Privacy Policy
Last updated August 15, 2026
Provided for general information — not a substitute for legal advice.
Who we are
Museum Compass is operated by ramjac, LLC, a North Carolina limited liability company (“we”, “us”), publishing at museumcompass.com. We are the controller of the personal data described here. Write to us at privacy@museumcompass.com.
Effective August 15, 2026.
What we collect
Museum Compass is a reference catalog. Browsing it requires no account, and we do not ask for a name or an email address to read anything.
- Your cookie choice. A single cookie storing whether you accepted analytics, and the policy version it was made against.
- Your recent searches. The last five things you typed into the search field are kept in your browser’s local storage so the panel can offer them again. They stay on your device, are never sent to us, and clearing your site data removes them.
- Google Analytics 4 — regional basis. In the EEA, the United Kingdom and Switzerland, we load Google Analytics 4 only after you explicitly consent; Consent Mode v2 signals stay denied until then. Elsewhere, including the United States, analytics is enabled by default and the Consent Mode v2 analytics signal reflects that, with a one-click opt-out shown on arrival and always available under “Cookie preferences”. In every region IP anonymisation is on and
ad_storage,ad_user_dataandad_personalizationremain denied — no advertising, remarketing, or personalisation signals, anywhere. - Outbound-link analytics. On the same basis, following a link to a museum, ticketing site, or partner records an anonymous event: the link, the page, and the time. No profile, no identifier tied to you personally. Opting out stops it immediately.
- Trip plan data. If you generate a saved itinerary, we store what you entered — the exhibition, dates, and preferences — so the plan can be retrieved and shared by its link.
- Staff accounts. Editorial staff sign in to internal tools; we store their email address, an authentication record, and their role.
- Server logs. Our hosting provider processes standard request logs, including IP address, for security and reliability.
Why we use it
To operate and secure the site; to remember your cookie choice; to understand, in aggregate, which exhibitions and links readers find useful; to produce and retrieve trip plans you asked for; and to administer staff access to editorial tools.
Legal bases (GDPR)
- Consent (Art. 6(1)(a)) — outbound-link analytics and any future measurement. Withdrawable at any time from the footer.
- Legitimate interests (Art. 6(1)(f)) — operating, securing, and maintaining the site, and recording your consent choice so we do not have to ask repeatedly.
- Contract / pre-contractual steps (Art. 6(1)(b)) — producing and storing a trip plan you requested, and providing staff accounts.
We do not sell personal data
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act as amended. We have not done so in the preceding twelve months. There is nothing to opt out of, because the practice does not exist here.
Retention
The consent cookie expires after 180 days. Outbound-click events are kept in aggregate form for up to 24 months. Trip plans are kept until you ask us to delete them or the plan link is retired. Staff account records are kept for the duration of the role and a short period afterwards. Server logs are kept on our provider’s standard short-term schedule.
Third parties
Our database, authentication, and hosting run on Supabase infrastructure, which processes data on our instructions as a processor. Where you have accepted analytics, Google LLC processes measurement data as our processor through Google Analytics 4; its practices are described in the Google privacy policy. We enable no advertising or personalisation features on that account. Generated trip-plan text is produced through an AI service on a per-request basis; the prompt is not used to train third-party models.
The site links out to museum websites, ticketing services, and travel partners. Some of those links are affiliate links and are marked as sponsored. Once you follow a link you are on that organisation’s site under its own privacy policy, which we do not control.
International transfers
We are based in the United States, and our providers process data there. Where data is transferred out of the European Economic Area or the United Kingdom, it is done under the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable), together with our providers’ technical safeguards.
Your rights — GDPR / UK GDPR
If you are in the EEA, the UK, or Switzerland you may request access to your personal data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting prior processing. You may also lodge a complaint with your national supervisory authority.
Your rights — California (CCPA/CPRA)
California residents may request to know the categories and specific pieces of personal information we have collected, request deletion, request correction, and are entitled not to be discriminated against for exercising those rights. We do not sell or share personal information as defined by the statute. Requests may be made through an authorised agent with proof of authority.
Making a request
Email privacy@museumcompass.com. We respond within 30 days (45 days for California requests, extendable once where permitted). We may ask for information sufficient to verify the request, particularly for deletion.
Children
The site is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has provided data, contact us and we will delete it.
Changes
If we change this policy materially, we will update the date above and — where the change affects cookies or consent — re-prompt for your choice through the banner.
Museum Compass is operated by ramjac, LLC, a North Carolina limited liability company. Questions about this document: privacy@museumcompass.com.