Legal
Privacy policy
What we collect, where it goes, how long we keep it, and how to make us delete it.
Updated
Draft for legal review. This text has not been read by counsel yet. It says what we intend to do; the wording is not final.
The short version
We collect three things: what you tell us when you book, your email address if you join the list or ask us a question, and numbers about how the site is used.
We do not sell your data, to anyone, ever. Nothing that measures or tracks you loads before you say yes. Your card number never reaches our servers.
The rest of this page is the detail behind those three sentences.
Who we are, and who to write to
SONAMARKETING LLC, trading as The Caribbean Guys, 2880 W Oakland Park Blvd, Suite 225C, Oakland Park, FL 33311, USA, decides what happens to personal data on this site. Under EU and UK law that makes us the controller.
Everything on this page: hello@thecaribbeanguys.com. We do not have a data protection officer — we are three people, and one of us answers.
When you book a room
To book a room we need:
- The lead guest's name, email address and phone number.
- The names of the other guests, as on their passports.
- Your country and postal code, for the card check.
- The dates, the resort and the room.
- Anything you ask us to pass on — a late arrival, an accessible room, an allergy, a birthday.
Where it goes
To Nuitée Travel Limited (Dublin, Ireland), who take the payment and send the booking, and from them to the resort, which needs your name to give you a room and needs a special request in order to act on it.
The resort is in the Dominican Republic. Booking a room there means your name, your dates and your requests go there. There is no way to book a hotel room without telling the hotel who is coming.
Your card
Card details are typed into Nuitée's own payment form, which is embedded in our page. The card number, expiry and security code never reach our servers, and we never store them. We see the last four digits and the card brand on the booking record, and nothing else.
Health and accessibility
If you tell us about an allergy, a mobility need or a medical device, we pass it to the resort and nowhere else. Under EU and UK law that is special-category data; we handle it only because you asked us to pass it on, and we delete it from our own records once the stay is over.
Your email address
We run two lists, both in MailerLite, an email tool run by a Lithuanian company in Vilnius, with servers in the EU and the US:
- Members
- The list that unlocks the members' rate. We store your email address, the resort you were looking at, and the page you joined from. About one email a month. There is an unsubscribe link in every one and it works immediately.
- Questions
- If you use the ask form we store your name, email, question, and the resort and dates if you gave them, so we can find the thread again. The question is also emailed to the three of us.
Both forms post to a small endpoint we run on guides.descubriendoviajes.com, a server operated by one of the three of us. It stores the same fields and nothing more, and it is rate-limited so nobody can use it to send mail through us.
We do not sell or rent the list. We do not pass it to a resort. We do not upload it to an advertising platform to build an audience.
Server logs
Our host writes an ordinary web-server log for every request: IP address, the page asked for, the time, the browser string and the referring page. That is how a web server works, and it is what shows us an attack.
We keep the logs for 30 days and use them only for security and debugging. They are not joined to your booking or to your email address.
Why we are allowed to do this (EU and UK)
- Contract
- Everything needed to take your booking, deliver it to the resort and answer you about it.
- Legal obligation
- Keeping sales and tax records for the period US law requires.
- Consent
- The email lists, and every analytics and advertising cookie. You can withdraw it at any time.
- Legitimate interests
- Keeping the site up, stopping fraud, and replying to an email you sent us. You can object to these and we will look at it properly.
Who else sees your data
| Who | What they get | Why |
|---|---|---|
| Nuitée Travel Limited (Ireland) | Booking and payment data | Merchant of record: they charge the card and send the booking |
| The resort you booked | Guest names, dates, room, special requests | They cannot give you a room otherwise |
| MailerLite (Lithuania) | Email address, name, the fields on the form | Runs the members' list and the question inbox |
| Google (Analytics 4) | Page views, source, city-level location | Only with the performance consent |
| Microsoft (Clarity) | Masked session replay, heatmaps | Only with the performance consent |
| Meta Platforms | Page view, search, checkout and purchase events | Only with the targeting consent |
| Cloudflare and Hetzner | Request data, server logs | Hosting and delivery |
| Our accountant, and a lawyer if we need one | Booking records | Tax filings and disputes |
We do not sell data and we do not give it to data brokers. Some of these companies are outside the EEA and the UK. Those transfers ride on the EU–US Data Privacy Framework or on standard contractual clauses; ask us and we will tell you which one covers which vendor.
