Privacy Policy
Last updated: 2026-07-20
Short version. This website is a brochure with one optional booking-request form. It uses analytics and advertising cookies (Google Analytics, Microsoft Clarity, Meta Pixel, Google Ads), but only after you accept them in the cookie banner — decline and none are set. Most visitors get in touch by clicking a WhatsApp, telephone or e-mail link, which opens an app on your own device — conversations then happen off this website. If you prefer, you can instead fill in the booking-request form: it asks only for what is needed to answer a booking enquiry, is sent only after you tick a consent box, and is stored in a small database on our own server — no third-party form service. See section 3 below for the detail.
Scope
This Privacy Policy covers:
- the Buggy Trip Marrakech brochure website at buggytripmarrakech.com (English, French, Spanish, and Dutch editions); and
- the internal Buggy Trip Marrakech app,
used by SSV BUGGY TRIP to publish its own promotional
content (short videos, photos, captions) to its own
official accounts on TikTok, Instagram, Facebook, YouTube
and Pinterest, through those platforms' public APIs. This
app:
- is not distributed to the public and is not downloadable;
- does not allow any third-party user to sign in — only the website operator has access;
- does not read any direct messages, comments or follower data: it only publishes to the company's own official accounts.
- the internal Buggy Trip Marrakech operations apps, used by SSV BUGGY TRIP to handle client enquiries (drafting replies and quotes) and to organise the delivery of confirmed bookings (scheduling, vehicle and guide assignment, and deposit / balance records). These apps are private, accessible only to the operator and authorised staff, and run on our own server; what they process is described in section 3.
1. Data Controller
The controller under the EU General Data Protection Regulation (GDPR, EU 2016/679) and Moroccan Law n° 09-08 is:
SSV BUGGY TRIP
Société à Responsabilité Limitée à Associé Unique (SARL AU)
Registered seat: Dom. chez Miz Expert, Mhamid Sud, Ain Souna, Imm. E19, étage 3, apt. 3, Marrakech, Maroc
Commercial Register (RC) no. 160417
I.C.E.: 003656887000060
Phone: +212 7 07 01 44 44
Privacy contact: [email protected]
2. What Happens on This Website
When you view a page on buggytripmarrakech.com our content-delivery / security layer and our origin web server see the usual technical data any website sees:
- your IP address;
- the user-agent string sent by your browser;
- the URL you requested and the HTTP status returned;
- the date and time of the request.
This data is processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in keeping the site online and defending it against abuse. Server access logs are size-capped by the container runtime to approximately 30 megabytes in total; once that ceiling is reached the oldest entries are overwritten. The logs are not consulted, exported or correlated with any other data source held by us.
With your consent, the site loads analytics and advertising tools: Google Analytics 4 and Microsoft Clarity (audience measurement and anonymised session insights), Meta Pixel and the Google Ads tag (measuring and retargeting our advertising). These set cookies and send data to those providers. They are governed by a consent banner using Google Consent Mode v2: until you accept, no such cookie is set and only cookieless, aggregated signals are sent; if you decline, none are sent at all. You can change your choice at any time by clearing this site's storage in your browser. Webfonts are self-hosted from our own domain; no request is made to any font CDN.
3. Booking-Request Form
The site offers one optional form, at /book/ (and the locale paths /fr/reserver/, /en/book/, /es/reservar/, /nl/boeken/). Submitting it is entirely your choice — the WhatsApp, phone and e-mail links remain available as before.
The form collects only what is needed to answer a booking enquiry: your e-mail (required), an optional name (a nickname is fine) and phone number, one or more vehicles (with a quantity each) and a single 1 h / 2 h ride duration, the date, number of participants and an optional start time and message. An indicative dirham total is computed in your browser and stored for the operator's reference only.
- Legal basis: your consent (Art. 6(1)(a) GDPR). The form cannot be sent unless you actively tick a box referring to this policy. The time of consent and the policy version in force are stored with the record as proof under Art. 7(1).
