Privacy Policy

Last Updated: February 2026

1. Data Controller

Chacahua.com ("the Platform") is the data controller responsible for the personal data collected through this website. This Privacy Policy complies with Mexico's Federal Law for the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares — LFPDPPP). Contact: hello@chacahua.com

2. Personal Data We Collect

We collect the following categories of personal data: From Guests (Travelers): - Name and email address (when subscribing to newsletter or making a booking) - Payment information (processed by Stripe — we do not store card details) - IP address and browser information (for analytics and security) - Language preference From Hosts (Business Owners): - Full name, email address, phone number, WhatsApp number - Business name, description, location, and other listing information - Banking/payment information (processed and stored by Stripe Connect) From Claim/Submission Forms: - Owner name, email, phone, WhatsApp - Business details and verification information

3. Purpose of Data Processing

We process personal data for the following purposes: - Service delivery: To display listings, process bookings, and facilitate communication between Guests and Hosts - Account management: To manage Host profiles and listing information - Payment processing: To process booking payments through Stripe Connect - Communication: To send booking confirmations, service updates, and newsletter content (with consent) - Analytics: To understand Platform usage and improve our services - Legal compliance: To comply with applicable laws and regulations - Security: To prevent fraud and protect our users

4. Legal Basis for Processing

Under the LFPDPPP, we process personal data based on: - Consent: You provide consent when submitting forms, subscribing to newsletters, or creating listings - Contractual necessity: Processing required to fulfill booking services - Legitimate interest: Analytics, security, and service improvement - Legal obligation: Tax records, PROFECO compliance

5. Data Sharing

We share personal data with: - Stripe, Inc.: For payment processing (Stripe's own privacy policy applies) - Hosts: Guest booking information necessary to fulfill the reservation - Guests: Host contact information displayed on listings (as configured by the Host) - Service providers: Analytics tools (Google Analytics), hosting (Vercel) - Legal authorities: When required by law or to protect our legal rights We do NOT sell personal data to third parties.

6. ARCO Rights (LFPDPPP)

Under Mexican law, you have the following rights regarding your personal data: - Access (Acceso): Request a copy of your personal data we hold - Rectification (Rectificación): Request correction of inaccurate data - Cancellation (Cancelación): Request deletion of your personal data - Opposition (Oposición): Object to the processing of your personal data To exercise any of these rights, send an email to: hello@chacahua.com with the subject line "ARCO Request" including: 1. Your full name 2. The specific right you wish to exercise 3. A description of the data concerned 4. A copy of official identification We will respond within 20 business days as required by the LFPDPPP.

7. Data Retention

We retain personal data for as long as necessary to fulfill the purposes described in this policy: - Booking data: 5 years (tax and legal compliance) - Newsletter subscribers: Until unsubscription - Listing data: Duration of the listing + 1 year - Claim/submission forms: 1 year after resolution - Analytics data: 26 months (Google Analytics default)

8. Cookies and Tracking

We use: - Essential cookies: Language preference, session management - Analytics cookies: Google Analytics (anonymized IP) to understand traffic patterns - No advertising cookies or trackers You can control cookies through your browser settings. Our Cookie Consent banner allows you to accept or decline non-essential cookies.

9. Data Security

We implement appropriate technical and organizational measures to protect personal data: - HTTPS encryption for all data in transit - Payment data processed by PCI-DSS compliant Stripe - Access controls on our database (Supabase with Row Level Security) - Regular security reviews No system is 100% secure. We cannot guarantee absolute security but we take reasonable measures to protect your data.

10. International Data Transfers

Your data may be processed in the United States (where our hosting provider Vercel and payment processor Stripe are located). These transfers are necessary to provide our services and are protected by the service providers' data protection agreements.

11. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted on this page with an updated date. We encourage you to review this policy regularly.

12. Contact

For privacy questions or ARCO requests: Email: hello@chacahua.com