Fernandes Journeys

Legal

Privacy Policy

How Fernandes Journeys collects and uses information — public browsing, reader accounts, Turnstile, Resend, Mailchimp, cookies, and your rights.

Effective / last updated: September 20, 2026

Hey — this is the plain-language privacy policy for Fernandes Journeys, the personal travel journal run by Alex Fernandes. It covers how the site works today: public reading, optional reader accounts, newsletter signup, contact forms, and the private CMS Alex uses to publish.

Questions or requests: [email protected] · Site: https://www.fernandesjourneys.com.

Who we are

Fernandes Journeys is a personal travel journal — trip notes, destinations, guides, and photos from the road. It is not a travel agency and does not sell bookings as a primary product.

Controller / operator: Alex Fernandes · Email: [email protected].

Public browsing (no account needed)

You can read stories, browse destinations, and use most of the site without creating an account or signing in. Public browsing does not require Google Sign-In or an email/password account.

Depending on how you use the site, we may still process:

  • Anonymous or aggregated analytics (when enabled) — visit timing, approximate region, pages viewed — to see what is useful. We do not sell individual browsing profiles.
  • Affiliate / advertising cookies — when you click outbound partner links (for example from /tools) or view ads, partners may set their own cookies. See the Affiliate disclosure.
  • Newsletter email — if you subscribe, we collect the email you submit (and any optional form fields) to send travel dispatches.
  • Contact form messages — if you write via the contact form, we receive what you send so we can reply.

We do not sell personal information. We do not use Google Sign-In or account data for advertising.

Reader accounts

Optional reader accounts let you save posts to a personal list on /account. You can create or sign in with:

  • Google Sign-In (OpenID Connect scopes openid, email, profile) — we typically receive your email, display name, profile picture URL, and a stable Google account id for the session. We do not request Drive, Gmail, Contacts, Calendar, or other sensitive scopes.
  • Email and password — passwords are stored only as bcrypt hashes in Firestore. We never store plaintext passwords.

Account profile data may include your display name and profile photo (from Google or a photo you set). Saved posts are stored in Firestore and tied to your user id so you can view or remove them later.

Change email

You can request an email change from Account settings. We send a verification link to the new address (via Resend), and a notice to the old address. The email on your account updates only after you confirm the new address.

Password reset

Forgot-password and reset flows send transactional email through Resend. Reset links expire; choosing a new password updates the hashed password in Firestore.

Cloudflare Turnstile (forms)

Spam-prone forms — including newsletter, contact, signup / register, and forgot-password — may show a Cloudflare Turnstile challenge. When configured, we verify the Turnstile token with Cloudflare before accepting the submission. Turnstile helps reduce bots; it is not used to build advertising profiles for us.

Email & newsletter providers

  • Resend — transactional email (password reset, email-change verification and notices, and similar system mail).
  • Mailchimp — newsletter subscriptions when Mailchimp API credentials are configured on the server. Your email (and any merge fields on the form) are sent to Mailchimp so we can send The Traveler's Journal dispatches. Unsubscribe via the link in each email or contact us.

Cookies & sessions

  • Essential / session cookies — Auth.js session cookies (authjs.session-token / __Secure-authjs.session-token) when you sign in. Optional CMS passcode cookies for admin unlock of /cms. Theme preference may live in localStorage (not a cookie).
  • Analytics — anonymous or aggregated usage when analytics are enabled.
  • Advertising / affiliate — partners may set cookies when ads or outbound affiliate links are present.

You can block non-essential cookies in your browser. Blocking essential session cookies will prevent Sign-In and CMS unlock from working.

CMS admin / allowlist

The private content management system at /cms is only for the site owner and any emails listed in a server allowlist. Admins may sign in with Google (or GitHub where configured). A reader session alone never unlocks the CMS. Misuse of admin tools is prohibited.

Google Sign-In / OAuth app

The Google Cloud OAuth application named Fernandes Journeys powers Google Sign-In. Home page: https://www.fernandesjourneys.com. This privacy policy: https://www.fernandesjourneys.com/privacy. App purpose: /app.

Google Sign-In is used only for (1) optional reader saved posts and (2) allowlisted CMS access — not as a consumer social network or general “login product.”

Revoke Google access anytime at Google Account → Third-party access, then sign out here. To delete account-associated data we control, email [email protected].

Third parties we rely on

We use trusted processors to run the journal:

  • Vercel — hosting and edge delivery
  • Cloudflare — Turnstile bot protection on forms
  • Google — Google Sign-In / OAuth (and optionally AdSense if ads are shown)
  • GitHub — source repository; CMS publish commits; GitHub OAuth may be available for allowlisted admins
  • Firebase / Google Cloud Firestore — reader profiles, hashed passwords, saved posts, and related account tokens
  • Resend — transactional email
  • Mailchimp — newsletter (when configured)
  • Affiliate partners — may set cookies when you follow outbound booking or product links

Each provider processes data under its own privacy policy. We only share what is needed to operate the features above.

Children

Fernandes Journeys is a travel journal for a general audience. It is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided data, contact us and we will delete it.

Retention

  • Sessions — until you sign out or the Auth.js session expires.
  • Saved posts & profile — until you remove them or request deletion.
  • Newsletter — until you unsubscribe or we remove the list record.
  • Contact messages — as long as needed to reply and keep a reasonable record of correspondence.
  • Email-change / password-reset tokens — short-lived; expire after use or timeout.

Your rights (GDPR / CCPA) & no sell

We do not sell personal information. If you are in the EU, UK, California, or another place with similar laws, you may have rights to access, correct, delete, or receive a copy of personal data we hold about you, and to object to certain processing. Contact [email protected]. We will respond within a reasonable time consistent with applicable law.

International processing

The site is operated from wherever Alex is based and hosted on infrastructure that may process data in the United States and other countries (for example Vercel, Google/Firebase, Cloudflare, Resend, Mailchimp). If you visit from another country, your information may be transferred to and processed in those locations. Where required, we rely on appropriate safeguards offered by those providers.

Contact

Alex Fernandes · Fernandes Journeys
Email: [email protected]
Web: https://www.fernandesjourneys.com

Related: Terms of Use · Affiliate disclosure · Policies hub · About Google Sign-In.