- Purpose: to get back to you about the excursion you asked about. Your enquiry is never sold or shared with third parties; we carry out no individual profiling and make no automated decision that produces legal or similarly significant effects about you (Art. 22 GDPR). We do keep an internal record of whether an enquiry led to a booking and its indicative value, and we use aggregated, anonymous statistics from booking enquiries — such as weekly totals, ride duration, vehicle mix, marketing channel, and overall conversion and revenue — to measure and improve our marketing and service. These aggregate figures contain nothing that identifies you.
- Advertising measurement: if you reach the site by
clicking one of our online advertisements, the advertising platform
adds a click identifier to the link (for Google ads, a
gclid,gbraidorwbraiddepending on your device and privacy settings). When you submit the form, that identifier is stored with your request. Only if your enquiry becomes a confirmed booking do we send that click identifier, together with the conversion outcome (date and an indicative value), to the advertising provider so it can measure which ads lead to bookings. No name, e-mail, phone number or message is ever sent for this purpose — only the click identifier and the conversion figure. The legal basis is your consent, given through the same form checkbox; this adds the advertising-measurement provider as a recipient (section 5) and an international transfer (section 6). - Advertising measurement when you contact us directly: if you arrived from one of our online ads and then use a WhatsApp (or other contact) link instead of the form, the same click identifier is briefly stored on our own server behind a short, random reference code as soon as you arrive from that advertisement, so the reference is ready if you then choose that channel; the pre-filled message you send carries only that short reference — not the identifier itself. This lets us recognise, if your message becomes a confirmed booking, that it came from an advertisement, and apply exactly the same measurement as above: only the click identifier and the conversion figure are ever sent to the advertising provider, never your name, phone number or message. As no form checkbox is involved here, the legal basis for this brief storage is our legitimate interest in measuring our own advertising (Art. 6(1)(f) GDPR); the data held is a single pseudonymous click identifier with no contact details, and you can object at any time (Art. 21 GDPR — see section 7). The reference record also notes the moment you tap a contact button (a simple timestamp on the same record): if the reference is missing from the message you send (for example because you rewrote it), the operator may recognise, by simple time proximity and after human confirmation, that a message received moments later most likely came from that advertisement — same legitimate-interest basis, no data beyond the timestamp. This same reference record also carries the advertising platform's own campaign-targeting parameters for that click (for example the campaign, ad group, matched keyword, match type and device type), plus the page and site language you were on at the moment you tapped the button — again only non-personal advertising-targeting data, never any contact details, used to refine the same effectiveness measurement described above. These reference records are deleted automatically within 90 days, or sooner on request. This adds no new recipient and no new transfer beyond the advertising-measurement provider already described above.
- Where it is stored: a small database on our own server. There is no third-party form service. Apart from the advertising-measurement provider just described — which only ever receives a click identifier and a conversion figure, never your contact details — only the providers already described in section 5 are involved. The database file is readable only by the application's own system user, and the server only accepts connections through our content-delivery / security provider.
- Notification e-mail: each submission also sends a notification to our own business mailbox so the request is not missed — this stays with our hosting / e-mail provider.
- Retention: records are kept only as long as needed to handle your enquiry and any booking that follows, and in any case no longer than 12 months, after which they are deleted. Advertising reference records (a short code paired with a click identifier, no contact details) are kept at most 90 days and then deleted automatically.
- Withdrawing consent: you can withdraw consent or ask for erasure at any time by writing to the address in section 7; withdrawal does not affect processing carried out beforehand.
Once your booking is confirmed
When a request becomes a confirmed trip, we organise its delivery in an internal back-office system ("dispatch"), separate from this website and accessible only to the operator and authorised staff.
- What we use: the booking details you already gave (name, contact, language, date and time, vehicle(s), number of participants, pickup and any notes); a payment record (the deposit / balance amount, the method — e.g. a bank or Revolut transfer — and the dates); and operational notes. We do not store card numbers or bank-account details — you pay through your own bank or payment provider, never on our systems.
- Legal basis: performing the booking you requested (Art. 6(1)(b) GDPR), and — for the payment / accounting records — our legal accounting and tax obligations (Art. 6(1)(c) GDPR).
