Skip to content
El Badi Palace
  • Home
  • Tickets
  • Gallery
  • Blog
  • FAQ
  • About
  • Contact
  • English
  • Français
  • Deutsch
  • Italiano
  • Español
  • العربية

Privacy Policy

2026-07-29

What personal data MarrakechLocal LLC collects, why, who we share it with, and the rights you have over it. Written to be read — if anything here is unclear, ask us at [email protected] and we will explain it.

1. Who is responsible

The data controller is MarrakechLocal LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, United States. Contact for all privacy matters: [email protected].

We are established outside the EU and the UK but we offer services to people in both, which requires us to appoint representatives under Article 27 of the GDPR and Article 27 of the UK GDPR. That appointment is in progress and this page will name them as soon as it is complete. Until then, please write to us directly at [email protected] — we answer every request ourselves and within the same deadlines.

  • EU representative: Appointment in progress — contact us directly in the meantime
  • UK representative: Appointment in progress — contact us directly in the meantime

2. What we collect and why

We do not collect special-category data, we do not profile you, and we do not make automated decisions that produce legal effects for you.

DataWhy we have itLawful basisKept for
Name, email, phone/WhatsApp numberTo create your booking, deliver your ticket and audio guide, and contact you about your visitPerformance of a contract7 years
Booking details (monument, date, number of visitors, amount paid)To fulfil the booking and to meet accounting and tax obligationsContract; legal obligation7 years
Consent record (the wording you were shown and the time you accepted it)To demonstrate what was agreed, and to answer payment disputesLegal obligation; legitimate interests in defending claims7 years
Checkout evidence snapshot (prices and disclaimers displayed, browser user-agent, country)To respond to chargebacks and fraud claimsLegitimate interests in preventing and contesting payment fraud24 months
Payment dataTo take payment. Card details are entered directly into Stripe and never reach our serversContractHeld by Stripe under its own policy
Analytics data (pages viewed, approximate location, device)To understand which guides are usefulConsent — off until you allow it14 months
Newsletter addressTo send the monthly letter you asked forConsentUntil you unsubscribe
Contact form messagesTo answer youLegitimate interests in responding to enquiries24 months
Server logs (IP address, request, timestamp)Security, abuse prevention, diagnosing faultsLegitimate interests in keeping the service secure30 days

3. Children

Our services are not directed at children and we do not knowingly collect data from anyone under 16. Where a booking includes children, we collect only the number of visitors, not their names or ages.

4. Who we share data with

We do not sell personal data and we never will. We share it only with the service providers we need to run the business, each of which processes it on our instructions under a written agreement:

  • Stripe, Inc. — payment processing, fraud prevention, chargeback handling (United States / Ireland; basis: Contract; Standard Contractual Clauses for transfers); PayPal (Europe) S.à r.l. et Cie, S.C.A. — optional alternative payment method (Luxembourg / United States; basis: Contract; Standard Contractual Clauses for transfers); Vercel Inc. — website hosting, CDN, server logs (United States (edge nodes worldwide); basis: Contract; Standard Contractual Clauses for transfers); Resend, Inc. — transactional email — order confirmations and ticket delivery (United States; basis: Contract; Standard Contractual Clauses for transfers); WhatsApp Ireland Ltd (Meta) — optional ticket delivery and customer support messaging (Ireland / United States; basis: Contract; Standard Contractual Clauses for transfers); Google Ireland Ltd — analytics and, once enabled, advertising — consent-gated (Ireland / United States; basis: Consent; Standard Contractual Clauses for transfers)
  • The official ticketing channel, which receives the visitor details required to issue your ticket.
  • Professional advisers, and public authorities where we are legally required to disclose.

5. International transfers

We are a US company, and several of our providers are based in or transfer data to the United States. Where personal data of people in the EU or UK is transferred outside those areas, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and we assess whether additional safeguards are needed in each case.

You may request a copy of the transfer safeguards in place by writing to [email protected].

6. Your rights

If the GDPR or UK GDPR applies to you, you have the right to:

  • Access the personal data we hold about you, and receive a copy.
  • Have inaccurate data corrected.
  • Have data erased, where we no longer need it and no legal obligation requires us to keep it.
  • Restrict or object to processing that we carry out on the basis of legitimate interests.
  • Receive data you gave us in a portable, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent — this does not affect processing carried out before you withdrew it.
  • Complain to your national data-protection authority. In the UK this is the Information Commissioner's Office.

7. How to exercise them

Email [email protected]. We will respond within one month. We may ask you to confirm your identity, but only to the extent necessary — we will not demand a passport scan to answer a question about a €13.99 booking.

Note that we cannot erase data we are required to keep for accounting purposes, or a consent record and evidence snapshot relating to a payment while a dispute window remains open. We will tell you if that applies and when the data will be deleted.

8. Security

All traffic is encrypted in transit. Card details are entered directly into Stripe's hosted payment fields and are never transmitted to or stored on our servers, so we hold no card numbers. Access to order data is limited to the people who need it to provide support.

If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and, where the risk is high, tell you directly.

9. Cookies

Cookies and similar technologies are covered separately in our Cookie Policy, which also explains how to change or withdraw your choices.

10. Changes

We will update this policy when our processing changes. Where a change is significant we will say so prominently rather than silently amending the date at the top.

← Legal Notice

El Badi Palace

An independent travel guide to El Badi Palace, Marrakech.

Explore

  • Home
  • Tickets
  • Gallery
  • Blog
  • FAQ
  • About
  • Contact

Languages

  • English
  • Français
  • Deutsch
  • Italiano
  • Español
  • العربية
  • Terms of Sale
  • Refund & Cancellation Policy
  • Delivery & Fulfilment Policy
  • Payments & Security
  • Privacy Policy
  • Cookie Policy
  • Accessibility Statement
  • Legal Notice
  • Affiliate & Advertising Disclosure
Company: MarrakechLocal LLCLegal form: Limited Liability Company (LLC), formed in Wyoming, United StatesRegistered office: 30 N Gould St, Ste R, Sheridan, WY 82801, United StatesRegistered agent: Registered Agents Inc, 30 N Gould St Ste R, Sheridan, WY 82801, United StatesCompany registration number: 2026-002047078US Employer Identification Number (EIN): 98-1960250Represented by: Abdellah AmejalEmail: [email protected]Customer support: [email protected] · WhatsApp +212 607-223008 · 09:00–21:00 (GMT+1), 7 days a week

Not affiliated with the palace administration or the Moroccan Ministry of Culture. Part of an independent network of Morocco monument guides.

© 2026 El Badi Palace. All rights reserved.

100 MAD · 9am–5pm daily

Get Tickets Online