Legal

Privacy Policy

Last updated — Leer en español

Golf in Mexico° is an editorial guide and a bespoke trip-planning service. We collect personal data in two places only: the forms you choose to fill in, and the analytics that measure how the site is used. This page explains exactly what is collected, who receives it, how long we keep it, and how to make us delete it.

01

Who is responsible for your data

Golf in Mexico° (“Golf in Mexico”, “we”, “us”) is the data controller — the responsable in the sense of Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) — for the personal data collected through golf-in-mexico.com.

You can reach us about anything on this page at hello@golf-in-mexico.com. We answer privacy requests ourselves; there is no help desk in between.

02

What we collect, and where

Every piece of personal data we hold about you comes from one of the forms below. None of them is required to read the site — you can browse every guide and article without giving us anything.

Newsletter signup (site footer, articles, destination guides)
Your email address.
Trip Builder (/trip-builder)
Your name, email address, and phone number, plus the trip details you enter: destinations, trip type, preferred months, trip length, package, and budget range. If you leave the wizard part-way after entering your contact details, we keep what you had entered up to that point.
Trip Builder exit capture
Your email address and the trip preferences you had selected before leaving.
Destination waitlist / guide requests
Your email address and the destination or region you asked about.
General inquiries
Your email address and any details you include.
03

Technical and usage data

Alongside form data, the analytics tools described below record technical information automatically: your IP address (used to approximate your city or country, then discarded by the provider), device and browser type, screen size, referring website, the pages you view and how long you spend on them, and your clicks and scrolling.

When you arrive from a campaign link, we also store the campaign parameters on that URL — utm_source, utm_medium, utm_campaign, utm_term, utm_content — and the Google (gclid) and Meta (fbclid) click identifiers. These sit in your browser's session storage for the duration of your visit and are attached to a form submission if you make one, so we know which channel brought you. Close the tab and they are gone.

04

Why we use it

We use your data for these purposes and no others:

To answer you and plan your trip
Replying to inquiries, building trip proposals, and following up on a request you started.
To send the newsletter
Only if you asked for it. Every email carries a one-click unsubscribe link.
To understand and improve the site
Aggregate analytics — which guides get read, where people drop off, what breaks on which device.
To measure our advertising
Attributing signups to the campaign that produced them.

We do not sell your personal data, we do not rent or trade our contact lists, and we do not use your data to make automated decisions about you.

05

Who else receives it

We run a small stack of third-party services. Each one is named here with what it receives. All of them are established providers operating under their own privacy terms, and several process data on servers in the United States — by using the site you acknowledge that transfer.

HubSpot (CRM and email)
Receives every form submission and stores it as a contact record. HubSpot also sets a cookie (hutk) that links your later visits to your contact record, and receives the page URL you submitted from.
Google Analytics 4 (via Google Tag Manager)
Receives page views, events, and the technical data above. Used for aggregate traffic measurement.
Meta Pixel (Facebook / Instagram)
Receives page views and lead events so we can measure and target advertising on Meta platforms.
Microsoft Clarity
Records session replays and heatmaps — a reconstruction of your mouse movement, clicks, and scrolling on the page. Clarity masks text input by default, so what you type into a form is not captured in the replay.
Vercel (hosting)
Serves the site and keeps standard server logs, including IP addresses, for security and performance.

We will also disclose data where the law requires it — a valid order from a competent authority — and we would tell you unless legally barred from doing so.

06

Cookies and similar technologies

The services above set cookies and use your browser's local and session storage. In practical terms there are three kinds: strictly necessary storage that makes the site work (for example, remembering that you have already seen the intro animation), analytics cookies from Google Analytics and Microsoft Clarity, and advertising cookies from Meta and HubSpot.

We do not currently show a cookie consent banner, which means analytics and advertising cookies load when you arrive. If you would rather not be measured, you have direct control:

  • Block or delete cookies in your browser settings — every major browser can do this per-site.
  • Turn on “Do Not Track” or use a tracker-blocking extension; our analytics and pixel scripts are blocked by all of the common ones.
  • Opt out of Google Analytics specifically with Google's browser add-on at tools.google.com/dlpage/gaoptout.
  • Manage Meta ad personalisation in your Facebook or Instagram account settings.

Blocking any of this has no effect on the site's content or on your ability to contact us.

07

How long we keep it

Trip and inquiry data stays in our CRM for as long as the conversation is live and for up to 24 months afterwards, so that a returning traveller does not have to start over. Newsletter subscribers are kept until they unsubscribe. Analytics data follows each provider's own retention window — 14 months for Google Analytics, 30 days for Microsoft Clarity session recordings.

You can shorten any of this by asking us to delete your data, which we do without argument.

08

Your rights

Under the LFPDPPP you hold what Mexican law calls your derechos ARCO — the right to Access the data we hold about you, to Rectify it if it is wrong, to Cancel it (have it deleted), and to Object to a particular use. You may also withdraw consent at any time, and limit the use or disclosure of your data.

If you are in the European Economic Area or the United Kingdom, the equivalent GDPR rights apply, including data portability and the right to lodge a complaint with your supervisory authority. If you are a California resident, you have the CCPA rights to know, delete, and opt out of sale — and, as stated above, we do not sell personal data.

To exercise any of these, email hello@golf-in-mexico.com and tell us what you want done. We do not require a form or a particular format. We will confirm your identity, act within 20 business days, and never charge you for it.

09

How we protect it

The site is served over HTTPS only. Form submissions travel encrypted to HubSpot, and access to the CRM is limited to the two founders and restricted by two-factor authentication. We keep no separate database of our own and no copies of your data outside the services named above.

No system is perfect. If a breach ever affected your data, we would notify you and the relevant authority as the law requires.

10

Children

The site is aimed at adults planning golf travel. We do not knowingly collect data from anyone under 18. If a minor's data has reached us, write to us and we will delete it.

11

Changes to this policy

When we add a tool or change how we use data, we update this page and move the “last updated” date at the top. Material changes will be announced in the newsletter. The version you are reading now is the one that applies.

12

Contact

Questions, corrections, deletions, or a complaint about how we have handled your data — write to hello@golf-in-mexico.com. A real person reads it.

If you are not satisfied with our answer, you may file a complaint with Mexico's data-protection authority.

Want to see, correct, or delete your data?

hello@golf-in-mexico.com