- Who can see it: the operator and authorised office staff. A field guide assigned to your trip sees only your first name, the time, the pickup, the vehicle(s) and any special notes, through a personal, revocable link — never payment information or any other client's trip. If we source an extra vehicle from a partner, the partner gets only the machine booking, not your contact details.
- Where and how long: on our own server (the same host as the rest of the site), in a private database behind an authenticated gate; this adds no new provider outside the EEA and no new transfer beyond sections 5–6. Booking and payment records are kept for as long as needed to deliver the trip and to meet our legal accounting and tax obligations, then deleted; you can ask about your data or request erasure at any time (subject to those legal obligations) — section 7.
4. External Links You Can Click
The site contains three kinds of click-out links. They are ordinary hyperlinks: nothing is loaded from these third parties until you click, at which point you leave our site and enter theirs.
- WhatsApp (wa.me/…) — operated by Meta Platforms Ireland Ltd. When you click, a chat opens in your WhatsApp app. The contents of the conversation, your phone number and any data WhatsApp routinely records are processed by Meta under WhatsApp's own privacy policy.
- Google Maps (link to the business listing) — we do not embed a map; the link simply opens Google Maps in a new tab when you click it. From that point on Google's own privacy terms apply.
- Instagram (link in the footer) — opens the public Instagram profile. Meta's privacy policy applies once you are on instagram.com.
5. Service Providers (Processors)
The following providers process data strictly on our behalf, in the course of keeping the website online. None receives data for its own purposes.
- A hosting and business e-mail provider (EU data centres) — runs the server, the booking database and the notification mailbox. Art. 28 GDPR processing agreement in place.
- A content-delivery and security provider (US-based, with an EU edge presence) — reverse proxy, TLS termination and DDoS protection. Its Data Processing Addendum and the European Commission's Standard Contractual Clauses (SCCs) cover any transfer of technical data outside the EU/EEA.
- A TLS certificate authority — issues the certificate used for HTTPS. No personal data of visitors is sent to it.
- An advertising-measurement provider (US-based, with an EU presence) — receives an advertising click identifier and conversion figure (never your contact details), and only for visitors who arrived via one of our online ads and whose enquiry converted. Its Data Processing Addendum and the SCCs / EU–US Data Privacy Framework cover the transfer.
We name our providers by category to keep this page provider-neutral; the specific named list is available on request at [email protected].
6. Transfers Outside the EU/EEA
Two flows may reach outside the EU/EEA: the edge-level technical data handled by our content-delivery / security provider, and — only for visitors who arrived via an online ad and whose enquiry converted — the advertising click identifier and conversion figure sent to our advertising-measurement provider (section 5). Such transfers are covered by the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. A copy of the relevant clauses is available on request at the address in section 10.
7. Your Rights
Even though we keep almost nothing about you, you have the rights provided by Arts. 15–22 GDPR and by the corresponding provisions of Moroccan Law n° 09-08, in particular:
- right of access (Art. 15);
- right to rectification (Art. 16);
- right to erasure (Art. 17);
- right to restriction of processing (Art. 18);
- right to object (Art. 21);
- right to lodge a complaint with a supervisory authority.
To exercise any right, write to [email protected]. We respond within one month. We may ask for proof of identity if there is reasonable doubt about who is making the request.
8. Complaints
Without prejudice to any other remedy, you have the right to lodge a complaint:
- with the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) in Morocco — www.cndp.ma;
- with the supervisory authority of your EU/EEA Member State — list published by the European Data Protection Board at edpb.europa.eu.
9. Security
- Encryption in transit: TLS 1.2/1.3 on every page.
- Origin reachable only through our content-delivery / security provider; direct access blocked at the firewall.
- Administrative access to the server is key-based, over a private mesh VPN, not exposed to the public internet.
- The personal-data stores are the booking-request database and the internal operations database for confirmed bookings (section 3): both sit on our own server, each file is readable only by the application's unprivileged system user, and outbound network access is firewall-restricted. No copy is sent to any third party.
10. Contact and Changes
For any question about this policy or about data concerning you, write to [email protected].
We will update this policy if our practices change. The current text on this page is always authoritative; substantive changes are reflected in the "last updated" date above.