OUR PRIVACY POLICY

Welcome to Aloha Surf Nosara Vacation Rentals (short: Aloha Surf Nosara)

ALOHA’S PRIVACY POLICY

LAST UPDATED AUGUST 7, 2023

At Aloha Surf Nosara Vacation Rentals (“Aloha Surf Nosara”, “we”, “us”, “our”), accessible from alohasurfnosara.com, one of our main priorities is the privacy of our visitors.

This Privacy Policy document contains types of information that is collected and recorded by Aloha Surf Nosara and how we use it.

If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us.

This Privacy Policy applies only to our online activities and is valid for visitors to our website with regard to the information that they shared and/or collect in Aloha Surf Nosara. This policy is not applicable to any information collected offline or via channels other than this website.

Consent

By using our website, you hereby consent to our Privacy Policy and agree to its terms.

Owner and Data Controller

Aloha Surf Nosara Vacation Rentals
Calle Los Mangos, Nosara, Guanacaste, Costa Rica
CR VAT No:
Legal Representative: Tyler Marsh

Owner contact email: alohasurfnosara@gmail.com

Information we collect

The personal information that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point we ask you to provide your personal information.

If you contact us directly, we may receive additional information about you such as your name, email address, phone number, the contents of the message and/or attachments you may send us, and any other information you may choose to provide.

    How we use your information

    The purposes of processing

    The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following: Contacting the User, Registration and authentication provided directly by this Application, Analytics and SPAM protection.

    For specific information about the Personal Data used for each purpose, the User may refer to the section “Detailed information on the processing of Personal Data”.

    Detailed information on the processing of Personal Data

    Personal Data is collected for the following purposes and using the following services:

    Wordpress self-hosted

    Key components of this Application are built and run directly by the Owner by making use of the software listed below.

    WordPress (self-hosted) (this Application)

    This Application is built and run by the Owner via a CMS software (Content Management System) called WordPress.

    Personal Data processed: Data communicated while using the service; Usage Data.

    Analytics

    The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.

    Google Analytics with anonymized IP (Google LLC)

    Google Analytics is a web analysis service provided by Google LLC (“Google”). Google utilizes the Data collected to track and examine the use of this Application, to prepare reports on its activities and share them with other Google services.

    Google may use the Data collected to contextualize and personalize the ads of its own advertising network.

    This integration of Google Analytics anonymizes your IP address. It works by shortening Users’ IP addresses within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the complete IP address be sent to a Google server and shortened within the US.

    Personal Data processed: Trackers; Usage Data.

    Place of processing: United States – Privacy PolicyOpt Out.

    Google Ads conversion tracking 

    –> Currently no Google Ads conversion tracking in place.

    Google Ads conversion tracking is an analytics service provided by Google LLC or by Google Ireland Limited, depending on how the Owner manages the Data processing, that connects data from the Google Ads advertising network with actions performed on this Website.

    Personal Data processed: Trackers; Usage Data.

    Legal basis for processing: Consent.

    Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.

    Legal basis for data transfer: Standard data protection clauses.

    Category of personal information collected according to the CCPA: internet information.

    This processing constitutes:

    • a sale according to the CCPA, VCDPA, CPA, CTDPA and UCPA
    Meta ads conversion tracking (Meta pixel) (Meta Platforms, Inc.) 

    –> Currently not Meta ads conversion tracking in place.

    Meta ads conversion tracking (Meta pixel) is an analytics service provided by Meta Platforms, Inc. that connects data from the Meta Audience Network with actions performed on this Website. The Meta pixel tracks conversions that can be attributed to ads on Facebook, Instagram and Meta Audience Network.

    Personal Data processed: Trackers; Usage Data.

    Legal basis for processing: Consent.

    Place of processing: United States – Privacy PolicyOpt out.

    Legal basis for data transfer: Standard data protection clauses.

    Category of personal information collected according to the CCPA: internet information.

    This processing constitutes:

    • a sale according to the CCPA, VCDPA, CPA, CTDPA and UCPA
    Tag Management

    This type of service helps the Owner to manage the tags or scripts needed on this Application in a centralized fashion.
    This results in the Users’ Data flowing through these services, potentially resulting in the retention of this Data.

    Google Tag Manager (Google LLC)

    Google Tag Manager is a tag management service provided by Google LLC.

    Personal Data processed: Trackers; Usage Data.

    Place of processing: United States – Privacy Policy.

    Contacting the User

    Contact form (this Application)

    By filling in the contact form with their Data, the User authorizes this Application to use these details to reply to requests for information, quotes or any other kind of request as indicated by the form’s header.

    Personal Data processed: email address; first name; phone number.

