1. Purpose and scope
This Privacy Policy explains how Morales Inns & Suites (“Morales Inns & Suites,” “we,” “us,” or “our”) collects, uses, discloses, stores, transfers, and protects personal information in connection with our hospitality, accommodation, reservation, guest-support, marketing, property-management, and digital services. Morales Inns & Suites is a Delaware-organized hospitality company within the Invstur Group and may operate, manage, market, or support accommodations and services in multiple countries.
This Policy applies when you visit or use our websites, booking pages, guest portals, forms, email communications, newsletters, messaging channels, social-media pages, properties, and any other service that links to this Policy. It also applies when we receive information about you from travel agencies, online travel platforms, payment providers, property owners, building administrators, business partners, or other authorized sources.
A separate privacy notice, consent statement, property notice, or service-specific disclosure may supplement this Policy. If a supplemental notice conflicts with this Policy, the supplemental notice controls for the specific activity it covers.
Global privacy framework
Privacy law is territorial and no single law applies everywhere. This Policy is designed around internationally recognized privacy principles - lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, security, accountability, individual choice, and access to remedies - and is intended to address the requirements of applicable privacy and data-protection laws in the jurisdictions where we operate or offer services. These may include, where applicable, the EU General Data Protection Regulation (GDPR), the United Kingdom GDPR and Data Protection Act, the Delaware Personal Data Privacy Act, the California Consumer Privacy Act as amended by the California Privacy Rights Act, Brazil’s Lei Geral de Protecao de Dados (LGPD), Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial laws, Costa Rica’s Law No. 8968, and other national or subnational privacy laws.
References to these frameworks do not mean that every law applies to every interaction. Rights, obligations, response periods, and legal bases depend on the individual’s location, the location and nature of the processing, the services involved, and each law’s scope and thresholds. Where a local law provides stronger or additional protections, we will apply those protections to the extent required.
2. Who is responsible for your information
Morales Inns & Suites is the controller, business, organization, or responsible party - as those terms may be defined under applicable law - for personal information processed for the purposes described in this Policy, except where another organization independently determines how and why information is processed.
Some properties, building administrations, property owners, online travel agencies, payment processors, and service providers may act as independent controllers or responsible parties under their own privacy notices. Their privacy practices are not controlled by this Policy.
3. Personal information we collect
Depending on how you interact with us, we may collect the categories of information described below. We limit collection to information reasonably relevant to the stated purpose and applicable legal requirements.
3.1 Identity and contact information
Name, preferred name, signature, date of birth, nationality, physical address, email address, telephone number, WhatsApp number, emergency contact, and similar identifiers.
3.2 Reservation and stay information
Reservation number, property, room or unit, dates of stay, number and identity of guests, arrival and departure details, special requests, accessibility requests, preferences, communications, service history, incidents, complaints, refunds, credits, charges, loyalty or referral information, and records needed to administer a reservation or stay.
3.3 Identification and compliance information
Government-issued identification information, passport or national identity details, age verification, immigration or registration information, and other documentation required by law, building rules, security procedures, fraud prevention, or guest verification. We do not request more identification information than reasonably necessary for the applicable purpose.
3.4 Payment and transaction information
Billing address, payment method type, transaction amount, currency, invoice details, payment status, refunds, chargebacks, deposits, and related records. Full payment-card data is generally processed by authorized payment providers rather than stored directly by us, although limited payment data may be visible to us for reconciliation, fraud prevention, and support.
3.5 Communications and support information
Messages, inquiry forms, callback requests, emails, telephone or WhatsApp communications, chatbot or Concierge interactions when enabled, attachments, photographs, maintenance reports, housekeeping requests, reviews, feedback, and records of how an inquiry was routed or resolved.
3.6 Marketing and preference information
Newsletter enrollment, consent records, communication preferences, campaign interactions, referral source, interests, language, preferred destination, and opt-out, unsubscribe, suppression, or preference-management records.
3.7 Device, usage, and technical information
IP address, browser type, device type, operating system, language, approximate location derived from IP, pages viewed, links clicked, referring URL, timestamps, session information, error logs, security events, cookie identifiers, and similar data generated when you use our digital services.
3.8 Property access, security, and incident information
Where applicable and disclosed, we may process access-control logs, key or smart-lock events, visitor registration, front-desk records, building access information, security-camera footage in common areas, incident reports, lost-property records, and information needed to protect guests, staff, owners, and property. We do not use cameras in private guest areas.
