Skip to content

Built in the 402 · No paid placement

The 402 · Your privacy

Privacy Policy

Last updated August 30, 2026

There are no accounts. Most preferences stay in your browser, while information you deliberately submit, subscribe with, share by link, upload, or send to an optional AI feature leaves your device as described below. This policy applies to OmahaSpots, operated by the operator of OmahaSpots.

1. Browser-only preferences

Your taste profile, ratings, saved lists, planner companions, personal notes, self-marked visits, and favorite dishes are stored in localStorage on your device. We do not receive that local data merely because you use the site. Clearing OmahaSpots site data deletes it from that browser, but does not retract a shared link or AI request you already created.

If you download a list backup, your browser creates a JSON file containing those lists and any private list notes. OmahaSpots does not receive that file unless you deliberately send it. Store it somewhere you trust and restore only a backup you recognize.

On supported devices, OmahaSpots may cache public pages and app assets so a recently viewed guide can reopen during a network interruption. Encoded shared lists, shared recaps, signed business check-in pages, and group-join pages are excluded from that offline page cache. Your browser or operating system may still retain ordinary history or network caches under its own controls.

If you tap “Use my neighborhood,” your browser may ask for location permission. OmahaSpots uses that one location reading in your browser to select a named Omaha neighborhood and nearby areas. We do not store the coordinates, add them to a shared link, send them to our server or analytics, or track your location in the background. Your browser or operating system controls the permission and may let you revoke it.

2. What we do not do

We do not sell personal information, set advertising or cross-site tracking cookies, or build a cross-site advertising profile of you.

3. Forms, corrections, and business submissions

Feedback, correction, local-tip, business, and Local Voice forms first send the fields you enter—including any relationship disclosure or optional source link—to our server. If delivery is configured, the message then goes to our email provider or a private automation webhook for human review. If delivery is unavailable, the interface may offer a mail link instead; your email provider then handles what you send.

The business form requires a contact name, reachable email, disclosed role, and an authority attestation so we can review the relationship rather than accept an anonymous owner claim. When an existing listing is selected, its OmahaSpots path and slug are included with the submission to identify the intended location.

We use submissions to review the request, improve the guide, prevent abuse, and respond when appropriate. Local tips are research leads, and business, Local Voice, and local-tip submissions are never published automatically or allowed to change a score.

If you tap “I need this answer too” on the public research radar or send an unconfirmed search detail for research, we may keep the selected question or normalized search request, up to three missing-detail labels, any optional constraint you type, the submission time, and keyed one-way request hashes in a private research ledger. The hashes help deduplicate requests and limit abuse without storing the raw IP address or browser string in that ledger. An optional email is stored separately for follow-up. These signals can order our research queue, but are not public votes and cannot change a venue's score, tags, ranking, or published facts.

Staff may keep an append-only research-state receipt—including the question ID, state, registered OmahaSpots Answer path, review note, and staff identifier—for up to 24 months. It does not include your email or request hashes. If a question already has a current Answer, the form may return that internal Answer link instead of recording another signal.

A business contact may separately request verified-contact review and opt in to operational listing-accuracy checks. We use the contact email, disclosed role, submitted website, and review notes to assess whether the person appears authorized. A matching business-domain email is only a verification signal, not automatic proof. We may instead verify through a public business email, a callback to a publicly listed number, or a code placed on a business-controlled site or social account.

A listing check-in email may contain an expiring signed link. The link contains an opaque contact-record ID and listing details, not the contact email address. A response confirms access to the contacted inbox but is still reviewed before publication. Accuracy-check emails are separate from marketing and include a way to stop future checks.

4. Newsletter

If newsletter signup is enabled and you subscribe, we send your email address, the page where you signed up, and a coarse source tag such as “via-restaurants” to our newsletter provider or private automation webhook. We use it to deliver and improve the newsletter. Use the unsubscribe link in an email or contact us to stop future messages.

5. Uploads and public media

Business photo uploads are disabled unless we expressly enable them. If enabled, a selected image is uploaded to our hosting provider's public object storage and receives a public URL. Do not upload private, confidential, location-sensitive, or third-party material without permission.

