Saltar al contenido
Brasa Brava
ESEN
Book
Legal

Privacy policy

Last updated: April 27, 2026

At Brasa Brava we respect your privacy. This policy explains what data we collect when you use brasabrava.com, what we use it for, who we share it with, and what rights you have over it. It is drafted in line with Costa Rica's Law 8968 (Personal Data Protection Act).

1. Who controls your data

The data controller is Brasa Brava, located at Por confirmar, San José, Costa Rica. For privacy questions, write to Brasabravacr@gmail.com.

2. What data we collect

We only collect what we need to handle your reservation or quote:

  • Contact data: full name, phone and email.
  • Reservation details: date, time, party size and optional comments (allergies, occasion).
  • Event quote data: event type, approximate date, estimated budget and free-form message.
  • Automatic technical data: IP address and browser user-agent, kept only to prevent form abuse.

We do not collect sensitive data (race, beliefs, health, etc.).

3. What we use it for

  • Confirm your reservation and email you the details.
  • Notify the restaurant team so they can prepare your table or quote.
  • Contact you if we need to clarify any detail.
  • Detect and prevent spam, fraud or abuse (via reCAPTCHA and per-IP rate-limit).

We do not use your data for advertising, automated marketing profiles, nor do we sell it to third parties. We do not make automated decisions with legal effect about you.

4. Legal basis

Processing is based on your consent when submitting the form and on the fulfilment of the request you make to us (handling the reservation or quote).

5. Who we share data with

We share strictly necessary data with the following providers:

  • Resend (resend.com): to send reservation emails. Receives only your name and email.
  • Google reCAPTCHA (google.com/recaptcha): validates the form is sent by a person, not a bot. Receives browser metadata, not your personal data.
  • Mapbox (mapbox.com): renders the location map. Receives no form data, only loads the map when you visit the page.
  • Vercel (vercel.com): hosts the website and logs anonymous HTTP requests for operational diagnostics.
  • Neon (neon.tech): hosts our encrypted database with pending and confirmed reservations.

All these providers have their own privacy policies and meet international standards.

6. How long we keep the data

Confirmed and completed reservations are kept for 12 months after the service date for operational audit and no-show tracking. Cancelled reservations are kept for 6 months. After that, the data is automatically deleted or anonymised.

7. Your rights

As the data subject, you can:

  • Access the data we hold about you.
  • Correct incorrect data.
  • Delete your data before the retention deadline, unless the law requires us to keep it.
  • Object to processing or request data portability.
  • Withdraw consent at any time.

To exercise any right, write to Brasabravacr@gmail.com with the reservation code. We respond within 5 business days. If you believe we did not address your request, you can contact the PRODHAB (Costa Rica Data Protection Agency).

8. Security

We apply HTTPS for all communications, encryption at rest, role-based access control for the admin panel, and database-level tenant isolation (Row-Level Security). If we detect an incident that affects your data, we will notify you without delay.

9. Cookies

This site uses a single localStorage entry (brasa.locale) to remember your preferred language. We do not use ad-tracking cookies or third-party analytics with cookies.

10. Changes to this policy

If we update this policy, we will change the date at the top. For material changes we will email you if we have your address.