Who We Are

Airport Smoking Zones (airportsmokingzones.com) is a free information service helping travelers find smoking areas at airports worldwide. We have been serving travelers since 2017.

Information We Collect

Information You Provide

When you use our contribution features, we collect:

  • Smoking area tips — the text you submit, your name (optional), and a hashed form of your IP address
  • Photos — images you upload along with the airport code, description, contributor name (optional), and your IP address. Faces detected in a published photo are blurred automatically before it appears on the site
  • Ratings — your score for an airport’s smoking facilities, optional comments, and a hashed form of your IP address
  • Contact messages — your name, email address, and message content when you use our contact form, plus your IP address

Information Collected Automatically

  • Cookieless web analytics — a third-party analytics service tells us which pages are read and where visitors arrive from. It sets no cookies, stores nothing in your browser, and builds no cross-site profile
  • Google AdSense — we display advertisements through Google AdSense. Google and its advertising partners may use cookies to serve ads based on your prior visits to this site or other websites
  • Our own performance beacon — a script we host ourselves that reports how pages are read and how they perform. It is set out in full just below
  • Server logs — our web server and content delivery network record your IP address, browser type, pages requested, and referring URL

What our performance beacon collects

A small script we host ourselves sends usage and performance data to our own server. It sets no cookies and stores no identifier in your browser. If your browser sends a Do Not Track signal, the script sends nothing at all. What it does send falls into five groups:

  • Page view — the full page address including any query string and campaign (UTM) parameters, the page title, the referring address, your screen size and browser window size, your browser language, and whether the page was reached by a fresh load, a reload, a back/forward step, or an in-page navigation
  • Device and connection hints — whether your device is set to a light or dark colour scheme and, where your browser exposes them, your connection type, estimated speed, round-trip time, Save Data setting, device memory class, and number of processor cores
  • Engagement — how far down the page you scrolled and how long the page was actively in front of you
  • Interaction events — clicks on outbound links and file downloads (the destination address), form submissions (the form’s name or address, never what you typed into it), two friction signals (repeated rapid clicks in one spot, and a click on something that does not respond), and any named event a page of ours chooses to report. These carry a short description of the element clicked — its HTML tag plus its id or first CSS class — and never the content of a field
  • Performance and errors — Core Web Vitals (LCP, CLS, INP, FCP, TTFB) with their timing breakdowns and network connection timings, short descriptions of the page elements involved in each measurement, the address of the image or file behind the largest element on the page, and JavaScript errors, including the error message, the script and line it came from, a trimmed stack trace, and the address of any file that failed to load

How the beacon recognises a visit without cookies

Instead of a cookie, our server derives one-way identifiers: it hashes your IP address and browser user-agent string together with a random secret salt (SHA-256, truncated). Nothing is stored on your device. There are two such identifiers, with different lifetimes:

1. The visit identifier (daily salt). This is what lets us count a visitor once instead of once per page, and group your page views into a session that closes after 30 minutes of inactivity. Its salt is generated at random on our own server, never leaves it, and is replaced every day. Only the current and previous day’s salts are kept, so this identifier changes daily and cannot connect your visits across days.

2. The returning-visitor key (weekly salt). So we can tell first-time readers from returning ones, we store a second hash of the same inputs under a salt that is replaced every week. Only the current and previous week’s salts are kept, so this key can match a return visit within the same week or from the week before — a linkability window of roughly one to two weeks — and nothing older. Once a weekly salt is deleted, the visits it identified can no longer be linked to each other or back to an IP address. This key is stored alongside the visit record in our analytics database.

Your raw IP address and user-agent are used only to compute those hashes, to look up an approximate country, region, and city from an offline geolocation database, and for spam filtering. Neither is written to the beacon’s session and event tables — they have no IP address column and no user-agent column.

Information We Do Not Collect

We do not require user accounts or registration. We do not collect email addresses except through the contact form. We do not use social login and we do not run third-party tracking pixels. We stopped using Google Analytics in July 2026, and no Google Analytics tags are loaded on this site.

Visitors in the EEA, UK, and Switzerland

When you first visit our site from the European Economic Area, United Kingdom, or Switzerland, you will see a consent banner. You may:

  • Accept — advertising cookies are enabled and ads may be personalized
  • Decline — only essential cookies are used and ads are shown without personalization
  • Change your preferences — click “Privacy Policy” in the website footer at any time to reopen the consent choices

When consent is declined, advertising runs in non-personalized mode: Google is instructed not to use advertising storage, ad user data, or ad personalization, ad request data is redacted, and ad click information passes through URL parameters instead for basic measurement. Your choice itself has to be remembered, so the consent management platform (Google’s Funding Choices) stores it in your browser — that is the “Consent preferences” entry in the cookie table below, and it is set whichever way you answer.

