What personal data MarrakechLocal LLC collects, why, who we share it with, and the rights you have over it. Written to be read — if anything here is unclear, ask us at privacy@marrakechlocal.com and we will explain it.
Last updated: 2026-07-29
The data controller is MarrakechLocal LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, United States. Contact for all privacy matters: privacy@marrakechlocal.com.
We are established outside the EU and the UK but we offer services to people in both, which requires us to appoint representatives under Article 27 of the GDPR and Article 27 of the UK GDPR. That appointment is in progress and this page will name them as soon as it is complete. Until then, please write to us directly at privacy@marrakechlocal.com — we answer every request ourselves and within the same deadlines.
We do not collect special-category data, we do not profile you, and we do not make automated decisions that produce legal effects for you.
| Data | Why we have it | Lawful basis | Kept for |
|---|---|---|---|
| Name, email, phone/WhatsApp number | To create your booking, deliver your ticket and audio guide, and contact you about your visit | Performance of a contract | 7 years |
| Booking details (monument, date, number of visitors, amount paid) | To fulfil the booking and to meet accounting and tax obligations | Contract; legal obligation | 7 years |
| Consent record (the wording you were shown and the time you accepted it) | To demonstrate what was agreed, and to answer payment disputes | Legal obligation; legitimate interests in defending claims | 7 years |
| Checkout evidence snapshot (prices and disclaimers displayed, browser user-agent, country) | To respond to chargebacks and fraud claims | Legitimate interests in preventing and contesting payment fraud | 24 months |
| Payment data | To take payment. Card details are entered directly into Stripe and never reach our servers | Contract | Held by Stripe under its own policy |
| Analytics data (pages viewed, approximate location, device) | To understand which guides are useful | Consent — off until you allow it | 14 months |
| Newsletter address | To send the monthly letter you asked for | Consent | Until you unsubscribe |
| Contact form messages | To answer you | Legitimate interests in responding to enquiries | 24 months |
| Server logs (IP address, request, timestamp) | Security, abuse prevention, diagnosing faults | Legitimate interests in keeping the service secure | 30 days |
Our services are not directed at children and we do not knowingly collect data from anyone under 16. Where a booking includes children, we collect only the number of visitors, not their names or ages.
We are a US company, and several of our providers are based in or transfer data to the United States. Where personal data of people in the EU or UK is transferred outside those areas, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and we assess whether additional safeguards are needed in each case.
You may request a copy of the transfer safeguards in place by writing to privacy@marrakechlocal.com.
If the GDPR or UK GDPR applies to you, you have the right to:
Email privacy@marrakechlocal.com. We will respond within one month. We may ask you to confirm your identity, but only to the extent necessary — we will not demand a passport scan to answer a question about a €11.99 booking.
Note that we cannot erase data we are required to keep for accounting purposes, or a consent record and evidence snapshot relating to a payment while a dispute window remains open. We will tell you if that applies and when the data will be deleted.
All traffic is encrypted in transit. Card details are entered directly into Stripe's hosted payment fields and are never transmitted to or stored on our servers, so we hold no card numbers. Access to order data is limited to the people who need it to provide support.
If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and, where the risk is high, tell you directly.
We will update this policy when our processing changes. Where a change is significant we will say so prominently rather than silently amending the date at the top.
Questions? We're here to help.
Contact Us