Privacy Policy
Effective Date: [August 13, 2026]
1. Introduction and Scope
Welcome to We Travel Morocco. This Privacy Policy explains how We Travel Morocco (“We Travel Morocco,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you visit or use https://wetravelmorocco.com/ (the “Website”), contact us, subscribe to our communications, or book or inquire about travel services through us.
For applicable data-protection laws, We Travel Morocco is the data controller or business responsible for the personal information described in this Policy, except where a booking platform, payment provider, hotel, transport company, tour operator, guide, or other travel provider processes your information for its own purposes. Those organizations may act as separate controllers or businesses and will provide their own privacy notices.
This Policy does not apply to third-party websites or services that we do not control, even when they are linked from our Website.
2. Information We Collect
The information we collect depends on how you interact with us.
Information You Provide Directly
We may collect:
- Contact information, such as your name, email address, telephone number, country of residence, and mailing address.
- Booking and traveler information, such as travel dates, destination interests, accommodation preferences, group details, arrival information, and the names and ages of travelers.
- Identity and document information, such as passport or identification details, only when needed to arrange a requested service or comply with law.
- Payment and billing information. Our payment providers may collect card or bank details directly. We may receive limited billing information, a payment token, transaction status, and payment history rather than complete card details.
- Communications, including inquiries, support requests, survey responses, reviews, and other messages you send us.
- Marketing preferences, including newsletter subscriptions and consent records.
- Optional sensitive information, such as dietary, health, accessibility, or religious requirements, when you choose to provide it and it is necessary to arrange your trip. Please provide only what is needed.
If you give us personal information about another traveler, you confirm that you have permission to do so and have shared this Policy with them.
Information Collected Automatically
When you use the Website, we and our service providers may automatically collect:
- IP address and approximate location derived from it;
- browser type, device type, operating system, language, and device identifiers;
- pages viewed, links clicked, referring pages, dates and times of visits, and session activity;
- cookie identifiers, advertising identifiers, and similar tracking data;
- general location information and, only with your permission, more precise device location; and
- diagnostic, performance, security, and fraud-prevention information.
Information From Other Sources
We may receive information from booking platforms, payment processors, travel providers, referral partners, social-media platforms, advertising and analytics providers, or a person organizing travel for you. We handle that information as described in this Policy.
3. How We Use Your Information
We use personal information to:
- respond to inquiries and provide requested travel information;
- create itineraries, arrange reservations, and deliver travel services;
- personalize content and recommendations;
- process payments, refunds, and transaction records;
- send booking confirmations, service notices, safety information, and customer-support messages;
- send newsletters and promotional communications when permitted by law;
- operate, analyze, secure, troubleshoot, and improve the Website and our services;
- prevent fraud, misuse, and security incidents;
- enforce our terms and protect our rights, users, partners, and the public; and
- meet tax, accounting, regulatory, court-order, and other legal requirements.
Legal Bases for Processing
Where the GDPR, UK GDPR, or a similar law applies, we rely on one or more of these legal bases:
| Purpose | Typical legal basis |
|---|---|
| Answering pre-booking questions and providing booked services | Taking steps at your request and performing our contract with you |
| Processing payments and keeping required booking records | Contract and legal obligations |
| Service communications and customer support | Contract and our legitimate interests in serving customers |
| Website security, fraud prevention, and service improvement | Our legitimate interests, balanced against your rights |
| Non-essential cookies, targeted advertising, and certain analytics | Your consent where required |
| Email marketing | Your consent or our legitimate interests where permitted by law |
| Legal claims and regulatory compliance | Legal obligations and our legitimate interests |
| Optional health, accessibility, or other sensitive information | Your explicit consent or another legal basis permitted by law |
You may withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal. Where we rely on legitimate interests, you may ask us to explain our balancing assessment.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects for travelers.
4. Cookies and Tracking Technologies
We use cookies, pixels, tags, local storage, and similar technologies. These technologies may be placed by us or by third parties.
Types of Cookies We Use
- Necessary cookies help the Website work, support security, remember privacy choices, and enable requested features. They cannot generally be switched off through our consent tool.
- Performance and analytics cookies help us understand visits, traffic sources, and how people use the Website so we can improve it.
- Functionality cookies remember choices such as language, region, or other preferences.
