Privacy Policy
This policy explains what the Sayulita Guide app and the sayulitaguide.com website collect about you, what we do with it, who else receives it, how long we keep it, and the choices you have. It describes version 1.13.1 of the app and later.
The short version: we do not sell your personal information, we do not use advertising networks, and we do not track you across other companies' apps or websites for advertising. The app does use product analytics and crash reporting. Both are on by default, and you can turn them off in Settings.
1. Who We Are
- Operator: Get X Media Inc.
- Mailing address: 4441 76 Ave SE, Suite 214, Calgary, AB T2C 2G8, Canada
- Privacy contact: [email protected]
Depending on where you live, laws such as Mexico's LFPDPPP, Canada's PIPEDA, the GDPR in the EU and the UK, and California's CCPA give you rights over your personal data. Section 6 explains how to use them.
2. What We Collect
2.1 Information you give us
- Account: your name and email address. If you sign in with Apple or Google, we receive your name and email from them, and from Google also your profile picture, and we keep the sign-in token Apple or Google gives us, which identifies your account with them. If you sign up with an email and password, we store the password only as a hash, never the password itself.
- Phone number: optional for your account, but you need one to send an inquiry to a business (see 2.4). If you create a business listing with a contact phone and your profile has no phone yet, we save that number to your profile.
- Profile photo (optional).
- What you post: community posts (text, photos, and a location if you choose to add one), comments, likes, reviews, and reports you file about content or people. When you earn a passport stamp or complete a mission photo or review step, the app also shares it in the community feed under your name, with the photo and your review text.
- Business requests: listing claims (a contact name, email, phone, your role and a message), change requests, and the listings and events you submit.
- Your activity in the app: favorites and saved lists, trips, mission progress and votes, passport stamps, points, game scores, coupon redemptions, and the people you block.
- Settings: your notification choices and time zone, and when you accepted our Terms and which version. Your language choice is saved only on your phone.
- Messages to us: emails and in-app reports you send us.
Your name and profile photo appear next to your community posts and comments, where other signed-in users of Sayulita Guide can see them. Reviews are public: your full name, profile photo, rating and review text are shown in the app and on our website, where anyone, including search engines, can see them. The public leaderboards show your first name and the initial of your last name (or your whole name if it is a single word), your profile photo, your points and the number of missions you completed; the games leaderboard also shows how many games you played and your best score.
2.2 Location and photos
The app only asks for location access "while using the app". It never asks for background location and does not collect your location while it is closed. With your permission, it uses your location for:
- Maps: showing where you are.
- Directions: your current location and the destination are sent to Mapbox to get a route.
- Missions: checking that you are in Sayulita. This check happens on your phone.
- Passport stamps: if you check in with the camera, we receive your current coordinates and their GPS accuracy. If you check in with a photo from your library, the app does not use your location permission: it reads the location and date saved inside that photo and sends those instead. With the stamp we store the coordinates, the accuracy (camera only), when the photo was taken, and whether it came from the camera or your library.
- Community posts: only if you tap to add your location. We store the coordinates and a place name with the post, and other signed-in users can see them. The place name is looked up by your phone's own location service (Apple on iPhone, and on Android usually Google), which receives the coordinates.
Your last known location. If you have allowed location access, when the app starts and you are signed in, the app sends your phone's last known location to our server, if your phone has a reading from the last few minutes (at most once every 10 minutes). We store it on your profile, replacing the previous one. This happens whether or not you have turned on Deals & offers. We use it to decide whether you are in or near Sayulita when a local business sends a promotional notification to people in town, and to tell a business how many people such a notification would reach (a number only). A reading older than 72 hours is not used for this. To stop it, turn off location access for Sayulita Guide in your phone's settings.
Photos. Before any photo leaves your phone, the app re-encodes it, which removes the location data (GPS) stored inside the file. If that cannot be done, the photo is not uploaded. Uploaded photos are stored on our content delivery network (CDN) at public web addresses: anyone who has a photo's link can view it. For passport stamps, the check-in coordinates are sent separately from the photo, as described above.
2.3 Collected automatically in the app
- Product analytics (PostHog), on by default: which screens you open and certain actions, such as viewing a listing, starting or finishing a mission, sending an inquiry, scanning a QR code or playing a game, together with the listing, mission or game involved and your game scores. It also records when the app is installed, updated, opened or closed. Once you sign in, these events, including earlier ones from the same phone, are linked to your account ID, not to your name or email. PostHog also receives device and app details (such as phone model, operating system, app version, language and time zone) and estimates your approximate location (such as city, region and country) from your IP address. It does not record your screen or your taps, and it does not receive the text of your posts, reviews or messages, or your photos.
