- We collect what we need to answer you and run your tour, and nothing to sell.
- Riads, camps and your driver see only what they need. Card numbers never touch us.
- Health and dietary notes are deleted 30 days after the tour.
- Analytics and Google Ads cookies only with your consent, and you can change your mind any time.
- Email us to see, correct or delete your data. We answer within 30 days.
01Who is responsible for your data
[Legal company name] (Morocco Tiziri), [Street address], Marrakech, Morocco, is the data controller. Contact: [email]. We are registered with the Moroccan data protection authority (CNDP) under [number].
02What we collect
- What you give us: name, email, phone or WhatsApp number, nationality and passport details where a hotel or camp requires them, travel dates, dietary needs, and any health or mobility information you choose to share so we can plan safely.
- What our website collects: pages visited, device and browser type, approximate location from your IP address, and the cookies described in section 6.
- What we do not collect: card numbers (handled by [payment provider]), and any data about children beyond what is needed for the booking.
03Why we use it
| Purpose | Legal basis |
|---|---|
| Answering your enquiry and sending a proposal | Steps before a contract, at your request |
| Running your tour: bookings with riads and camps, driver briefing, emergencies | Performance of the contract |
| Health, dietary and mobility details | Your explicit consent, to keep you safe |
| Invoices, tax and legal records | Legal obligation |
| Our monthly email, if you subscribed | Consent, withdrawable any time |
| Improving the website (analytics) | Legitimate interest, or consent for non-essential cookies |
We do not sell your data and we do not use it for automated decisions.
04Who we share it with
- The riads, camps and activity providers on your itinerary (name, number of travellers, dietary needs, arrival time; passport details only where Moroccan law requires hotels to record them).
- Your driver-guide (name, phone, pick-up address, relevant health or mobility notes).
- Our payment provider, email and WhatsApp Business tools, and website hosting, under contracts that limit what they can do with the data.
- Authorities, where the law requires it.
Some of these providers are outside Morocco (for example in the EU or the US). Where data leaves Morocco or the EU, we rely on the provider's standard contractual safeguards.
05WhatsApp and messaging
If you contact us on WhatsApp, your messages are processed by WhatsApp (Meta) under its own privacy policy. We keep the conversation in our business account for as long as your booking file exists. Do not send passport photos by WhatsApp unless we ask; if you do, we delete them once the booking no longer needs them.
06Cookies
Three kinds, and you choose two of them:
- Essential: always on. They make bookings, language and your cookie choice work.
- Analytics (Google Analytics 4): only with your consent, to see which pages are read. No names, IP addresses anonymised.
- Marketing (Google Ads): only with your consent. They let us show you our tours again on Google and partner sites after you leave, and measure whether an ad led to a booking. We do not sell this data and we do not use it for anything else.
Nothing in the analytics or marketing categories loads before you choose. You can change your choice at any time from the cookie icon at the bottom left of every page, and you can block cookies in your browser. We use Google Consent Mode, so your choice is passed to Google as “granted” or “denied”.
07How long we keep it
| Data | Kept for |
|---|---|
| Enquiries that do not become bookings | 12 months |
| Booking files (itinerary, messages, invoices) | 5 years after the tour, for tax and legal reasons |
| Health, dietary and mobility notes | Deleted 30 days after the tour ends |
| Newsletter subscription | Until you unsubscribe |
| Analytics | 14 months |
08Your rights
You can ask us to show you the data we hold, correct it, delete it, limit how we use it, or send it to you in a usable format. You can withdraw consent at any time (for example to the newsletter or to health notes) without affecting the rest of your booking. Write to [email]; we answer within 30 days. If you are in the EU or the UK you also have the right to complain to your local data protection authority; in Morocco, to the CNDP.
09Security
Booking data is stored in password-protected systems with access limited to the people who need it for your tour. Card payments never pass through our servers. We cannot guarantee the security of email or WhatsApp in transit; for sensitive documents, ask us for a secure upload link.
10Children
We only collect information about travellers under 18 from the adult who books for them, and only what is needed for the tour (name, age, dietary needs, child seat).
11Changes to this policy
We update this page when our practices change and show the date at the top. Significant changes affecting existing bookings are notified by email.
Questions about these terms: hello@moroccotiziri.com. This page is a template drafted for Morocco Tiziri; have it reviewed by a Moroccan lawyer before publication, and replace every [placeholder].
