Privacy Policy
Effective date: September 10, 2026
ParkBeast ("ParkBeast," "we," "us," or "our") provides ParkBeast Wait Times, a mobile app for viewing Walt Disney World wait times, attraction information, park hours, favorites, widgets, optional location-based sorting, and optional wait-time alerts.
This Privacy Policy explains what information ParkBeast Wait Times handles, why it is handled, when it is shared, how long it is kept, and the choices available to you. The app does not require or offer a ParkBeast account and does not ask you to provide a name, email address, phone number, or payment-card information.
Summary of Our Analytics Approach
- Product analytics is optional and off unless you affirmatively enable it.
- Declining analytics does not limit the app or any paid feature.
- Analytics uses a random identifier that changes each app session; it is not linked to a ParkBeast account, name, email address, advertising identifier, or persistent device identifier.
- We collect only a defined list of product events and limited properties needed to understand aggregate feature use.
- We do not use PostHog session replay, screen recording, automatic screen or tap capture, person profiles, surveys, feature flags, or automatic error capture.
- You can withdraw analytics consent at any time in Settings > Options > Share Limited Analytics.
Analytics choices are separate from location permission, notification permission, and advertising privacy choices.
Information We Handle
Information You Provide
The app does not include account registration or general-purpose forms for submitting personal information. If you contact ParkBeast by email, we receive the information you include and use it to respond and provide support.
Preferences and App Data Stored on Your Device
The app may store appearance and feature preferences, default park, onboarding status, favorites, pinned attractions, alert settings and snapshots, notification and location toggles, your analytics choice, and cached purchase-entitlement information. The app and its widget may use a shared local container to make favorite-attraction and wait-time information available to the widget.
Optional Product Analytics
If you affirmatively enable Share Limited Analytics, the app sends a deliberately limited set of events to PostHog in the United States so we can understand aggregate feature use and improve the app.
The allowed event types are app opened; park changed; attraction viewed; favorite added or removed; alert created, updated, or deleted; Premium screen viewed or plan selected; purchase completed or canceled; and purchases restored.
Depending on the event, the allowed properties are limited to a park identifier and selection method; attraction content identifier and operating status; a broad wait-time range; alert condition, broad target-wait range, repeat and expiration settings; Premium entitlement category, selected plan, or StoreKit product identifier; and app version/build, SDK version, and anonymous session/window identifiers.
PostHog requires an event identifier to group events. Before an allowed event leaves the app, ParkBeast replaces the SDK's identifier with a random session identifier that changes each time the app starts. We do not call PostHog's identify function or create person profiles.
Our analytics filter does not allow names, email addresses, phone numbers, account identifiers, exact device location, attraction names, exact wait times, notification tokens, purchase prices, transaction identifiers, device name or model, hardware identifiers, advertising identifiers, screen dimensions, locale, network information, IP-address properties, or IP-derived location properties. The app also disables automatic lifecycle events, automatic screen and element capture, rage-click detection, session replay, surveys, feature flags, automatic error capture, and SDK swizzling.
The source IP address is necessarily visible to PostHog's network systems while an analytics request is delivered, as it is for ordinary internet communications. ParkBeast does not include the IP address as an analytics event property, and each event instructs PostHog not to perform IP-based location enrichment. PostHog may retain limited security and service logs under its own policies.
If analytics is off, the app does not send product analytics events to PostHog. Turning analytics off stops future collection. Previously collected events remain subject to the retention rules below.
Optional Location Information
If you allow location access, the app uses your device's approximate or precise location, as provided by iOS, to identify whether you appear to be inside a supported park and to sort nearby attractions. The app requests location only while in use and refreshes it periodically while location functionality is active.
Location access is optional. ParkBeast does not transmit your device's precise location to PostHog or store it in Firebase. The app may request attraction coordinates from ThemeParks.wiki so distance sorting can be calculated on your device.
