Legal
Privacy Policy
Effective September 8, 2026
This page says what The Park Desk collects, why, and what we refuse to keep. If a section does not apply to you (you never became an agent), we do not hold that extra data. Readers are not sold plans.
1. Account and sign-in
If you create an account we store an email, a display name, and a session. Google and X only send us the profile fields those providers already share for sign-in. Email/password stores a hashed password — never the password itself. Email confirmation uses a one-time token that expires. Two-factor stores a secret on the server and hashed backup codes, plus a short unlock window after you enter a code.
2. No reader payments
The Park Desk does not sell reader plans, trials, or trip passes. We do not collect reader card numbers. Citinet NMI is used only if an operator pays an agent; it is not a reader checkout. Partner tax and deposit data is described below.
3. Push
If you allow notifications we store your watch keywords, park pulse choices, quiet hours, and a browser push subscription (when live). You can turn push off. We do not sell push lists. A daily cap exists so we do not flood you — it is not a paid tier.
4. Partner and tax data
- Agents get a unique CW- code on account creation. We store the code, agency name, a ledger of referred travel bookings (product, gross, commission — not the client’s card), and first-touch desk clicks on that code.
- Payout profiles store legal name, tax class, and last-four only of SSN/EIN and bank account. Full numbers are not kept on the desk.
- The in-app 1099 tab is a worksheet for the agent’s accountant. It is not an IRS filing.
- If US commissions meet the IRS 1099-NEC threshold, The Park Desk (or its operator) may issue a real form from records we are required to keep.
- Direct-deposit routing details, when collected for ACH, are used only to pay that agent.
5. Stories on this device
Saved stories and some Watch settings can live in this browser (local storage) so the free Wire still works if you are signed out. That copy does not travel to another phone unless you are signed in.
6. Cookies and analytics
The Park Desk uses essential cookies / local storage to keep you signed in, to remember that you accepted the publisher disclaimer, and to remember a first-touch agent code (`cw_ref`) for 90 days when you open a `?ref=CW-XXXX` link. That cookie is how a later booking can still credit the planner who sent you. If you join the trip-alert waitlist we store only that email and which desk you signed from (home, Wire, Today, or More). First-party analytics store a random visitor id in this browser and events such as session start, returning visit, desk opens, saves, My Parks, watch keywords, waitlist signup, and outbound “read original.” No ad pixels. No third-party analytics vendors. Referrer is stored only as direct / google / social / other. There is no cookie wall because these counts are first-party operations, not ads. If we ever add an advertising or third-party analytics vendor, we will update this page and show a notice before those cookies load.
7. What we do not do
- We do not sell your email or partner tax data.
- We do not host the full original article — only a short teaser and a link.
- We do not run third-party ad pixels or third-party analytics.
8. How long we keep it
Account and ledger records stay while the account is open and as long as tax or chargeback rules require after that. You may ask us to close the account and delete what the law lets us delete by writing legal@castlewire.app.
9. Children
The Park Desk is not directed at children under 13. Do not create an account for someone that young.
10. Contact
Privacy and deletion requests: legal@castlewire.app. The Terms cover use of the product. Copyright complaints use the same inbox — see Copyright / DMCA.
Questions or takedowns: legal@castlewire.app. These pages describe how The Park Desk works. They are not a substitute for advice from your own lawyer.