Privacy & Cookie Policy
Effective Date: January 1, 2025
ANANA Hospitality S.A.S. de C.V. | Guadalajara, Jalisco, Mexico
Table of Contents
- Introduction and Data Controller
- What Personal Information We Collect
- Purposes of Processing Your Personal Data
- How We Share Your Information
- Legal Basis for Processing
- Your ARCO Rights
- Data Retention Policy
- Data Security
- Cookies and Similar Technologies
- Third-Party Links and Services
- Children’s Privacy
- Policy Updates
- Contact Information
1. Introduction and Data Controller
Who We Are
ANANA Hospitality S.A.S. de C.V. is a Mexican commercial corporation registered under Folio N-2024093395 of the Public Commerce Registry of Jalisco, with its principal place of business at Avenida Miguel Hidalgo y Costilla 1323, Colonia Centro, 44100 Guadalajara, Jalisco, Mexico.
Data Controller
ANANA Hospitality S.A.S. de C.V. acts as the data controller responsible for your personal information. As the data controller, we determine the purposes and means of processing your personal data in accordance with Mexican data protection laws, specifically the Federal Law for the Protection of Personal Information (Ley Federal de Protección de Datos Personales en Posesión de Particulares) and the General Data Protection Law (Ley General de Protección de Datos Personales).
Scope of This Policy
This Policy applies to:
- Guests, travelers, and renters (“Guests”) who use our booking platform
- Property owners and managers (“Property Owners”) who list or manage properties on our platform
- Business partners, contractors, and service providers (“Partners”) who work with ANANA
- Website visitors and platform users of all types
2. What Personal Information We Collect
ANANA collects personal information in several ways, depending on how you interact with our Services.
2.1 Information You Provide Directly
Account Registration and Profile
When you create an account or profile, we collect:
- Full legal name
- Email address
- Mobile phone number
- Home or business address
- Date of birth (for certain transactions or legal compliance)
- Government-issued identification number (passport, national ID, RFC tax ID)
- Profile picture or avatar
- Password (encrypted)
Payment and Financial Information
To process bookings and payments, we collect:
- Credit or debit card information (processed securely by external payment providers; we do not store full card details)
- Bank account information (for property owner payouts)
- Billing address
- Transaction history and payment status
Property Information (for Property Owners)
- Property address and legal description
- Property ownership documentation
- Property photographs and media
- Amenities and features descriptions
- House rules and policies
- Property management instructions
Communication and Correspondence
- Messages and communications with ANANA support or other users
- Feedback, complaints, and inquiries you submit
- Survey responses and reviews
2.2 Information Collected Automatically
Technical Information
- IP address and device identifier
- Browser type, operating system, and version
- Device hardware model and specifications
- Mobile device unique identifiers (UDID, GAID, IDFA)
Browsing and Usage Data
- Pages visited and features accessed
- Time spent on each page
- Search queries and filters applied
- Booking history and incomplete transactions
- Links clicked and content interactions
- Referral source (how you found ANANA)
Location Information
- Approximate location based on IP address (city/country level)
- GPS location data (if you enable location services on your device)
- Property location information
2.3 Information from Third Parties
- Identity verification services (age, address, legal status verification)
- Payment processors and financial institutions
- Social media platforms (if you connect your account to ANANA)
- Public records and property registries
- Guest reviews and ratings from other platforms
- Service providers (cleaning services, maintenance contractors)
3. Purposes of Processing Your Personal Data
3.1 Primary (Necessary) Purposes
We process your personal data for the following essential purposes:
| Purpose | Description | Legal Basis |
|---|---|---|
| Account Management | Create and maintain your account, verify identity, and manage user credentials | Contract execution |
| Booking Processing | Process reservations, confirm bookings, and manage guest check-in/check-out | Contract execution |
| Payment Processing | Process payments, issue refunds, and reconcile transactions | Contract execution and legal obligation |
| Service Delivery | Provide platform functionality, property management services, and customer support | Contract execution |
| Communication | Send transactional emails (confirmations, receipts, service notifications) | Contract execution |
| Legal Compliance | Comply with tax obligations, rental regulations, anti-money laundering laws | Legal obligation |
| Fraud Prevention | Detect and prevent fraudulent transactions, unauthorized access, and security threats | Legitimate interest |
| Service Improvement | Analyze platform performance, identify bugs, and troubleshoot technical issues | Legitimate interest |
3.2 Secondary (Optional) Purposes
With your consent, we may process your personal data for:
- Marketing Communications: Promotional emails, newsletters, special offers, and seasonal campaigns related to ANANA services
- Personalization: Tailoring the platform experience to your preferences, property recommendations, and custom content
- Analytics and Research: Statistical analysis, market research, user behavior studies, and platform optimization
- Guest Reviews and Ratings: Collecting feedback and displaying reviews to improve services and inform other users
- Social Media Integration: Sharing booking information or experiences on social media platforms (at your direction)
- Event Invitations: Invitations to ANANA events, webinars, training sessions, or networking opportunities
3.3 Right to Opt Out
