Skip to main content

    Privacy Policy

    Last updated: October 1, 2026

    In short: we collect only what we need to run your booking, never sell it, don't use tracking or advertising cookies, and you can download or delete your data yourself from your account settings.

    1Who we are

    [Registered business name] ("Zenithska Glow", "we", "us") runs this website and books excursions in and around Agadir, Morocco. We are the data controller for the personal data described here.

    • Address: [Registered business address], Agadir, Morocco
    • Privacy contact: privacy@zenithska.io
    • Our representative in the EU (GDPR Article 27): [EU representative name and address]

    We are based in Morocco, so Moroccan Law 09-08 applies to us. Because we offer our excursions to people in the European Union, the EEA and the UK, the GDPR (and UK GDPR) applies as well. This policy explains what we collect, why, who we share it with, how long we keep it and what rights you have.

    2What we collect and why

    We only collect what we need to run your booking and the features you choose to use.

    Your account

    Email address, username and password (stored only as a secure hash). Optionally your full name, location and a profile photo.
    Why: to give you an account, order history, wishlist and community features. Legal basis: contract (Art. 6(1)(b) GDPR).

    Bookings

    Your name, email, phone number, hotel or pickup location, the excursions, dates and number of guests, the amount paid and your booking reference. Card details go straight to our payment provider, Stripe; we never see or store your card number.
    Why: to arrange and run your excursion, contact you about it and handle refunds. Legal basis: contract, and our legal obligation to keep accounting records (Art. 6(1)(c)).

    Reviews, photos, videos and the forum

    Reviews, ratings, photos and videos you add to a review, forum posts, comments and likes. These are public and show your username and profile photo.
    Why: to share travellers' experiences, which you choose to do. Legal basis: contract (providing the feature you use). You can edit or delete your content at any time.

    Contact form

    Your name, email, optional phone number and your message.
    Why: to answer you. Legal basis: our legitimate interest in replying to enquiries, or steps you ask us to take before a booking (Art. 6(1)(f) and (b)).

    Newsletter

    Your email address, language and when you confirmed. We only add you after you click the confirmation link in our email.
    Why: to send news and offers. Legal basis: your consent (Art. 6(1)(a)). Every email has an unsubscribe link.

    Security

    To stop abuse (for example repeated login attempts), we keep a one-way hash of your IP address or email for up to 24 hours. Our hosting providers also keep short-lived technical logs.
    Legal basis: our legitimate interest in keeping the site and your account secure.

    We do not collect passport details, dates of birth or health information through this website. If you tell us about dietary or medical needs for an excursion, we use that only to keep you safe on that trip.

    3Who we share it with

    We never sell your personal data. We share it only with the providers below, who process it for us under data processing terms, and only as far as needed:

    • Supabase (database, login and file storage), servers in the EU
    • Cloudflare (domain, security and fast delivery of the site; storage for review photos and videos)
    • Hostinger (hosting the website files)
    • Stripe (payments). Stripe is also an independent controller for fraud prevention and legal compliance
    • Resend (sending booking, contact and newsletter emails)
    • Our local excursion partners and guides, who receive your name, phone number, pickup location, group size and any needs you've told us about, so they can run your trip

    A few things on the site load from other providers. Your browser contacts them directly, so they see your IP address but nothing else about you:

    • Open-Meteo (weather forecast on excursion pages)
    • ExchangeRate-API (currency conversion)
    • Google Maps, only if you click to load the map on our Contact page

    We may also disclose data where the law requires it, for example to Moroccan authorities.

    4International transfers

    Our main database is in the EU. Our team works from Morocco and some of our providers (such as Stripe, Resend and Cloudflare) are based in the United States, so your data may be accessed from or transferred to those countries.

    Morocco does not have an EU "adequacy decision". Where a transfer is needed to deliver the excursion you booked, we rely on that necessity (Art. 49(1)(b) GDPR). Our US providers are certified under the EU-US Data Privacy Framework or use the European Commission's Standard Contractual Clauses. You can ask us for details of these safeguards.

    5Cookies and browser storage

    We don't use advertising or analytics cookies and we don't track you across other websites.

    We only store what the site needs to work, in your browser's local storage:

    • your login session
    • your cart, wishlist and trip planner
    • your chosen language, currency and light or dark theme

    These are strictly necessary for features you use, so they don't need your consent. That's why there is no cookie banner. The Google map on our Contact page only loads after you click it.

    6How long we keep it

    • Account and profile: until you delete your account
    • Reviews, photos, videos and forum posts: until you delete them or your account
    • Booking and payment records: as long as Moroccan accounting and tax law requires (up to 10 years). If you delete your account, these records are kept but no longer linked to it
    • Contact messages: up to 2 years after our last reply
    • Newsletter: until you unsubscribe
    • Security hashes: 24 hours

    7Your rights

    You have the right to:

    • access your data and get a copy
    • correct inaccurate data
    • delete your data ("right to be forgotten")
    • restrict or object to how we use it, including at any time to direct marketing
    • data portability, a copy in a machine-readable format
    • withdraw consent at any time, without affecting what we did before

    Do it yourself

    • Download your data: Account settings → Your data → Download my data
    • Delete your account: Account settings → Delete account. This also deletes your reviews, forum posts, photos and videos
    • Correct your details: Account settings
    • Stop the newsletter: the unsubscribe link in any email

    For anything else, email privacy@zenithska.io. We'll reply within one month and may ask you to confirm your identity first.

    You can also complain to a data protection authority: the one where you live or work in the EU or EEA, the ICO in the UK, or the CNDP in Morocco (www.cndp.ma). We'd appreciate the chance to sort it out with you first.

    8Security

    All traffic to the site is encrypted (HTTPS). Database access is locked down so each person can only reach their own data, passwords are stored as secure hashes, and card details never touch our servers. If a breach puts your data at risk, we will tell the authorities and you as the law requires.

    9Children

    Accounts are for people aged 16 and over. Children are welcome on many excursions, but a parent or guardian must make the booking. If you think a child has given us personal data, email privacy@zenithska.io and we'll delete it.

    10Automated decisions

    We don't make decisions about you based solely on automated processing or profiling.

    11Changes to this policy

    If we change this policy, we'll update the date at the top. If the changes are significant, we'll also show a notice on the site or email registered users.