PRIVACY POLICY

Effective date: July 10, 2026
Last updated: July 10, 2026

1. Who we are

Off Grid Destinations is operated by:

Little Frog S.R.L.
Costa Rican legal entity number: 3-102-711410
Trading as:
Off Grid Destinations
Country of establishment:
Costa Rica
Email: info@offgriddestinations.com

In this Privacy Policy, “OGD,” “we,” “us” and “our” refer to Little Frog S.R.L.

This Policy explains how we collect, use, disclose, store and protect personal information when you visit or use Off Grid Destinations.

2. Scope

This Policy applies to personal information processed through:

  • the OGD website;
  • user accounts and profiles;
  • listings;
  • booking requests;
  • booking payments;
  • identity verification;
  • digital agreements;
  • messages and enquiries;
  • comments and reviews;
  • support communications;
  • property and land enquiries;
  • platform security, analytics and administration.

Third-party websites and services have their own privacy policies.

3. Information we collect

3.1 Information you provide

We may collect:

  • username;
  • full or display name;
  • email address;
  • password in hashed form;
  • profile photograph or avatar;
  • biography and profile information;
  • telephone number;
  • country or general location;
  • messages and enquiries;
  • customer-support communications;
  • comments and reviews;
  • information submitted through forms.

3.2 Listing information

Owners may provide:

  • property descriptions;
  • photographs and files;
  • address or location information;
  • map coordinates;
  • amenities and property features;
  • availability and prices;
  • house rules;
  • cancellation terms;
  • check-in and check-out information;
  • access and arrival instructions;
  • owner payment instructions;
  • contact details;
  • ownership or authority declarations;
  • insurance, permit and compliance declarations.

Some listing and profile information is intended to be displayed publicly.

Sensitive payment or arrival information is intended to be restricted to authorised users at the applicable stage of a booking.

3.3 Booking information

We may collect and retain:

  • guest and owner names and emails;
  • listing and property identifiers;
  • requested and confirmed dates;
  • number of guests;
  • prices and currency;
  • OGD’s 10% platform payment;
  • remaining owner balance;
  • payment status;
  • PayPal or payment-provider transaction references;
  • timestamps;
  • cancellation-policy information;
  • booking status;
  • guest and owner acceptance records;
  • refund and cancellation history;
  • evidence that a direct payment was recorded as sent or received;
  • support and dispute records.

We may preserve a booking snapshot so that the terms and listing information applicable to a booking are not silently changed afterward.

3.4 Identity-verification information

Where identity verification is required, a third-party provider such as Didit may process:

  • legal name;
  • identity-document information;
  • copies or images of identity documents;
  • facial images or video;
  • liveness information;
  • biometric comparison information;
  • age or date-of-birth information;
  • country and document type;
  • verification results.

OGD may receive and store:

  • verification status;
  • session or decision references;
  • dates and timestamps;
  • expiry or rejection status;
  • limited audit and troubleshooting information.

Identity documents, facial imagery and biometric information may be collected and retained directly by the verification provider rather than in OGD’s ordinary WordPress database.

The provider’s own privacy notice explains its processing and retention practices.

3.5 Digital-agreement information

When a booking agreement is created or signed through Firma or another provider, we may process:

  • names and email addresses;
  • booking details;
  • payment amounts and references;
  • listing and policy information;
  • acceptance records;
  • signature status;
  • signing timestamps;
  • signed agreement documents;
  • provider submission and document identifiers.

A completed agreement may be stored with the booking record.

3.6 Technical and usage information

We may automatically receive:

  • IP address;
  • browser type;
  • device and operating-system information;
  • date and time of access;
  • pages visited;
  • referring pages;
  • login and session information;
  • cookie and consent preferences;
  • security and activity events;
  • approximate geographic information derived from IP;
  • analytics information where consent is required and obtained.

3.7 Information from third parties

We may receive information from:

  • Google login;
  • payment providers;
  • identity-verification providers;
  • electronic-signature providers;
  • owners or guests involved in a booking;
  • email-delivery providers;
  • security and anti-spam services;
  • analytics services;
  • support or legal representatives.

4. Why we use personal information

We use personal information to:

  • create and manage accounts;
  • verify email addresses;
  • provide Google login or other authentication;
  • prevent bots, spam and abuse;
  • publish and manage listings;
  • connect owners with suitable prospective guests;
  • process booking requests;
  • collect OGD’s platform fee;
  • reserve dates;
  • conduct identity verification;
  • create and sign booking agreements;
  • provide booking status and payment tools;
  • communicate transactional updates;
  • provide support;
  • handle cancellation and refund requests;
  • investigate fraud, chargebacks or misuse;
  • enforce our Terms;
  • maintain security and audit records;
  • comply with legal, tax and accounting duties;
  • maintain backups;
  • improve the platform;
  • measure website usage where legally permitted;
  • defend legal claims;
  • protect users, OGD and third parties.

5. Legal grounds for processing

Depending on the information, location and context, we may process personal information because:

Contract

Processing is necessary to provide an account, listing, booking workflow, digital agreement or another service requested by the user.

