Privacy Policy

Effective: April 16, 2026 · Version 1.0

Compliant with GDPR · CCPA · LFPDPPP (México)

Contents

1. Overview

Kapitec Soluciones ("we", "us", "our") operates Safe Travel México at safetravelmexico.com. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service.

We are committed to protecting your privacy and complying with applicable data protection laws including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP).

2. Data We Collect

Account data (if you register): name, email address, hashed password, subscription tier, registration date.

Assessment data: travel destinations, travel dates, trip purpose, accommodation type, experience level. This data is used solely to generate your safety assessment and improve our models.

Payment data: subscription tier, billing period, payment status. We do NOT store full card numbers. Payment processing is handled by Stripe, Inc. (see Stripe's Privacy Policy). We store a Stripe customer ID.

Usage data (automatically collected): pages visited, features used, search queries, assessment completions, click events. This data is anonymized and aggregated.

Technical data: IP address (anonymized), browser type, device type, operating system, referrer URL, session duration.

Newsletter subscribers: email address, subscription date, unsubscribe status. No name required.

What we do NOT collect: precise geolocation, biometric data, health data, government IDs, financial account numbers.

3. How We Use Your Data

We use your data to:

  • Provide and improve the Service (legal basis: contract performance)
  • Process payments and manage subscriptions (legal basis: contract)
  • Send transactional emails (account confirmation, receipts, password reset) (legal basis: contract)
  • Send marketing emails if you opted in (legal basis: consent — revocable)
  • Analyze usage patterns to improve features (legal basis: legitimate interest)
  • Detect and prevent fraud and abuse (legal basis: legitimate interest)
  • Comply with legal obligations (legal basis: legal obligation)

We do NOT sell your personal data. We do NOT use your data for automated profiling that produces legal or significant effects without human review.

4. Data Sharing

We share data only with trusted service providers who help operate the Service:

Stripe, Inc.Payment processingUSA
SendGrid (Twilio)Transactional email deliveryUSA
Google Analytics (GA4)Anonymized usage analyticsUSA (data anonymized)
DreamhostWeb hosting & databaseUSA

We may disclose data when required by law, court order, or to protect the rights, property, or safety of the Company, our users, or the public.

In the event of a merger, acquisition, or sale of assets, user data may be transferred with 30 days notice and the ability to delete your account before transfer.

5. Cookies & Tracking

We use the following categories of cookies:

EssentialAlways on

Authentication tokens, session management, cookie consent preference. Cannot be disabled.

Analytics

Google Analytics 4 (anonymized IP, no cross-site tracking). Plausible (privacy-first, cookieless).

Functional

Remember your preferences (language, theme). localStorage only.

You can manage cookie preferences via the cookie banner or your browser settings. Rejecting analytics cookies does not affect Service functionality.

6. Data Retention

  • Account data: retained until account deletion, then deleted within 30 days
  • Assessment data: retained for 24 months after last activity (used to improve models)
  • Payment records: retained for 7 years (legal/tax requirement)
  • Analytics data: aggregated, anonymized data retained indefinitely; raw logs deleted after 14 months
  • Email subscription data: retained until unsubscribe + 30 days
  • Backup copies: deleted within 90 days of primary deletion

7. Your Rights (GDPR — EU/EEA Users)

If you are in the EU or EEA, you have the right to:

  • Access: request a copy of your personal data
  • Rectification: correct inaccurate data
  • Erasure: request deletion ("right to be forgotten")
  • Restriction: limit how we process your data
  • Portability: receive your data in machine-readable format
  • Object: opt out of legitimate-interest processing
  • Withdraw consent: revoke consent at any time (e.g., unsubscribe)
  • Complain: lodge a complaint with your national DPA

To exercise these rights, email privacy@safetravel.mx. We will respond within 30 days.

8. California Rights (CCPA/CPRA)

California residents have the right to:

  • Know what personal information we collect and how we use it
  • Request deletion of your personal information
  • Opt out of the sale or sharing of your personal information
  • Non-discrimination for exercising CCPA rights
  • Correct inaccurate personal information (CPRA)
  • Limit use of sensitive personal information (CPRA)

We do not sell personal information. To exercise rights, email privacy@safetravel.mx with subject "CCPA Request".

9. Mexico Rights (LFPDPPP)

In accordance with Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), you have ARCO rights:

  • Acceso (Access): know what data we hold about you
  • Rectificación (Rectification): correct your data
  • Cancelación (Cancellation): request deletion
  • Oposición (Objection): object to specific processing

To exercise ARCO rights, contact our Privacy Officer at privacy@safetravel.mx. We will respond within 20 business days as required by LFPDPPP. You may also file a complaint with INAI (Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales) at inai.org.mx.

10. Security

We implement industry-standard security measures including:

  • TLS/HTTPS encryption for all data in transit
  • bcrypt hashing (cost 12) for passwords — we never store plaintext passwords
  • JWT tokens with 24h expiry for authentication sessions
  • SQL injection prevention via prepared statements in all database queries
  • Rate limiting on authentication endpoints
  • Regular security reviews

No system is 100% secure. In the event of a data breach affecting your rights and freedoms, we will notify you within 72 hours of becoming aware of the breach (as required by GDPR), and within the timeframe required by applicable Mexican law.

11. Children's Privacy

The Service is not directed to children under 18 years of age. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us and we will delete it promptly.

12. International Data Transfers

Your data may be processed in the United States (Dreamhost, Stripe, SendGrid, Google) and the European Union. When transferring data from the EU/EEA, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) as approved by the European Commission.

By using the Service from outside Mexico or the US, you consent to having your data processed in those countries, subject to this Privacy Policy.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (if registered) and update the "Effective" date above. We encourage you to review this Policy periodically.

14. Contact / Privacy Officer

For privacy questions, data requests, or complaints:

Privacy Officer — Kapitec Soluciones

Email: privacy@safetravel.mx

Subject line: "Privacy Request — [your request type]"

Response time: 30 days (GDPR) / 20 business days (LFPDPPP)

See also our Terms of Service for usage conditions.

GDPR CompliantCCPA CompliantLFPDPPP CompliantNo Data Sales