    Registration and authentication provided directly by this Application

    By registering or authenticating, Users allow this Application to identify them and give them access to dedicated services. The Personal Data is collected and stored for registration or identification purposes only. The Data collected are only those necessary for the provision of the service requested by the Users.

    Direct registration (this Application)

    The User registers by filling out the registration form and providing the Personal Data directly to this Application.

    Personal Data processed: email address; first name; last name; phone number.

    SPAM protection

    This type of service analyzes the traffic of this Application, potentially containing Users’ Personal Data, with the purpose of filtering it from parts of traffic, messages and content that are recognized as SPAM.

    Google reCAPTCHA (Google LLC)

    Google reCAPTCHA is a SPAM protection service provided by Google LLC.

    The use of reCAPTCHA is subject to the Google privacy policy and terms of use.

    Personal Data processed: answers to questions; clicks; keypress events; motion sensor events; mouse movements; scroll position; touch events; Trackers; Usage Data.

    Place of processing: United States – Privacy Policy.

    Displaying content from external platforms

    This type of service allows you to view content hosted on external platforms directly from the pages of this Application and interact with them.
    This type of service might still collect web traffic data for the pages where the service is installed, even when Users do not use it.

    Google Fonts (Google LLC)

    Google Fonts is a typeface visualization service provided by Google LLC that allows this Application to incorporate content of this kind on its pages.

    Personal Data processed: Trackers; Usage Data.

    Place of processing: United States – Privacy Policy.

    Retention of Your Personal Data

    Aloha Surf Nosara will retain your Personal information only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your personal data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.

    Aloha Surf Nosara will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our website, or we are legally obligated to retain this data for longer time periods.

    Transfer of Your Personal Data

    Your information, including Personal Data, is processed at the Aloha Surf Nosara operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those from your jurisdiction.

    Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

    Aloha Surf Nosara will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.

    Delete Your Personal Data

    You have the right to delete or request that we assist in deleting the Personal Data that we have collected about you.

    Please note, however, that we may need to retain certain information when we have a legal obligation or lawful basis to do so.

    Disclosure of Your Personal Data

    Business Transactions

    If Aloha Surf Nosara is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.

    Law enforcement

    Under certain circumstances, Aloha Surf Nosara may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

    Other legal requirements

    The Company may disclose your Personal Data in the good faith belief that such action is necessary to:

    • Comply with a legal obligation
    • Protect and defend the rights or property of the Company
    • Prevent or investigate possible wrongdoing in connection with the Service
    • Protect the personal safety of Users of the Service or the public
    • Protect against legal liability

    Security of Your Personal Data

    The security of your Personal Data is important to us, but remember that no method of transmission over the internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

    Log Files

    Aloha Surf Nosara follows a standard procedure of using log files. These files log visitors when they visit websites. All hosting companies do this and are a part of hosting services’ analytics. The information collected by log files includes internet protocol (IP) addresses, browser type, Internet Service Provider (ISP), date and time stamp, referring/exit pages, and possibly the number of clicks. These are not linked to any information that is personally identifiable. The purpose of the information is to analyze trends, administer the site, track users’ movement on the website, and gather demographic information.

    When accessing the website by or through a mobile device, we may collect certain information automatically, including, but not limited to, the type of mobile device you use, your mobile device’s unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile internet browser you use, unique device identifiers and other diagnostic data.

    We may also collect information that your browser sends whenever you visit our website or when you access the service by or through a mobile device.

    Tracking Technologies and Cookies

    We use Cookies and similar tracking technologies to track the activity on website and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyze our website. The technologies we use may include:

    • Cookies or Browser Cookies. A cookie is a small file placed on your Device. You can instruct your browser to refuse all Cookies or to indicate when a cookie is being sent. However, if you do not accept Cookies, you may not be able to use some parts of our website. Unless you have adjusted your browser setting so that it will refuse cookies, our website may use Cookies.
    • Web Beacons. Certain sections of our website and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit Aloha Surf Nosara, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of a certain section and verifying system and server integrity).

      Advertising Partners Privacy Policies

      You may consult this list to find the Privacy Policy for each of the advertising partners of Aloha Surf Nosara.

      Third-party ad servers or ad networks uses technologies like Cookies, JavaScript, or Web Beacons that are used in their respective advertisements and links that appear on Aloha Surf Nosara, which are sent directly to users’ browser. They automatically receive your IP address when this occurs. These technologies are used to measure the effectiveness of their advertising campaigns and/or to personalize the advertising content that you see on websites that you visit.

      Note that Aloha Surf Nosara has no access to or control over these cookies that are used by third-party advertisers.