- Our own usage log, on by default: a short record, sent to our own server, when you see a listing in a list, open it, tap one of its contact buttons (call, WhatsApp, email, Instagram, website, menu or directions), share or save it, search, go through the welcome screens, create an account, open one of our notifications, or tap an item in a digest. Each record says what happened, which listing or promotion it concerned, where it appeared on the screen and when. For a search it keeps only how many results you got and how long your search was, never the words you typed. Records carry a random ID created for this installation of the app and a random session ID and, while you are signed in, your account ID. The records themselves do not include your name, email, IP address or location. We use them to improve the app and to tell businesses how often their listing is seen and contacted.
- Crash reports (Sentry), on by default: each time you use the app, Sentry receives a short session record (when it started and ended and whether the app crashed). When the app hits an error or crashes, and for a sample of performance measurements, Sentry also receives technical details such as your phone model, operating system, app version and what the app was doing, including the addresses of recent requests to our server. We do not attach your account to these reports; Sentry's software adds a random identifier for your installation of the app. In about 1 in 10 sessions where an error happens, the report includes a replay of the screens involved, with text and images masked on your phone before it is sent.
- Push notifications: if you allow notifications, we store a push token for each of your devices so we can deliver them.
- Connection data: we store the IP address and the device or browser type (user agent) with your sign-in sessions and with any account deletion request, and we use IP addresses to limit how often requests can be made. Our server logs record the address of each request (which can include IDs and search terms) and messages that can include your account ID and a partly hidden version of your email address (its first letter and domain). Passwords, sign-in tokens and the one-time codes in links we email you are never written to the logs.
- Server crash reports (Sentry): when our server hits an error, and for a sample of ordinary requests, Sentry receives the address of the request without its query string, the device or browser type, and technical details. It does not receive the request body, cookies, sign-in headers or your IP address.
- Maps: depending on your phone, Mapbox's map software in the app may also send Mapbox its own usage data, which can include location. Mapbox's privacy policy covers that data.
- App updates: the app checks Expo's servers for updates, which see your IP address, your app version and a random identifier for your installation of the app.
2.4 Inquiries to businesses
To contact a business through the app you need a phone number on your profile. When you send an inquiry, we build a message that includes your name, email, phone number, the details you chose (such as dates and number of people) and what you wrote, save a copy of it, and open WhatsApp or your email app with the message filled in. You send it. From then on the business has your details and handles them under its own practices. We keep our copy until you delete your account, when it is deleted with everything else (see 5.1).
On this website you can also write to a business from its page, without an account, when the business has an email address with us. The form asks for your name, your email and your message. We email them to the business through SendGrid, our email provider, with your email set as the reply address, so the business answers you directly. We never show you the business's email address. We do not save your message on our servers: the only thing we keep is a record of the listing, contact method, sending time and reference code, without your name, email or message. We use these records to count sent enquiries separately from contact-button taps and keep them for 13 months. Open and click tracking is switched off for these emails. A Cloudflare Turnstile check on the form stops spam (see 2.6). Once the business has your message, it handles your details under its own practices.
2.5 Purchases (business owners)
Business products are paid through the Apple App Store or Google Play Billing. Some earlier subscriptions were paid through Stripe on our website. We store which product you bought and for which listing, its tier, status and dates, the price paid for promotions, and the transaction identifiers from Apple, Google or Stripe. For Stripe subscriptions we also created a customer record at Stripe with your name and email. We never receive your card number.
2.6 On this website
- Google Analytics, only if you agree: after you accept analytics cookies, Google Analytics measures website visits and interactions through our server-side Google Tag Manager setup. Google receives your IP address, browser and device information, page addresses and pseudonymous analytics identifiers. Advertising consent remains denied. Rejecting analytics or withdrawing consent stops it loading.
- Our own usage log, only if you agree: if you accept analytics in the cookie banner, the website records when you open a listing page or its detail panel, or tap a contact button on a listing page (call, WhatsApp, email, Instagram, website, menu or directions), the same kind of record the app sends (see 2.3). It keeps a random ID, a session ID and any records not yet sent in your browser's local storage, remembers the clicked listing placement in tab storage for up to 30 minutes, and adds your account ID if you are signed in. If you refuse, send a GPC signal, or later withdraw your agreement, it records nothing and deletes what it stored.
