Your privacy at stormstoke
Last updated October 2, 2026
This policy explains what information stormstoke collects, why, who helps us run the service, how long we keep it, and the choices and rights you have. It applies wherever you use stormstoke.
1. Who we are
stormstoke (stormstoke.com, demo.stormstoke.com and any stormstoke app) is a snow forecast and storm alert service for ski areas in the United States and Canada. It is operated by Matt Dyck, Calgary, Alberta, Canada (“stormstoke”, “we”, “us”).
We are responsible for your personal information under this policy. For the purposes of the EU and UK General Data Protection Regulation (GDPR), we are the “controller”. You can reach us about anything in this policy at snow@stormstoke.com.
This policy covers the website, the demo and our emails. It does not cover resort websites or other sites we link to; they have their own policies.
2. What we collect
You can browse forecasts, the map, the directory and comparisons without an account. We only collect information that identifies you if you create an account, send feedback or contact us.
| Information | What it includes | Where it comes from |
|---|---|---|
| Account | Your email address. If you sign in with Google, also your name and Google account ID. When your account was created and when you last signed in. | You, or Google if you choose Google sign-in |
| Sign-in codes | If you sign in by email, a one-time six-digit code. We store only a scrambled (hashed) version, and it expires after 10 minutes. | Generated by us |
| Your settings | Favourite and followed resorts, alert thresholds, units, time zone, quiet hours, delivery times, email limits, alert channels and which alerts you have seen. | You |
| Alert history | Which storm alerts we sent you, for which resort, when, and whether the email was delivered. | Generated by us |
| Sign-in history (signed-in users only) | When you signed in, how (Google or email code), and an approximate location (country, region and city) plus your device type, browser and operating system. Cloudflare works out the approximate location from your IP address and passes it to us. We do not store your IP address or your full browser identifier. | Your browser and Cloudflare |
| Activity (signed-in users only) | Visits (at most one counted every 30 minutes), resorts you open, follows and unfollows, settings changes, unsubscribes, sign-outs and account deletion. | Your use of stormstoke |
| Storm alert email engagement | Whether a storm alert email was opened and whether its link was clicked (see section 6). | Your email app |
| Feedback | Your message. If you are signed in, it is sent to our inbox with your name, email and account ID so we can reply. To limit spam we keep a one-way, keyed code made from your IP address, never the address itself. | You |
| Error reports | When the site hits an error in your browser: the page, the error message and your browser’s identifier (user agent). Not linked to your account. | Your browser |
| Technical data | Like any website, our hosting provider processes your IP address and request details to deliver pages and protect the service from abuse. We also use Cloudflare Web Analytics, which counts page views without cookies and without identifying you. | Your browser and Cloudflare |
Your location. If you tap “Show my location”, your browser asks for permission and your position is used on your device to place you on the map. It is never sent to us. We remember only that you turned the feature on.
We do not collect payment information, contacts, photos or any sensitive categories of information, and we do not buy information about you from anyone.
3. How we use it, and our legal bases
We use your information only to run and improve stormstoke. The GDPR asks us to name a legal basis for each use:
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating your account, signing you in, saving your favourites and settings across devices | Performing our agreement with you (the Terms of Use) |
| Sending the storm alerts and sign-in codes you ask for, and service messages such as changes to these policies | Performing our agreement with you |
| Keeping the service secure, preventing abuse and spam, rate limiting, and fixing errors | Our legitimate interest in a safe, working service |
| Understanding how stormstoke is used (sign-in history, activity, alert email opens and clicks) so we can improve forecasts, alerts and the site | Our legitimate interest in improving the service. You can object at any time (section 10). |
| Showing your position on the map | Your consent, given through your browser’s location prompt. You can withdraw it in your browser settings. |
| Keeping a list of addresses that bounced or reported our email as spam, so we stop sending to them | Our legitimate interest, and email laws such as Canada’s Anti-Spam Legislation |
| Answering legal requests and meeting legal duties | Legal obligation |
Storm alerts are generated automatically from forecasts and the thresholds you set. This does not produce legal or similarly significant effects for you. We do not use your information for advertising, we do not build advertising profiles, and we do not sell or rent personal information to anyone.
4. Information from Google sign-in
If you choose “Continue with Google”, Google shares your name, email address, whether the email is verified, and a Google account ID with us. We ask only for these basic profile details (the openid, email and profile permissions). We cannot see your password, Gmail, contacts, files or anything else in your Google account.
We use this information only to create your stormstoke account and sign you in. We do not sell it, use it for advertising, or transfer it to others except the service providers in section 7 that help us run stormstoke, or where the law requires. We do not use information from Google to develop, improve or train generalised AI or machine-learning models.
stormstoke’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can remove stormstoke’s access at any time from your Google Account at myaccount.google.com/connections. That stops future Google sign-ins; to remove the information we already hold, delete your stormstoke account.