- Advertising cookies help measure campaigns, limit repeated ads, and show advertising that may be more relevant based on activity across websites or services.
Where required by law, we ask for consent before placing non-essential cookies. You can accept, reject, or adjust these technologies through the [Cookie Settings] link on the Website. You can also delete or block cookies through your browser settings, although some Website features may not work correctly.
We recognize legally valid browser-based opt-out signals, including Global Privacy Control, where required by law. Because there is no universally accepted standard for other “Do Not Track” signals, the Website may not respond to them.
5. How We Share Personal Information
We may share personal information only as reasonably necessary for the purposes described in this Policy:
- Booking platforms and travel providers. We share relevant booking and traveler details with hotels, riads, camps, transport companies, airlines, tour operators, guides, activity providers, and similar partners so they can confirm and deliver requested services.
- Payment and fraud-prevention providers. These providers process payments, refunds, chargebacks, and fraud checks.
- Website and business-service providers. We may use hosting, cloud storage, customer-support, communications, email, customer-management, security, and technical-support providers.
- Analytics providers. These providers help us measure Website use, performance, and marketing effectiveness.
- Advertising and social-media partners. If advertising technologies are enabled for your browser, these partners may receive identifiers, device information, and online activity to measure or personalize advertising.
- Professional advisers and authorities. We may disclose information to lawyers, accountants, insurers, auditors, regulators, law-enforcement agencies, courts, or other parties when necessary to comply with law or protect rights and safety.
- Corporate transactions. Information may be disclosed as part of a merger, financing, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality protections.
- With your direction or consent. We may share information when you ask us to or clearly agree.
Service providers that process information for us are expected to use it only for agreed services and to protect it appropriately. Travel providers and booking partners that use information for their own purposes are responsible for their own privacy practices.
We do not sell personal information for money. If advertising technologies are enabled, disclosure of identifiers and online activity to advertising partners may be considered “sharing” for cross-context behavioral advertising under California law. See Your Privacy Choices below for how to opt out.
6. California Privacy Notice
This section applies to California residents when the California Consumer Privacy Act, as amended (CCPA), applies to our processing.
Depending on how you interacted with us, we may have collected the following categories of personal information during the preceding 12 months:
| CCPA category | Examples | Sources | Purposes and recipient categories | Sold or shared |
| Identifiers | Name, email, phone number, IP address, online identifiers | You, your device, booking or referral partners | Bookings, support, security, marketing; travel providers and business-service providers | Not sold; online identifiers may be shared with advertising partners |
| Customer records and financial information | Address, billing details, payment status, traveler details | You and payment or booking providers | Payments, bookings, accounting; payment providers and travel providers | Not sold or shared for targeted advertising |
| Commercial information | Inquiries, purchases, booking history, travel preferences | You and booking or travel providers | Provide and personalize services; travel and business-service providers | Not sold or shared for targeted advertising |
| Internet or electronic activity | Browsing activity, interactions, cookie and device data | Your browser or device and analytics providers | Analytics, security, advertising; analytics, security, and advertising providers | Not sold; may be shared with advertising partners |
| Geolocation | Approximate location and, with permission, precise location | Your device | Localization, requested services, security; technical and travel providers | Not sold or shared for targeted advertising |
| Inferences | Likely travel or content interests | Website activity and booking history | Personalization and advertising; analytics or advertising providers | Not sold; may be shared with advertising partners |
| Sensitive personal information | Payment-account details handled by processors, passport details, precise location, or health/accessibility needs you provide | You, your device, and payment or booking providers | Complete requested travel, payments, security, and legal compliance; relevant service providers | Not sold or shared for targeted advertising |
We retain these categories as described in Data Retention below. We use sensitive personal information only as reasonably necessary to provide requested services, process payments, protect security, or comply with law. We do not use it to infer characteristics about you.
7. Your Rights and Choices
Depending on where you live and subject to legal exceptions, you may have the right to:
- access or know whether we process your personal information and receive a copy;
- correct inaccurate or incomplete information;
- delete personal information;
- restrict certain processing;
- object to processing based on legitimate interests or to direct marketing;
- receive or transfer certain information in a portable format;
- withdraw consent at any time;
- opt out of marketing by using the unsubscribe link in an email or contacting us;
- opt out of the sale or sharing of personal information for cross-context behavioral advertising;
- limit certain uses of sensitive personal information, where applicable; and
- complain to a competent data-protection authority.
