Privacy Policy – Raíces House
Last updated: ⟦August 26, 2025⟧1) Who we are
We are Raíces House (⟦full legal entity name⟧, ⟦Tax ID/NIT or registration number⟧), registered at ⟦address⟧. Contact: ⟦info@raiceshouse.com⟧. We act as the data controller for personal data collected through our website, booking processes, communications, and customer support (including WhatsApp/Social Media if used).2) Scope of this policy
This policy applies to personal data of website visitors, guests and prospective guests, business contacts, and subscribers collected through:- raiceshouse.com (and subdomains)
- Booking engine, contact forms, newsletter sign-ups
- Customer service channels (email, phone, WhatsApp, social media)
- On‑site stay (e.g., check‑in records)
3) Data we collect
3.1 Data you provide
- Identification & contact: first/last name, email, phone, country/city.
- Booking details: dates, number of guests, preferences (e.g., bed, meals), promo codes.
- Billing: ID document (as required by law), billing address, tax details.
- Support & communications: messages, inquiries, reviews, testimonials.
- Marketing: your consent to receive communications, travel interests.
- Images: photos you authorize us to use for testimonials or social media (with prior consent).
Sensitive data (optional, with consent): health/allergies, accessibility or special requirements to personalize your stay.
3.2 Data collected automatically
- Technical data: IP, device/browser type, OS, language, time zones.
- Site usage: pages viewed, clicks, referring URLs.
- Cookies & similar tech: see section 9.
3.3 Data from third parties
- Payment gateway: payment confirmation (we do not store your card number).
- Booking engine/OTAs: booking data forwarded to us (e.g., Booking, Airbnb, etc.).
- Social media: if you interact with our profiles or log in via these platforms.
4) Purposes and legal bases
We process your data for:Purpose | Examples | Legal basis (as applicable) |
---|---|---|
Manage bookings & deliver services | Confirm, modify, cancel; check‑in; customer service | Contract performance / legitimate interests |
Process payments & invoicing | Charges, refunds, receipts | Contract performance / legal obligation |
Operational communications | Emails/SMS/WhatsApp about your booking | Contract performance / legitimate interests |
Customer support | Respond to inquiries and requests | Legitimate interests |
Marketing & newsletter | Offers, news, surveys | Consent (withdrawable) / legitimate interests (customers, where permitted) |
Stay personalization | Preferences, allergies, accessibility | Explicit consent (sensitive data) |
Security & fraud prevention | Detect unlawful activities | Legitimate interests / legal obligation |
Analytics & site improvement | Usage metrics, performance | Consent (cookies) / legitimate interests |
Legal compliance | Regulatory requests, recordkeeping | Legal obligation |
Testimonials & images | Publishing on website/socials | Consent (withdrawable) |
5) Children
Our site is not directed to individuals under 18 for making reservations. Family stays are welcome, but the booking must be made by an adult. If you believe a minor provided data without appropriate consent, contact us at ⟦info@raiceshouse.com⟧ so we can delete it.6) Data retention
We retain data only as long as necessary:- Bookings & billing: up to ⟦5–10⟧ years to meet accounting/legal obligations.
- Customer support: up to ⟦2⟧ years from last interaction.
- Marketing: until you withdraw consent or after ⟦2⟧ years of inactivity.
- Sensitive data: deleted after your stay unless you ask us to keep it for future visits.
7) Sharing and processors
We may share data with service providers acting on our behalf (processors) under confidentiality and data processing agreements:- Web hosting & infrastructure: ⟦e.g., AWS/Google Cloud/other⟧
- Booking engine/PMS: ⟦e.g., Cloudbeds, SiteMinder, Sirvoy, etc.⟧
- Payment gateway: ⟦e.g., Stripe, PayU, Mercado Pago⟧
- Email & marketing: ⟦Mailchimp, Sendgrid, Brevo, etc.⟧
- Analytics & cookies: ⟦Google Analytics/Tag Manager, Meta Pixel, etc.⟧
- Messaging: ⟦WhatsApp Business, Twilio⟧
8) International transfers
If we transfer data outside your country (e.g., to providers in the EU/US), we implement appropriate safeguards (standard contractual clauses, transfer impact assessments, and technical/organizational measures) to protect your information.9) Cookies and similar technologies
We use first‑party and third‑party cookies for: (a) site functionality, (b) statistics/analytics, (c) personalization, and (d) advertising.- We display a consent banner on your first visit.
