1. Identity and address of the data controller
In accordance with Mexico's Federal Law on the Protection of Personal Data Held by Private Parties and its Regulations, Aro ("Aro", "we") is the controller responsible for the personal data collected through the platform — from the businesses that use it (the "Operators"), their teams, authorized resellers, and the end customers who make bookings.
For any matter related to this notice you can write to us at [email protected].
2. Personal data we collect
From Operators and their team: name, email address, password (stored encrypted, never in plain text), phone number when provided, business information (trade name, logo, description, services, prices, and availability), role and permissions within the team, and subscription and billing details.
Account security data: if you enable two-factor verification, we store your authenticator app secret encrypted and the hash of your backup codes. We never store your password or these secrets in readable text.
Payout data: if you connect an account to receive online payments, our payment service provider collects and verifies your identity, bank details, and any other information required by its fraud-prevention and compliance (KYC) processes. Aro only receives that account's identifier and status, not your full banking details. To set up your payout account we also collect your IP address, which is sent to our payment service provider as part of its terms-acceptance record.
From end customers: name, email address and, where applicable, phone number, together with the details of the booking made (experience, date, time, party size, notes, and price). Online payments are processed directly by our payment service provider; Aro does not collect or store the full card number.
From resellers: name, email address, phone number, the hash of their access key, and the pricing and booking history they manage through their portal.
Technical and browsing data: session cookies, IP address, and device data associated with those cookies, as described in our cookie policy.
We do not collect sensitive personal data (health, biometric, ethnic origin, religious beliefs, or sexual orientation). Please do not include this type of information in the platform's free-text fields (for example, booking notes or descriptions).
3. Purposes of processing
Primary purposes, necessary for the service: creating and managing your account and your team's; verifying your identity and preventing fraud; managing bookings, availability, and pricing; processing payments and commissions; billing your subscription; sending you transactional communications (confirmations, reminders, security and service notices); providing support; and complying with legal, tax, and regulatory obligations, including those imposed on us by our payment providers.
Secondary purposes, not necessary for the service but that let us improve it: compiling internal platform-usage statistics. You may object to these secondary purposes at any time without affecting your access to the service, by writing to [email protected].
We do not use the data we collect for third-party advertising or to build profiles for purposes other than those described here. We do not sell or share personal data with third parties.
4. Processors, providers, and transfers
We share data only with providers that help us operate the platform, under agreements that require them to protect the information and use it solely to deliver the contracted service. We currently use: a primary payment service provider (payment processing, subscriptions, and connected payout accounts); an alternative payment processing provider; a transactional email delivery provider; an instant-messaging provider for booking confirmations and reminders when the Operator enables this feature; a cloud image and file storage provider; and an anti-bot verification provider during registration and login.
Some of these providers process data on servers located outside Mexico (for example, the United States or the European Union). In those cases, the transfer is carried out under the protection mechanisms required by applicable law and each provider's own contractual commitments and certifications (including, where applicable, compliance with the PCI-DSS standard for handling payment data).
We only disclose personal data to authorities when there is a valid legal requirement to do so.
5. End-customer data: Aro as processor
With respect to the data of customers who book with an Operator, Aro acts as a data processor: the Operator decides the purposes and means of processing that data and is responsible to its customers under applicable law. Operators undertake to use that data solely to manage bookings and related communications, and to directly handle any data-rights request they receive from their own customers.
6. Use of cookies and similar technologies
We use essential cookies to keep you signed in (including secure, server-only session cookies for operators and administrators), attribution cookies for the reseller program (valid for 24 hours), and anti-bot verification during registration and login. Full details are in our cookie policy.
7. Data retention
We retain your personal data while your account is active and for as long as necessary for the purposes described in this notice. When you request that your account be closed, we delete or anonymize the data we are no longer legally required to keep; records that tax, commercial, or anti-money-laundering law requires us to retain are kept only for the corresponding legal period.
8. Security measures
We apply technical and organizational measures to protect your personal data, including: encryption of data in transit (HTTPS/TLS), encrypted storage of passwords and two-factor secrets, role- and permission-based access control, logical isolation of information between different Operators, and session rotation via short-lived access tokens with secure renewal.
No system is completely infallible; if we detect a security breach that significantly affects your personal data, we will notify you as required by applicable law.
9. Your rights and withdrawing consent
You have the right to access your personal data, rectify it if inaccurate, request its erasure when you consider it is no longer required for the purposes described here, and object to processing for specific purposes. You may also withdraw any consent you have given us.
To exercise these rights, write to [email protected] from the email address associated with your account, indicating the right you wish to exercise and including identification that proves you are the data subject. We will respond within a maximum of 20 business days and, where applicable, give effect to the request within the following 15 business days.
10. Minors
The platform is not directed at minors. Registering as an Operator requires being of legal age. If you become aware that a minor has provided us with personal data without their guardian's consent, please contact us so we can delete it.
11. Supervisory authority
If you believe your right to the protection of personal data has been violated, you have the right to file a complaint with Mexico's National Institute for Transparency, Access to Information and Personal Data Protection (INAI), without prejudice to first raising a direct request with us.
12. Changes to this notice
We may update this notice to reflect changes in the service, our providers, or applicable law. We will publish the current version on this page indicating the date of the last update and, in case of material changes, we will notify you by email.