Analytics is optional
When you first arrive you'll see a small banner with two equal choices: Allow analytics or Decline. Until you choose “Allow analytics”, no Google Analytics script is loaded and no measurement request is sent. Declining is a complete answer — the site works exactly the same.
Your choice is stored on your own device only, in your browser’s local storage, as the single word granted or denied. If your browser blocks storage, we simply treat you as not having consented and ask again.
Live Google Maps reviews
Restaurant detail pages can show live reviews from Google Maps. This is operational page content, not analytics, so it is separate from your GA4 analytics choice and can happen whether you allowed or declined analytics.
- It happens only on restaurant detail pages, and only as the reviews section approaches your screen — never on the home page, island hubs, cards, or in search.
- Your browser calls our own site. We then make the request to Google from our server, using the Place ID we already store for that restaurant. Your browser never talks to Google’s Places service directly, and we never send it your IP for this.
- Google returns a small, fixed set of content for immediate display: the rating and review count, review text, the author’s display name, profile link and avatar link, links to the review and to Google’s report form, and provider attribution.
- We do not store, cache, prefetch, or analyse that payload. It is rendered once and discarded; nothing from it is saved to our database or used in our own editorial notes, ratings, rankings, or structured data.
- Because author avatars are displayed, your browser may request an image directly from Google’s image hosts. That image request is made by your browser to Google.
- Google controls that data and its own handling of these requests under the Google Privacy Policy and the Google Maps Platform Terms of Service.
Where analytics can run
Analytics is a separate choice from the reviews described above. Even after you allow it, Google Analytics 4 only loads on our public editorial and directory pages:
- the home page, About, and this privacy page
- the blog index and individual blog posts
- long-form guides
- island hub pages for Oʻahu, Māui, Kauaʻi, and Hawaiʻi Island
- island “new restaurants” and “best of” collection pages
- region pages and restaurant detail pages
These pages are never measured, whatever your choice:
- admin and any signed-in or private area
- search results
- contact, advertise, and list-your-restaurant forms
- kamaʻāina deals pages
- API endpoints, robots.txt, sitemap.xml, and not-found pages
What gets sent
After you allow analytics, and only on the eligible public pages listed above, we intentionally send one page view per page you land on. It contains the page path (for example /maui/lahaina), that same path joined to this site’s address, and the page title.
Google Analytics 4 may also generate its own standard events alongside that page view — typically first_visit, session_start and user_engagement — together with basic technical context such as your browser, device type, approximate coarse location and basic referrer context. We pin those events to the same sanitized page context we send ourselves, so they carry the page path only. Referrer is reduced to the source site’s address alone (for example https://www.google.com) — never the referring path, query string or # fragment.
On eligible pages we also count a short, fixed list of interaction events, and each one is sent as a bare event name with no extra details attached:
search_usedandfilter_applied— that a search or a filter happened. The search text and the filter values are never sent.restaurant_view— a restaurant detail page was viewed.menu_click,website_click,directions_click,call_click,reservation_clickandorder_click— that an outbound restaurant link was used. The destination address and the phone number are never sent.claim_start— a “list your restaurant” link was opened.newsletter_subscribe— a newsletter signup succeeded. No email address is sent.
Because our listing, sponsor, and contact forms sit on pages that are never measured, no form submission is reported to Google Analytics at all. We count listing submissions, sponsor submissions, and newsletter signups ourselves, first-party and in aggregate totals only, with no personal details in those counts.
We strip query strings and # fragments before anything is sent. We do not collect or derive your name, email, phone number, anything you type into a form, full URLs with parameters, advertising identifiers, user IDs, custom dimensions or cross-site identifiers.
No advertising
Advertising consent is never requested and never granted. Ad storage, ad user data, and ad personalisation stay denied at all times, Google signals and ad personalisation signals are switched off, and there are no Meta, Google Ads, TikTok, or Tag Manager pixels on this site.
Changing your mind
Use the Privacy settings control below (it also lives in the site footer and as a small button in the corner of every page) to allow or decline at any time. Declining immediately switches every consent signal back to denied, disables the Google tag for the rest of the session, and stops any further page views. Allowing again turns on analytics storage only.
See also our Terms of use. Questions? Get in touch.