3.9 Sensitive or special-category information
We may process information that may be considered sensitive under applicable law, such as government identification details, health or accessibility information you voluntarily provide, precise location when necessary for a service, or account credentials. We process such information only when reasonably necessary, legally permitted, and protected with measures appropriate to its sensitivity.
4. How we collect information
We collect information directly from you; automatically through our websites and systems; from other guests or people acting on your behalf; from property owners and building administrators; from online travel agencies and travel professionals; from payment, identity, security, analytics, communications, and technology providers; from publicly available sources; and from government or law-enforcement authorities where legally permitted.
If you provide information about another person, you represent that you are authorized to do so and that you have provided any notice required by law.
5. How we use personal information
We may use personal information to:
- search availability, provide quotations, create and manage reservations, process payments, issue invoices, administer check-in and check-out, and deliver accommodation services;
- verify identity, guest eligibility, occupancy, and compliance with legal, property, and building requirements;
- communicate before, during, and after a stay, including arrival information, property instructions, service messages, support, and follow-up;
- respond to inquiries, route requests to reservations, administration, marketing, housekeeping, maintenance, owners, or other appropriate teams, and maintain service records;
- provide requested accessibility arrangements and personalize a stay;
- investigate incidents, protect health and safety, prevent fraud, enforce policies, recover unpaid amounts, manage claims, and protect legal rights;
- operate, secure, test, troubleshoot, analyze, and improve our websites, systems, properties, and services;
- understand demand, service quality, guest preferences, and business performance using aggregated or appropriately de-identified information where feasible;
- send marketing communications where permitted and maintain proof of consent, preference, suppression, and unsubscribe choices;
- comply with legal, regulatory, tax, accounting, immigration, registration, insurance, contractual, and law-enforcement obligations; and
- support a merger, financing, restructuring, sale, transfer, or similar business transaction subject to appropriate confidentiality and legal safeguards.
6. Legal grounds for processing
Where applicable law requires a legal basis, we rely on one or more of the following: performance of a contract or steps requested before entering a contract; compliance with legal obligations; our legitimate interests or those of another party, provided those interests are not overridden by your rights; protection of vital interests; establishment, exercise, or defense of legal claims; and your consent.
You may withdraw consent at any time for future processing that depends on consent. Withdrawal does not affect processing already completed lawfully or processing supported by another legal basis.
7. Reservations made through third parties
If you book through Airbnb, Booking.com, Vrbo, Expedia, a travel agent, a corporate travel program, or another third party, that party may collect and process your information under its own privacy policy and share relevant reservation information with us. We may return stay, incident, payment, or service information to that party where necessary to administer the reservation, address a dispute, comply with platform rules, or protect rights and safety.
Questions about a third party’s independent practices should be directed to that third party.
8. Payments
We use payment processors, banks, and payment platforms to process transactions. These providers may collect payment-card and authentication information directly from you. We receive information necessary to confirm, reconcile, refund, dispute, and account for the transaction.
We do not ask you to send full payment-card numbers, passwords, or security codes through ordinary email, contact forms, WhatsApp, or Concierge communications.
9. Guest communications, WhatsApp, and messaging services
If you contact us or ask us to contact you through WhatsApp, email, telephone, social media, or another messaging service, your information is also processed by the applicable platform provider under its own terms and privacy policy. Messages may be routed to the team best suited to assist you.
When our Concierge or department-routing services are enabled, they may classify a request, assemble relevant reservation or property context, and prepare a message for the appropriate department. Individual staff contact details will not be displayed publicly unless authorized. We will not request passwords, full payment-card details, or highly sensitive credentials through chat.
10. Artificial intelligence and automated tools
We may use automated tools, including a future Concierge, to classify inquiries, suggest responses, translate content, detect spam or fraud, summarize communications, or route requests. These tools may make recommendations, but they are not authorized to independently approve refunds, alter binding reservation terms, make legal determinations, or create final decisions that significantly affect you without appropriate human review where required.
We will identify material AI-enabled guest interactions when appropriate and provide a route to human assistance. We do not permit public AI tools to use guest information for unrelated model training unless lawfully authorized and subject to appropriate contractual and privacy safeguards.
11. Marketing communications
We send promotional email, SMS, WhatsApp, or similar communications only where permitted. Marketing enrollment is separate from transactional communications needed to administer a reservation, inquiry, account, security matter, or legal obligation.
Where double opt-in is used, a subscription remains pending until the confirmation link is completed. You can unsubscribe using the link in a marketing email or by contacting us. We retain limited suppression information to honor your choice and prevent accidental re-enrollment.
We do not sell personal information for money. If a future practice is treated as a sale or targeted-advertising share under applicable law, we will provide any required notice and opt-out mechanism before engaging in that practice.