- You can configure or withdraw your consent at “Cookie Settings” anytime.
- See our Cookie Policy for details of each cookie, purpose, and lifespan.
- Cookie preferences: ⟦/cookies-preferences⟧
- Cookie Policy: ⟦/cookie-policy⟧
10) Information security
We apply reasonable technical and organizational measures: TLS encryption, access controls, activity logging, data minimization, and staff training. Still, no system is 100% secure; if we detect an incident that materially affects you, we will notify you as required by law.11) Your privacy rights
Depending on your jurisdiction, you may exercise:- Access: know what data we process.
- Rectification: correct inaccurate data.
- Erasure: request deletion where applicable.
- Objection and restriction: to certain processing (e.g., marketing).
- Portability: receive your data in a structured format.
- Withdraw consent: without affecting prior lawful processing.
- Complain to a supervisory authority.
How to exercise your rights
Email ⟦info@raiceshouse.com⟧ with subject “Privacy Rights Request”. We will respond within ⟦15–30⟧ days (as required by applicable law). We may need to verify your identity.12) Complaints to authorities
- Colombia: Superintendence of Industry and Commerce (SIC).
- European Union/EEA: your local supervisory authority.
- California (US): California Attorney General. (We will indicate the specific authority if you tell us your country of residence.)
13) Changes to this policy
We may update this policy to reflect legal or service changes. We will post the current version on this page with the last updated date. If changes are material, we will notify you through reasonable means.14) Contact
- Controller: ⟦Raíces House / Legal entity⟧
- Privacy email: ⟦info@raiceshouse.com⟧
- Postal address: ⟦Full address⟧
- Data Protection Officer (if applicable): ⟦Name and contact⟧
- WhatsApp/Support: ⟦+57 XXX XXX XXXX⟧
Jurisdictional Annexes (optional but recommended)
A) Colombia – Habeas Data (Law 1581 of 2012 and regulations)
- Data subject: the natural person to whom the data relates.
- Processing: any operation on personal data.
- Data subject rights: know, update, rectify, delete, and revoke authorization; file complaints before the SIC.
- Procedure for inquiries and claims:
- Inquiries: response within 10 business days (extendable 5 more with justification).
- Claims: response within 15 business days (extendable 8 more with justification).
- Authorization: we obtain your prior, express, and informed consent where required (especially for sensitive data and marketing).
B) EU/EEA & United Kingdom – GDPR/UK GDPR
- Controller: Raíces House ⟦or EU/UK representative, if required⟧.
- Legal bases: Art. 6 GDPR (contract, consent, legal obligation, legitimate interests) and Art. 9 GDPR for special categories (explicit consent).
- Transfers: rely on Standard Contractual Clauses or other safeguards.
- Right to complain: to your local supervisory authority.
C) United States – California (CCPA/CPRA)
- Categories of data: identifiers, commercial information (bookings), internet/activity data, approximate geolocation, limited inferences for preferences.
- Rights: know/access/portability, deletion, correction, opt‑out of cross‑context behavioral advertising/“sale”/“sharing” (where applicable).
- Global Privacy Control (GPC): we honor GPC signals where feasible via our consent tool.
- Non‑discrimination: we will not deny services for exercising your rights.
Cookie Policy (summary for your site)
Publish this as a separate page /cookie-policy and link it from the banner.What are cookies? Small files your browser stores to remember information about your visit. Types we use
- Essential: required for navigation and booking (no consent needed).
- Analytics: measure site usage (consent required in many jurisdictions).
- Personalization: remember your preferences.
- Advertising: show relevant ads (require consent and provide opt‑out).
- Configure or withdraw your consent in “Cookie Settings”.
- You can also delete or block cookies from your browser settings.