LEGAL
Privacy Policy
Effective April 1, 2026 · Lakeside Landing FLX (operated by SilverSprinter LLC)
What we collect
We collect email addresses when you voluntarily sign up for our Finger Lakes Insider Guide or other communications. When you inquire about a booking or submit a direct-booking application, we collect the specific information you provide — name, email, phone, home address (for background verification), date of birth (optional, for background verification), group makeup, purpose of visit, and dates. Standard web analytics (page views, referral source, general location) are collected automatically through Vercel Analytics.
How we use it
Your email is used to send you the guide you requested, and occasionally to share property updates, seasonal availability, and direct booking offers. We send roughly four emails a year — not a newsletter mill. Inquiry and application information is used solely to evaluate and respond to your booking, coordinate your stay, and communicate reservation-related updates.
SMS text messages (TCPA)
By providing your phone number on a booking application or inquiry form, you consent to receive booking-related SMS messages from Lakeside Landing FLX — application status updates, arrival details, urgent stay communications, and post-stay follow-up. Message and data rates may apply. You can opt out at any time by replying STOP to any message; you'll receive one confirmation reply and then no further messages. Reply HELP for help. We do not send marketing or promotional SMS. Message frequency varies with your booking activity.
Sensitive data + encryption
Guest personal information — including legal names, email addresses, phone numbers, home addresses, and dates of birth — is encrypted at rest using AES-256-GCM before being written to our database. This is the same industry-standard encryption used by financial institutions. Only authorized operators can decrypt this information, and every access is logged. Payment card data is never stored on our servers — it's handled directly by Stripe.
Background verification (FOREWARN)
Direct-booking applications include a consent step for a FOREWARN identity + criminal history check on the primary guest. This is the same tool licensed real-estate agents use for open-house showings. Results are used solely to make our approval decision and are not shared with anyone outside our operation. The check is optional in the sense that you can choose not to submit a direct-booking application — but it is required for those who do.
What we don't do
We don't sell your data. We don't share it with third parties for advertising purposes. We don't run Facebook Pixel, retargeting tracking, or other third-party analytics. When you complete a booking, your payment information is handled by Stripe and your reservation by OwnerRez — both of which have their own privacy policies. We never see your full card number.
Cookies
We use standard Vercel Analytics cookies to understand how guests find and use the site (page views, referral source, general geographic region — no personally identifying analytics). There are no advertising trackers, no Facebook Pixel, no retargeting cookies. Session cookies are used for the admin login flow and expire when the browser closes.
Data retention
Email addresses on the Insider List are retained until you unsubscribe. Booking-related information (applications, reservations, guest records) is retained for seven years to comply with New York tax and business-records requirements. Encrypted PII fields (names, emails, phones, addresses, DOB) are retained for the same period but are only decrypted on legitimate operator access. Web analytics data is retained per Vercel's default retention window (currently 12 months for detailed events, longer for aggregated data). On request, we can delete guest records prior to the seven-year threshold, subject to any legal-hold or tax-audit exceptions.
California residents (CCPA)
California residents have specific rights under the California Consumer Privacy Act: the right to know what personal information we've collected about you, the right to request deletion, the right to correct inaccurate information, and the right to opt out of the sale or sharing of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising, so the opt-out right is effectively pre-satisfied. To exercise any of these rights, email stay@lakesidelandingflx.com with the subject "CCPA Request" and we'll respond within 45 days.
Unsubscribe
Every email we send includes an unsubscribe link at the bottom. Click it and you're off the list immediately. You can also email us directly at stay@lakesidelandingflx.com and we'll remove you manually. For SMS, reply STOP to any text message. These opt-outs are honored across all future communications and do not affect transactional messages tied to an active booking (arrival details, urgent stay information).
Changes to this policy
We update this policy from time to time as our practices evolve. Material changes are noted at the top of the page with a new effective date. Continued use of the site after a policy update constitutes acceptance of the new terms.
Contact
Questions about your data or this policy? Email stay@lakesidelandingflx.com. We're a small operation and we respond to everything.