12. Cookies and similar technologies
Our digital services may use cookies, local storage, pixels, tags, and similar technologies to operate essential functions, remember preferences, maintain security, understand performance, and, where permitted, support analytics or marketing.
Non-essential technologies will be used in accordance with applicable consent and preference requirements. Details about technologies in use and available controls are provided in our Cookie Policy and any cookie-preference tool made available on the site. Browser settings may also allow you to block or delete cookies, but doing so may affect functionality.
13. When we disclose personal information
We may disclose relevant information to:
- properties, property owners, building administrators, front desks, housekeeping, maintenance, security, and authorized personnel involved in providing or protecting the stay;
- online travel agencies, travel professionals, reservation partners, and corporate travel programs;
- payment processors, banks, fraud-prevention providers, insurers, accountants, auditors, and professional advisers;
- cloud hosting, database, email, communications, customer-support, analytics, security, identity-verification, access-control, and technology providers;
- government, regulatory, judicial, tax, immigration, public-health, emergency, or law-enforcement authorities when required or permitted by law;
- parties to a dispute, claim, investigation, transaction, financing, restructuring, merger, sale, or transfer, subject to appropriate safeguards; and
- other parties at your direction or with your consent.
Service providers may use information only for authorized purposes and are expected to protect it under contractual or legal obligations appropriate to their role.
14. International transfers
Our guests, service providers, technology systems, booking platforms, and communications services may operate in different countries. Personal information may therefore be processed outside the country where it was collected.
Where required, we use recognized safeguards such as contractual protections, transfer agreements, adequacy mechanisms, consent, or another lawful transfer basis. Privacy and government-access rules may differ between countries.
15. Data retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including to provide services, comply with law, maintain financial and tax records, resolve disputes, enforce agreements, prevent fraud, document consent and opt-outs, and protect legal rights.
Retention periods vary by record type, legal requirement, limitation period, property obligation, and operational need. We delete, anonymize, aggregate, or securely isolate information when it is no longer required, subject to backup cycles and lawful exceptions. We apply storage-limitation and data-minimization principles and will not retain personal information longer than reasonably necessary or legally permitted for the purposes described in this Policy.
16. Security
We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, loss, or destruction. Measures may include access controls, role-based permissions, encryption in transit, credential management, logging, monitoring, backups, vendor assessment, employee confidentiality, and incident-response procedures.
No system is completely secure. You are responsible for protecting your passwords, devices, and account access and for notifying us promptly of suspected unauthorized use.
17. Data incidents
If we become aware of a personal-information incident, we will investigate, contain, document, and remediate it. We will notify affected individuals and authorities when required by applicable law, taking into account the nature of the information, likely risks, available mitigation, and legal instructions.
18. Your privacy rights
Depending on applicable law and your relationship with us, you may have the right to be informed; access personal information; correct inaccurate or incomplete information; request deletion; restrict or object to processing; withdraw consent; obtain portable information; opt out of direct marketing; request information about disclosures; limit certain uses of sensitive information; and request human review of qualifying automated decisions.
Rights are not absolute. We may retain or continue processing information where required or permitted by law, including to complete a transaction, protect safety, prevent fraud, comply with tax or legal obligations, establish or defend claims, preserve another person’s rights, or maintain a lawful suppression record.
19. How to exercise your rights
Submit a request by emailing reservations@invstur.com with the subject line “Privacy Request.” Please describe the right you wish to exercise and the information or service involved.
We may need to verify your identity and authority before completing a request. Verification information will be used only for that purpose. Authorized agents may submit requests where permitted, but we may require evidence of authorization and direct verification with the individual.
We will respond within the period required by applicable law. If we deny or limit a request, we will explain the basis when legally permitted and provide information about available complaint or appeal rights. We will not discriminate against you for exercising a privacy right.
20. Jurisdiction-specific privacy rights
The rights below apply only when the relevant law applies to the processing. We may provide a supplemental regional notice when required.
20.1 Delaware and other United States state privacy laws
Morales Inns & Suites is organized in Delaware. Where the Delaware Personal Data Privacy Act or another applicable U.S. state privacy law applies, eligible residents may have rights to confirm whether we process their personal data; access, correct, delete, or obtain a portable copy of personal data; opt out of qualifying targeted advertising, sale, or certain profiling; limit uses of sensitive data; and appeal a denied request. We will not discriminate against a person for exercising a legally protected privacy right.
