1. Privacy Overview
Temple de la Luna is committed to protecting your privacy and ensuring transparency about how we collect, use, and protect your personal information. This Privacy Policy explains our data practices for all interactions with our website, services, applications, and communications.
We adhere to applicable privacy laws including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and industry standards for A2P messaging compliance.
3. How We Use Your Information
Temple de la Luna uses your information for the following purposes:
| Purpose | Data Used | Legal Basis |
| Service Delivery | Account, membership, event registration data | Contract performance |
| Communication | Email, phone, messaging preferences | Legitimate interest & consent |
| Marketing | Email, phone (with explicit consent) | Explicit consent (opt-in) |
| Personalization | Preferences, browsing history, interests | Legitimate interest |
| Analytics & Improvement | Usage data, behavior patterns | Legitimate interest |
| Legal Compliance | Any relevant data | Legal obligation |
| Security & Fraud Prevention | Activity logs, transaction data | Legitimate interest & legal obligation |
Marketing Communications
We only send marketing communications to users who have explicitly opted in. You have complete control over these communications:
- You can opt out at any time through email footer links
- You can modify preferences in your account settings
- You can contact us to unsubscribe from specific message types
- Opting out of marketing does not affect transactional messages (order confirmations, account notifications)
4. Data Sharing & Third Parties
How We Share Your Data
Temple de la Luna does not sell your personal information. We may share data with:
Service Providers
- GoHighLevel (GHL): CRM platform for managing customer relationships and automating communications
- Email Service Providers: For sending newsletters and transactional emails
- SMS & Messaging Providers: For A2P messaging services (see A2P SMS section)
- Payment Processors: For secure transaction processing
- Analytics Providers: For aggregated usage insights
- Hosting Providers: For website and application infrastructure
Legal Requirements
We may disclose information when required by law, including:
- Court orders or subpoenas
- Government requests compliant with legal process
- Protection of our legal rights or public safety
- Investigation of fraud or illegal activity
Business Transfers
If Temple de la Luna is acquired, merged, or assets are sold, your information may be transferred as part of that transaction. We will provide notice before such a transfer occurs.
Data Processing Agreements
All third-party processors are bound by Data Processing Agreements requiring them to:
- Use data only for specified purposes
- Maintain appropriate security measures
- Comply with applicable privacy laws
- Delete or return data upon request
5. A2P SMS & Messaging Data
Consent & Opt-In Requirements
Temple de la Luna complies with all carrier guidelines for A2P (Application-to-Person) SMS messaging:
- All SMS recipients have provided explicit written consent via an opt-in form
- Consent is documented and retained for audit purposes
- Separate consent may be obtained for different message categories (promotions, transactional, educational)
- Recipients receive clear information about message frequency and types before opting in
- Consent can be withdrawn at any time with no penalty
Message Data Handling
- Phone Number Protection: Phone numbers are treated as sensitive personal data and stored securely
- Encryption: All messaging data is encrypted in transit (TLS/SSL) and at rest
- Access Controls: Only authorized personnel can access messaging systems
- Audit Trails: All message sends are logged for compliance verification
- No Third-Party Sales: Phone numbers are never sold to third parties
Message Standards
All A2P messages from Temple de la Luna:
- Include clear sender identification (Temple de la Luna)
- Provide easy opt-out instructions ("Reply STOP to unsubscribe")
- Include customer service contact information
- Comply with carrier quiet hours (no messages 9 PM - 8 AM recipient local time)
- Are sent at reasonable frequencies (no message flooding or spam)
- Match the category for which consent was given
Unsubscribe Management
- When a recipient replies "STOP," they are automatically removed from all SMS marketing
- Removal is processed immediately; no further messages are sent
- Recipients can specify which message types to receive or frequencies
- Transactional messages (order updates, account alerts) may still be sent to opted-out users unless explicitly requested otherwise
- All unsubscribe requests are documented for compliance
Carrier Compliance
Temple de la Luna maintains compliance with:
- TCPA (Telephone Consumer Protection Act) requirements
- Carrier guidelines for Sprint, Verizon, AT&T, T-Mobile, and others
- GDPR requirements for EU residents' SMS
- CCPA requirements for California residents' SMS
- Regulations prohibiting messages to minors without parental consent
6. Data Retention
Temple de la Luna retains personal information as long as necessary to provide services and fulfill the purposes outlined in this policy:
- Active Account Data: Retained while your account is active plus 12 months after closure
- Marketing Consent Records: Retained for 3+ years for compliance documentation
- Transaction Data: Retained for 7 years (tax and legal requirements)
- Website Analytics: Retained for 24 months (aggregated after 12 months)
- Support Communications: Retained for 2 years for service quality purposes
- SMS Logs: Retained for 12 months for compliance audits
Once the retention period expires, we delete or anonymize your data. You may request earlier deletion by contacting us, except where legal obligations require retention.
