Oops! Sorry!!


This site doesn't support Internet Explorer. Please use a modern browser like Chrome, Firefox or Edge.

Privacy Policy

Last updated: 3/31/2026

Naya Surf & Tours ("we," "our," or "us") is committed to protecting your privacy and being transparent about how we collect, use, and protect your personal information. This Privacy Policy explains our data practices in clear, understandable terms.

Quick Summary: We collect only the information necessary to provide our services, never sell your personal data, and give you full control over your information. You have the right to access, correct, or delete your data at any time.

1. Data Controller Information

Naya Surf & Tours is the data controller responsible for your personal information. You can contact us at:

Naya Surf & ToursCAMARON # 53LA CRUZ DE HUANACAXTLE, NAYARIT 63731MEXICOEmail: [email protected]: +52 322 107 1443

2. Information We Collect

Information You Provide Directly

Account Information: Name, email address, password, and profile detailsCommunication Data: Messages you send us, support requests, and feedbackPayment Information: Billing address and payment method details (processed securely by our payment processors)Service Data: Content you create, upload, or share through our services

Information We Collect Automatically

Usage Data: How you interact with our services, features used, and time spentDevice Information: IP address, browser type, operating system, device identifiersAnalytics Data: Performance metrics, error logs, and usage patternsLocation Data: General geographic location based on IP address

Information from Third Parties

We may receive information from business partners, social media platforms (if you connect your accounts), and public databases, but only when necessary for providing our services.

3. How We Use Your Information

We process your personal information for the following purposes:

Service Provision (Legal Basis: Contract Performance)

Creating and managing your accountProviding our services and featuresProcessing payments and transactionsProviding customer support

Service Improvement (Legal Basis: Legitimate Interest)

Analyzing usage patterns to improve functionalityDeveloping new features and servicesConducting research and analyticsTesting and optimizing our platform

Communication (Legal Basis: Consent or Legitimate Interest)

Sending service updates and important noticesResponding to your inquiries and support requestsMarketing communications (only with your consent)Security alerts and fraud prevention

Legal Compliance (Legal Basis: Legal Obligation)

Complying with applicable laws and regulationsResponding to legal processes and law enforcement requestsProtecting our rights and preventing fraud

4. Information Sharing and Disclosure

We never sell your personal information. We only share your information in the following limited circumstances:

Service Providers

We work with trusted third-party companies that help us operate our services, such as cloud hosting providers, payment processors, and analytics services. These providers are contractually bound to protect your information and use it only for the services they provide to us.

Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.

Legal Requirements

We may disclose your information if required by law, legal process, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

Consent

We may share your information with your explicit consent for specific purposes not covered in this policy.

5. Data Security

We implement industry-standard security measures to protect your personal information:

Encryption: Data is encrypted in transit and at rest using advanced encryption standardsAccess Controls: Strict access controls ensure only authorized personnel can access your dataRegular Audits: We regularly review and update our security practicesIncident Response: We have procedures in place to detect and respond to security incidentsEmployee Training: Our team is trained on data protection and security best practices

While we take extensive precautions, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security but are committed to protecting your information using the most current security standards.

6. Data Retention

We retain your personal information only as long as necessary for the purposes outlined in this policy:

Account Data: For the duration of your account plus 90 days after deletionTransaction Records: 7 years for tax and legal complianceSupport Communications: 3 years for service improvementAnalytics Data: Anonymized data may be retained indefinitely for researchMarketing Data: Until you withdraw consent or 2 years of inactivity

7. Your Privacy Rights

You have significant control over your personal information. Depending on your location, you may have the following rights:

Universal Rights

Access: Request a copy of the personal information we hold about youCorrection: Update or correct inaccurate personal informationDeletion: Request deletion of your personal informationPortability: Receive your data in a portable formatWithdrawal of Consent: Withdraw consent for processing at any time

EU/UK Residents (GDPR)

Restriction: Limit how we process your informationObjection: Object to processing based on legitimate interestsAutomated Decision-Making: Opt out of automated profilingComplaint: File a complaint with your local data protection authority

California Residents (CCPA/CPRA)

Know: Detailed information about data collection and sharingDelete: Request deletion of personal informationOpt-Out: Opt out of the "sale" or "sharing" of personal informationNon-Discrimination: Equal service regardless of privacy choicesSensitive Data: Limit use of sensitive personal information

To exercise your rights: Email us at [email protected] or use our privacy request form. We will respond within 30 days and may need to verify your identity for security purposes.

8. International Data Transfers

We may transfer your information to countries outside your country of residence. When we do:

We ensure appropriate safeguards are in place (such as EU Standard Contractual Clauses)We work only with partners who provide adequate protection for your dataWe implement additional security measures for international transfers

9. Cookies and Tracking Technologies

We use cookies and similar technologies to improve your experience. See our Cookie Policy for detailed information about the cookies we use and how to manage your preferences.

10. Children's Privacy

Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately so we can delete it.

11. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will:

Notify you of material changes via email or prominent notice on our websitePost the updated policy with the new effective dateMaintain previous versions for your reference

12. California "Do Not Sell" Notice

We do not sell personal information as defined by California law. We do not and will not sell your personal information to third parties.

13. Contact Information

For privacy-related questions, to exercise your rights, or to file a complaint:

Email: [email protected]:Naya Surf & ToursAttention: Privacy OfficerCAMARON # 53LA CRUZ DE HUANACAXTLE, NAYARIT 63731MEXICO

Response Time: We respond to privacy requests within 30 days.

14. Regulatory Information

EU/UK Residents: You can file complaints with your local data protection authority.

California Residents: You can file complaints with the California Privacy Protection Agency.

Industry-Specific Note: [Add any industry-specific privacy requirements here, such as HIPAA for healthcare, FERPA for education, etc.]

This Privacy Policy is designed to be comprehensive and compliant with major privacy regulations worldwide. For questions about specific legal requirements in your jurisdiction, please contact us.

naya surf and tours logo

Bucerias, Mexico

Phone:+523221071443

Email: [email protected]

© 2026 Naya Surf and Tours. All Rights Reserved

Designed by Agathos-Fides.com