Privacy Policy
Last Updated: May 11, 2026
Introduction
Loma de Atitlán is a wellness sanctuary operating in Tzununa, Sololá, Guatemala, owned and operated by Lomas de Tzununa, S.A. ("we," "us," or "our"). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the rights you have over it when you visit lomadeatitlan.com, use our guest portal, communicate with us, or stay at our sanctuary.
Information We Collect
Personal Information You Provide
We collect information you voluntarily provide when you make a reservation, create a guest portal account, sign up for our newsletter, request information, or contact us. This may include:
- Full name, email address, phone number, and country of residence
- Booking and reservation details (dates, room type, number of guests, special requests)
- Payment information (collected and processed securely by Stripe — we do not store full card numbers on our servers)
- Health, dietary, and wellness preferences you voluntarily share for retreat customization
- Communications with us (email, WhatsApp, SMS, contact form submissions)
- Marketing preferences and consent records
Information Collected Automatically
When you visit our website or use our guest portal, certain information is collected automatically through cookies, analytics scripts, and advertising tags, including:
- Browser type, version, language, and operating system
- Device type, screen size, and mobile vs desktop identifiers
- IP address and approximate geographic location (city/country level)
- Pages viewed, time on page, referring URL, click and scroll behavior, and session recordings (anonymized)
- Booking funnel events (search performed, room selected, booking modal opened, abandoned, completed)
- Cookies, pixels, local storage, and similar tracking technologies described in the Cookies section below
How We Use Your Information
We use the information we collect for the following purposes:
- Process, confirm, and manage your reservations and any associated payments or refunds
- Authenticate your guest portal account and protect it from unauthorized access
- Deliver pre-arrival, in-stay, and post-stay communications by email, SMS, and WhatsApp
- Personalize your retreat experience and tailor activity recommendations
- Send marketing communications, retreat invitations, and newsletters where you have given consent (you can unsubscribe at any time)
- Measure website performance, conversion rates, and marketing effectiveness across paid and organic channels
- Run remarketing and lookalike advertising campaigns on Google, Meta (Facebook/Instagram), and similar platforms
- Detect, prevent, and respond to fraud, abuse, and security incidents
- Comply with tax, accounting, and other legal obligations under Guatemalan law and applicable international regulations
Information Sharing and Third-Party Service Providers
We do not sell or rent your personal information to third parties for their independent marketing. We do share specific data with the following processors and service providers strictly so they can perform their function on our behalf. Each is bound by data-processing terms and its own published privacy policy (linked below):
- Stripe (United States / Ireland) — payment processing and card-on-file tokenization. PCI-DSS compliant. https://stripe.com/privacy
- Cloudbeds (United States) — property management system, reservation records, room availability. https://www.cloudbeds.com/privacy-policy/
- Supabase (United States / EU) — database, authentication, and file storage (row-level-security protected). https://supabase.com/privacy
- Postmark (United States) — transactional email delivery (booking confirmations, magic-link sign-in, receipts). https://postmarkapp.com/privacy-policy
- GoHighLevel / LeadConnector (United States) — CRM, SMS, and WhatsApp messaging to guests. https://www.gohighlevel.com/privacy-policy
- Google LLC (United States) — Google Analytics 4, Google Tag Manager, Google Ads conversion tracking and remarketing, Google Business Profile. https://policies.google.com/privacy
- Meta Platforms, Inc. (United States) — Meta Pixel for conversion measurement and remarketing on Facebook and Instagram. https://www.facebook.com/privacy/policy
- PostHog (United States / EU) — product analytics, funnel measurement, and feature flagging (no advertising use). https://posthog.com/privacy
- Microsoft Clarity (United States) — anonymized session recording and heatmaps for UX improvement. https://privacy.microsoft.com/en-us/privacystatement
- Rollbar (United States) — error tracking and crash diagnostics for our website and apps. https://rollbar.com/privacy/
- Online travel agencies you choose to book through (Airbnb, Booking.com, Expedia, TripAdvisor, Hospitable) — only when you originate a booking on their platform
- Government, tax, or law-enforcement authorities when we are legally required to disclose information
Advertising, Analytics, and Conversion Tracking
We use Google Analytics 4, Google Ads, and the Meta Pixel to measure how visitors find and interact with our website, to attribute bookings to the marketing channels that drove them, and to show relevant ads to people who have previously visited our site (remarketing). These services may set cookies or process limited identifiers (such as a hashed email or phone number when you submit a form) to match your activity across devices. They do not receive your full payment information or government IDs.
