Privacy Policy
Last updated: July 8, 2026
Before you publish: replace the highlighted placeholders below — [LEGAL ENTITY NAME], [BUSINESS ADDRESS], [SUPPORT EMAIL], and [SUPPORT PHONE] — with your real details, and have this reviewed by legal counsel for your jurisdiction. This template is written to satisfy US (CAN-SPAM, TCPA/CTIA), Canadian (CASL), and EU/UK (GDPR/PECR) requirements as well as GoHighLevel / A2P 10DLC opt-in review.
1. Who we are
Mila Hotel ("Mila Hotel," "we," "us," or "our") is a boutique pet boarding, daycare, and grooming business operated by [LEGAL ENTITY NAME], located at [BUSINESS ADDRESS]. This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have. It applies to milapethotel.com and any related booking, email, and text-message communications.
For the purposes of the EU/UK General Data Protection Regulation (GDPR/UK-GDPR), the data controller is [LEGAL ENTITY NAME]. You can reach us using the details in the Contact us section below.
2. Information we collect
We collect the following categories of personal information:
- Contact details you give us — your name, email address, mobile phone number, and (optionally) your birthday.
- Booking & pet information — details about your reservation, your pet(s), dates, and requested services.
- Marketing preferences & consent records — whether you opted in to email and/or SMS marketing, the exact consent wording shown to you, and the date, time, and page URL where you gave consent.
- Technical & usage data — IP address, browser type, and how you interact with our site, collected through standard web logs and privacy-respecting analytics.
You do not have to provide marketing consent to book with us or to receive your one-time discount code — those consents are entirely optional.
3. How we use your information
- To respond to reservation requests, confirm bookings, and provide our services.
- To send you transactional messages you asked for (for example, your one-time discount code, booking confirmations, and replies to enquiries).
- With your consent, to send email and/or SMS marketing about special offers, discounts, seasonal promotions, and news.
- To maintain records of marketing consent as required by law.
- To operate, secure, and improve our website.
- To comply with legal obligations and enforce our terms.
4. Legal bases for processing (GDPR/UK-GDPR)
Where GDPR or UK-GDPR applies, we rely on: consent for email and SMS marketing (which you may withdraw at any time); performance of a contract to fulfil your bookings and services; legitimate interests to secure and improve our site and prevent fraud; and legal obligation where we must retain records or respond to lawful requests.
5. Email marketing
We send marketing emails only to people who have opted in by ticking the email consent box on our sign-up form. Every marketing email includes a clear unsubscribe link and our valid physical postal address, consistent with the US CAN-SPAM Act and Canada's CASL. You can withdraw consent at any time by clicking "unsubscribe" in any email or by contacting us. We honour opt-out requests promptly.
6. SMS / text-message marketing
We send recurring marketing text messages only to people who provide a mobile number and separately tick the SMS consent box. SMS consent is not a condition of purchasing any product or service. Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP, and get help by replying HELP. Full program details are in our SMS Terms & Conditions.
Mobile information sharing. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors in support services, such as customer service, is permitted. All other use-case categories exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties. Text-messaging originator opt-in data and consent will not be shared with any third parties, except for aggregators and providers of the text-message services who help us deliver the messages you requested.
7. How we share your information
We do not sell your personal information. We share it only with service providers ("processors") who help us operate, and only as needed to provide the service:
- HighLevel (GoHighLevel) — our CRM and email/SMS marketing platform, which stores your contact details, consent records, and delivers the messages you opted into.
- Netlify — our website and form-hosting provider.
- SMS aggregators and telecom carriers, solely to deliver text messages you requested.
- Professional advisors or authorities where required by law.
As stated above, mobile opt-in data and consent are never shared with third parties for their own marketing.
8. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent at any time. In the EU/UK you also have the right to lodge a complaint with your data protection authority. In Canada (CASL) you may withdraw marketing consent at any time. If you are a resident of California or another US state with privacy legislation, you may have the right to opt out of certain sharing and to not be discriminated against for exercising your rights. To make a request, contact us using the details below; we will verify and respond within the timeframe required by applicable law.
9. Data retention
We keep your personal information for as long as needed to provide our services and to meet legal, tax, and record-keeping obligations — including retaining proof-of-consent records for as long as we message you and for a reasonable period afterward. When information is no longer needed, we securely delete or anonymise it.
10. Security
We use reasonable administrative, technical, and organisational measures to protect your information. No method of transmission or storage is completely secure, but we work to safeguard your data and to notify you and regulators of breaches where required.
11. International data transfers
We operate globally and may process your information in countries other than your own, including the United States. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses.
12. Children's privacy
Our services are intended for adults. We do not knowingly collect personal information from children under 16 (or the age defined by your local law). If you believe a child has provided us information, contact us and we will delete it.
13. Cookies & analytics
We use a small number of cookies and similar technologies necessary to run the site and to understand aggregate usage. You can control cookies through your browser settings. Where required, we obtain consent before setting non-essential cookies.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version here with a new "Last updated" date and, where appropriate, notify you.
15. Contact us
Questions or requests about this policy or your information? Reach us at:
- Email: [SUPPORT EMAIL] (e.g. stay@milapethotel.com)
- Phone: [SUPPORT PHONE]
- Mail: [LEGAL ENTITY NAME], [BUSINESS ADDRESS]