Skip to content
Mesa Notes

Privacy

Last updated May 4, 2026

Plain English. Mesa Notes is a small, independent fan site for Hotel Xcaret Mexico dining. We collect as little as we can get away with, and we name every third party that sees anything.

What we collect

  • Account info. Email address and a hashed password if you create an account. Stored in Supabase. We never see your plain-text password.
  • Wish list. Trip dates, party size, celebration, special requests, and the restaurants and times you pick. Stored in Postgres alongside your account.
  • Newsletter opt-in. If you check the box at signup, your email goes to Resend so we can send updates. Unsubscribing in any email removes you instantly.
  • Standard request data. Cookies for keeping you signed in (HttpOnly + Secure), and the request metadata every server logs (IP, user agent, timestamp). We don’t build behavior profiles from this.

What we don’t collect

  • Real names (unless you choose to put one in your wish list).
  • Phone numbers.
  • Payment info (we don’t take payment).
  • Location, beyond what your IP implies.
  • Cross-site tracking from us. We don’t run our own analytics tracker.

Third parties that see your data

Supabase
Hosts our database and runs the auth system. Sees your email, hashed password, and wish list. Supabase’s privacy policy.
Resend
Sends transactional and newsletter emails. Sees your email if you opt in. Resend’s privacy policy.
Vercel
Hosts the site. Sees standard request logs. Vercel’s privacy policy.
Anthropic
Powers our dining concierge chat. Receives your chat messages when you use the chat widget. Anthropic’s privacy policy.
Google AdSense (when ads are enabled)
Serves the display ads that fund the site. Google may use cookies to serve ads based on your prior visits to this site or other sites. You can opt out of personalized ads in your Google Ads Settings or via the Digital Advertising Alliance opt-out. See Google’s ad policies for full detail.
Booking.com and Expedia
Click an affiliate link and they see standard referrer data. We earn a commission if you book; you don’t pay more.

Your rights

Email mesa-notes@proton.me from the address on your account and we’ll:

  • Show you what we have on you.
  • Delete your account and all associated wish-list data.
  • Correct anything that’s wrong.

We aim to respond within 7 days.

Changes to this policy

If we materially change what we collect or who we share it with, we’ll update the date at the top and, when it matters, email registered users. The current version always lives at https://mesanotes.com/privacy.