map. At that
point Strava can see your IP address and may set cookies, exactly as if you had visited their site
directly. That choice applies to that one embed, on that visit only — we store nothing about
it, so it is not remembered and not carried to any other page.
We never send Strava anything about you, and we receive nothing back about you. What Strava does with the request is governed by Strava’s own privacy policy (opens in new tab).
Local storage — your progress, on your device
Three things live in your browser’s localStorage, on your device, and none of them leaves it: your light-or-dark theme choice, your answer to the Instagram question (mirroring the cookie above), and your fell-bagging progress. If you use the "tick fells you've climbed" feature, your list of bagged fells is saved only in your own browser's localStorage, on your device. This data never leaves your device and is never sent to, or seen by, hikes.guide or any third party — there is no account and no server copy. It's purely functional storage that you actively request by ticking fells, so it doesn't require a consent banner under PECR. You can back it up with the Export button, and remove it at any time by clearing your browser's site data (note that doing so, or your browser evicting local storage, will erase your progress — Export first if you want to keep it).
The Fell Report newsletter
If you subscribe to the Fell Report, the form sends your email address and the page you signed up from to MailerLite (opens in new tab), the service that stores the list and sends the emails for us. You get one email asking you to confirm; nothing is sent until you click it. Nothing else is collected with the address, and it is used for the Report and for nothing else. Every email carries an unsubscribe link. Unsubscribing stops the emails at once; MailerLite keeps the address marked as unsubscribed so it cannot be added back by mistake, and if you would like it deleted outright, ask through the Contact page and we do it. We keep an address for as long as you are subscribed, and delete it when you ask. MailerLite process the address as our processor under their own policy, linked above.
Third-party services (maps & weather)
To show maps and forecasts, your browser makes requests directly to a small number of outside services:
- Map tiles — OpenStreetMap (opens in new tab) and OpenTopoMap (opens in new tab).
- Weather — Open-Meteo (opens in new tab).
Like any web request, these may record your IP address in those services' own server logs under their respective privacy policies. They do not set cookies through this Website. We don't send them any information about you beyond the ordinary technical details of the request.
Server logs
The Website is hosted by IONOS. Standard hosting server logs (such as IP addresses and request times) may be kept by the host for security and operational purposes, in accordance with UK data-protection law — the UK GDPR and the Data Protection Act 2018. We don't use these logs to build profiles of visitors.
Your rights under UK GDPR
Because we don't hold personal data about you (no account, and no contact details unless you email us or subscribe to the Fell Report), there's normally nothing for us to look up, change or delete. If you have emailed us, you still have the usual rights under UK GDPR — to access, correct or erase any personal data we hold, to object to or restrict its processing, and to complain to the Information Commissioner's Office (ICO) (opens in new tab). To exercise any of these, get in touch (below).
How to contact us about privacy
For any privacy question or request, please use our Contact page. The Website operator is the data controller for hikes.guide.
Changes to this policy
If this policy changes, the "Last updated" date above will be revised. Given how little data is involved, we don't expect substantial changes.