Privacy
Privacy Policy
This Privacy Policy explains how the Deep South Journeys website handles information submitted through its forms and optional cookie preferences.
Information We Collect
Who we are
This website is presented under the Deep South Journeys name.
Information you provide
The website collects information only when a visitor submits a booking, inquiry or footer form, or chooses cookie preferences.
- Contact
- First name, last name, full name, email, phone and country, depending on the form used.
- Stay request
- Check-in, check-out, number of guests, selected activities or preferences, and message.
- Form context
- Form type/source and submission timing used by the implemented request and anti-abuse flow.
- Technical
- IP address and user-agent are read server-side for rate limiting and request metadata. Page path and title can be sent to Google Analytics when analytics storage is permitted.
How We Use Your Information
The implemented application uses submitted information to process inquiries, create or update a CRM contact, notify the administrative recipient, and send a receipt confirmation where that flow is configured.
- Validate, sanitize and route booking and contact requests.
- Create or update a contact in HubSpot using the submitted email address.
- Send an administrative email through the configured Brevo SMTP service.
- Send a confirmation email for booking and desktop footer inquiries; the mobile email-lead flow does not send a visitor confirmation.
- Limit automated or excessive submissions using a honeypot, form timing and an in-memory IP-based rate limit.
- Measure page views and successful booking submissions when the analytics integration is available and the configured consent state permits analytics storage.
The applicable legal bases and any additional business purposes are not defined in the codebase and require legal approval.
Back to topBooking & Inquiry Data
Booking and page inquiry forms
The booking request contract can send first name, last name, email, phone, country, check-in, check-out, guests, included/additional/external activity preferences, message and form type.
Desktop footer
The desktop footer sends full name, email, message and the footerContact form type.
Mobile footer
The mobile footer sends email and the footerEmailLead form type. It does not send name, phone, dates, guests, activities or message.
All three flows also send a hidden honeypot value and a form-load timestamp for anti-abuse checks. These controls are not used as guest profile fields.
Service Providers
The following integrations are present in production code. Their contractual privacy roles, locations and transfer terms require legal and vendor review.
| Technology | Data or access | Technical purpose |
|---|---|---|
| HubSpot | Submitted contact and booking fields; request metadata within the booking payload. | Create or update CRM contacts by email. |
| Brevo SMTP | Submitted inquiry details in administrative email; visitor email and name in confirmations. | Administrative delivery and confirmation messages. |
| Google Analytics / gtag | Page path/title, consent events, successful booking event metadata, and a consented anonymous ID. | Website analytics under the configured consent state. |
| Carto | Browser requests for map tiles when the map is initialized. | Render the interactive estate map. |
| Google Maps | Navigation to an external maps URL when a visitor chooses a directions/place link. | External directions and place information. |
| Destination phone number and prefilled message when a visitor opens an external wa.me link. | Visitor-initiated messaging. | |
| Cloudinary and site media CDN | Browser requests for image and video assets. | Deliver website media. |
Data Retention & Security
No approved retention schedule for CRM contacts, emails or inquiries is defined in this repository. The localStorage consent records and anonymous analytics identifier also have no programmed expiry. Retention periods must be supplied and approved outside this implementation.
Implemented controls include JSON and origin checks, field validation, length limits, sanitization, honeypots, form timing checks, no-store API responses and in-memory IP-based rate limiting. These are technical controls, not a complete security or compliance statement.
The rate-limit store is process memory and is not a durable visitor record; entries are filtered by the configured request windows and periodic cleanup logic.
Back to topYour Rights
Privacy rights and the process for exercising them depend on the law applicable to the visitor.
- Access, rectification and erasure, where applicable.
- Restriction, objection and portability, where applicable.
- Withdrawal of consent where processing relies on consent.
- A complaint to the applicable supervisory authority, where applicable.
Visitors can change or withdraw the website's optional analytics choice at any time using Cookie Preferences.
Contact
For questions about this Privacy Policy, use the current contact details below.
Ruta Provincial 11, KM 544, calle 749deepsouthjourneys@gmail.com+54 9 11 4078-9169+1 (202) 320-6001Back to top