Skip to content

Privacy

Last updated September 19, 2026 · K Consulting LLC

MagicFinders is run by K Consulting LLC. Postal address available on request at hello@magicfinders.com. Email hello@magicfinders.com. This page says what we keep, why, who else touches it, how long we keep it, and what you can do about it.

What we keep

Your email address (it is your sign-in and where alerts go), your name if you give one, your time zone, your mobile number if you turn on text alerts (confirmed with a one-time code; removable at any time), the alerts you set (venue, dates, party size), a log of checks and alerts sent, the openings we spot for you, sign-in sessions (device summary, IP address, timestamps), the date and address from which you accepted our Terms, and — if you buy a pass — the purchase record Stripe gives us (amount, dates, a receipt link; never your card number). We do not collect your Disney credentials.

Partners. If you apply to our partner program, we also keep your name, email, site address, what you told us about how you would mention us, your partner code, the payout details you give us (such as a PayPal or Venmo name) and our notes on your account. We create your code in Stripe. The coupon behind it is named “Partner:” followed by your name.

How we use it

No ads, no selling data. MagicFinders has no advertising and never sells, rents or shares your information for marketing. The Trip Pass is how the business is paid for.

Visit counting. We count visits to our public pages on our own server — no cookies, no third-party analytics script. For each visit we keep the page, the referring site, the day, whether it was a phone or a computer, and an approximate location (country and region) derived from your network address at that moment using an offline database; the address itself is not stored, and a visitor is represented by a code that changes every day, so visits can’t be tied to a person or across days. Signed-in pages are not counted at all.

Only to run the service: check the openings you set alerts for, email you sign-in links, alerts and pass confirmations, prevent abuse, handle payment questions and disputes, and keep required tax and payment records. No newsletter unless you ask for one; no selling or renting of data; no advertising pixels.

Text alerts. If you add a mobile number, we store it and the date you confirmed it, and we text you only the confirmation code, alerts for openings you asked for, and test texts you request — a few messages per trip. Message and data rates may apply. Reply STOP to any text to stop, HELP for help, or turn texts off / remove the number on your Account page. We keep a record of your consent and any STOP request for four years even after you delete your account, because the law makes us prove it. We do not share, sell, rent or transfer your mobile number, your SMS opt-in, or your consent with any third party or affiliate for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except Twilio, which delivers the messages.

Tracking

No third party collects information about you across other websites through MagicFinders. There are no advertising pixels or analytics trackers on the site today; if we ever add privacy-friendly analytics we’ll name it here first. Because there is nothing to opt out of, we don’t respond differently to Do Not Track or Global Privacy Control signals.

We do set a few small cookies of our own, from our own site only: they keep you signed in, remember how you first found us, and one long-lived cookie helps us keep the service reliable and prevent abuse of free accounts: it holds a random code, not your name or address, and it lets us tell when several free accounts were created from the same browser so the Free plan’s alert limit can be counted across them (see the Terms). None of them follow you to other sites, and none are used for advertising.

First-visit cookie. If you are not signed in and your first visit comes from another site or a tagged link, we set one cookie, named mf_ft, for 90 days. It holds the name of the referring site (not the full address), any utm tags, a Google ad click id or a ref code, the page you landed on and the time. If you create an account, we copy where you came from into your account record. If you buy a pass, we send the same details to Stripe with the purchase.

Two things we do measure about the email and texts we send you, so we can tell whether alerts arrive and get used: whether an email we sent you was delivered and opened (Resend, which sends our email, reports that back to us using a small image in the message), and whether the “book” link in an alert — or the “Book on Disney.com” button on your My alerts page while something is open — was followed: that link passes through magicfinders.com on its way to Disney’s booking page and we note the time. We keep those two facts with the alert; we don’t record what you do on Disney’s site.

Who else touches your data

Service providers acting for us, each getting only what it needs for its part: Railway (hosting; servers in the United States), Resend (sends our email), Stripe (payments — we never see or store your card number), Twilio (sends and receives text messages, only if you add a mobile number), Squarespace (our domain registration), Mailgun (receives email you send to hello@magicfinders.com), GitHub (where our code lives, and a daily automated check that our own site is working). We disclose data if the law requires it.

How long we keep things

Check logs about two weeks after each check (so an ended alert’s log is gone about two weeks after it ends); the alert itself and your activity list stay until you delete them or your account; sign-in sessions 30 days after they expire; hashed email-delivery records about two weeks and hashed text-message delivery records about 90 days; the openings we’ve spotted for you up to 120 days; internal health-check runs up to 90 days. When you delete your account we remove your profile, alerts, sessions, logs, delivery records and openings the same day; we keep purchase records (amount, date, receipt link, and the email you used) as tax and payment law requires (typically up to 7 years), and the text-message consent record described above.

Security

Everything is served over HTTPS; sign-in links and device tokens are stored only as one-way hashes; card details never reach our servers. If an incident ever exposes your data we’ll email you within 30 days.

Your choices

See and delete your data from Account, stop any alert from the link in its email, or email hello@magicfinders.com to ask for a copy or a correction. California residents have the rights the CCPA provides; we honor them for everyone.

If you’re outside the United States

MagicFinders is a US business and stores data in the United States. We process your information to provide the service you asked for and to keep it secure. Email hello@magicfinders.com to exercise any rights your local law gives you; we honor deletion and copy requests for everyone.

Children

MagicFinders isn’t for children under 13 and we don’t knowingly collect their information. If you think a child has given us data, email us and we’ll delete it.

When this policy changes

We’ll post the new date at the top of this page. If a change is material — new categories of data, a new purpose, or a new kind of recipient — we’ll email the address on your account before it takes effect.