Privacy Policy - Temple de la Luna

Privacy Policy

Temple de la Luna • Your Privacy Matters to Us

1. Privacy Overview

Temple de la Luna is committed to protecting your privacy and ensuring transparency about how we collect, use, and protect your personal information. This Privacy Policy explains our data practices for all interactions with our website, services, applications, and communications.

We adhere to applicable privacy laws including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and industry standards for A2P messaging compliance.

2. Information We Collect

Information You Provide

When you interact with Temple de la Luna, we may collect:

  • Account Information: Name, email address, phone number, postal address, date of birth
  • Communication Data: Messages, inquiries, feedback, testimonials, and support requests
  • Membership Information: Subscription tier, membership duration, preferences
  • Event Registration: Class enrollment, event attendance, workshop participation
  • Consent Records: Documentation of opt-ins, preferences, and communication choices
  • Payment Information: Billing address, payment method (processed securely; we don't store full card numbers)

Information Collected Automatically

  • Website Activity: Pages visited, time spent, links clicked, referral source
  • Device Information: Browser type, operating system, IP address, device identifiers
  • Log Data: Access logs, error reports, usage statistics
  • Cookies & Tracking: See our Cookies section below for details

Information From Third Parties

  • Payment processors (transaction confirmations)
  • Email service providers (delivery status)
  • Analytics services (aggregated usage data)
  • Social media platforms (if you connect your accounts)

3. How We Use Your Information

Temple de la Luna uses your information for the following purposes:

Purpose Data Used Legal Basis
Service Delivery Account, membership, event registration data Contract performance
Communication Email, phone, messaging preferences Legitimate interest & consent
Marketing Email, phone (with explicit consent) Explicit consent (opt-in)
Personalization Preferences, browsing history, interests Legitimate interest
Analytics & Improvement Usage data, behavior patterns Legitimate interest
Legal Compliance Any relevant data Legal obligation
Security & Fraud Prevention Activity logs, transaction data Legitimate interest & legal obligation

Marketing Communications

We only send marketing communications to users who have explicitly opted in. You have complete control over these communications:

  • You can opt out at any time through email footer links
  • You can modify preferences in your account settings
  • You can contact us to unsubscribe from specific message types
  • Opting out of marketing does not affect transactional messages (order confirmations, account notifications)

4. Data Sharing & Third Parties

How We Share Your Data

Temple de la Luna does not sell your personal information. We may share data with:

Service Providers

  • GoHighLevel (GHL): CRM platform for managing customer relationships and automating communications
  • Email Service Providers: For sending newsletters and transactional emails
  • SMS & Messaging Providers: For A2P messaging services (see A2P SMS section)
  • Payment Processors: For secure transaction processing
  • Analytics Providers: For aggregated usage insights
  • Hosting Providers: For website and application infrastructure

Legal Requirements

We may disclose information when required by law, including:

  • Court orders or subpoenas
  • Government requests compliant with legal process
  • Protection of our legal rights or public safety
  • Investigation of fraud or illegal activity

Business Transfers

If Temple de la Luna is acquired, merged, or assets are sold, your information may be transferred as part of that transaction. We will provide notice before such a transfer occurs.

Data Processing Agreements

All third-party processors are bound by Data Processing Agreements requiring them to:

  • Use data only for specified purposes
  • Maintain appropriate security measures
  • Comply with applicable privacy laws
  • Delete or return data upon request

5. A2P SMS & Messaging Data

Consent & Opt-In Requirements

Temple de la Luna complies with all carrier guidelines for A2P (Application-to-Person) SMS messaging:

  • All SMS recipients have provided explicit written consent via an opt-in form
  • Consent is documented and retained for audit purposes
  • Separate consent may be obtained for different message categories (promotions, transactional, educational)
  • Recipients receive clear information about message frequency and types before opting in
  • Consent can be withdrawn at any time with no penalty

