Effective date: August 1, 2026
Last updated: August 1, 2026
Off Grid Destinations is operated by:
Little Frog S.R.L.
Costa Rican legal entity number: 3-102-711410
Trading as: Off Grid Destinations
Country of establishment: Costa Rica
Email: info@offgriddestinations.com
In this Privacy Policy, “OGD,” “we,” “us” and “our” refer to Little Frog S.R.L.
This Policy explains how we collect, use, disclose, store and protect personal information when you visit or use Off Grid Destinations.
This Policy applies to personal information processed through:
Third-party websites and services have their own privacy policies.
We may collect:
Owners may provide:
Some listing and profile information is intended to be displayed publicly.
Sensitive payment or arrival information is intended to be restricted to authorised users at the applicable stage of a booking.
We may collect and retain:
We may preserve a booking snapshot so that the terms and listing information applicable to a booking are not silently changed afterward.
The OGD booking deposit is the amount OGD’s booking workflow displays and processes for a given booking; it is not a single fixed percentage, since the amount and the way it is calculated can differ between types of stay — for example, a nightly stay compared with a longer monthly stay. The remaining balance, whatever it is for a given booking, is paid directly between guest and owner, as described in Section 10.
Where identity verification is required, a third-party provider such as Didit may process:
OGD may receive and store:
Identity documents, facial imagery and biometric information may be collected and retained directly by the verification provider rather than in OGD’s ordinary WordPress database.
The provider’s own privacy notice explains its processing and retention practices.
When a booking agreement is created or signed through Firma or another provider, we may process:
A completed agreement may be stored with the booking record.
We may automatically receive:
We may receive information from:
Separately from the booking-specific acceptance records described in Section 3.3, when you accept or acknowledge an account-level document — the Platform Terms, this Privacy Policy, or the Host Agreement — we record: which document and version was involved; a checksum of its full text at the time; the full text of the version you accepted or acknowledged; the short wording shown next to the relevant checkbox; your account identifier; the role you were acting in (Guest or Host); which of a small set of defined completion paths your acceptance or acknowledgement came through (for example, direct registration, completion following a Google sign-in, or completion through a follow-up review step); and the date and time, in UTC. This record does not include your IP address or browser/user-agent information — those are collected separately, where applicable, as described in Section 3.6, not as part of this specific record. While retained, an acceptance or acknowledgement record is not overwritten by a later acceptance. A later acceptance of a newer version is stored as an additional record. Retention and deletion of these records are governed by Section 14 and applicable law.
Separately, if a required account-level document has not yet been accepted, your account may temporarily carry a short account flag noting that fact and, at most, a general reason for it drawn from the same small set of completion paths described above. This flag is cleared automatically once the outstanding document has been accepted, is used only to determine whether a required step is still outstanding, and is not shared with third parties or used for marketing.
We use personal information to:
Depending on the information, location and context, we may process personal information because:
Processing is necessary to provide an account, listing, booking workflow, digital agreement or another service requested by the user.
Processing is necessary for legitimate interests such as:
We consider the effect of this processing on individual rights.
We may process and retain information to comply with:
We may rely on consent for activities such as:
Consent may be withdrawn, but withdrawal does not make earlier lawful processing invalid.
Acknowledging this Policy, on its own, is not one of these grounds for a particular processing activity — it confirms you have reviewed this Policy. Where we need your consent specifically (as in this “Consent” ground above), we ask for it separately, in the context where it applies.
Information may be processed where necessary to establish, exercise or defend legal claims, investigate fraud, or protect users and the platform.
Identity verification can involve highly sensitive information.
Before starting verification, users should be informed that a third-party verification provider may process identity documents, facial images, liveness information and biometric comparison data.
OGD uses identity verification for purposes including:
A successful verification is not a guarantee of character, future conduct, property ownership or transaction performance.
Where applicable law requires explicit consent for biometric processing, the verification flow should request it before that processing begins.
Users who do not complete required verification may be unable to perform restricted booking actions.
Information intentionally published in a profile or listing may be visible to the public and indexed by search engines.
This may include:
Owners should not place sensitive personal information in public listing fields.
Exact payment instructions, identity-verification information, signed agreements and restricted arrival information are not intended to be publicly displayed.
To facilitate a booking, OGD may share relevant information between the owner and guest, including:
Users must use this information only for the booking or legitimate related purposes.
They may not sell it, use it for unrelated marketing or disclose it unlawfully.
We may disclose information to providers that help operate OGD.
Hosting, database, caching, backup and technical providers may process website files, account information, logs and database content.
Payment providers process payment, identity, device, risk and transaction information under their own terms.
OGD does not ordinarily receive a user’s complete payment-card or bank-login credentials.
Didit may process identity documents, facial images, liveness and related verification information.
Firma may receive names, email addresses, booking information and agreement documents to arrange electronic signatures.
Email providers may process names, addresses, booking information and message content needed to deliver transactional communications.
Google services may support:
Google may receive technical, device, account or usage information depending on the service and the user’s choices.