You may opt out of secondary (optional) purposes at any time without affecting your ability to use ANANA’s core services. To opt out of marketing communications or personalization, you may:
- Click the “Unsubscribe” link in any promotional email
- Log into your account and adjust your communication preferences
- Correo electrónico privacy@ananahomes.com with your opt-out request
5. Legal Basis for Processing
Under Mexican data protection laws, ANANA’s processing of your personal data is justified under the following legal bases:
5.1 Contractual Necessity
Processing is necessary to enter into or perform a contract with you. Examples include:
- Creating your account and maintaining user credentials
- Processing bookings and payments
- Delivering property management or platform services
5.2 Legal Obligation
Processing is required by Mexican law, including:
- Tax reporting to the Servicio de Administración Tributaria (SAT)
- Anti-money laundering compliance under Federal Law to Prevent and Identify Illicit Proceeds Operations
- Immigration and guest registration requirements in Jalisco and Mexico
- Financial reporting and audit requirements
5.3 Legitimate Interest
ANANA processes personal data for our legitimate business interests, which are balanced against your rights and freedoms:
- Fraud prevention and security protection
- Service improvement and platform optimization
- Analytics and market research
- Dispute resolution and collection of unpaid fees
5.4 Consent
For optional purposes not covered above (marketing, personalization, social media integration), ANANA relies on your express consent. You may withdraw consent at any time without penalty.
6. Your ARCO Rights
Under Mexican data protection laws, you have the right to exercise your ARCO rights: Access, Rectification, Cancellation, and Opposition.
6.1 Right to Access (Acceso)
You have the right to obtain confirmation of whether ANANA processes your personal data and to access a complete copy of that information in a clear, understandable format. ANANA will provide your data within 15 business days of your request.
6.2 Right to Rectification (Rectificación)
You may request correction of inaccurate, incomplete, or outdated personal information. ANANA will make the requested corrections within 15 business days and notify you and relevant third parties of the changes (where required).
6.3 Right to Cancellation/Deletion (Cancelación)
You may request deletion of your personal information in the following circumstances:
- The information is no longer necessary for the purposes for which it was collected
- You withdraw consent for optional processing
- You oppose processing based on legitimate interests and no other legal basis exists
- Processing violates applicable law
6.4 Right to Opposition (Oposición)
You may object to the processing of your personal data when:
- Processing is based on ANANA’s legitimate interests (excluding obligatory legal processing)
- Processing is for direct marketing purposes
- Processing is for profiling or automated decision-making that affects you
6.5 Right to Data Portability
You may request a copy of your personal data in a structured, commonly used, machine-readable format (such as CSV or JSON) to transfer to another data controller.
6.6 How to Exercise Your ARCO Rights
- Email your request to privacy@ananahomes.com with the subject line “ARCO Request – [Your Name]“
- Include the following information:
- Your full legal name
- Email address or phone number associated with your account
- Copy of government-issued identification (national ID, passport, driver’s license)
- Specific ARCO right you wish to exercise (Access, Rectification, Cancellation, Opposition)
- Clear description of the personal information involved
- Preferred method of receiving the response (email, certified mail, or in-person pickup)
- ANANA’s Response Timeframe:
- Initial acknowledgment: 5 business days
- Substantive response: 20 business days (extendable by an additional 10 business days if the request is complex)
- Additional Submissions: If ANANA denies your request, you will receive written explanation of the denial. You may appeal to ANANA’s Data Protection Officer or file a complaint with the competent authority.
6.7 No Discrimination
ANANA will not discriminate against you for exercising your ARCO rights. We will not refuse service, charge additional fees, or treat you unfavorably because you requested access, correction, deletion, or opposed processing of your personal data.
7. Data Retention Policy
7.1 General Retention Periods
ANANA retains personal information for the minimum period necessary to achieve the purposes for which it was collected:
| Type of Information | Retention Period | Reason |
|---|---|---|
| Account Information | Duration of account + 3 years after account closure | Legal and tax compliance, dispute resolution |
| Transaction and Payment Records | 7 years | Mexican tax law requires 5 years minimum; we retain 7 years for legal compliance |
| Guest Booking Information | 3 years after checkout | Guest service, dispute resolution, refund claims |
| Communication Records | 2 years | Dispute resolution, quality assurance, legal protection |
| Marketing and Analytics Data | 1 year (unless you opt out) | Service optimization, performance analysis |
| IP Address and Device Identifiers | 90 days | Security, fraud prevention, platform optimization |
| Cookies and Tracking Data | As specified in cookie settings; max 24 months | User preferences, analytics |
7.2 Longer Retention for Legal Reasons
ANANA may retain personal information longer than stated above if:
- Required by applicable law (tax, regulatory, immigration requirements)
- Necessary to defend legal claims or disputes
- Related to ongoing fraud investigations or security threats
- You have not requested deletion and consent to extended retention
7.3 Secure Deletion
When personal information is no longer needed, ANANA will securely delete or anonymize it using industry-standard methods. Deleted or anonymized data cannot be used to identify you.
