Legal
Privacy Policy
Last updated: 2026-05-29. We keep data handling simple, minimal, and transparent.
Casa Venturas ("we", "us") operates https://casaventuras.com and provides small-group tours in Puerto Rico. This policy explains what personal information we collect, why, how we protect it, and the rights you have. It is designed to comply with Puerto Rico Act 39 (Privacy Policy Notification) and Act 111-2005 (Citizen Information on Data Banks Security Act), the California Online Privacy Protection Act (CalOPPA), and the EU General Data Protection Regulation (GDPR) for visitors from the European Economic Area.
1.Who we are
Casa Venturas, San Juan, Puerto Rico. micasaventuras@gmail.com, +1 929 372 4529. We are the data controller for information collected through this website.
2.Information we collect
- Booking information: name, email, phone, tour date, number of guests. Submitted via our booking form and processed through Bókun (our booking engine).
- Contact form: name, email, message.
- Chat with Cavi (AI guide): Cavi runs entirely client-side in your browser as a deterministic intent matcher. No LLM API is called, no conversation content is sent to our servers, no transcript is retained anywhere. Your messages exist only in this tab and disappear when you close it.
- Technical data: IP address, browser type, pages visited. Collected automatically by our hosting provider (Cloudflare) for security and performance.
We do not sell your personal information. We do not use advertising cookies or cross-site trackers.
3.Why we collect it (legal basis)
- To confirm and operate your tour (performance of contract, GDPR Art. 6(1)(b)).
- To answer questions sent via our contact form or chat (legitimate interest).
- To comply with Puerto Rico tax and tourism regulations (legal obligation).
- To protect the site against fraud and abuse (legitimate interest).
4.Who we share it with (processors)
We rely on a small number of trusted service providers that process data strictly on our instructions:
- Bókun (a TripAdvisor company), booking engine and payment processing (PCI-DSS compliant). Bókun acts as data processor under a signed Data Processing Agreement.
- Stripe, payment card processing (PCI-DSS compliant). Card details are entered in a Stripe-hosted iframe and never reach our servers. Stripe acts as data processor under its standard Data Processing Agreement.
- Resend, transactional email delivery (booking confirmations, replies to contact messages).
- Cloudflare, website hosting, CDN, and DDoS protection.
- Google Analytics 4, website analytics, enabled only after your explicit consent on the cookie banner. Measurement ID
G-02DN83KF2B, IPs anonymized. See our Cookie Policy for details. - Nominatim (OpenStreetMap), geographic address autocomplete for the booking pickup field. Queries are proxied through our server; we do not retain Nominatim responses beyond the live request. Operated by the OpenStreetMap Foundation (UK) under the Open Data Commons license.
- YouTube, video embeds on our tour pages. Videos are loaded from
youtube-nocookie.comby default to minimize tracking; full youtube.com is allowed as a fallback for compatibility.
If you book one of our tours through a third-party platform such as Viator, TripAdvisor Experiences, GetYourGuide, or Airbnb Experiences, that platform is the data controller for your booking data. Their own privacy policies apply to those transactions, we only receive the information we need to operate the tour.
5.How long we keep it
- Booking records: 7 years (US tax retention requirement).
- Contact form messages: up to 2 years.
- Server logs: up to 30 days.
6.Your rights
You have the right to:
- Access the personal information we hold about you.
- Ask us to correct or delete it.
- Opt out of any future marketing messages (we do not currently send any).
- Receive your data in a portable format (GDPR Art. 20).
- Lodge a complaint with a data protection authority (e.g. Puerto Rico DACO, or your local EU authority).
To exercise any of these rights, email micasaventuras@gmail.com. We respond within 30 days. California residents may request a "Do Not Sell or Share" opt-out; note that we do not sell or share personal information for advertising purposes.
If you reside in Virginia, Colorado, Connecticut, Utah, Texas, Florida, Oregon, Montana, Iowa, Tennessee, Indiana, Delaware, Nebraska, New Hampshire, New Jersey, Maryland, or Minnesota, your state may grant rights similar to those above (access, correction, deletion, portability, opt-out of sale/share/targeted advertising). We treat such requests under the same 30-day response window and the same contact email. We do not engage in targeted advertising, profiling for legal effects, or sale of personal information.
We honor "Do Not Track" browser signals: we do not use cross-site tracking cookies, so no additional action is taken beyond our baseline minimal collection.
7.Data security and breach notification
All data is transmitted over HTTPS and stored in encrypted form by our processors. In the event of a security breach affecting personal information of Puerto Rico residents, we will notify affected individuals and the Puerto Rico Department of Consumer Affairs (DACO) within ten (10) days from the detection of the breach, as required by Act 111-2005. For California residents, we will notify affected individuals in the most expedient time possible and without unreasonable delay, as required by California Civil Code §1798.82. For EU residents, we will also notify the relevant supervisory authority within 72 hours as required by GDPR Art. 33.
8.International transfers
Several of our processors (Bókun, Stripe, Resend, Cloudflare, Google Analytics 4, YouTube) are based in or operated from the United States; each name links to that processor's Data Processing Agreement (DPA). If you are located in the European Economic Area, the United Kingdom, or Switzerland, your data may be transferred to and processed in the US under Standard Contractual Clauses (SCCs) approved by the European Commission. In addition, Stripe, Google LLC (Google Analytics and YouTube), Resend, and Cloudflare are certified under the EU-U.S. Data Privacy Framework (DPF) and its UK Extension, which provides a complementary legal basis alongside the SCCs; you can verify any company's current certification at dataprivacyframework.gov. Bókun relies on SCCs only. Nominatim is operated from the United Kingdom by the OpenStreetMap Foundation under Open Data Commons; no transfer mechanism is required for that service.
9.Children
Our services are not directed to children under 13. We do not knowingly collect personal information from children under 13 (COPPA, 15 U.S.C. 6501-6506). Tours that welcome children (El Yunque, Catamaran) require a parent or legal guardian to book and accompany the minor.
10.Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. For material changes, we will post a notice on this page at least 30 days before the change takes effect.
11.Contact
Questions about this policy or your personal information:
Casa Venturas, San Juan, Puerto Rico
micasaventuras@gmail.com, +1 929 372 4529