Privacy Policy
Last updated: June 2026 · privacy@ex-plore.com
ex-plore (“we”, “us”, “our”) is a Morocco tour-booking marketplace. This policy explains what personal data we collect when you use our website (ex-plore.com), why we collect it, how we use it, and the rights you have over it.
Counsel note: This document is a good-faith template drafted for the ex-plore prototype. It must be reviewed by qualified legal counsel and adapted to reflect the exact corporate entity, registered address, applicable jurisdiction(s) (including GDPR if serving EU residents, UK GDPR, and any Moroccan data-protection law), and live operational details before publication.
1. Who we are
ex-plore is a tour-booking marketplace specialising in curated Morocco journeys. We act as a data controller for the personal information collected through this website. Our registered office and principal place of business is in Marrakech, Morocco.
For all privacy-related queries, please contact us at privacy@ex-plore.com.
2. Data we collect
We collect personal data in the following situations:
2.1 Account registration (OTP sign-in)
When you create an account or sign in, we collect your email address. We use a one-time password (OTP) delivered by email — we never store a password. Your email is held in our authentication system (Supabase Auth).
2.2 Traveller profile
If you complete your traveller profile, you may optionally provide your full name, phone number, nationality, dietary requirements, and travel preferences. This information is stored in your profile record and used only to personalise your journey proposals and support your booking.
2.3 Enquiries
When you submit a travel enquiry, we collect your name, email address, phone number, and your message/requirements. This information is used to respond to your enquiry and to match you with an appropriate specialist.
2.4 Bookings
When you make a booking (deposit or full payment), we record your name, email address, tour selection, traveller count, travel dates, comfort preference, and booking reference. Payment card details are processed exclusively by Stripe — we never see or store your full card number, CVV, or expiry date on our servers.
2.5 Payment data
We store only a payment intent reference provided by Stripe to allow us to reconcile bookings. Stripe operates as an independent data processor under its own Privacy Policy.
2.6 Technical / log data
Our servers automatically record standard web server logs (IP address, browser user-agent, pages visited, timestamps) for security, abuse prevention, and debugging. These logs are retained for up to 90 days.
2.7 Cookies and local storage
We use browser local storage (not third-party tracking cookies) to:
- Maintain your authentication session (essential — required for the service to function)
- Remember your consent choice for this banner
- Remember UI preferences such as currency and language
At present, we do not use any third-party analytics cookies, advertising pixels, or social-media tracking scripts. If that changes, we will update this policy and obtain fresh consent where required.
3. How we use your data
We use your personal data for the following purposes:
| Purpose | Legal basis |
|---|---|
| Providing the booking and trip-planning service | Contract performance |
| Sending transactional emails (OTP, booking confirmation) | Contract performance / Legitimate interest |
| Responding to enquiries and matching you with a specialist | Contract performance / Legitimate interest |
| Processing payments via Stripe | Contract performance |
| Fraud prevention and security | Legitimate interest / Legal obligation |
| Improving our service (aggregate analytics, no PII) | Legitimate interest |
| Sending occasional trip inspiration (only if you opted in) | Consent |
| Complying with legal obligations | Legal obligation |
5. Data retention
We retain personal data for as long as necessary for the purposes described:
- Active accounts: for as long as your account is open
- Enquiry records: 3 years from the enquiry date, for dispute resolution
- Booking records: 7 years from the booking date, to comply with accounting and tax obligations (note: PII fields may be anonymised earlier on your request — see Section 7)
- Server logs: up to 90 days
- Marketing consent: until you withdraw consent
When retention periods expire, data is securely deleted or anonymised.
6. Security
We take appropriate technical and organisational measures to protect your data, including:
- TLS encryption in transit for all communications
- Encryption at rest for the database (managed by Supabase)
- Row-level security policies restricting data access to authorised users
- Service-role keys never exposed to the browser
- Stripe Elements for card data — card numbers never touch our servers
- Rate limiting and CAPTCHA on public-facing forms
No transmission over the internet is 100% secure. Please contact us immediately at security@ex-plore.com if you believe your account has been compromised.
7. Your rights
Depending on your jurisdiction, you may have the following rights over your personal data. We will respond to verified requests within 30 days:
- Access: obtain a copy of the data we hold about you
- Rectification: correct inaccurate or incomplete data — you can do this directly in your account under “Traveller details”
- Erasure (right to be forgotten): request deletion of your account and anonymisation of your enquiry/booking PII — available directly from your account settings
- Restriction: request that we limit processing of your data in certain circumstances
- Portability: receive your data in a machine-readable format
- Objection: object to processing based on legitimate interest
- Withdraw consent: for marketing communications at any time via the Settings tab in your account
To exercise any right, contact privacy@ex-plore.com or use the “Delete my account” feature in your account settings.
8. International transfers
Our infrastructure providers (Supabase, Stripe, Resend, Cloudflare) may process data in the United States and other countries outside the EEA. Where such transfers occur, we rely on standard contractual clauses (SCCs) or equivalent safeguards approved by the relevant supervisory authority.
9. Children
Our service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to this policy
We may update this policy to reflect changes in our practices or legal requirements. We will post the updated policy on this page with a new “Last updated” date. Material changes will be notified by email where required by law.
11. Complaints
If you have concerns about our use of your data that we have not resolved to your satisfaction, you have the right to lodge a complaint with the relevant supervisory authority (for example, the ICO in the UK or your national data protection authority in the EU).