GroList

Privacy Policy

How GroList handles information from this website — and how we handle guest data on behalf of the host companies we power.

Last updated: July 26, 2026

1. Two different roles

On grolist.do, GroList — a service of BMB Global Trading, LLC — is the data controller: we decide what we collect from visitors and enquiries, and this policy describes it.

On a host company's site (for example a villa manager's own branded subdomain), the host company is the controller and GroList is its processor — we store and process guest data on that company's instructions. Guests should read the privacy policy published on the site where they placed their order.

2. What we collect on this site

This site does not use advertising cookies, tracking pixels or third-party analytics.

  • Enquiry form — your name, email address, company, phone number, the number of villas or properties you manage, and whatever you write in the message field.
  • Technical data — IP address, browser and device type, and server logs, kept for security and troubleshooting.
  • Local storage — your language preference.

3. Why we use it

To reply to your enquiry, arrange a demonstration, prepare a proposal, and keep a record of our conversation. If we go on to work together, your details become part of the account record for that engagement. We do not sell your information or share it for advertising.

4. Who processes it for us

  • Google Firebase — storage of enquiry and account records.
  • Vercel — hosting.
  • Resend — email delivery.
  • Stripe — payment processing, where a payment is involved.
  • Anthropic — AI features within the platform. Data sent for these purposes is not used to train AI models.

5. Guest data we process for host companies

Guest orders placed on a host company's site contain contact details, stay details, party size, product selections, receipts and billing totals. GroList stores this data in an access-controlled, per-organization structure so one host company's staff cannot read another's records. We use it only to run the service for that company, to provide support, and to keep the platform secure — never to build our own marketing lists.

Requests from a guest to access or delete their data should go to the host company that took the order; we assist that company in responding.

6. Retention

Enquiries are kept for as long as we have a reasonable business interest in the conversation, and account records for as long as required by contract and by Dominican tax and accounting rules. Ask us and we will delete what we are not required to keep.

7. Where data is stored

Our providers operate infrastructure outside the Dominican Republic, principally in the United States and Europe, under their contractual data-protection commitments.

8. Your rights

Under Dominican Law 172-13 on the protection of personal data — and, where applicable, equivalent European rules — you may request a copy of your information, its correction or deletion, or object to particular uses. Write to hello@grolist.do.

9. Security

Data travels over encrypted connections and is stored with per-organization access rules. Administrative access uses one-time email sign-in links rather than reusable passwords. If a breach affects your information, we will notify you and the relevant authority as required by law.

10. Changes and contact

We will update this page when our practices change; the "last updated" date reflects the current version. Privacy questions: hello@grolist.do.

Controller: BMB Global Trading, LLC.