Privacy policy
Last updated: September 25, 2026
Who is responsible
QueHacerRD.com is a guide to restaurants, places, events and plans in cities of the Dominican Republic. The portal and the personal data processed on it are the responsibility of Rubén Tejada, an individual domiciled in Santo Domingo, Dominican Republic.
This policy explains, under Dominican Law 172-13 on the protection of personal data, what data we process when you use the portal and what you can do about it. For anything about your data, write to us through the contact form choosing “My personal data”.
What we collect
- Your account: when you sign in with Google or with the link we email you, we store your name, your email address, the date you created the account and the date you last signed in. We store no passwords: Google or your own inbox is what proves it is you. From Google we receive only your name, your email and whether it is verified.
- Your reviews: the rating and comment you publish about a place, with the date. They are shown publicly next to your name; your email is never shown.
- Your favourites: the places you save. Only you can see them.
- Contact form: your name, your email, your phone and business if you give them, and your message.
- Reservation requests: the date, time, party size, your name, email, phone and notes.
- Technical data: the IP address and browser you visit with, which we use to limit abuse of the forms.
- Measurement, only if you accept it: the pages you visit and how you reached them, collected by Google Analytics and the Meta pixel.
We do not ask for or want sensitive data (health, religion, political opinions and the like). Please do not write it in a review or a message.
What we use it for, and on what basis
- Your account, reviews and favourites: to provide the service you ask for when you create the account. The basis is your consent, given when you sign up and withdrawn by deleting the account.
- Your messages and reservation requests: to deal with what you ask us, which includes passing the reservation request on to the venue or operator you chose. The basis is your own request.
- Moderation and abuse prevention: hiding a review or suspending an account that breaks the terms of use, and limiting submissions from one IP. The basis is our legitimate interest in protecting the portal and the people who use it.
- Measuring how the portal and our ads are used: only if you accept it in the cookie notice. You can withdraw it at any time under “Cookie preferences” at the foot of every page.
- Complying with the law: keeping or handing over data when a law or a court requires it.
We do not sell your data, we do not use it to send you marketing email, and we make no automated decisions that affect you.
Who we share it with
- Venues and operators: when you request a reservation, they receive your request and contact details to confirm it. From then on they process them as controllers in their own right.
- Google: Google sign-in and the maps. If you accept measurement, Google Analytics too.
- Meta (Facebook and Instagram): only if you accept measurement. Its pixel measures visits coming from our ads, and when you send the contact form we report that event with your email and phone irreversibly hashed, your IP and your browser.
- Microsoft Azure: hosts the portal and its database.
- Our email provider: sends the sign-in link, the confirmations and the form notifications.
- Authorities: when a law or a court order obliges us.
Several of these providers store information outside the Dominican Republic, mainly in the United States. We only work with providers that commit by contract to protecting the data, and measurement — the part not needed to provide the service — only runs with your consent. Each of them processes the data under its own privacy policy.
Cookies and browser storage
Essential, which need no consent:
- Session (qh_session): keeps you signed in for up to 60 days.
- Google sign-in: three ten-minute cookies that protect the round trip to Google.
- Your cookie choice (qh_consent): remembered for six months, after which we ask again.
- Light or dark theme: your preference is kept in the browser's local storage.
Measurement, only if you accept it: Google Analytics (_ga, _ga_*) and the Meta pixel (_fbp, _fbc). Until you answer the notice, or if you reject it, they are not loaded. If you withdraw consent you gave earlier, we delete them.
You can change your choice under “Cookie preferences” at the foot of every page, and delete or block cookies in your browser. If you block the session cookie you will not be able to sign in.
How long we keep it
- Your account, reviews and favourites: while the account exists. Deleting it deletes your reviews and favourites too.
- Contact messages: two years, then deleted automatically.
- Reservation requests: one year, then deleted automatically.
- Measurement data: as set in the Google Analytics and Meta configuration.
A backup may hold deleted data for the short time it takes to be replaced.
Your rights
Law 172-13 gives you, free of charge, the right to:
- Access your data: “Download my data” in your account menu gives you your account, reviews and favourites at once.
- Correct it: change your name by signing in again with the email link, and your reviews by editing them on the place's page.
- Delete it: “Delete my account” in your account menu erases everything on the spot. Reviews can also be deleted one by one.
- Object to its use and withdraw your consent: reject measurement under “Cookie preferences”; what was done with it before remains valid.
For anything else — the data in a message or a reservation, for instance — write to us through the contact form with the type “My personal data”, from the same email you used, so we can check it is you. If we do not answer or you disagree with the answer, the Constitution (article 70) and Law 172-13 let you go to court through a habeas data action.
If you live in the European Union or the United Kingdom, the General Data Protection Regulation also gives you the right to data portability (the data download serves that purpose) and to complain to your country's data protection authority.
Security
The portal is served over HTTPS only; the session is a signed cookie that cannot be tampered with; we store no passwords; messages and reservations are never published and only the portal's editors see them; and what we send to Meta travels irreversibly hashed. No system is infallible: if a breach affected your data, we would let you know.
Children
The portal is not aimed at minors. You must be at least 18 to create an account, publish reviews or request a reservation. If we learn an account belongs to a minor, we delete it.
Changes to this policy
If we change what we do with your data, we will update this page and its date. If the change needs your consent, we will ask for it again.