Optional Alerts and Push Notifications
If you enable wait-time alerts or push notifications, the app and our Firebase backend may process a randomly generated installation ID; a Firebase Cloud Messaging token; bundle ID, app version, platform, and notification status; alert rules such as attraction, condition, target wait, cooldown, enabled and expiration settings; and alert state such as prior snapshots, last-triggered time, delivery status, retry state, invalid-token status, and timestamps.
The backend stores installation records and may also store individual alertSubscriptions records so it can evaluate only alerts affected by changed attraction data, retry transient delivery failures, disable one-time alerts after delivery, and deactivate alerts associated with an invalid notification token. Notifications are delivered using Firebase Cloud Messaging and Apple's push notification service. The notification installation ID is not sent to PostHog.
Advertising and Privacy Choices
The free version of the app may display banner ads supplied by Google AdMob. Before requesting ads, the app uses Google's User Messaging Platform to determine whether a privacy message or consent choice is required in your region.
Depending on your region, choices, device settings, and Google's ad-serving mode, Google and participating advertising partners may collect or process information such as IP address, device and app identifiers, advertising data, coarse location inferred from IP address, ad interactions, app interactions, diagnostics, and fraud-prevention signals to select, deliver, measure, limit, and secure ads.
ParkBeast Wait Times does not request Apple's App Tracking Transparency permission and does not include an NSUserTrackingUsageDescription key. Without that permission, the app does not intentionally access the iOS advertising identifier for cross-app tracking. The app includes Apple's SKAdNetwork identifiers, which can support privacy-preserving ad attribution without making the advertising identifier available to ParkBeast.
Ads are configured with a maximum content rating of T. The app is not configured as a child-directed service. Where Google determines it is required, a Privacy Choices control is available in Settings.
ParkBeast does not sell personal information for money. Advertising-partner processing may be considered targeted advertising, a "sale," or "sharing" under some privacy laws. Where applicable, you can use the in-app Privacy Choices control or contact us about available privacy rights. Advertising choices and optional PostHog analytics choices are independent.
Purchases and Subscriptions
The app offers a non-renewing 10-day pass and auto-renewing monthly and annual subscriptions through Apple's App Store. Apple processes your Apple Account, payment information, billing, cancellations, and refund requests. ParkBeast does not receive your full payment-card details or Apple Account password.
The app processes StoreKit product and transaction information needed to load plans, complete and verify purchases, restore purchases, and determine whether ads should be removed. This may include product identifier, transaction identifier, purchase date, expiration date, verification status, and refund or revocation status. The 10-day pass transaction identifier and calculated expiration date may be cached on your device.
If limited analytics is enabled, PostHog receives only the StoreKit product identifier and purchase-event type. It does not receive the transaction identifier, displayed price, currency, Apple Account information, or payment details.
Technical, Security, and Service Information
The app uses Firebase Core, Cloud Firestore, Cloud Functions, Cloud Messaging, App Check, and Hosting. Firebase and related infrastructure may process device, app, network, IP address, request-integrity, diagnostic, and service-log information needed to secure and operate those services.
ParkBeast Wait Times does not integrate Firebase Analytics, Google Analytics, or Firebase Crashlytics. PostHog is used only for the optional, limited product analytics described above.
How We Use Information
We use information to display app and widget content; provide optional location sorting; sync and deliver alerts; understand aggregate feature use when limited analytics is enabled; load ads and honor advertising choices; verify and restore purchases; protect services from abuse; maintain and secure the app; and respond to support or privacy requests.
We do not use PostHog analytics to identify you, build an advertising profile, target advertising, determine your precise location, or sell or share personal information for cross-context behavioral advertising.
Third-Party Services
ParkBeast Wait Times uses Apple services; Firebase Core, Cloud Firestore, Cloud Functions, Cloud Messaging, App Check, and Hosting; Google AdMob and Google's User Messaging Platform; PostHog US Cloud for optional, consent-based product analytics; and ThemeParks.wiki for park and attraction information.
These providers process information under their own terms and privacy policies. We require service providers handling information for ParkBeast to use it only to provide the contracted service and to protect it consistently with this Policy and applicable law.
