Privacy Policy and Legal Notice
1. Data controller
In compliance with Mexico's Federal Law for the Protection of Personal Data Held by Private Parties (LFPDPPP) and applicable provisions of the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and Canada's PIPEDA, we inform you that:
XPECTATIVE TRAVEL SRL DE CV (hereinafter, "Cancun100" or "the Agency"), with registered address at Calle Tejón 14, Ground Floor, Cancun, Quintana Roo, ZIP 77500, Mexico, Mexican Tax ID XTR2306232CA, is the data controller responsible for the processing, use and protection of your personal data collected through cancun100.com and associated channels (WhatsApp, email, forms, social media).
2. Personal data we collect
Depending on your interaction, we may collect the following categories of personal data:
Identification data
- Full name, nationality, date of birth or age.
Contact data
- Email address, mobile phone and/or WhatsApp.
Booking data
- Tour, package or service contracted, dates, number of people, hotel and pickup point, special conditions (allergies, mobility needs).
Tax data (only if you request an invoice)
- Mexican Tax ID (RFC), legal name, tax address, CFDI use, tax regime.
Payment data
- We do NOT store full credit card numbers. Payments are processed through PCI DSS-certified platforms (Stripe, PayPal, MercadoPago). We only receive a transaction reference.
Browsing data
- IP address, browser type, operating system, device, approximate location (city level), pages visited, time on site, referral source.
We do not collect sensitive personal data (racial or ethnic origin, health, religious beliefs, sexual preference, political opinions) unless you voluntarily share information relevant to service delivery (e.g. allergies, physical restrictions).
3. Processing purposes
A. Primary purposes (necessary for service)
- Manage your reservation, process payments and issue confirmations.
- Contact you to confirm, modify or cancel services.
- Coordinate transportation and logistics with tour operators.
- Issue invoices and tax receipts as required by law.
- Address questions, clarifications, complaints or requests.
- Comply with legal obligations (tax, accounting, consumer protection).
- Prevent fraud and protect our systems' security.
B. Secondary purposes (optional — require consent)
- Send promotions, discounts, news and travel recommendations.
- Conduct satisfaction surveys.
- Analyze preferences and consumer behavior to improve our offering.
- Show you personalized ads through Meta (Facebook/Instagram), Google Ads, TikTok and other advertising platforms.
If you do not want your data used for secondary purposes, send an email to info@cancun100.com with subject "Opt-out secondary purposes". This will not affect your contracted services.
4. Legal basis for processing
We process your personal data based on:
- Consent: for secondary purposes and marketing communications.
- Contract performance: to manage your reservation and provide the contracted service.
- Legal obligation: for issuing invoices, tax records and responding to authority requests.
- Legitimate interest: to prevent fraud, improve site security and analyze aggregate usage trends.
5. Retention periods
We keep your personal data only for as long as necessary to fulfill the purposes for which it was collected:
| Data type | Retention period |
|---|---|
| Tax data (invoices, receipts) | 5 years from issuance, per Mexican Federal Tax Code. |
| Booking and operational data | 3 years after service delivery for incident resolution and claims. |
| Marketing data (subscriptions, profiles) | Until you request cancellation or exercise your rights. |
| Browsing data (logs, analytics) | 14 to 26 months depending on the tool (see section 7). |
Once retention periods elapse, data is securely deleted or anonymized.
6. Data transfers
Your personal data may be transferred to:
- Tour operators and certified transportation providers, exclusively to provide the service you contracted.
- Hotels to manage your accommodation when applicable.
- Payment processors (Stripe, PayPal, MercadoPago) to validate transactions.
- Technology providers (hosting, email, CRM, analytics) under confidentiality agreements.
- Advertising platforms (Meta, Google, TikTok) for marketing campaigns — with prior consent.
- Competent authorities in compliance with legal or judicial mandates.
We do not sell or commercialize your personal data to third parties for their own use.
