Who runs this site
taghazout.io is an independent surf-travel service based in the Taghazout area of Morocco, operated by its founder, Adnane Ettazrouti. We publish guides and live surf forecasts, and we organise stays, lessons and activities delivered together with a small circle of vetted local hosts and activity partners. For anything in this policy, write to [email protected] — the inbox is read by the person who runs the site, not a ticket system.
The data we receive
Most of what we hold, you typed yourself: a booking or contact request (name, email, optional WhatsApp number, travel dates, group size, dietary notes and anything you add in a message), a newsletter signup, or an optional surf-alert subscription in your browser. Alongside that, our server keeps standard technical logs (IP address, browser type, pages requested) for security and abuse prevention, and remembers small preferences such as language, currency and light or dark theme.
What we use it for
Booking details are used to answer you, prepare a reviewed quote, hold your room and dates with the host, and arrange the transfers or activities you asked for — in legal terms, steps taken before and under a contract. Technical logs rest on legitimate interest: keeping the site online and fraud-free. Analytics and marketing run only on your consent. We never sell personal data, and we do not build advertising profiles.
Payments
Deposits are paid on our checkout page and processed by PayPal. Card and wallet details go directly to PayPal — they never touch our server, and we cannot see or store them. What we keep is the payment reference PayPal returns, the amount and its status, attached to your booking record.
Services we rely on
The companies that process something when you use the site: Cloudflare (delivery, security and the Turnstile anti-spam check on forms), Namecheap (server hosting), Google (Analytics 4 in cookieless Consent Mode until you opt in, and Google Fonts for the site’s typefaces), Microsoft Clarity (optional session analytics, off until you consent) and PayPal (deposits). If you choose to talk to us on WhatsApp, Meta processes that conversation under its own terms. Some flight and stay widgets link to partners such as Aviasales, Stay22 and Tripaneer; they load or track only under the marketing consent category, and their own policies apply on their sites. To host you, we share with the relevant local partner exactly what they need — names, dates, group size, dietary and arrival notes — never more.
Cookies and your choices
Necessary cookies keep the basics working: your session, security checks, consent memory, language, currency and theme. Optional categories — analytics and marketing — stay off until you say yes, and “Reject” is a single click that we treat as the default. You can change your mind at any time:
How long we keep things
Booking records and the emails around them stay while your trip is upcoming, and afterwards for as long as bookkeeping and dispute rules require. Enquiries that never became a booking are cleaned out periodically. Technical logs rotate on a short cycle. Newsletter and surf-alert subscriptions last until you unsubscribe — every email has the link, and push alerts can be turned off in your browser in one tap.
Your rights
You can ask what we hold about you, have it corrected, receive a copy, restrict or object to a use, or have it deleted. If you are in the EU/EEA or the UK, these are your GDPR rights, and you may also complain to your local supervisory authority. In Morocco, personal data is protected by Law 09-08 under the CNDP. Wherever you are, the practical route is the same: email us — we do not make you fill in forms.
Deleting your data
To have your data deleted, email [email protected] with the subject “Delete my data” from the address you used, or follow the short checklist on our data requests page. Tell us roughly when and what you sent so we can find it. We confirm, delete everything we are not legally required to keep (a completed booking’s accounting record, for instance, must survive its retention period), and reply when it is done — within 30 days at the latest.
How it is protected
Everything travels over HTTPS. Booking records live on access-restricted storage, administrative access is limited to the operator, and we deliberately collect little — the best-protected data is the data we never asked for.
Changes and contact
When this policy changes, the date at the top changes with it; meaningful changes are announced on the site rather than buried. Questions, doubts or requests: [email protected].