01Who is responsible for your data
Golf in Mexico° (“Golf in Mexico”, “we”, “us”) is the data controller — the responsable in the sense of Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) — for the personal data collected through golf-in-mexico.com.
You can reach us about anything on this page at hello@golf-in-mexico.com. We answer privacy requests ourselves; there is no help desk in between.
02What we collect, and where
Every piece of personal data we hold about you comes from one of the forms below. None of them is required to read the site — you can browse every guide and article without giving us anything.
- Newsletter signup (site footer, articles, destination guides)
- Your email address.
- Trip Builder (/trip-builder)
- Your name, email address, and phone number, plus the trip details you enter: destinations, trip type, preferred months, trip length, package, and budget range. If you leave the wizard part-way after entering your contact details, we keep what you had entered up to that point.
- Trip Builder exit capture
- Your email address and the trip preferences you had selected before leaving.
- Destination waitlist / guide requests
- Your email address and the destination or region you asked about.
- General inquiries
- Your email address and any details you include.
03Technical and usage data
Alongside form data, the analytics tools described below record technical information automatically: your IP address (used to approximate your city or country, then discarded by the provider), device and browser type, screen size, referring website, the pages you view and how long you spend on them, and your clicks and scrolling.
When you arrive from a campaign link, we also store the campaign parameters on that URL — utm_source, utm_medium, utm_campaign, utm_term, utm_content — and the Google (gclid) and Meta (fbclid) click identifiers. These sit in your browser's session storage for the duration of your visit and are attached to a form submission if you make one, so we know which channel brought you. Close the tab and they are gone.
04Why we use it
We use your data for these purposes and no others:
- To answer you and plan your trip
- Replying to inquiries, building trip proposals, and following up on a request you started.
- To send the newsletter
- Only if you asked for it. Every email carries a one-click unsubscribe link.
- To understand and improve the site
- Aggregate analytics — which guides get read, where people drop off, what breaks on which device.
- To measure our advertising
- Attributing signups to the campaign that produced them.
We do not sell your personal data, we do not rent or trade our contact lists, and we do not use your data to make automated decisions about you.
05Who else receives it
We run a small stack of third-party services. Each one is named here with what it receives. All of them are established providers operating under their own privacy terms, and several process data on servers in the United States — by using the site you acknowledge that transfer.
- HubSpot (CRM and email)
- Receives every form submission and stores it as a contact record. HubSpot also sets a cookie (hutk) that links your later visits to your contact record, and receives the page URL you submitted from.
- Google Analytics 4 (via Google Tag Manager)
- Receives page views, events, and the technical data above. Used for aggregate traffic measurement.
- Meta Pixel (Facebook / Instagram)
- Receives page views and lead events so we can measure and target advertising on Meta platforms.
- Microsoft Clarity
- Records session replays and heatmaps — a reconstruction of your mouse movement, clicks, and scrolling on the page. Clarity masks text input by default, so what you type into a form is not captured in the replay.
- Vercel (hosting)
- Serves the site and keeps standard server logs, including IP addresses, for security and performance.
We will also disclose data where the law requires it — a valid order from a competent authority — and we would tell you unless legally barred from doing so.
06Cookies and similar technologies
The services above set cookies and use your browser's local and session storage. In practical terms there are three kinds: strictly necessary storage that makes the site work (for example, remembering that you have already seen the intro animation), analytics cookies from Google Analytics and Microsoft Clarity, and advertising cookies from Meta and HubSpot.
We do not currently show a cookie consent banner, which means analytics and advertising cookies load when you arrive. If you would rather not be measured, you have direct control:
- Block or delete cookies in your browser settings — every major browser can do this per-site.
- Turn on “Do Not Track” or use a tracker-blocking extension; our analytics and pixel scripts are blocked by all of the common ones.
- Opt out of Google Analytics specifically with Google's browser add-on at tools.google.com/dlpage/gaoptout.
- Manage Meta ad personalisation in your Facebook or Instagram account settings.
Blocking any of this has no effect on the site's content or on your ability to contact us.
07How long we keep it
Trip and inquiry data stays in our CRM for as long as the conversation is live and for up to 24 months afterwards, so that a returning traveller does not have to start over. Newsletter subscribers are kept until they unsubscribe. Analytics data follows each provider's own retention window — 14 months for Google Analytics, 30 days for Microsoft Clarity session recordings.
You can shorten any of this by asking us to delete your data, which we do without argument.
08Your rights
Under the LFPDPPP you hold what Mexican law calls your derechos ARCO — the right to Access the data we hold about you, to Rectify it if it is wrong, to Cancel it (have it deleted), and to Object to a particular use. You may also withdraw consent at any time, and limit the use or disclosure of your data.
If you are in the European Economic Area or the United Kingdom, the equivalent GDPR rights apply, including data portability and the right to lodge a complaint with your supervisory authority. If you are a California resident, you have the CCPA rights to know, delete, and opt out of sale — and, as stated above, we do not sell personal data.
To exercise any of these, email hello@golf-in-mexico.com and tell us what you want done. We do not require a form or a particular format. We will confirm your identity, act within 20 business days, and never charge you for it.
09How we protect it
The site is served over HTTPS only. Form submissions travel encrypted to HubSpot, and access to the CRM is limited to the two founders and restricted by two-factor authentication. We keep no separate database of our own and no copies of your data outside the services named above.
No system is perfect. If a breach ever affected your data, we would notify you and the relevant authority as the law requires.
10Children
The site is aimed at adults planning golf travel. We do not knowingly collect data from anyone under 18. If a minor's data has reached us, write to us and we will delete it.
11Changes to this policy
When we add a tool or change how we use data, we update this page and move the “last updated” date at the top. Material changes will be announced in the newsletter. The version you are reading now is the one that applies.
12Contact
Questions, corrections, deletions, or a complaint about how we have handled your data — write to hello@golf-in-mexico.com. A real person reads it.
If you are not satisfied with our answer, you may file a complaint with Mexico's data-protection authority.