8. Data Security
8.1 Security Measures
ANANA implements comprehensive security controls to protect your personal information from unauthorized access, alteration, disclosure, or destruction:
- Encryption: Data in transit uses HTTPS/TLS encryption; sensitive data at rest is encrypted using AES-256 or equivalent
- Access Controls: Personal information is accessible only to authorized employees, contractors, and service providers with a legitimate business need
- Authentication: Multi-factor authentication (MFA) for sensitive accounts and administrative access
- Firewalls and Intrusion Detection: Network firewalls and intrusion prevention systems protect against unauthorized access
- Regular Audits and Testing: Vulnerability assessments, penetration testing, and security audits conducted regularly
- Backup and Disaster Recovery: Regular backups stored securely to prevent data loss; disaster recovery plans tested periodically
- Employee Training: Data protection and privacy training for all ANANA employees
8.2 Limitations of Security
8.3 Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, ANANA will:
- Notify you without undue delay (within 72 hours of discovery)
- Describe the nature and scope of the breach
- Explain the likely consequences
- Provide measures we have taken or recommend to mitigate harm (password reset, credit monitoring, etc.)
- Provide contact information for further assistance
10. Third-Party Links and Services
10.1 External Links
ANANA’s websites and platforms may contain links to third-party websites, including online travel agencies, payment processors, social media platforms, and partner services. This Privacy Policy applies only to ANANA-controlled domains. We are not responsible for the privacy practices of third-party websites.
10.2 Third-Party Services
ANANA integrates with third-party services including:
- Booking.com, Airbnb, Vrbo, Expedia (distribution partners)
- Stripe, PayPal, Mercado Pago (payment processors)
- Google, Facebook, Instagram (analytics and advertising)
- WhatsApp, Twilio (communication services)
When you interact with these services, their privacy policies apply. We encourage you to review their privacy disclosures before sharing information.
10.3 Social Media Integration
If you choose to connect your ANANA account to social media platforms (Facebook, Google, Instagram), ANANA may access and store certain profile information (name, email, profile picture) as permitted by the social media platform. You may revoke social media integration at any time through your account settings.
11. Children’s Privacy
ANANA’s Services are not intended for children under the age of 18 (“Minor”). ANANA does not knowingly collect personal information from Minors without verifiable parental consent.
11.1 Parental Consent
If you believe your child has provided personal information to ANANA without your consent, please contact us immediately at privacy@ananahomes.com. We will investigate and delete the information within a reasonable timeframe.
11.2 Account by Legal Guardians
If you create an ANANA account on behalf of a Minor, you represent that you are the legal guardian and accept full responsibility for the account and any activities conducted under it.
12. Policy Updates
12.1 Changes to This Policy
ANANA may update this Privacy & Cookie Policy at any time to reflect changes in our practices, technology, legal requirements, or other factors. Changes will be effective immediately upon posting to the website, unless otherwise specified. The “Effective Date” at the top of this Policy will be updated to reflect the latest revision.
12.2 Material Changes
For material changes that affect your rights or how we use your information, ANANA will provide advance notice through:
- Prominent notice on our website
- Email notification to your registered email address
- Pop-up notification on your account dashboard
12.3 Your Acceptance
Your continued use of ANANA’s Services following notification of changes constitutes your acceptance of the revised Policy. If you do not agree with changes, you may request data deletion or terminate your account.
13. Contact Information
Data Protection Officer and Privacy Contact
ANANA Hospitality S.A.S. de C.V.
Address: Avenida Miguel Hidalgo y Costilla 1323, Colonia Centro, 44100 Guadalajara, Jalisco, Mexico
Email (Privacy Inquiries): privacy@ananahomes.com
Email (ARCO Requests): privacy@ananahomes.com (Subject: “ARCO Request – [Your Name]”)
Email (Legal & Data Protection): legal@ananahomes.com
Telephone: Available upon request
Business Hours: Monday – Friday, 9:00 AM – 6:00 PM (CST)
Tax ID (RFC): AHO2410314M7
Legal Representative: Guillem Pasarín Real, Administrador General Único
Regulatory Authorities
If you have concerns about ANANA’s privacy practices that we cannot resolve, you may lodge a complaint with Mexico’s data protection authority:
Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI)
Avenida Paseo de la Reforma 931, Piso 6, Colonia Juárez, Cuauhtémoc, 06598 Mexico City
Phone: +52 (55) 1925-2700
Website: https://www.gob.mx/inai
Response Timeline
ANANA commits to responding to privacy inquiries and ARCO requests within the timeframes specified in this Policy. If you do not receive a response within the specified period, you may escalate your request to the Data Protection Officer or file a complaint with INAI.