Privacy Policy
Floating Hotel is a personal, fictional worldbuilding project. We collect only the minimum data required to operate the site. We never sell, trade, or use your data for advertising.
1 · Who We AreSite Operator
This site (https://floatinghotelart.com) is run by an individual creator. All content is original fiction — a novel, a creature codex, music, and concept art. Products, prices, currencies and transactions shown on the site are fictional simulations with no real payment processing of any kind.
Contact: [email protected]
2 · What We CollectData We Collect
2.1 Data you give us
| Feature | Collected | Purpose |
|---|---|---|
| Reservation (simulated) | Name, email, check-in / check-out dates, party size, room type, notes | Create and display your simulated booking record |
| Awakened profile (membership) | Email, display name, chosen race | Identify you and preserve your progress (aura, streak, insignia) |
| Sign in with Google | Email, Google account name, avatar URL, Google user identifier | Verify you own that email address, so nobody else can claim your membership |
| The Lounge (chat) | Display name and the message text you type | Show your message in a public channel |
About Google sign-in. You enter your password on Google's own site — we never see it and never
store it. Google tells us only your email, name and avatar. We request just three basic scopes
(openid, email, profile), which means we cannot read your Gmail,
contacts, Drive, or any other Google service. You can revoke our access at any time in your
Google account permissions.
We do not collect passwords, physical addresses, phone numbers, government IDs, credit cards, or any payment information. The site has no payment processing whatsoever.
2.2 Data collected automatically
- Cloudflare Web Analytics — injected at the edge by Cloudflare. Records page views, referrers, country/region, device type and page-load performance. It uses no cookies and no cross-site tracking identifiers, and cannot identify you individually.
- Server logs — standard connection records generated by Cloudflare while serving requests.
- Session cookie (essential) — after you sign in we set a cookie named
fh_sessso the site remembers you are logged in. It is HttpOnly (unreadable by page scripts) and Secure (HTTPS only), lasts 30 days, and is destroyed when you sign out. It is strictly necessary for the site to work and is never used for tracking, advertising, or cross-site identification. - Temporary sign-in cookie — when you press “Sign in with Google” we set a cookie named
fh_oauthholding a random string, used to confirm that the request coming back from Google is the same one you started (CSRF protection). It lasts only 10 minutes, is cleared as soon as sign-in finishes or is abandoned, is likewise HttpOnly and Secure, and contains no personal data.
2.3 Data stored in your browser
These live in your device's localStorage, are never sent to our servers, and disappear when you clear your browser data:
fh_lang— language preferencefh_member— local cache of your awakened profilefh_market— market cart, watchlist, and the simulated in-fiction walletfh_story_ch— reading position in the novel
3 · Social Platform APIsPinterest & Social Platform APIs
Our Pinterest API access is limited to our own brand account (@floatinghotel_). We do not access, collect, or store data belonging to any other Pinterest user.
Specifically:
- Scope — read-only. We retrieve performance figures for our own pins and boards (impressions, saves, pin clicks, outbound clicks).
- Purpose — displayed on a password-protected dashboard that only the site operator can reach, to understand which of our own content works.
- What we never do — read other people's accounts, scrape other people's pins, build user lists, share data with any third party, or use it for advertising or retargeting.
- Retention — we keep aggregate numbers only. We store no personal data of any Pinterest user.
The same principle applies to every other social integration we use (Instagram, Threads, and the scheduling tool Blotato): our own accounts only, for internal performance review only.
4 · How We Store ItStorage & Protection
- Data is stored in Cloudflare D1 (Cloudflare's database service) and transmitted over HTTPS.
- The site sends a Content Security Policy and other security headers; the internal operations dashboard is additionally password-protected.
- We do not sell, rent, or trade your data.
- No third party other than Cloudflare (our hosting and database provider) receives your data.
5 · Retention & Your RightsRetention & Your Rights
We keep your data until you ask us to delete it. You may email us at any time to:
- ask what data we hold about you
- correct anything that is wrong
- delete all of your data (bookings, member profile, lounge messages)
Write to [email protected] and we will handle it within a reasonable time.
6 · ChildrenChildren's Privacy
This site is not directed at children under 13, and we do not knowingly collect their data. If you believe we have, please contact us and we will delete it immediately.
7 · ChangesChanges to This Policy
If this policy changes we will update this page and the date below. Material changes will be announced on the site.
8 · ContactContact Us
Any privacy question — [email protected].