Legitimate interests

Processing is necessary for legitimate interests such as:

  • operating and improving the platform;
  • preventing fraud and abuse;
  • securing accounts;
  • maintaining transaction records;
  • handling disputes;
  • communicating service information;
  • protecting OGD and users.

We consider the effect of this processing on individual rights.

Legal obligations

We may process and retain information to comply with:

  • tax and accounting duties;
  • court orders;
  • lawful authority requests;
  • consumer-protection requirements;
  • privacy and security obligations;
  • fraud or financial-record requirements.

Consent

We may rely on consent for activities such as:

  • non-essential analytics cookies;
  • advertising or affiliate tracking where consent is legally required;
  • optional marketing communications;
  • particular identity or biometric processing where explicit consent is the appropriate legal basis.

Consent may be withdrawn, but withdrawal does not make earlier lawful processing invalid.

Legal claims and substantial protection interests

Information may be processed where necessary to establish, exercise or defend legal claims, investigate fraud, or protect users and the platform.

6. Identity and biometric processing

Identity verification can involve highly sensitive information.

Before starting verification, users should be informed that a third-party verification provider may process identity documents, facial images, liveness information and biometric comparison data.

OGD uses identity verification for purposes including:

  • reducing impersonation and fraud;
  • confirming that users involved in bookings are real;
  • protecting payments and agreements;
  • enforcing minimum-age and eligibility requirements where configured;
  • supporting platform trust and safety.

A successful verification is not a guarantee of character, future conduct, property ownership or transaction performance.

Where applicable law requires explicit consent for biometric processing, the verification flow should request it before that processing begins.

Users who do not complete required verification may be unable to perform restricted booking actions.

7. Public information

Information intentionally published in a profile or listing may be visible to the public and indexed by search engines.

This may include:

  • display name;
  • avatar;
  • biography;
  • listing title and description;
  • photographs;
  • amenities;
  • general location;
  • public reviews and comments.

Owners should not place sensitive personal information in public listing fields.

Exact payment instructions, identity-verification information, signed agreements and restricted arrival information are not intended to be publicly displayed.

8. Information shared between owners and guests

To facilitate a booking, OGD may share relevant information between the owner and guest, including:

  • names;
  • contact details;
  • booking dates;
  • party or reservation information;
  • booking status;
  • signed agreement information;
  • owner payment instructions;
  • arrival and check-in details;
  • relevant messages.

Users must use this information only for the booking or legitimate related purposes.

They may not sell it, use it for unrelated marketing or disclose it unlawfully.

9. Service providers and third parties

We may disclose information to providers that help operate OGD.

Hosting and website infrastructure

Hosting, database, caching, backup and technical providers may process website files, account information, logs and database content.

PayPal and payment providers

Payment providers process payment, identity, device, risk and transaction information under their own terms.

OGD does not ordinarily receive a user’s complete payment-card or bank-login credentials.

Didit

Didit may process identity documents, facial images, liveness and related verification information.

Firma

Firma may receive names, email addresses, booking information and agreement documents to arrange electronic signatures.

Brevo and email providers

Email providers may process names, addresses, booking information and message content needed to deliver transactional communications.

Google

Google services may support:

  • account login;
  • reCAPTCHA and bot prevention;
  • analytics;
  • maps;
  • search-performance tools;
  • cloud or backup storage.

Google may receive technical, device, account or usage information depending on the service and the user’s choices.

Security and logging providers

Security services may process IP addresses, login events, account actions and technical information.

Professional and legal advisers

Information may be shared where reasonably necessary with accountants, lawyers, insurers, auditors or advisers subject to appropriate confidentiality duties.

Authorities

We may disclose information where required by law, court order or a valid request from a competent authority.

Corporate transactions

Information may be transferred as part of a merger, restructuring, financing, asset sale or transfer of OGD, subject to applicable law and continued protection.

Different providers may act as processors, service providers or independent controllers depending on their role.

10. Direct owner payments

The remaining 90% booking balance is paid directly between the guest and owner.

OGD may display owner-provided payment instructions and record the status of the payment, but does not control the transfer.

Payment services selected by the owner may collect additional personal and financial information under their own privacy policies.

Users should review the relevant provider’s terms before making payment.

11. Transactional communications

OGD may send emails or platform notices concerning:

  • account verification;
  • password and security events;
  • listing activity;
  • booking requests;
  • owner approval or decline;
  • payment status;
  • identity verification;
  • digital agreements;
  • cancellation or expiry;
  • direct-payment status;
  • booking confirmation;
  • arrival information;
  • support and policy updates.

These are service communications rather than promotional marketing.

OGD does not currently send promotional marketing emails. If optional marketing is introduced, we will provide the choices or consent required by applicable law.

12. Cookies and similar technologies

OGD uses cookies and similar technologies for:

  • login and account sessions;
  • security and fraud prevention;
  • cookie-preference storage;
  • forms and platform functionality;
  • Google login;
  • reCAPTCHA;
  • payment features;
  • maps and embedded services;
  • analytics where permitted;
  • affiliate attribution where applicable.