You can opt out of personalized advertising at any time through these tools:
- Google Ads personalization: https://adssettings.google.com
- Google Analytics opt-out: https://tools.google.com/dlpage/gaoptout
- Meta / Facebook ad preferences: https://www.facebook.com/adpreferences
- Digital Advertising Alliance opt-out: https://optout.aboutads.info
- Use the cookie banner on our site to decline analytics and advertising categories
Data Security
We protect personal data with a layered set of technical and organizational measures, including: TLS/HTTPS encryption for all data in transit; bcrypt password hashing for guest portal credentials; PCI-DSS-compliant tokenization of card data by Stripe (full card numbers never touch our servers); row-level-security policies on our Supabase database; least-privilege access controls for staff and vendors; multi-factor authentication on administrative accounts; and continuous monitoring for unauthorized access. While we follow industry best practices, no system is 100% secure, and we cannot guarantee absolute security.
How Long We Keep Your Data
We retain personal data only as long as needed for the purposes described above or as required by law. Booking and accounting records are kept for a minimum of five years to comply with Guatemalan tax law. Guest portal accounts are kept for as long as the account is active and for up to 24 months after the last sign-in, after which inactive accounts may be deleted. Marketing data is kept until you unsubscribe and for a short grace period thereafter. You can request earlier deletion at any time (see Your Rights below).
Your Rights
Subject to applicable law (including the GDPR, CCPA/CPRA, LGPD, and the Guatemalan Constitutional right to data protection), you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate or incomplete information
- Request deletion of your personal data (subject to legal retention obligations)
- Withdraw consent for marketing communications at any time
- Object to or restrict processing of your information
- Request portability of your data in a structured, machine-readable format
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email info@lomadeatitlan.com. We respond to verified requests within 30 days.
Cookies and Tracking Technologies
We use cookies and similar technologies that fall into three categories. You can manage your preferences at any time using the cookie banner on our site or your browser settings.
Categories of cookies we use:
- Strictly necessary — required for the website, guest portal, and booking flow to function (session, authentication, cart, security, fraud prevention). These cannot be disabled.
- Analytics — Google Analytics 4, PostHog, and Microsoft Clarity, used to understand how visitors use our site so we can improve it. You can decline these.
- Advertising — Google Ads and Meta Pixel, used to measure ad effectiveness and show relevant ads on other sites. You can decline these.
Children's Privacy
Our website, guest portal, and online booking services are not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact info@lomadeatitlan.com and we will delete it.
International Data Transfers
Loma de Atitlán is based in Guatemala. Many of our service providers (Stripe, Google, Meta, Cloudbeds, Supabase, Postmark, GoHighLevel, PostHog, Microsoft, Rollbar) are located in the United States or European Union. By using our services, you understand that your data may be transferred to and processed in these jurisdictions, which may have different data-protection laws than your country. Where required, we rely on standard contractual clauses or equivalent safeguards.
Contact Us
If you have any questions about this Privacy Policy, want to exercise your rights, or wish to lodge a complaint, please contact our data privacy contact:
Email: info@lomadeatitlan.com
Phone: +502 4316 7566
Address: Lomas de Tzununá, Aldea Tzununá Sector Chalets, Tzununá, Sololá 07014
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the services we use, or applicable law. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you by email or by a prominent notice on the website. Continued use of our services after a change takes effect constitutes acceptance of the revised policy.