Message Data Handling

  • Phone Number Protection: Phone numbers are treated as sensitive personal data and stored securely
  • Encryption: All messaging data is encrypted in transit (TLS/SSL) and at rest
  • Access Controls: Only authorized personnel can access messaging systems
  • Audit Trails: All message sends are logged for compliance verification
  • No Third-Party Sales: Phone numbers are never sold to third parties

Message Standards

All A2P messages from Temple de la Luna:

  • Include clear sender identification (Temple de la Luna)
  • Provide easy opt-out instructions ("Reply STOP to unsubscribe")
  • Include customer service contact information
  • Comply with carrier quiet hours (no messages 9 PM - 8 AM recipient local time)
  • Are sent at reasonable frequencies (no message flooding or spam)
  • Match the category for which consent was given

Unsubscribe Management

  • When a recipient replies "STOP," they are automatically removed from all SMS marketing
  • Removal is processed immediately; no further messages are sent
  • Recipients can specify which message types to receive or frequencies
  • Transactional messages (order updates, account alerts) may still be sent to opted-out users unless explicitly requested otherwise
  • All unsubscribe requests are documented for compliance

Carrier Compliance

Temple de la Luna maintains compliance with:

  • TCPA (Telephone Consumer Protection Act) requirements
  • Carrier guidelines for Sprint, Verizon, AT&T, T-Mobile, and others
  • GDPR requirements for EU residents' SMS
  • CCPA requirements for California residents' SMS
  • Regulations prohibiting messages to minors without parental consent

6. Data Retention

Temple de la Luna retains personal information as long as necessary to provide services and fulfill the purposes outlined in this policy:

  • Active Account Data: Retained while your account is active plus 12 months after closure
  • Marketing Consent Records: Retained for 3+ years for compliance documentation
  • Transaction Data: Retained for 7 years (tax and legal requirements)
  • Website Analytics: Retained for 24 months (aggregated after 12 months)
  • Support Communications: Retained for 2 years for service quality purposes
  • SMS Logs: Retained for 12 months for compliance audits

Once the retention period expires, we delete or anonymize your data. You may request earlier deletion by contacting us, except where legal obligations require retention.

7. Data Security

Security Measures

Temple de la Luna implements comprehensive security measures to protect your personal information:

  • Encryption: TLS/SSL encryption for all data in transit; AES-256 for data at rest
  • Access Controls: Role-based access; only authorized staff can access sensitive data
  • Authentication: Secure password requirements; optional multi-factor authentication
  • Firewalls & Intrusion Detection: Network protection and monitoring
  • Regular Security Audits: Annual security assessments and penetration testing
  • Secure Infrastructure: Hosted on enterprise-grade servers with redundancy
  • Employee Training: Staff trained in data protection and privacy practices
  • Incident Response Plan: Documented procedures for responding to security breaches

Limitations

While we employ robust security measures, no system is completely immune to breaches. Transmission over the internet is never 100% secure. We are not responsible for unauthorized access resulting from user negligence or security failures beyond our reasonable control.

Breach Notification

In the event of a data breach involving personal information, we will notify affected individuals and regulatory authorities as required by law, typically within 72 hours (or as mandated by applicable regulations).

8. Your Privacy Rights

Universal Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Update or correct inaccurate information
  • Deletion: Request that we delete your personal data (right to be forgotten)
  • Opt-Out: Unsubscribe from marketing communications anytime
  • Transparency: Understand how your data is processed

GDPR Rights (for EU/UK Residents)

  • Data Portability: Receive your data in a portable format
  • Restriction: Request we limit processing of your data
  • Objection: Object to processing for legitimate interests
  • Automated Decision Making: Not be subject to decisions based solely on automated processing
  • Withdraw Consent: Withdraw consent for data processing at any time

CCPA Rights (for California Residents)

  • Know: Request the categories and specific pieces of personal information collected
  • Delete: Request deletion of personal information (with some exceptions)
  • Opt-Out: Opt out of the selling/sharing of personal information
  • Non-Discrimination: Not be discriminated against for exercising your rights
  • Correct: Request correction of inaccurate personal information

How to Exercise Your Rights

To submit a request, contact us with:

  • Your full name and email address
  • Description of the right you're exercising
  • Any supporting documentation

We will verify your identity and respond within the timeframe required by applicable law (typically 30-45 days).