If we engage in an activity that applicable law defines as a sale, sharing for cross-context behavioral advertising, or targeted advertising, we will provide any legally required notice and opt-out mechanism, including recognition of a qualifying universal opt-out signal where required. We do not currently sell personal information for money.
20.2 European Economic Area, United Kingdom, and Switzerland
Where the GDPR, UK GDPR, Swiss data-protection law, or a substantially similar framework applies, individuals may have rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and complaint to a competent supervisory authority. Individuals may also have rights concerning qualifying automated decision-making and profiling.
When required, we identify a lawful basis for processing, apply additional conditions to sensitive or special-category data, provide required transparency information, and use an approved transfer mechanism for international transfers.
20.3 California
Where the California Consumer Privacy Act, as amended, applies, California residents may have rights to know or access personal information; request deletion or correction; opt out of qualifying sale or sharing; limit certain uses and disclosures of sensitive personal information; receive required notices at collection; and receive equal service and pricing when exercising their rights. We will honor a legally valid Global Privacy Control signal when required.
20.4 Brazil
Where Brazil’s LGPD applies, individuals may have rights to confirmation of processing; access; correction; anonymization, blocking, or deletion of unnecessary or unlawfully processed data; portability where regulated; information about sharing; withdrawal of consent; review of qualifying automated decisions; and petition to the Autoridade Nacional de Protecao de Dados (ANPD). We apply the LGPD principles of purpose, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination, and accountability where applicable.
20.5 Canada
Where PIPEDA or an applicable Canadian provincial privacy law applies, individuals may have rights to know why information is collected, provide or withdraw consent where consent is the appropriate basis, access and correct personal information, challenge compliance, and expect reasonable safeguards, limited collection, and limited retention.
20.6 Costa Rica
Where Costa Rica’s Law No. 8968 applies, individuals may exercise rights related to informational self-determination, including access, correction, updating, and deletion as provided by law. Individuals may also contact the Agencia de Proteccion de Datos de los Habitantes (PRODHAB) regarding qualifying data-protection concerns.
20.7 Other jurisdictions
Residents of other jurisdictions may have additional rights under applicable national, state, provincial, territorial, or sector-specific law. Where those laws apply, we will provide any required supplemental notice, opt-out method, appeal process, authorized-agent procedure, or regulator contact. Nothing in this Policy limits a right that cannot legally be waived.
21. International transfers and global operations
Morales Inns & Suites may serve guests, receive reservations, engage service providers, and use technology systems across borders. Personal information may be processed in the United States, Costa Rica, and other countries where we or our service providers operate.
Where required by applicable law, we use recognized transfer safeguards such as adequacy decisions, standard contractual clauses, the United Kingdom International Data Transfer Agreement or Addendum, contractual and organizational safeguards, consent, or another lawful transfer mechanism. We also assess the nature of the information, destination, recipients, and available security protections when required.
Laws and government-access standards differ by country. Regardless of processing location, we require personal information under our control to be handled consistently with this Policy and applicable contractual and legal safeguards.
22. Children and minors
Our services are intended for adults arranging accommodation for themselves or authorized guests. We do not knowingly use our public website to collect personal information directly from children for independent marketing or account creation.
Information about minors may be processed when supplied by a parent, guardian, or authorized adult for a reservation, legal registration, safety, accessibility, or emergency purpose. If you believe a child provided information without appropriate authorization, contact us.
23. Third-party links and services
Our services may link to third-party websites, maps, social networks, payment pages, travel platforms, or applications. Their privacy practices are governed by their own notices. A link does not mean that we control or endorse a third party’s privacy practices.
24. Accuracy and your responsibilities
Please provide accurate, current information and update it when necessary. Inaccurate guest, contact, identity, or reservation information may prevent us from completing a booking, granting access, providing a requested service, or responding to an inquiry.
25. Changes to this Policy
We may update this Policy to reflect changes in law, technology, services, properties, or business practices. The revised version will display an updated effective date. Where required, we will provide additional notice or obtain consent before materially changing how information is used.
Archived versions may be retained for governance and legal-record purposes.
26. Contact us and company information
Privacy requests and questions:
Morales Inns & SuitesA Delaware-organized hospitality company within the Invstur Group
Email: reservations@invstur.com
Telephone / WhatsApp: +506 6470 7946
Morales Inns & Suites provides and supports hospitality services internationally, including services associated with properties in Costa Rica. A service location is not necessarily the company’s legal domicile. A registered-agent or legal-notice address may be provided separately where required by applicable law or valid legal process.
For security, do not include full payment-card numbers, passwords, door codes, or other highly sensitive credentials in an ordinary email.