Non-essential analytics or advertising technologies will be managed through the cookie-consent mechanism where required.

More information appears in the Cookie Policy.

13. International transfers

OGD is operated from Costa Rica and uses providers that may process information in other countries.

Information may therefore be transferred to and stored in countries whose privacy laws differ from those in the user’s country.

Where legally required, OGD and its providers may use contractual protections, adequacy mechanisms or other lawful safeguards for international transfers.

Users may contact us for further information about a relevant transfer.

14. Data retention

We retain information only for as long as reasonably required for the purposes described in this Policy, subject to legal, accounting, contractual, security and dispute requirements.

Typical principles include:

Accounts and profiles

Retained while active and for a reasonable period after closure where necessary for security, fraud prevention, disputes or legal obligations.

Listings and user content

Retained while published or active, and afterward where needed for booking records, complaints, fraud prevention, moderation or legal claims.

Booking and payment records

Booking snapshots, payment references, refund records, user acceptances and related accounting information may generally be retained for up to five years, or longer where required by law or an active dispute.

Signed agreements

Retained with the relevant booking record for the period reasonably needed to establish and enforce contractual rights.

Identity verification

OGD retains verification status and necessary audit information only for as long as reasonably needed for security, fraud prevention, legal compliance or transaction records.

The verification provider controls its own retention of documents and biometric information according to its terms and legal obligations.

Messages and support records

Retained for as long as needed to provide support, administer a booking, investigate misuse or address a dispute.

Security logs

Retained for a proportionate operational period unless needed for an investigation or legal claim.

Backups

Information may remain temporarily in protected backups until deleted through the normal backup-rotation process.

Legal holds

Information relevant to a complaint, chargeback, investigation or legal claim may be retained until that matter and any relevant limitation period have ended.

15. Account deletion and privacy requests

Users may request access, correction or deletion of their account information by contacting:

info@offgriddestinations.com

Deletion may not be immediate or complete where information must be retained for:

  • an active booking;
  • a signed agreement;
  • accounting or tax records;
  • fraud prevention;
  • security;
  • a dispute or chargeback;
  • compliance with law;
  • establishment or defence of legal claims;
  • protected backup rotation.

Where appropriate, information may be anonymised instead of deleted.

16. Privacy rights

Depending on applicable law and location, users may have rights to:

  • know whether we process their information;
  • access their information;
  • correct inaccurate information;
  • request deletion;
  • object to certain processing;
  • restrict processing;
  • receive portable information;
  • withdraw consent;
  • complain to a privacy authority;
  • receive information about international transfers;
  • request human review of certain automated decisions, where applicable.

These rights may be subject to legal exceptions.

We may need to verify the requester’s identity before responding.

Requests should be sent to:

info@offgriddestinations.com

Costa Rican users may also have the right to submit a complaint to the Agencia de Protección de Datos de los Habitantes, commonly known as PRODHAB.

17. Automated checks

OGD and its providers may use automated systems to:

  • detect spam or bots;
  • evaluate suspicious login activity;
  • assess payment risk;
  • conduct identity and liveness checks;
  • identify possible fraud or misuse.

These checks may affect whether an action is permitted.

Where required by applicable law, users may request information or human review of a consequential automated decision.

OGD’s property-fit or search tools provide informational recommendations and do not make legally binding decisions about a user.

18. Security

OGD uses administrative and technical safeguards intended to protect information, which may include:

  • encrypted HTTPS connections;
  • password hashing;
  • email verification;
  • Google authentication;
  • reCAPTCHA;
  • access and role controls;
  • security logging;
  • webhook verification;
  • restricted administrative access;
  • backups;
  • provider security controls.

No system is completely secure. OGD cannot guarantee that unauthorised access, loss or misuse will never occur.

Users are responsible for protecting their own account credentials and devices.

19. Data incidents

Where OGD becomes aware of a personal-data incident, we will investigate and take reasonable steps to contain and address it.

Where required by applicable law, we will notify affected individuals or the relevant authority.

20. Children

OGD accounts and transaction features are intended only for people aged 18 or older.

We do not knowingly permit children to create accounts, publish listings, make bookings or sign agreements.

Where we learn that an account was created by a person under 18, we may restrict or delete it, subject to legal and record-retention requirements.

21. External links and affiliate services

OGD content may link to third-party websites, booking services, products or affiliate partners.

Those services control their own collection and use of information. OGD’s Privacy Policy does not govern them.

Users should review the third party’s privacy notice before providing information.

22. Changes to this Policy

We may update this Privacy Policy to reflect changes in:

  • services;
  • providers;
  • legal requirements;
  • data practices;
  • security measures.

The updated Policy will show a revised effective date.

Where a change materially affects users, we may provide additional notice.

23. Contact and complaints

Questions, requests or complaints about privacy may be sent to:

Little Frog S.R.L., trading as Off Grid Destinations
Costa Rica
info@offgriddestinations.com