Home Legal Privacy policy
Legal document

Privacy policy

Your data is yours. Here we explain what we collect, why, who we share it with, and how you can exercise your rights at any time.

Last updated: Version: 3.2 Jurisdiction: Dominican Republic ES · EN · PT · FR

01. Who is responsible

The controller of your data is MDT Tours SRL, RNC 1-31-12345-6, headquartered at Av. Roberto Pastoriza esquina Federico Geraldino, Edificio Madison Plaza, Piantini, Santo Domingo, Dominican Republic.

For any data protection matter, contact our Data Protection Officer at privacidad@mydominicantrip.com.

02. What data we collect

We only collect what is strictly necessary:

Identification
First name, last name, email, phone, country of residence, preferred language.
Payment
Card details processed by Stripe (we do not store full numbers), transaction history.
Bookings
Dates, booked products, arrival/departure flight, hotel, preferences.
Technical
IP, browser, device, pages visited (via cookies — see cookie policy).
Optional
Profile photo, comments, reviews, chat messages.

03. What we use it for

  • Manage your bookings and share them with the corresponding operator.
  • Process payments through Stripe and PayPal (PCI-DSS certified processors).
  • Communicate with you before, during, and after the trip (email, WhatsApp).
  • Improve the service through anonymized statistical analysis.
  • Send you the newsletter (only if you subscribed; you can unsubscribe in 1 click).
  • Comply with legal obligations (tax, accounting, judicial).

05. Who we share your data with

Only with those who need access to provide the service:

  • Local operators: the minimum data needed to fulfill your booking (name, flight, hotel, preferences).
  • Payment processors: Stripe and PayPal, PCI-DSS certified, outside MDT's control.
  • Technology providers: hosting (AWS, Frankfurt), email (Resend), CRM (HubSpot), analytics (Plausible — anonymized).
  • Tax or judicial authorities: when required by law.

We never sell or transfer data to third parties for advertising purposes.

06. International transfers

Some providers (AWS, Stripe, PayPal) operate from the United States or the European Union. These transfers are carried out under the standard contractual clauses approved by the European Commission and with safeguards equivalent to those required by Law 172-13.

07. How long we keep it

Type of dataRetention period
Active booking dataFor the duration of the relationship + 4 years (accounting obligation)
Tax data10 years (DR Tax Code)
NewsletterUntil you unsubscribe
Analytics cookies13 months maximum
Reviews / commentsWhile the content remains published

08. Your rights

At any time you can exercise the following rights over your personal data:

Access
Know what data of yours we hold.
Rectification
Correct inaccurate or incomplete data.
Erasure
"Right to be forgotten" — delete your data if it is no longer necessary.
Objection
Object to processing on legitimate grounds.
Portability
Receive your data in JSON format to take it to another service.
Restriction
Restrict the use of your data without deleting it.
Complaint
Before INAIP (DR) or your local supervisory authority.

To exercise any of these rights, write to privacidad@mydominicantrip.com. We respond within 30 days.

09. Security measures

  • 256-bit SSL encryption across the entire platform.
  • Payments certified PCI-DSS Level 1.
  • Servers in Frankfurt (AWS eu-central-1) with encrypted backups.
  • Role-based internal access, with mandatory two-factor authentication.
  • Annual external audit and a breach response plan (notification within 72 h).

10. Minors

The platform is intended for people over 18 years of age. Minors may participate in bookings only when a responsible adult contracts the service on their behalf and takes responsibility for the processing of their data.

Have questions about this document?

Our legal team answers questions in Spanish, English, Portuguese, and French. Average response time: 24 hours.