For more information, see Apple's Privacy Policy, Google's Privacy Policy, PostHog's Privacy Policy, and ThemeParks.wiki.
When Information Is Disclosed
Information may be disclosed to providers that operate app, analytics, advertising, purchase, notification, hosting, security, and backend functionality; at your direction or with consent; to comply with law; to protect rights, safety, and security; or in connection with a business transaction.
We do not sell information collected through PostHog analytics or disclose it to advertising networks for ad targeting.
Data Retention
Device-stored preferences and cached data generally remain until you delete them, change the setting, or uninstall the app. Apple may retain purchase records under its own policies.
Raw optional analytics events are currently stored by PostHog. We review this data periodically and keep it only while it remains reasonably necessary to understand feature use; our standard retention target is no more than 12 months. Events may be deleted or converted to aggregate statistics sooner. Aggregate statistics that no longer identify an app session may be retained longer. PostHog may retain limited backups, security logs, or records required by law under its own practices.
Location used for park detection and attraction sorting is held in app memory and is cleared when location functionality is turned off. ParkBeast does not store your precise device location in Firebase or send it to PostHog.
Firebase installation records used for notifications currently remain until ParkBeast deletes them. Individual alert-subscription records remain until the corresponding rule is removed, expires and is cleaned up, becomes invalid, or ParkBeast deletes it.
Alerts configured to expire at the end of the day are ignored after expiration and are scheduled for cleanup after the end of the alert's creation day plus a three-hour grace period, with cleanup running at approximately 3:00 AM America/New_York. Related alert state and subscription records are removed or deactivated.
Alerts not configured for daily expiration remain until changed or removed. If Firebase reports an invalid token, the backend removes or nulls it, stores an invalidation timestamp and reason, and deactivates associated alert subscriptions. The installation record is not automatically deleted solely because its token becomes invalid.
Your Choices and Rights
You can use the app without a ParkBeast account; decline or disable limited analytics, location, and notifications; review advertising privacy choices when available; manage purchases through Apple; delete favorites, pins, and alerts; uninstall the app; or contact us about information handled by ParkBeast.
Limited analytics is off unless you enable it. You can stop future analytics collection at any time in Settings > Options > Share Limited Analytics. Turning analytics off does not automatically delete events collected while it was enabled. Because analytics uses short-lived session identifiers and is not linked to an account or contact information, we generally cannot connect a past analytics session to a particular person. We will nevertheless assess and respond to verifiable privacy requests as required by law.
Because the app does not use ParkBeast accounts, we may need information from your device or support correspondence to identify a Firebase notification installation record. Depending on where you live, you may have rights to know, access, correct, delete, obtain a copy of, or restrict certain processing; withdraw consent; opt out of targeted advertising, sale, or sharing; or appeal our response. Contact contact@parkbeast.com. We will not discriminate against you for exercising a privacy right.
Legal Bases for Processing
Where a legal basis is required, we process optional PostHog analytics based on your consent. We process information needed to provide requested app, alert, support, and purchase functionality to perform our agreement with you or take steps at your request. We process limited technical and security information for our legitimate interests in operating and securing the service, provided those interests are not overridden by your rights. We may also process information to comply with law or protect legal rights.
Children's Privacy
ParkBeast Wait Times is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to us, contact us and we will take appropriate steps.
Security
We use reasonable safeguards, including data minimization, an event allowlist, client-side analytics filtering, consent-based analytics controls, transport encryption, Apple transaction verification, Firebase App Check, and access rules. No transmission or storage method is completely secure.
International Processing
The app is primarily intended for users in the United States. Information may be processed in the United States or other locations where Apple, Google, Firebase, PostHog, or other providers operate. Where required, providers use appropriate safeguards for international transfers.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date and may provide additional notice or request new consent where required. We will not use information collected under an earlier consent for a materially different purpose without an appropriate legal basis or further consent where required.
Contact Us
ParkBeast
contact@parkbeast.com