California residents also have the right not to receive discriminatory treatment for exercising CCPA rights and may use an authorized agent to submit a request. Residents of certain other U.S. states may have a right to appeal our decision on a privacy request; instructions will be included in our response where applicable.
To exercise a right, email contact@wetravelmorocco.com with the subject line Privacy Request. To opt out of advertising-related sale or sharing, use the [Your Privacy Choices / Do Not Sell or Share My Personal Information] link on the Website or enable Global Privacy Control in a supported browser.
Please describe your request and the email address or booking information connected with your interaction. We may need to verify your identity before completing certain requests. If an authorized agent acts for you, we may request proof of authorization and, where permitted, direct confirmation from you.
We will respond within the period required by applicable law, generally within one month under the GDPR or 45 days under the CCPA. Some rights are not absolute, and we may retain information when required by law, needed to complete a transaction, or necessary to establish or defend legal claims. If we deny a request, we will explain why when required.
You may unsubscribe from promotional email at any time. We may still send non-promotional messages about an inquiry, booking, payment, safety issue, or our ongoing relationship with you.
8. Data Retention
We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, including legal, tax, accounting, security, and dispute-resolution requirements. Our typical retention periods are:
| Data type | Typical retention period |
| Booking, invoice, and transaction records | Up to 7 years after the trip or transaction, or longer if required by applicable tax, accounting, or travel law |
| Payment data | Limited transaction records for up to 7 years; complete card details are retained by the payment provider under its own policy |
| Inquiries and customer-support communications | Up to 2 years after the last interaction, unless connected to a booking or dispute |
| Newsletter subscriber information | Until you unsubscribe or after 24 months of inactivity; we may keep a minimal suppression record to honor your opt-out |
| Marketing-consent records | Up to 5 years after consent is withdrawn or our last marketing interaction, as needed to demonstrate compliance |
| Raw analytics data linked to a cookie or device identifier | Typically up to 14 months; aggregated or de-identified statistics may be kept longer |
| Cookie data | For the duration shown in our cookie settings, generally from the session length up to 24 months |
| Security and privacy-request records | Typically up to 5 years after the event or request |
We may keep information longer when a law, legal claim, investigation, chargeback, or fraud concern requires it. We may retain aggregated or de-identified information that can no longer reasonably identify you.
9. Security Measures
We use reasonable technical and organizational safeguards designed to protect personal information. These may include HTTPS, encryption in transit and where appropriate at rest, access controls, authentication, system monitoring, backups, staff confidentiality requirements, vendor reviews, and procedures for responding to security incidents.
No website, transmission, or storage system is completely secure. Please use caution when sending sensitive information and contact us if you believe your interaction with us is no longer secure.
10. International Data Transfers
We operate in Morocco and work with travelers and service providers around the world. Your personal information may therefore be transferred to, stored in, or accessed from a country other than your own, including countries whose privacy laws may provide different protections.
When we transfer personal information from the European Economic Area, United Kingdom, or another jurisdiction that restricts international transfers, we use an approved legal mechanism where required. Depending on the destination and provider, this may include an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, contractual and technical safeguards, or another lawful mechanism. You may contact us for more information about the safeguards relevant to your information.
11. Children’s Privacy
The Website is intended for adults arranging travel and is not directed to children under 16. We do not knowingly collect personal information directly from a child under 16 without the authorization required by applicable law.
A parent, guardian, or trip organizer may provide limited information about a child traveler when needed to arrange a family booking. The person providing that information must have authority to do so, and we use it only to deliver the requested services, protect the traveler, and meet legal requirements. We do not knowingly sell or share the personal information of anyone under 16 for targeted advertising.
If you believe a child has provided personal information to us improperly, contact us so we can investigate and delete it where appropriate.
12. Third-Party Links and Services
The Website may link to booking sites, payment services, maps, social networks, or travel partners. Their privacy practices are governed by their own notices. We encourage you to review those notices before providing personal information.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in our services, technology, partners, or legal obligations. We will post the updated Policy on this page and revise the Effective Date above. If a change materially affects your rights, we will provide additional notice where required by law.
14. Contact Us
For privacy questions or requests, contact:
We Travel Morocco
Email: contact@wetravelmorocco.com
Website: https://wetravelmorocco.com/