- Your choice first: the cookie banner asks before anything optional loads, and you can change your choice at any time from Cookie preferences at the bottom of this page. If your browser sends a Global Privacy Control (GPC) signal, we record that as a refusal without asking you.
- Necessary cookies: one remembers your cookie choice; one remembers your language if you choose one different from your browser's, until you close the browser; if you sign in on the website (for example to delete your account), a sign-in cookie keeps you signed in; and if you open a private review link, a cookie keeps the review tool on until you close the browser.
- Our review tool (betterfeedback): a third-party tool that lets people reviewing a page leave notes pinned to it. It loads for visitors who accept functional cookies, and for anyone who opens a private review link we sent them, even if they refused cookies or their browser sends GPC, because that link exists only for this purpose. You can switch it off from Cookie preferences.
- Bot checks: signing up with an email address, on the website or in the app, shows a Cloudflare Turnstile check. Passing it lets more people sign up from the same shared network. The form for sending a message to a business on this website also shows one, and there a message cannot be sent without passing it. Cloudflare receives your IP address and browser details to run the check.
- Maps and images: maps on this website load tiles from OpenStreetMap. Like any website, the servers that deliver our pages, images and map tiles see your IP address. "Open in Google Maps" links take you to Google.
3. What We Do Not Do
- We do not sell your personal information.
- We do not use advertising networks such as Google AdMob or Meta Audience Network.
- We do not track you across other companies' apps or websites for advertising. Our iOS privacy manifest declares no tracking, and the app does not read your phone's advertising identifier.
- Paid placements are not personalized. Featured listings, sponsored spots, Verified badges and sponsor spots in games are the same for everyone. The one exception is Deals & offers notifications, which a business can aim at people in town or people who saved a similar place, and which you only get if you turn them on (see section 4).
- We do not currently send marketing emails. If we start, we will ask you first and include an unsubscribe link in every one.
- The app does not access your contacts. It uses your camera or photo library only when you choose to add a photo or scan a QR code.
4. How We Use Your Information
- Running the app: your account, showing you content, and the features you use, such as posts, favorites, trips, missions, stamps, points and rewards.
- Inquiries: preparing the messages you send to businesses in the app, and delivering the ones you send from this website (see 2.4).
- Emails you need: verifying your email, confirming an email change, resetting your password, updates on a listing claim, your account deletion request, and your data export.
- Local notifications: if you allow notifications, we may send you news such as new events in Sayulita. You can stop these in your phone's notification settings.
- Deals & offers: promotional notifications. These are offers paid for by local businesses, daily round-ups of specials and events, and, if you own a business listing, our own messages about upgrading it. You only get these if you turn on Deals & offers in Settings, which is off by default. A business can aim an offer at everyone who turned it on, at people whose last known location shows them in or near Sayulita within the last 72 hours, or at people who saved a place in the same category. Unless you choose All deals, you get at most 3 business offers in any 24 hours, and none arrive between 10 pm and 8 am your local time. We send them; the business does not receive your name or contact details.
- Fixing problems: crash reports (Sentry) and server logs (Better Stack).
- Improving the app: product analytics (PostHog) and our own usage log (see 2.3).
- Telling businesses how they are doing: our own usage log gives each business totals, such as how many times its listing was seen and how many people tapped to call or message it. Businesses see totals, never who you are.
- Safety: our team reviews reported content, you can block other users, passport stamp photos may be checked automatically for inappropriate content (Sightengine), and we limit request rates and check sign-ups for bots.
- Listings in two languages: listing text is translated automatically between English and Spanish (see section 7).
4.1 Our legal basis for each use
Where the law asks us to name a legal basis, these are ours:
- Performance of a contract: your account, the features you use, the inquiries you send, business purchases, and the emails you need for these.
- Consent: promotional notifications (Deals & offers), and the features that need a permission you grant on your phone, such as location for maps, directions, stamps and post locations, or the camera and photo library. You can withdraw consent at any time in Settings or in your phone's settings. Google Analytics and our own usage log on this website run on consent (see 2.6), which you can withdraw from Cookie preferences.