Security services may process IP addresses, login events, account actions and technical information.
Information may be shared where reasonably necessary with accountants, lawyers, insurers, auditors or advisers subject to appropriate confidentiality duties.
We may disclose information where required by law, court order or a valid request from a competent authority.
Information may be transferred as part of a merger, restructuring, financing, asset sale or transfer of OGD, subject to applicable law and continued protection.
Different providers may act as processors, service providers or independent controllers depending on their role.
The booking balance remaining beyond the OGD booking deposit is paid directly between the guest and owner.
OGD may display owner-provided payment instructions and record the status of the payment, but does not control the transfer.
Payment services selected by the owner may collect additional personal and financial information under their own privacy policies.
Users should review the relevant provider’s terms before making payment.
OGD may send emails or platform notices concerning:
These are service communications rather than promotional marketing.
OGD does not currently send promotional marketing emails. If optional marketing is introduced, we will provide the choices or consent required by applicable law.
OGD uses cookies and similar technologies for:
Non-essential analytics or advertising technologies will be managed through the cookie-consent mechanism where required.
More information appears in the Cookie Policy.
OGD is operated from Costa Rica and uses providers that may process information in other countries.
Information may therefore be transferred to and stored in countries whose privacy laws differ from those in the user’s country.
Where legally required, OGD and its providers may use contractual protections, adequacy mechanisms or other lawful safeguards for international transfers.
Users may contact us for further information about a relevant transfer.
We retain information only for as long as reasonably required for the purposes described in this Policy, subject to legal, accounting, contractual, security and dispute requirements.
Typical principles include:
Retained while active and for a reasonable period after closure where necessary for security, fraud prevention, disputes or legal obligations.
Retained while published or active, and afterward where needed for booking records, complaints, fraud prevention, moderation or legal claims.
Booking snapshots, payment references, refund records, user acceptances and related accounting information may generally be retained for up to five years, or longer where required by law or an active dispute.
Records of your acceptance or acknowledgement of an account-level document (Section 3.8) are retained while reasonably necessary to document the account relationship, the documents you accepted, related transactions, disputes, and our legal obligations. They may be retained after your account is closed where reasonably necessary for an active booking, a legal claim, an accounting requirement, a fraud or security purpose, or another lawful obligation. While a record is retained, a later acceptance of a newer version does not overwrite it — it is stored as an additional record — but this does not mean any individual record is kept forever: information is deleted or de-identified once it is no longer reasonably necessary for these purposes, subject to applicable law.
Retained with the relevant booking record for the period reasonably needed to establish and enforce contractual rights.
OGD retains verification status and necessary audit information only for as long as reasonably needed for security, fraud prevention, legal compliance or transaction records.
The verification provider controls its own retention of documents and biometric information according to its terms and legal obligations.
Retained for as long as needed to provide support, administer a booking, investigate misuse or address a dispute.
Retained for a proportionate operational period unless needed for an investigation or legal claim.
Information may remain temporarily in protected backups until deleted through the normal backup-rotation process.
Information relevant to a complaint, chargeback, investigation or legal claim may be retained until that matter and any relevant limitation period have ended.
Users may request access, correction or deletion of their account information by contacting:
Deletion may not be immediate or complete where information must be retained for:
Where appropriate, information may be anonymised instead of deleted.
Depending on applicable law and location, users may have rights to:
These rights may be subject to legal exceptions.
We may need to verify the requester’s identity before responding.
Requests should be sent to:
Costa Rican users may also have the right to submit a complaint to the Agencia de Protección de Datos de los Habitantes, commonly known as PRODHAB.
OGD and its providers may use automated systems to:
These checks may affect whether an action is permitted.
Where required by applicable law, users may request information or human review of a consequential automated decision.
OGD’s property-fit or search tools provide informational recommendations and do not make legally binding decisions about a user.
OGD uses administrative and technical safeguards intended to protect information, which may include:
No system is completely secure. OGD cannot guarantee that unauthorised access, loss or misuse will never occur.
Users are responsible for protecting their own account credentials and devices.
Where OGD becomes aware of a personal-data incident, we will investigate and take reasonable steps to contain and address it.
Where required by applicable law, we will notify affected individuals or the relevant authority.
OGD accounts and transaction features are intended only for people aged 18 or older.
We do not knowingly permit children to create accounts, publish listings, make bookings or sign agreements.
Where we learn that an account was created by a person under 18, we may restrict or delete it, subject to legal and record-retention requirements.
OGD content may link to third-party websites, booking services, products or affiliate partners.
Those services control their own collection and use of information. OGD’s Privacy Policy does not govern them.
Users should review the third party’s privacy notice before providing information.
We may update this Privacy Policy to reflect changes in:
The updated Policy will show a revised effective date.
Where a change materially affects users, we may ask you to review and re-acknowledge the updated Policy, in the same way described in the Platform Terms.
Questions, requests or complaints about privacy may be sent to:
Little Frog S.R.L., trading as Off Grid Destinations
Costa Rica
info@offgriddestinations.com