Plan a trip
Legal

Privacy Policy

Last updated: June 2026 · privacy@ex-plore.com

ex-plore (“we”, “us”, “our”) is a Morocco tour-booking marketplace. This policy explains what personal data we collect when you use our website (ex-plore.com), why we collect it, how we use it, and the rights you have over it.

Counsel note: This document is a good-faith template drafted for the ex-plore prototype. It must be reviewed by qualified legal counsel and adapted to reflect the exact corporate entity, registered address, applicable jurisdiction(s) (including GDPR if serving EU residents, UK GDPR, and any Moroccan data-protection law), and live operational details before publication.

1. Who we are

ex-plore is a tour-booking marketplace specialising in curated Morocco journeys. We act as a data controller for the personal information collected through this website. Our registered office and principal place of business is in Marrakech, Morocco.

For all privacy-related queries, please contact us at privacy@ex-plore.com.

2. Data we collect

We collect personal data in the following situations:

2.1 Account registration (OTP sign-in)

When you create an account or sign in, we collect your email address. We use a one-time password (OTP) delivered by email — we never store a password. Your email is held in our authentication system (Supabase Auth).

2.2 Traveller profile

If you complete your traveller profile, you may optionally provide your full name, phone number, nationality, dietary requirements, and travel preferences. This information is stored in your profile record and used only to personalise your journey proposals and support your booking.

2.3 Enquiries

When you submit a travel enquiry, we collect your name, email address, phone number, and your message/requirements. This information is used to respond to your enquiry and to match you with an appropriate specialist.

2.4 Bookings

When you make a booking (deposit or full payment), we record your name, email address, tour selection, traveller count, travel dates, comfort preference, and booking reference. Payment card details are processed exclusively by Stripe — we never see or store your full card number, CVV, or expiry date on our servers.

2.5 Payment data

We store only a payment intent reference provided by Stripe to allow us to reconcile bookings. Stripe operates as an independent data processor under its own Privacy Policy.

2.6 Technical / log data

Our servers automatically record standard web server logs (IP address, browser user-agent, pages visited, timestamps) for security, abuse prevention, and debugging. These logs are retained for up to 90 days.

2.7 Cookies and local storage

We use browser local storage (not third-party tracking cookies) to:

  • Maintain your authentication session (essential — required for the service to function)
  • Remember your consent choice for this banner
  • Remember UI preferences such as currency and language

At present, we do not use any third-party analytics cookies, advertising pixels, or social-media tracking scripts. If that changes, we will update this policy and obtain fresh consent where required.

3. How we use your data

We use your personal data for the following purposes:

PurposeLegal basis
Providing the booking and trip-planning serviceContract performance
Sending transactional emails (OTP, booking confirmation)Contract performance / Legitimate interest
Responding to enquiries and matching you with a specialistContract performance / Legitimate interest
Processing payments via StripeContract performance
Fraud prevention and securityLegitimate interest / Legal obligation
Improving our service (aggregate analytics, no PII)Legitimate interest
Sending occasional trip inspiration (only if you opted in)Consent
Complying with legal obligationsLegal obligation

4. Who we share data with

We do not sell your personal data. We share it only with the following sub-processors, each under a data-processing agreement:

  • Supabase Inc. — cloud database and authentication (EU region)
  • Stripe, Inc. — payment processing
  • Resend Inc. — transactional email delivery
  • Cloudflare, Inc. — CDN, DDoS protection, and Turnstile bot detection

We may disclose data to law-enforcement authorities or courts if required by applicable law.

5. Data retention

We retain personal data for as long as necessary for the purposes described:

  • Active accounts: for as long as your account is open
  • Enquiry records: 3 years from the enquiry date, for dispute resolution
  • Booking records: 7 years from the booking date, to comply with accounting and tax obligations (note: PII fields may be anonymised earlier on your request — see Section 7)
  • Server logs: up to 90 days
  • Marketing consent: until you withdraw consent

When retention periods expire, data is securely deleted or anonymised.

6. Security

We take appropriate technical and organisational measures to protect your data, including:

  • TLS encryption in transit for all communications
  • Encryption at rest for the database (managed by Supabase)
  • Row-level security policies restricting data access to authorised users
  • Service-role keys never exposed to the browser
  • Stripe Elements for card data — card numbers never touch our servers
  • Rate limiting and CAPTCHA on public-facing forms

No transmission over the internet is 100% secure. Please contact us immediately at security@ex-plore.com if you believe your account has been compromised.

7. Your rights

Depending on your jurisdiction, you may have the following rights over your personal data. We will respond to verified requests within 30 days:

  • Access: obtain a copy of the data we hold about you
  • Rectification: correct inaccurate or incomplete data — you can do this directly in your account under “Traveller details”
  • Erasure (right to be forgotten): request deletion of your account and anonymisation of your enquiry/booking PII — available directly from your account settings
  • Restriction: request that we limit processing of your data in certain circumstances
  • Portability: receive your data in a machine-readable format
  • Objection: object to processing based on legitimate interest
  • Withdraw consent: for marketing communications at any time via the Settings tab in your account

To exercise any right, contact privacy@ex-plore.com or use the “Delete my account” feature in your account settings.

8. International transfers

Our infrastructure providers (Supabase, Stripe, Resend, Cloudflare) may process data in the United States and other countries outside the EEA. Where such transfers occur, we rely on standard contractual clauses (SCCs) or equivalent safeguards approved by the relevant supervisory authority.

9. Children

Our service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

10. Changes to this policy

We may update this policy to reflect changes in our practices or legal requirements. We will post the updated policy on this page with a new “Last updated” date. Material changes will be notified by email where required by law.

11. Complaints

If you have concerns about our use of your data that we have not resolved to your satisfaction, you have the right to lodge a complaint with the relevant supervisory authority (for example, the ICO in the UK or your national data protection authority in the EU).

Terms of ServiceMy accountBack to explore