- Legitimate interests: product analytics, our own usage log in the app and crash reports, which are on by default and which you can turn off; keeping your last known location to decide who is in town for promotional notifications, which you can stop by turning off location access; local news notifications; security, fraud and abuse prevention and content moderation; and keeping records of deletion and privacy requests. Our interests are keeping the app working, improving it, keeping the community safe, and being able to show what we did.
- Legal obligation: responding to lawful requests from authorities.
5. How Long We Keep It
- Your account, profile, activity and content: until you delete your account (see 5.1). You can delete a community post yourself at any time, and doing so also removes its photos from our CDN. To delete a passport stamp photo, email [email protected].
- Last known location: we keep only the latest reading, replacing it with each update, until you delete your account.
- Copies of inquiries: app inquiries are kept until you delete your account, then deleted. Messages sent from the website form are not kept. Sending outcome records (listing, method, time and reference, without name, email or message) are kept for 13 months.
- Records of deletion and privacy requests: kept after your account is gone, as proof of what we did.
- Backups: our nightly database backups are encrypted and kept on our server for 7 days and with Cloudflare for 30 days. Before each update to our servers we also copy the database, protected by access controls rather than encryption, and keep that copy on our server for 14 days. Data you delete can remain in a backup until that backup expires.
- Our own usage log: each record is kept for 13 months from when it happened, then deleted by a weekly cleanup. We may keep totals that do not identify anyone, such as how many times a listing was seen in a month. Deleting your account deletes your records sooner (see 5.1).
- Analytics, crash reports and logs: Google Analytics, PostHog, Sentry and Better Stack keep these under the retention settings of our accounts with them. Deleting your account does not delete data already sent to them.
5.1 When you delete your account
Request it in the app under Profile → Settings → Privacy & Data → Delete Account. We email you to confirm. While the request is still pending, you can cancel it by replying to that email or writing to [email protected]. Our team reviews the request and completes it within 30 days of when you made it. When we delete your account, we also delete its link to your Apple or Google sign-in. To remove Sayulita Guide from your Apple or Google account as well, use Settings → your name → Sign in with Apple on your iPhone, or Security → Third-party connections in your Google account.
Deletion is permanent. Your content is deleted, not anonymized. We delete:
- your account, profile and sign-in links, sessions and push tokens, and your inquiries;
- your posts, your comments and likes (including on other people's posts), and your reviews;
- your favorites and saved lists, trips, missions and mission votes, passport stamps, points, notifications and coupon redemptions;
- the records in our own usage log that carry your account ID, and the records from any phone or browser you signed in on, including those from before you signed in (see 2.3);
- the reports, listing claims, change requests and submissions you made;
- your purchase records in our database, and the promotions, campaigns and coupons you created;
- your photos (profile photo, post photos, passport stamp photos, mission photos and report photos), which are also removed from our CDN.
Public listings and events you created stay in the directory with your name removed, and businesses you claimed stay listed without an owner. Photos you uploaded for a business listing are not removed from our CDN, because a listing that stays in the directory may use them.
What we keep after deletion:
- the record of your deletion request (your name, email, any reason you gave, the IP address and the app or browser details it was sent from, its dates, its status and any notes our team added), and records of other privacy requests you made;
- the purchase records that Apple, Google and Stripe keep themselves, including your customer record at Stripe;
- data already sent to Google Analytics, PostHog, Sentry and Better Stack (see above);
- backups, for up to 30 days (see section 5).
6. Your Rights
You can access, correct and delete your data, and withdraw consent. In Mexico these are known as ARCO rights.
- Access and portability: in the app under Profile → Settings → Privacy & Data → Export my data. We email a JSON file to the email address on your account, through SendGrid. It contains your account (name, email, whether it is verified, profile picture link and dates), your full profile (including phone number, language, notification settings, last known location, points, Terms acceptance and, if you have one, your Stripe customer ID), the listings you own or manage, your change requests, mission progress, favorites, trips, inquiries, reports and reviews, and your records in our own usage log (the same records we delete with your account). It does not yet include your posts, comments, passport stamps, photos, listing claims, submissions or purchases. For a copy of those, or anything else, email [email protected].
- Correction: edit your name, email, phone number, password and profile photo in the app, under Profile.
- Deletion: see 5.1.
- Analytics opt-out: turn off Share usage analytics under Profile → Settings → Privacy & Data. This stops product analytics (PostHog), our own usage log (and deletes the random IDs it kept on your phone), and the crash reports the app sends from its JavaScript code (Sentry). Crashes in the app's native code can still be reported.