Our own analytics do not depend on this choice, because neither our analytics service nor our performance beacon uses cookies or stores anything in your browser.

Visitors in California (CCPA/CPRA)

California residents may see a “Do Not Sell or Share My Personal Information” notice. You can opt out of the sale or sharing of personal information used for targeted advertising.

All Other Visitors

Advertising cookies are used by default. You can manage ad personalization through Google Ad Settings. Our own analytics are cookieless everywhere, and the performance beacon honours a browser Do Not Track signal in every region.

Cookies Used on This Site

CookiePurposeDuration
Google AdSense cookiesAd serving, frequency capping, and ad personalizationSet by Google
Consent preferencesStores your cookie consent choices, set by Google’s consent management platformSet by Google

We set no cookies of our own, and neither our analytics service nor our performance beacon stores any identifier in your browser. The beacon reads one local-storage flag, b_ignore, purely so we can switch it off on our own devices; it never writes to your browser.

How We Use Your Information

  • Contributions, photos, and ratings are reviewed by moderators before publishing to keep our airport guides accurate
  • IP addresses are used for spam prevention and rate limiting
  • Analytics data helps us understand which airports and content are most useful to travelers, and performance data tells us which pages are loading slowly or throwing errors
  • Contact form messages are used to respond to your inquiries

Third-Party Services

We use the following services that may process your data:

  • A cookieless web-analytics service — page-view statistics, as described above
  • Google AdSense (Google LLC) — advertising and consent management — How Google uses information
  • A cloud hosting and content-delivery provider — stores and delivers this site’s pages from servers close to you, and records the server logs described above
  • A DNS provider — answers the lookup that points your browser at our content delivery network; it does not sit in front of the site’s traffic
  • A private team-messaging service — every new tip, rating, photo, and contact message is relayed to a private moderation channel so it can be reviewed. That message carries the text you submitted, the name and (for contact messages) the email address you gave, the IP address the submission came from, and the photos exactly as uploaded — before the automatic face blur, which is applied only to the versions published on the site
  • A language-detection and translation service — the text of every non-empty rating comment is sent to detect which language it is written in, including comments that turn out to be English; comments that are not in English are translated in the same step, so they can be shown in English on our English pages alongside the original. Only the comment text is sent — never your name, email address, or IP address

Data Retention

We do not run scheduled deletion on most of this data. Where no expiry is listed below, the data is kept until we delete it by hand — and you can ask us to delete yours at any time through the contact form.

  • Contributions and ratings — retained indefinitely to maintain guide accuracy
  • Photos — retained until deleted
  • Contact messages — retained until deleted; there is no automatic expiry
  • Analytics identifiers — the daily salt behind the visit identifier is deleted after two days, and the weekly salt behind the returning-visitor key after two weeks. Once a salt is gone, the identifiers it produced can no longer be traced back to an IP address or linked to each other. The page, referrer, country, and performance statistics built from them are kept without any personal identifier
  • Server logs — content-delivery-network log objects expire from our cloud storage after 90 days. A copy of the raw logs is mirrored to an archive on our own server so we can re-run analytics over past traffic; that archive has no fixed deletion schedule. When logs are loaded into our analytics database, the visit records keep a hashed IP address, a visitor key, the browser user-agent string, the requested path and query string, and the referring address — that database also has no fixed deletion schedule

Your Rights

European Economic Area, UK, and Switzerland (GDPR)

You have the right to access, correct, or delete the personal data we hold about you, to object to processing, to restrict processing, and to withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing performed before withdrawal.

California (CCPA/CPRA)

California residents have the right to know what personal information is collected, to request deletion, to opt out of the sale or sharing of personal information, and to not be discriminated against for exercising these rights.

To exercise any of these rights, please contact us.

Data Security

We protect your data through HTTPS encryption on all connections, access-controlled servers, IP address hashing for privacy, and moderation of all user submissions before publication.

Children’s Privacy

Our service is not directed at children under 13. We do not knowingly collect personal information from children.

Changes to This Policy

We may update this privacy policy from time to time. The last modified date at the top of this page indicates when it was last revised.

Contact

For privacy-related inquiries, please use our contact form.

Last updated: