Security

Your data, handled carefully.

Cardinal House is a family-owned cabin, not a big booking platform. Here is exactly what we collect, how it is protected, and who to ask if you have a question.

Last updated: August 4, 2026

  • No card details here

    This site never asks for a credit card. Reservations and payments happen on Casago, VRBO, or Airbnb, on their own checkout systems.

  • Encrypted connections

    Every page and form is served over HTTPS, and browsers are told to refuse an unencrypted connection to this site.

  • Small on purpose

    We only ask for what we actually need — usually a name and email. Less collected means less that could ever be exposed.

  • Nothing sold or traded

    We do not sell, rent, or trade your information, and we do not run advertising trackers on this site.

What we actually collect

Everything we hold comes from something you chose to fill in:

  • Cardinal Club signup — your name, email, ZIP code, and whether you have stayed before.
  • Questions and inquiry forms — your name, email, dates you are considering, and whatever you write to us.
  • Saved weekend plans — the stops you picked and the email address the link is sent to.
  • Chats with Aria, our on-site guide — the questions asked, so we can spot what the site fails to explain. Don't include sensitive personal details in a chat; you don't need to identify yourself to use it.

We never take payment card numbers, government IDs, or Social Security numbers on this site — there is nowhere on it to enter them.

How it is protected

  • Encrypted in transit. The site is HTTPS-only, with strict transport security so browsers won't fall back to an insecure connection.
  • Locked-down storage. Guest submissions live in a managed database where every table denies access by default. Reading them requires an owner-authenticated session; the public website key cannot retrieve them.
  • Owner-only tools. The behind-the-scenes pages that show inquiries and subscribers are gated by sign-in, and the checks run on the server — not just hidden in the page.
  • Unguessable links. Share links for saved plans and chat sessions use cryptographically random identifiers, so someone can't guess their way into another guest's plan.
  • Spam and abuse controls. Forms are rate-limited and use a challenge whose answer stays encrypted on the server, so automated submissions can't flood us with junk.
  • Routine checking. An automated review runs weekly across site security headers, data-access rules, and software dependencies, and alerts us to anything new.

No website can promise perfect security, and we won't pretend otherwise. What we can say is that we keep the collected data minimal, closed by default, and reviewed on a schedule.

Who else touches your information

A short list of vendors runs parts of the site — hosting and the database, email delivery for confirmations and Cardinal Club notes, and Google Maps for the Area Guide. Reservations and payments are handled entirely by the booking channel you choose (Casago (formerly Vacasa), VRBO, or Airbnb) under their own policies. The full list is in our privacy policy.

Your choices

  • Stop the emails. Every message has a one-click unsubscribe, or use the email preferences page.
  • See it or delete it. Ask and we'll tell you what we hold about you or remove it, except where records must be kept for legal or tax reasons.
  • Browse with your own settings. Text size, contrast, and motion preferences stay in your browser and are never sent to us.

Found a problem? Tell us.

If you notice something that looks like a security or privacy issue, email hello@visitcardinalhouse.com with what you saw and how to reproduce it. We read every message and will confirm that we received yours. Please don't test in ways that could disrupt the site or reach other guests' information.

For anything else, the contact page is the fastest way to reach us, and the privacy policy has the formal detail behind this summary.

This page is maintained by the owners of Cardinal House to answer common security and privacy questions. It describes our own practices and is not a certification, audit result, or independent verification by any third party.

Mountain Lake Property Group, LLC · 8735 Dunwoody Place, Ste N, Atlanta, GA 30350, USA