- Promotional notifications: turn off Deals & offers under Profile → Settings.
- Location: turn off location access for Sayulita Guide in your phone's settings.
- Complaints: you can complain to the data protection authority where you live:
- Canada: Office of the Privacy Commissioner of Canada (priv.gc.ca)
- Mexico: Secretaría Anticorrupción y Buen Gobierno (gob.mx/buengobierno)
- EU and UK: your national data protection authority
- California: Office of the Attorney General (oag.ca.gov)
6.1 How long we take
We answer privacy requests within 30 days of receiving them. There is no charge. The in-app export is only ever sent to the email address on your account.
6.2 Why app analytics are on by default
In the app, product analytics and crash reports are on by default, and you can turn them off. That is an opt-out model, not an opt-in one. Here is why, so you can judge it:
- Analytics events are linked to an account ID, not to your name or email, and crash reports are not linked to your account.
- We do not use them for advertising, we do not sell them, and we do not combine them with data from other companies.
- They are how we find crashes and broken screens in an app used on many different phones and weak connections.
- The switch is in Profile → Settings → Privacy & Data. From then on the app stops sending product analytics, our own usage log, and the crash reports and performance data from its JavaScript code, and the switch stays off on that phone until you turn it back on or reinstall the app. It does not cover crashes in the app's native code, the short record of each app session, or, occasionally, a masked screen replay when an error happens. Each time the app opens it also asks PostHog for its settings, which shows PostHog your IP address, and an error in the first moments after the app opens can be sent before your choice has loaded.
The website is stricter: nothing optional loads there until you agree in the cookie banner, except the review tool for someone who opened a private review link (see 2.6).
7. Who Else Receives Data
These companies receive data when you use the app or the website. Most process it for us; some, such as Apple, Google, Mapbox and OpenStreetMap, also handle it under their own terms. Each has its own privacy policy.
- Hetzner: hosts our servers and database.
- Cloudflare: sits in front of our website and servers (and sees your IP address), stores uploaded photos and our encrypted backups, and runs the Turnstile bot check.
- Sentry: crash reports, session records and performance data from the app, and error reports and performance data from our server.
- PostHog: product analytics in the app, on servers in the United States.
- Better Stack: our server logs.
- SendGrid: sends our emails, including your data export and the messages you send to businesses from this website.
- Expo: delivers push notifications (through Apple and Google) and app updates.
- Apple: Sign in with Apple, App Store purchases, push notifications on iPhone, and place names for post locations on iPhone.
- Google: website analytics through Google Analytics, only after you agree to analytics cookies, as well as Sign in with Google and Google Play Billing purchases, push notifications on Android, and usually place names for post locations on Android.
- Stripe: payments for business subscriptions bought on our website. It receives your name, your email, the payment details you enter, and our internal IDs for your account and listing.
- Mapbox: maps and directions in the app. Directions requests include your current location and your destination.
- OpenStreetMap: map tiles on this website.
- Unsplash: some pictures in the app load from Unsplash, which sees your IP address and device type when they load.
- Anthropic, directly or through OpenRouter: translates listing titles and descriptions whenever a listing is created or edited. When our team drafts a listing with AI, the listing's photos, notes, business name and map location are sent as well, and the AI searches the web for information about the business. This is listing content, not your personal data, unless you put personal data in a listing.
- Sightengine: may check passport stamp photos for inappropriate content.
- betterfeedback: the website review tool described in 2.6.
8. Children
Sayulita Guide is not directed at children under 13. Signing up on the app's sign-up screen asks you to confirm that you are at least 13. If you believe a child under 13 has an account, email [email protected] and we will delete it.
9. Data Outside Your Country
We are based in Canada, and the companies in section 7 operate in several countries, including the United States. Your data may be processed outside the country where you live.
10. Security
Connections to the app's servers and this website use HTTPS. Passwords are stored as scrypt hashes. On your phone, the app keeps your sign-in token in the phone's secure storage (the iOS Keychain, or encrypted storage backed by the Android Keystore). We limit request rates, check email sign-ups for bots, run our servers behind Cloudflare, and encrypt our database backups. Remember that uploaded photos are at public web addresses, so do not post anything you would not want others to see. No system is perfectly secure.
11. Changes to This Policy
When we change this policy, we update this page and the date at the bottom of it.
12. Contact
Questions, requests or complaints about your privacy: [email protected]
This policy is also available in Spanish. If the two versions ever differ, the English version applies.