How long we keep it
- Booking records
- Seven years from the stay — US tax records, and the window in which a dispute can still arrive.
- Health and accessibility notes
- Deleted once the stay is over.
- Members' list
- Until you unsubscribe. After that we keep a suppression record — your address and the date — so nothing adds you back.
- Questions you sent us
- Two years.
- Google Analytics
- Fourteen months, which is the shortest retention Google offers.
- Microsoft Clarity
- Session recordings 30 days; the aggregate heatmaps and metrics up to 13 months.
- Server logs
- Thirty days.
Your rights if you are in the EU or the UK
You can:
- Ask what we hold about you, and get a copy.
- Have it corrected.
- Have it deleted — except a booking record we are required to keep for tax.
- Restrict what we do with it, or object to it.
- Take it elsewhere in a machine-readable file.
- Withdraw consent at any time, which stops that processing from then on.
Email us and we answer within 30 days. It is free. We verify you by replying to the address on your booking or your subscription, so we never hand your booking to somebody else.
If we get it wrong, complain to your national data-protection authority — in Ireland the Data Protection Commission, in the UK the Information Commissioner's Office.
One thing to be clear about: your stay is in the Dominican Republic and the seller is in Florida, so US law governs the contract itself. That does not touch your data rights. We answer an EU or UK request exactly the way we answer an American one.
If you are in California
Under the CCPA, as amended by the CPRA, you can ask us to:
- Tell you the categories and the specific pieces of personal information we collected in the last 12 months, where we got them, why we collected them and who we disclosed them to.
- Delete them.
- Correct them.
- Stop any "sale" or "sharing".
- Limit how we use sensitive personal information.
We do not sell personal information and never have. We "share" in the CPRA's narrow sense in exactly one way: if you accept the targeting category, the Meta pixel passes a page view or a purchase event to Meta for advertising. Decline that category — or send a Global Privacy Control signal — and nothing is shared.
We do not use or disclose sensitive personal information beyond the purposes the CPRA allows without a limit right.
We will not treat you differently for using any of this. Email hello@thecaribbeanguys.com with "California request" in the subject line. An authorised agent may act for you with written proof.
Global Privacy Control
If your browser sends a Global Privacy Control signal, we read it as an opt-out of the targeting category. The advertising tags are not loaded and no event is sent to Meta.
You do not have to do anything else, and you do not have to tell us.
If you are in Canada
PIPEDA applies to us when we handle a Canadian buyer's data. Your rights are close to the EU list: access, correction, and an explanation of why we hold something.
Consent is how we run the email list and the tracking tags, and you can withdraw it at any time.
If we do not resolve a complaint, you can take it to the Office of the Privacy Commissioner of Canada. Our site is in English and our prices are in US dollars; we do not target Quebec residents.
Children
This is a site for adults booking a hotel room. You must be 18 to book, and we do not knowingly collect data from anyone under 16.
If a child's name is in a booking it is because you put it there as their parent or guardian. We pass it to the resort, which needs it to prepare the room, and keep it on the booking record.
Keeping it safe
The site is static and served over HTTPS. Card data never touches our servers. The endpoint that receives the forms is rate-limited and stores only the fields listed above. Access to the email tool and the booking dashboard is limited to the three of us.
No system is perfect. If something goes wrong that affects you, we tell you, and we tell the regulator where the law says we must.
Changes to this policy
The date at the top is the date of the version you are reading. If we ever change something material — a new vendor, a new purpose — we say so on this page and email the list.