HospedaGuiaBack to site

PRIVACY

Privacy policy

Last updated: 7 August 2026.

Who the controller is

HospedaGuia is the controller of the property account data. For the content published in the guide, the property is the controller and HospedaGuia acts as a processor.

Data we collect from the property

  • Name, email and password (stored only as a hash, never in readable form).
  • Property name and the information you choose to publish in the guide.
  • Subscription identifiers at Mercado Pago. We never receive or store card details.

Data about guests reading the guide

The public guide requires no login and uses no tracking cookies. To count visits we derive a code from the IP address and browser combined with the current date. That code changes every day and cannot identify a person or follow them over time. We do not store the IP address.

What we use it for

  • Running the service: authenticating your account, publishing your guide and processing the subscription.
  • Emailing you about publication, trial expiry, payments and failed charges.
  • Producing aggregate usage statistics about your guide, for you.

Sharing

We share data only with the providers required to operate: Mercado Pago for payments, Resend for email delivery and, when AI generation is enabled, OpenAI: which receives only the property information you filled in, never guest data.

Retention and deletion

We keep your data for as long as the account exists. Guide access events are kept for 12 months. You can request deletion of your account and all associated data through the support address; we respond within 15 days.

Your rights

You have the right to confirmation of processing, access, correction, portability, anonymisation and deletion of your data, as well as withdrawal of consent. To exercise them, write to the support address.

Security

Passwords are protected with scrypt. Sessions use httpOnly cookies and only the token hash is stored in the database. All production traffic is served over HTTPS.