Removing a preview from the form does not necessarily delete a file already uploaded, and an abandoned upload may remain until our cleanup process removes it. Contact us with the file URL to request removal.

6. Shared links and share images

Saved lists, group invites, and Omaha recaps can place information you choose—such as a list title or description, companion name or taste notes, favorite dishes, and recap details—inside an encoded URL. Private per-place custom-list notes are not included in a shared list. The code is not encryption. Anyone who receives the full link may be able to view the information that is included, and link previews, messaging services, browser history, or server logs may process the URL. Do not put secrets or sensitive personal information in a shared link.

Visit-share cards and photos are composed on your device. OmahaSpots does not upload the finished share image unless a separate upload flow says so; your operating system or the app you choose for sharing then handles it.

7. Optional AI features

Common supported taste and category requests may be interpreted entirely in your browser. When a request is handled on your device, its text is not sent to Anthropic. If local interpretation cannot handle ordinary wording and the optional AI feature is enabled, the text you type and relevant likes or dislikes from your locally stored taste profile are sent to Anthropic. We do not intentionally attach your name or email address. Do not enter confidential or sensitive information. If the feature is off, you do not use it, or local interpretation handles the request, that information is not sent to the AI provider.

8. Technical data and security logs

Our hosting and security providers may process request data such as IP address, browser and device information, requested URL, time, and error or abuse signals to deliver the site, troubleshoot failures, and limit misuse. We do not use it to track you across unrelated sites.

9. Privacy-first analytics

If enabled, Plausible Analytics counts aggregate page views, coarse feature actions and share methods, referrers, and approximate region. Our event code does not intentionally send message text, email addresses, companion names, personal notes, or spot identifiers. Plausible sets no cookies and does not provide us a cross-site advertising profile. If analytics is not configured, no analytics script loads.

10. Providers and processing location

Depending on which optional features are enabled, providers may include Vercel (hosting and public object storage), Supabase (private operational records), Plausible (analytics), Anthropic (AI interpretation), Buttondown or a private newsletter webhook (subscriptions), and Resend or a private feedback webhook (form delivery). They process information for us under their own privacy and security terms. Information may be processed in the United States or other places where those providers operate.

11. Retention

Browser-only data stays until you clear it or the browser removes it. We keep submissions, business-contact verification records, listing confirmations, correspondence, subscriber records, delivery logs, and security records only as long as reasonably needed for the described purpose, legal compliance, disputes, and abuse prevention, subject to provider settings and backups. Public uploads may remain until reviewed or removed. We do not promise that a shared URL will remain available indefinitely.

If the private research ledger is enabled, a research signal has an 18-month deletion deadline and its separately stored optional follow-up email has a 12-month deletion deadline. Dynamic search-question text is also deleted after 18 months once no retained signal refers to it. Expired records are omitted from the reviewer queue and aggregate before a bounded deletion job physically removes them. Provider backups may take additional time to expire under the provider's backup schedule.

12. Your choices and requests

You can clear local data, avoid optional AI and sharing features, unsubscribe from email, and decline to submit a form. A business contact can stop listing-accuracy checks without changing the public listing or any separate newsletter preference. You may contact us to request access, correction, or deletion of information we control, withdraw Local Voice consent or a research follow-up request, or object to a use. We may need enough information to verify and locate the request. We honor rights required by applicable law; some records may be retained when legally permitted or required.

13. Security

We use reasonable safeguards appropriate to this preview, including transport encryption, bounded inputs, abuse throttling, and human review before publication. No website, provider, transmission, or storage system is completely secure, so do not send information you cannot accept the risk of disclosing.

14. Children

The site is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child sent us personal information, contact us so we can investigate and delete it where appropriate.

15. Changes to this policy

We will update this page and the last-updated date as the product changes. If we add accounts or materially new data collection, we will update this description before or when the change takes effect.

16. Contact

Privacy, correction, removal, and rights requests can be emailed to lkopietz3@gmail.com.

See also Terms · Privacy