5. Cookies and storage on your device
We use only what is strictly needed for the service to work. There are no advertising or cross-site tracking cookies, so we do not show a cookie banner.
| Name | Type | Purpose | Lasts |
|---|---|---|---|
ss_session | Cookie | Keeps you signed in. Holds a random token; we store only a hashed copy. | 90 days, or until you sign out |
ss_oauth | Cookie | Protects the Google sign-in step against forgery | Minutes, during sign-in |
| Saved settings | Browser storage | Your favourites, settings and seen alerts, so the site works before you sign in | Until you clear your browser data |
stormstoke-theme and location choice | Browser storage | Remembers light or dark mode and whether to show your location | Until you clear your browser data |
Cloudflare may set strictly necessary security cookies to tell people from bots. Cloudflare Web Analytics does not use cookies.
6. Emails, alerts and email tracking
We send sign-in codes when you ask for them, storm alerts for resorts you follow (if email alerts are on), and occasional service messages about your account or these policies. We do not send marketing email.
Storm alert emails contain a tiny image that tells us when the email is opened, and their main link passes through stormstoke.com so we know it was clicked. We use this only to judge whether alerts are useful and arriving. Most email apps let you block images, which stops open tracking. Sign-in code emails are not tracked.
Every storm alert has a one-click “Stop email alerts” link, and you can change or pause alerts any time in Snow alert settings.
7. Who we share it with
We use a few service providers to run stormstoke. They process information only on our instructions and under their data protection terms:
- Cloudflare, Inc. (United States): hosting, database, content delivery, security and privacy-friendly analytics.
- Resend (United States): sends our emails (your email address and the email content).
- Google LLC (United States): sign-in, only if you choose Google sign-in.
Forecasts come from Open-Meteo. We request forecasts for resorts, not for people, so no personal information is sent to them.
We may also disclose information if the law requires it, to protect people’s safety, or to defend stormstoke against legal claims. If stormstoke is transferred to a company (for example, a company set up to run it), your information would move with it under this policy and we would tell you first.
8. Where your information is stored
We are based in Canada. Our providers store and process information in Canada, the United States and other countries where they operate. Canada is recognised by the European Commission as providing adequate protection for personal data.
When information from the EU, EEA, UK or Switzerland goes to providers in the United States, it is protected by the EU–U.S. Data Privacy Framework (and its UK and Swiss extensions) where the provider is certified, or by the European Commission’s Standard Contractual Clauses in the provider’s data processing terms. You can ask us for more detail.
9. How long we keep it
| Information | Kept for |
|---|---|
| Account, settings, favourites, followed resorts and alert history | Until you delete your account |
| Sign-in sessions | 90 days, or until you sign out |
| Sign-in codes | 10 minutes, or until used |
| Sign-in history, activity, and alert email opens and clicks | Up to 400 days, then deleted automatically; removed straight away if you delete your account |
| Error reports | 30 days |
| Feedback messages | As long as we need to act on them; ask and we will delete yours |
| Record of emails sent (type, resort, subject, delivery status) | Kept for operating records; once your account is deleted it no longer contains or links to your email address |
| Bounce and spam-complaint list | Kept so we never email that address again |
Deleted information can remain in our database provider’s automatic backups for up to 30 days before it is overwritten. Our email provider keeps its own delivery logs for a limited time under its policies.
10. Your choices and rights
Delete your account yourself. Go to Account and choose “Delete account”. This removes your account, favourites, alert settings, alert history, sign-in history and activity from the live site and the demo straight away.
Change your information. Edit settings and alerts at any time in the app. Turn off email alerts with one click.
Depending on where you live, you also have rights to:
- get a copy of the personal information we hold about you, in a portable format;
- have inaccurate information corrected;
- have your information deleted;
- restrict or object to how we use it, including the usage analytics based on our legitimate interests;
- withdraw consent where we rely on it, without affecting earlier use; and
- complain to a data protection authority.
To use any of these rights, email snow@stormstoke.com from the address on your account. We will reply within 30 days and will not charge you. We may need to confirm it is you first. We will not treat you differently for using your rights.
Complaints. Please contact us first so we can try to fix it. You can also contact your local authority: in the EU or EEA, your national data protection authority; in the UK, the Information Commissioner’s Office; in Canada, the Office of the Privacy Commissioner of Canada or, in Alberta, the Office of the Information and Privacy Commissioner of Alberta.
United States residents. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of. Requests under US state privacy laws can be sent to snow@stormstoke.com.
11. Children
stormstoke accounts are for people aged 16 or older. We do not knowingly collect personal information from anyone younger. If you believe a child under 16 has created an account, email snow@stormstoke.com and we will delete it.
12. Security
All traffic uses HTTPS. Session tokens and sign-in codes are stored only in hashed form, sign-in attempts are limited, and access to stormstoke’s administration tools is restricted and protected by additional sign-in checks. No system is perfectly secure, but we work to protect your information and will notify you and the authorities of a breach where the law requires.
13. Changes to this policy
We will post any changes on this page and update the date at the top. If a change is significant, we will email account holders before it takes effect.
14. Contact us
Matt Dyck
stormstoke
Calgary, Alberta, Canada
snow@stormstoke.com