7. Data Security
Security Measures
Temple de la Luna implements comprehensive security measures to protect your personal information:
- Encryption: TLS/SSL encryption for all data in transit; AES-256 for data at rest
- Access Controls: Role-based access; only authorized staff can access sensitive data
- Authentication: Secure password requirements; optional multi-factor authentication
- Firewalls & Intrusion Detection: Network protection and monitoring
- Regular Security Audits: Annual security assessments and penetration testing
- Secure Infrastructure: Hosted on enterprise-grade servers with redundancy
- Employee Training: Staff trained in data protection and privacy practices
- Incident Response Plan: Documented procedures for responding to security breaches
Limitations
While we employ robust security measures, no system is completely immune to breaches. Transmission over the internet is never 100% secure. We are not responsible for unauthorized access resulting from user negligence or security failures beyond our reasonable control.
Breach Notification
In the event of a data breach involving personal information, we will notify affected individuals and regulatory authorities as required by law, typically within 72 hours (or as mandated by applicable regulations).
8. Your Privacy Rights
Universal Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Update or correct inaccurate information
- Deletion: Request that we delete your personal data (right to be forgotten)
- Opt-Out: Unsubscribe from marketing communications anytime
- Transparency: Understand how your data is processed
GDPR Rights (for EU/UK Residents)
- Data Portability: Receive your data in a portable format
- Restriction: Request we limit processing of your data
- Objection: Object to processing for legitimate interests
- Automated Decision Making: Not be subject to decisions based solely on automated processing
- Withdraw Consent: Withdraw consent for data processing at any time
CCPA Rights (for California Residents)
- Know: Request the categories and specific pieces of personal information collected
- Delete: Request deletion of personal information (with some exceptions)
- Opt-Out: Opt out of the selling/sharing of personal information
- Non-Discrimination: Not be discriminated against for exercising your rights
- Correct: Request correction of inaccurate personal information
How to Exercise Your Rights
To submit a request, contact us with:
- Your full name and email address
- Description of the right you're exercising
- Any supporting documentation
We will verify your identity and respond within the timeframe required by applicable law (typically 30-45 days).
9. Cookies & Tracking Technologies
What Are Cookies?
Cookies are small text files stored on your device that help us recognize you and enhance your experience. We use both session cookies (temporary) and persistent cookies (longer-term).
Types of Cookies We Use
- Essential Cookies: Required for website functionality (login, security)
- Performance Cookies: Measure usage patterns and site performance
- Preference Cookies: Remember your settings and choices
- Marketing Cookies: Track behavior for personalized advertising
Tracking Technologies
We may use:
- Pixels & Web Beacons: Track page views and user interactions
- Google Analytics: Aggregate usage statistics
- Conversion Tracking: Monitor campaign effectiveness
Your Cookie Choices
- You can disable cookies in your browser settings
- Disabling cookies may affect website functionality
- You can clear cookies from your device at any time
- Most browsers have a "Do Not Track" option you can enable
Third-Party Services
We may use third-party services (Google Analytics, GoHighLevel) that set their own cookies. These providers have their own privacy policies. We encourage you to review their practices.
10. Children's Privacy
Temple de la Luna Services are not directed to children under 13 years old. We do not knowingly collect personal information from children under 13. If we discover we have collected information from a child under 13, we will delete it immediately.
For users ages 13-18, we provide additional protections and require verifiable parental consent before processing their data for marketing purposes.
If you believe we have collected information from a child under 13, please contact us immediately.
11. GDPR & CCPA Compliance
GDPR Compliance (EU/UK/EEA Residents)
As a service provider for users in the European Union, United Kingdom, and European Economic Area, Temple de la Luna complies fully with the General Data Protection Regulation (GDPR):
- Data processing is based on explicit legal grounds (consent, contract, legitimate interest, legal obligation)
- You have the rights outlined in Section 8 above
- We conduct Data Protection Impact Assessments for high-risk processing
- Our Data Protection Officer can be reached at privacy@templedelaluna.com
- We comply with GDPR's international data transfer requirements
- Restrictions apply to processing children's data (under 16 in some jurisdictions)
CCPA Compliance (California Residents)
Temple de la Luna complies with the California Consumer Privacy Act (CCPA) and successor regulations (CPRA):
- California residents have the specific rights outlined in Section 8 above
- We do not sell personal information (as defined by CCPA)
- We limit data collection to what is necessary for stated purposes
- You can submit requests by emailing privacy@templedelaluna.com or calling [phone number]
- We respond to requests within 45 days of verification
- We do not discriminate against users for exercising CCPA rights
12. Changes to This Privacy Policy
Temple de la Luna may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Posting the updated policy on our website
- Sending email notification of significant changes
- Requesting your consent if required by applicable law
Your continued use of our Services following the posting of updates constitutes your acceptance of the changes. We encourage you to review this policy periodically.
Last Updated: April 2025 | Version 1.0