Privacy

Privacy Policy

Last updated: August 22, 2026 · Policy version: 2026-08-22

This Privacy Policy explains how Mexico Local Guide handles personal data when you visit mexicolocalguide.com, use an interactive map, make a privacy choice, submit a contact form, or email us. Optional analytics and external map services remain off unless you allow them.

Controller and contact

The website operator uses the public name Mexico Local Guide. In this policy, “Mexico Local Guide” refers to the controller responsible for the processing described here. For privacy questions or requests, email hola@mexicolocalguide.com.

Data we process

  • Connection and security data: IP address, request date and time, requested URL, referring page, browser and device information, response status, and security signals.
  • Privacy and display choices: the optional services you allow or reject and, if you choose a colour theme, the light or dark preference stored in your browser.
  • Analytics data, only with consent: IP address and connection data, page use, events, approximate location, browser and device details, referrer, and pseudonymous identifiers used by Google Analytics 4. We disable Google Signals and advertising personalisation in our implementation.
  • External-map data, only with consent: IP address, request headers, time, referring page, and the map tile, area, or zoom level requested from Esri or the OpenStreetMap Foundation.
  • Form and correspondence data: your name, email address, message, email headers, form type and source page, plus the page URL for an error report or any optional portfolio/profile URL, company, or website you submit.
  • Form abuse-prevention data: a short-lived pseudonymous rate-limit key derived from the form type and your IP address. We use it to prevent repeated automated submissions.

You do not have to allow analytics or external maps. The guide remains available without them, although interactive map imagery stays disabled. You do not have to contact us, but we cannot answer an inquiry without the information needed to respond.

Purposes and legal bases

Activity Purpose Legal basis
Site delivery, hosting, and security Deliver pages, balance traffic, diagnose errors, prevent fraud and abuse, and protect the site. Our legitimate interests in operating a reliable and secure publication (GDPR Article 6(1)(f)).
Consent choices Remember and respect whether you allowed or rejected each optional service and document the consent process we presented. Compliance with the duty to demonstrate consent under GDPR Article 7(1), where consent is given (Article 6(1)(c)), and our legitimate interest in recording and respecting a rejection (Article 6(1)(f)).
Colour-theme choice Provide the light or dark display preference you actively request. Our legitimate interest in providing the requested preference (Article 6(1)(f)); browser storage occurs only after you use the theme control and is limited to that function.
Google Analytics 4 Measure how visitors use the guide so we can understand performance and improve its content and navigation. Your consent (Article 6(1)(a)); device storage or access also occurs only after analytics consent.
External maps Display interactive satellite or street-map imagery from the selected external provider. Your consent (Article 6(1)(a)); the external connection occurs only after map consent.
Forms and email correspondence Deliver and answer error reports, contributor, partnership, editorial, privacy, or other inquiries and keep an appropriate record of the exchange. Steps you ask us to take before a possible agreement (Article 6(1)(b)) or our legitimate interest in replying and managing correspondence (Article 6(1)(f)). Legal duties or claims may also require Articles 6(1)(c) or 6(1)(f).
Form abuse prevention Limit repeated submissions and protect the site and editorial inbox. Our legitimate interest in service and communications security (Article 6(1)(f)).

Service providers and other recipients

  • Kinsta provides WordPress hosting and processes access and security logs for us. Kinsta states that website access-log analytics, including visitor IP addresses, are retained for up to 30 days and raw access, error, and cache logs for up to four days. See Kinsta’s storage information and server-log documentation.
  • Cloudflare provides content delivery, traffic management, and security. It may set strictly necessary security cookies and process IP addresses, request headers, and security signals. See Cloudflare’s Privacy Policy.
  • Google Analytics 4, provided by Google, receives IP and connection data plus analytics data only after consent. Google may act as our processor or as a separate controller for limited purposes described in its terms. See Google’s Privacy Policy and Analytics data safeguards.
  • Esri supplies the default satellite map tiles, and the OpenStreetMap Foundation supplies the optional street-map tiles. Your browser contacts the selected provider only after map consent. See the Esri Privacy Statement and OpenStreetMap Foundation Privacy Policy.
  • Postmark may deliver messages generated by the website forms when our transactional-mail integration is enabled. Mailgun is used in the domain’s email-delivery route, and the receiving mailbox provider also processes correspondence. These providers receive the message, recipient, subject, sender/reply-to details, routing metadata, and other content needed for delivery. See Postmark’s Privacy Policy and Mailgun’s GDPR information.

We do not sell personal data. We do not currently use advertising or affiliate-tracking cookies, and we do not use personal data for decisions that produce legal or similarly significant effects.

International transfers

Some providers operate in the United States, the United Kingdom, the European Economic Area, and other countries. This means data can be processed outside your country or the EEA. A transfer subject to GDPR rules must rely on an applicable adequacy decision or an Article 46 safeguard such as the European Commission’s Standard Contractual Clauses, with supplementary measures where required. You may request information about the mechanism and safeguard relevant to your data by emailing us.

Retention

  • The Klaro privacy-choice cookie lasts 180 days unless you delete it or we replace it after a material change.
  • The colour-theme preference remains in browser local storage until you change it or clear site storage.
  • Cloudflare’s observed __cf_bm security cookie expires after 30 minutes of inactivity. Additional essential Cloudflare cookies may appear when a configured security or traffic-management feature is triggered and follow Cloudflare’s stated duration.
  • Google Analytics first-party cookies may last up to two years, subject to our settings and browser limits. User- and event-level data in our standard GA4 property is retained for no more than 14 months; aggregated reports may remain longer.
  • Kinsta access-log analytics are retained for up to 30 days; raw access, error, and cache logs for up to four days. Separately retained security information may be kept longer when reasonably necessary to investigate an incident, meet a legal obligation, or establish, exercise, or defend a claim.
  • The form rate-limit key is configured to expire two minutes after a successful submission. Form payloads are emailed to the editorial inbox and are not intentionally stored as WordPress form entries.
  • Form and email correspondence is kept while we handle the request and afterward only as long as reasonably needed for follow-up, record-keeping, legal duties, or claims. Delivery providers and the receiving mailbox may retain message content and metadata under the account settings and periods described in their notices.
  • Esri, OpenStreetMap Foundation, and other independent recipients apply the retention periods in their own notices.

Your GDPR rights

Where the GDPR applies, you may request access to, correction of, deletion of, or restriction of your personal data. You may object to processing based on legitimate interests and request data portability where its legal conditions apply. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.

Email requests to hola@mexicolocalguide.com. We may need proportionate information to verify your identity. We normally respond within one month; the GDPR permits an extension for complex or numerous requests, and we will tell you if that applies.

You may also complain to a supervisory authority, particularly in the EEA country where you live, work, or believe an infringement occurred. The European Data Protection Board lists national authorities.

Changing or withdrawing consent

Use Privacy choices in the footer on any page. Rejecting or withdrawing analytics stops optional measurement and removes matching first-party analytics cookies that are accessible to the site. Rejecting or withdrawing map consent unloads the interactive map and stops new tile requests. You can also clear cookies and local storage in your browser.

Security, children, and changes

We use access controls, HTTPS, updates, backups, and service-provider security controls intended to protect data. No online system is completely secure.

The site is a general travel publication and is not directed to children. If you believe a child has sent us personal data, email us so we can review and delete it where appropriate.

We will update this policy when our practices or legal requirements materially change. If a change affects an optional service or the meaning of consent, we will ask visitors to choose again.

For exact browser-storage names and durations, see our Cookie Policy.