      Third-Party Privacy Policies

      Our Privacy Policy does not apply to other advertisers or websites. Thus, we are advising you to consult the respective Privacy Policies of these third-party ad servers for more detailed information. It may include their practices and instructions about how to opt out of specific options.

      You can choose to disable cookies through your individual browser options. To know more detailed information about cookie management with specific web browsers, it can be found on the browsers’ respective websites.

      Your Rights

      Under FDBR (Florida Digital Bill of Rights):

      • Access: Request access to your personal data.
      • Correction: Request correction of inaccurate personal data.
      • Deletion: Request deletion of personal data, subject to certain exceptions.
      • Opt-Out: Opt-out of the sale or sharing of personal data.

      Under OCPA (Oregon Consumer Privacy Act):

      • Access: Request access to specific pieces of personal data.
      • Correction: Request correction of inaccurate personal data.
      • Deletion: Request deletion of personal data.
      • Data Portability: Request to receive personal data in a portable and readily usable format.
      • Opt-Out: Opt-out of the sale of personal data.

      Under TDPSA (Texas Data Privacy and Security Act):

      • Access: Request access to personal data.
      • Correction: Request correction of inaccurate personal data.
      • Deletion: Request deletion of personal data.
      • Opt-Out: Opt-out of the sale of personal data.

      Under CCPA (California Consumer Privacy Act) and CPRA (California Privacy Rights Act):

      • Access: Request access to specific pieces of personal data collected about you.
      • Correction: Request correction of inaccurate personal data.
      • Deletion: Request deletion of personal data, subject to certain exceptions.
      • Data Portability: Request to receive personal data in a portable and readily usable format.
      • Opt-Out: Opt-out of the sale or sharing of personal data.
      • Limit Use of Sensitive Data: Request to limit the use and disclosure of sensitive personal data.
      • Non-Discrimination: You have the right not to be discriminated against for exercising any of your privacy rights.

      Under MCDPA (Montana Consumer Data Privacy Act):

      • Access: Request access to specific pieces of personal data.
      • Correction: Request correction of inaccurate personal data.
      • Deletion: Request deletion of personal data.
      • Data Portability: Request to receive personal data in a portable and readily usable format.
      • Opt-Out: Opt-out of the sale of personal data.
      • Limit Processing: Request to limit the processing of sensitive personal data.

      GDPR Data Protection Rights

      This section applies to all Users in the European Union, according to the General Data Protection Regulation (the “GDPR”), and, for such Users, supersedes any other possibly divergent or conflicting information contained in the privacy policy. Further details regarding the categories of Data processed, the purposes of processing, the categories of recipients of the Personal Data, if any, and further information about Personal Data can be found in the section titled “Detailed information on the processing of Personal Data” within this document.

      We would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following:

      The right to access – You have the right to request copies of your personal data. We may charge you a small fee for this service.

      The right to rectification – You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete the information you believe is incomplete.

      The right to erasure – You have the right to request that we erase your personal data, under certain conditions.

      The right to restrict processing – You have the right to request that we restrict the processing of your personal data, under certain conditions.

      The right to object to processing – You have the right to object to our processing of your personal data, under certain conditions.

      The right to data portability – You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.

      If you make a request, we have one month to respond to you. Please contact us if you would like to exercise any of these rights.

      Children’s Information

      Another part of our priority is adding protection for children while using the internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.

      Aloha Surf Nosara does not knowingly collect any Personal Identifiable Information from children under the age of 13. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records.

      Changes to this Privacy Policy

      We may update Our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.

      We will let you know via email and/or a prominent notice on this website, prior to the change becoming effective, and update the “Last updated” date at the top of this Privacy Policy.

      You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

      Definitions and Legal References

      Definitions and legal references

      Personal Data (or Data)

      Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.

      Usage Data

      Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.

      User

      The individual using this Application who, unless otherwise specified, coincides with the Data Subject.

      Data Subject

      The natural person to whom the Personal Data refers.

      Data Processor (or Processor)

      The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.

      Data Controller (or Owner)

      The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.

      This Application

      The means by which the Personal Data of the User is collected and processed.

      Service

      The service provided by this Application as described in the relative terms (if available) and on this site/application.

      European Union (or EU)

      Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.

      Cookie

      Cookies are Trackers consisting of small sets of data stored in the User’s browser.

      Tracker

      Tracker indicates any technology – e.g Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting – that enables the tracking of Users, for example by accessing or storing information on the User’s device.

      Contact Us

      If you have any questions about our Privacy Policy, you can contact us:

       

      Source

      Our Privacy Policy, including the Cookie Policy, has been prepared with the help of the following compliance solution privacy policy services: Termly and Iubenda