7. Analytics and marketing tools
To enhance your experience, measure site performance and show you relevant advertising, we use the following tools:
| Tool | Purpose | Data |
|---|---|---|
| Google Analytics 4 | Traffic and behavior analytics | Anonymized IP, events, device |
| Microsoft Clarity | Heatmaps and session recordings | Clicks, scroll, anonymized session |
| Meta Pixel | Remarketing on Facebook and Instagram | Conversion events, visits |
| TikTok Pixel | Remarketing and conversions on TikTok | Conversion events, visits |
| Google Ads | Remarketing and campaign attribution | Conversion events |
| WhatsApp Business | Direct communication with you | Phone number, conversation |
You can opt-out of these tools by configuring your browser to block cookies or using control tools such as the Google Analytics opt-out extension or each platform's advertising preferences.
For complete details, see our Cookie Policy.
8. Your data rights
You have the right to Access, Rectify, Cancel/Delete, and Object to the processing of your personal data, as well as to withdraw consent you have given. Under applicable laws, you may also have rights to data portability and processing restriction.
To exercise these rights, send a request to info@cancun100.com with subject "Data Rights Request" and the following information:
- Your full name and a legible copy of valid government-issued identification (passport, driver's license, ID).
- Clear and precise description of the data on which you want to exercise the right.
- Specific right you want to exercise (access, rectification, cancellation, opposition, portability).
- Contact method to receive our response (email or address).
- For rectification: documentation supporting the requested change.
We will respond within a maximum of 20 business days as per article 32 of the LFPDPPP. If the request is granted, the change will take effect within the following 15 business days.
This service is free of charge. We will only charge justified shipping or reproduction costs when applicable.
9. Use of cookies
This site uses cookies, web beacons and similar technologies to remember your preferences, analyze site usage and show personalized advertising.
To learn in detail about which cookies we use, their purposes and how to manage them, see our Cookie Policy.
10. Information security
We implement reasonable administrative, technical and physical measures to protect your data against unauthorized access, loss, alteration or disclosure. These measures include:
- SSL/TLS encrypted connections across the entire site.
- Restricted access to personal information limited to authorized personnel under confidentiality.
- PCI DSS-certified payment processors (we do not store card data).
- Regular backups and anomalous activity monitoring.
- Continuous software and security patch updates.
Despite our reasonable measures, no system is 100% impenetrable. In the event of a security incident significantly affecting your data, we will notify you without undue delay as per article 20 of the LFPDPPP.
11. Minors' data
Our services are intended for persons over 18 years old. We do not knowingly collect personal data from minors without express consent from their parent or legal guardian.
When a reservation includes minors as companions, the data is provided by the responsible adult, who declares having authorization to do so.
If you detect that a minor has provided us with data without authorization, contact us to delete it immediately.
12. International visitors
If you visit this site from the European Union, United Kingdom, California (USA), Canada or another jurisdiction with specific data protection laws:
- GDPR (European Union / United Kingdom): we acknowledge the applicable provisions on rights of access, rectification, erasure, portability, restriction and objection. You can exercise them through the same means indicated in section 8.
- CCPA (California): we acknowledge the rights to know, delete, opt-out of sale ("Do Not Sell My Personal Information") and non-discrimination.
- PIPEDA (Canada): we acknowledge the applicable provisions on use, disclosure and consent.
Without prejudice to the above, the primary applicable jurisdiction is Mexico as the country of incorporation of the Agency, and data is processed in accordance with the LFPDPPP.
13. Changes to this notice
Cancun100 reserves the right to update this Privacy Policy to reflect legal, operational or technological changes. Modifications will be published on this page, indicating the update date at the top.
We recommend reviewing this document periodically. Continued use of the site after any modification implies acceptance of the new notice.
14. Supervisory authority
If you believe your data protection rights have been violated, you may file a complaint with the National Institute of Transparency, Access to Information and Personal Data Protection (INAI) of Mexico:
- Website: home.inai.org.mx
- Phone: +52 800 835 4324
EU residents may also contact their national supervisory authority. California residents may contact the California Attorney General. Canadian residents may contact the Office of the Privacy Commissioner.
Before contacting any authority, we invite you to reach out to us directly to resolve any concerns.
15. Privacy officer contact
For any matter related to your personal data or this Privacy Policy, contact us:
- Data Protection Office: info@cancun100.com
- Phone / WhatsApp: +52 998 763 7653
- Address: Calle Tejón 14, Ground Floor, Cancun, Quintana Roo, ZIP 77500, Mexico
Data controller
XPECTATIVE TRAVEL SRL DE CV




