Privacy Policy
What personal data MarrakechLocal LLC collects, why, who we share it with, and the rights you have over it. Written to be read — if anything here is unclear, ask us at [email protected] and we will explain it.
1. Who is responsible
The data controller is MarrakechLocal LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, United States. Contact for all privacy matters: [email protected].
We are established outside the EU and the UK but we offer services to people in both, which requires us to appoint representatives under Article 27 of the GDPR and Article 27 of the UK GDPR. That appointment is in progress and this page will name them as soon as it is complete. Until then, please write to us directly at [email protected] — we answer every request ourselves and within the same deadlines.
- EU representative: Appointment in progress — contact us directly in the meantime
- UK representative: Appointment in progress — contact us directly in the meantime
2. What we collect and why
We do not collect special-category data, we do not profile you, and we do not make automated decisions that produce legal effects for you.
| Data | Why we have it | Lawful basis | Kept for |
|---|---|---|---|
| Name, email, phone/WhatsApp number | To create your booking, deliver your ticket and audio guide, and contact you about your visit | Performance of a contract | 7 years |
| Booking details (monument, date, number of visitors, amount paid) | To fulfil the booking and to meet accounting and tax obligations | Contract; legal obligation | 7 years |
| Consent record (the wording you were shown and the time you accepted it) | To demonstrate what was agreed, and to answer payment disputes | Legal obligation; legitimate interests in defending claims | 7 years |
| Checkout evidence snapshot (prices and disclaimers displayed, browser user-agent, country) | To respond to chargebacks and fraud claims | Legitimate interests in preventing and contesting payment fraud | 24 months |
| Payment data | To take payment. Card details are entered directly into Stripe and never reach our servers | Contract | Held by Stripe under its own policy |
| Analytics data (pages viewed, approximate location, device) | To understand which guides are useful | Consent — off until you allow it | 14 months |
| Newsletter address | To send the monthly letter you asked for | Consent | Until you unsubscribe |
| Contact form messages | To answer you | Legitimate interests in responding to enquiries | 24 months |
| Server logs (IP address, request, timestamp) | Security, abuse prevention, diagnosing faults | Legitimate interests in keeping the service secure | 30 days |
3. Children
Our services are not directed at children and we do not knowingly collect data from anyone under 16. Where a booking includes children, we collect only the number of visitors, not their names or ages.
5. International transfers
We are a US company, and several of our providers are based in or transfer data to the United States. Where personal data of people in the EU or UK is transferred outside those areas, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and we assess whether additional safeguards are needed in each case.
You may request a copy of the transfer safeguards in place by writing to [email protected].
6. Your rights
If the GDPR or UK GDPR applies to you, you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Have inaccurate data corrected.
- Have data erased, where we no longer need it and no legal obligation requires us to keep it.
- Restrict or object to processing that we carry out on the basis of legitimate interests.
- Receive data you gave us in a portable, machine-readable format.
- Withdraw consent at any time, where processing is based on consent — this does not affect processing carried out before you withdrew it.
- Complain to your national data-protection authority. In the UK this is the Information Commissioner's Office.
7. How to exercise them
Email [email protected]. We will respond within one month. We may ask you to confirm your identity, but only to the extent necessary — we will not demand a passport scan to answer a question about a €13.99 booking.
Note that we cannot erase data we are required to keep for accounting purposes, or a consent record and evidence snapshot relating to a payment while a dispute window remains open. We will tell you if that applies and when the data will be deleted.
8. Security
All traffic is encrypted in transit. Card details are entered directly into Stripe's hosted payment fields and are never transmitted to or stored on our servers, so we hold no card numbers. Access to order data is limited to the people who need it to provide support.
If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and, where the risk is high, tell you directly.
10. Changes
We will update this policy when our processing changes. Where a change is significant we will say so prominently rather than silently amending the date at the top.