9. Cookies & Tracking Technologies

What Are Cookies?

Cookies are small text files stored on your device that help us recognize you and enhance your experience. We use both session cookies (temporary) and persistent cookies (longer-term).

Types of Cookies We Use

  • Essential Cookies: Required for website functionality (login, security)
  • Performance Cookies: Measure usage patterns and site performance
  • Preference Cookies: Remember your settings and choices
  • Marketing Cookies: Track behavior for personalized advertising

Tracking Technologies

We may use:

  • Pixels & Web Beacons: Track page views and user interactions
  • Google Analytics: Aggregate usage statistics
  • Conversion Tracking: Monitor campaign effectiveness

Your Cookie Choices

  • You can disable cookies in your browser settings
  • Disabling cookies may affect website functionality
  • You can clear cookies from your device at any time
  • Most browsers have a "Do Not Track" option you can enable

Third-Party Services

We may use third-party services (Google Analytics, GoHighLevel) that set their own cookies. These providers have their own privacy policies. We encourage you to review their practices.

10. Children's Privacy

Temple de la Luna Services are not directed to children under 13 years old. We do not knowingly collect personal information from children under 13. If we discover we have collected information from a child under 13, we will delete it immediately.

For users ages 13-18, we provide additional protections and require verifiable parental consent before processing their data for marketing purposes.

If you believe we have collected information from a child under 13, please contact us immediately.

11. GDPR & CCPA Compliance

GDPR Compliance (EU/UK/EEA Residents)

As a service provider for users in the European Union, United Kingdom, and European Economic Area, Temple de la Luna complies fully with the General Data Protection Regulation (GDPR):

  • Data processing is based on explicit legal grounds (consent, contract, legitimate interest, legal obligation)
  • You have the rights outlined in Section 8 above
  • We conduct Data Protection Impact Assessments for high-risk processing
  • Our Data Protection Officer can be reached at privacy@templedelaluna.com
  • We comply with GDPR's international data transfer requirements
  • Restrictions apply to processing children's data (under 16 in some jurisdictions)

CCPA Compliance (California Residents)

Temple de la Luna complies with the California Consumer Privacy Act (CCPA) and successor regulations (CPRA):

  • California residents have the specific rights outlined in Section 8 above
  • We do not sell personal information (as defined by CCPA)
  • We limit data collection to what is necessary for stated purposes
  • You can submit requests by emailing privacy@templedelaluna.com or calling [phone number]
  • We respond to requests within 45 days of verification
  • We do not discriminate against users for exercising CCPA rights

12. Changes to This Privacy Policy

Temple de la Luna may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting the updated policy on our website
  • Sending email notification of significant changes
  • Requesting your consent if required by applicable law

Your continued use of our Services following the posting of updates constitutes your acceptance of the changes. We encourage you to review this policy periodically.

13. Contact Us

If you have questions about this Privacy Policy, concerns about our practices, or wish to exercise your privacy rights, please contact us:

Email: help@templedelaluna.com

Support Email: help@templedelaluna.com

Website: www.templedelaluna.com

Mailing Address: Temple de la Luna, St Petersburg, FL

Response Time: We aim to respond to all privacy inquiries within 5 business days

Data Protection Officer

For GDPR-related inquiries, you may contact our Data Protection Officer at dpo@templedelaluna.com

Dispute Resolution

If you are unsatisfied with our response to a privacy concern, you have the right to lodge a complaint with your local data protection authority (for GDPR) or the California Attorney General (for CCPA).

Last Updated: April 2025 | Version 1.0