Legal
Privacy Policy
What we collect, why, who it is shared with, and the rights you have over it — for travelers browsing the marketplace and operators using the suite.
Last updated: 9 September 2026 (destination autocomplete and live enrichment)
1. Scope
This policy covers the Safari Suite marketplace at safarisuite.africa and the operator software suite. It applies to travelers, to operator team members, and to anyone whose details end up on the Platform (for example, a co-traveler added to a trip room). Cookies have their own short page: Cookie note.
2. What we collect
- Account details — name, email, password (hashed), account type, and for operators: company details, branding, and payment receiving details.
- Trip planning data — inquiries and plan requests you send (dates, party size, budget band, interests), favorites, comparisons, trip room votes, comments, and preferences (including dietary and mobility notes you choose to give so operators can plan properly).
- Booking & payment records — quotes, invoices, payment confirmations. Card or mobile-money processing happens with the payment provider; we store references and outcomes, not full card numbers.
- Documents — files you deliberately upload to a trip room vault (passports, visas, insurance). See section 5.
- Reviews — the review text, rating, trip context, and the booking link that earns a "verified" badge.
- Technical data — IP address, device and browser type, and pages visited, used for security, rate limiting, and aggregate analytics.
3. Why we use it
We use personal data to: run the marketplace and deliver inquiries to the operators you choose; compute and display quotes; process and reconcile payments; publish moderated reviews; keep trip rooms private to their members; prevent fraud, spam, and abuse; comply with legal obligations (tax and accounting records); and — with your consent where required — send service and product emails. We do not sell personal data. We do not use your data to train third-party advertising profiles.
4. Who it is shared with
- The operator you contact. When you send an inquiry, plan request, or booking, the details in it go to that operator so they can respond — that is the point of the Platform. Operators are independent controllers of the data they receive and must handle it under their own obligations and the Operator Agreement.
- Your trip room. Content you post in a trip room is visible to the members of that room, according to the visibility you choose.
- Service providers — hosting, email delivery, payment processing — bound by contract to process data only on our instructions.
- Authorities, where the law genuinely requires it.
4.1 Optional Google Maps lookup
When you request a Google search, generate a Google-enriched itinerary, or open an itinerary with live destination fetching enabled, our server sends Google destination names, countries, optional region bias or selected place/photo identifiers. In the itinerary's labelled Where to field, Google suggestions sends your typed query after at least two characters and a short pause, together with a temporary autocomplete session token. You can turn Google suggestions off before typing to keep that query local. Suggestions use the configured request allowance and may incur Google usage charges. The itinerary enrichment step does not send traveler names, contacts, budgets or private day notes. Do not enter private traveler information into a place search. The standalone Destination photos workspace still waits for your lookup action; the itinerary builder can fetch its route destinations automatically and includes a Pause Google fetching control.
Photos and contributor avatars load directly from Google's servers when displayed. Google may receive your IP address and browser/device information when those images load or you follow a Google link. Its processing is governed by the Google Privacy Policy, incorporated here for this feature.
Clicking a destination suggestion adds it directly to your route. We retain the chosen route label, country, stable Place ID and operator/user linkage metadata, plus daily request counts for usage limits. Live results are held temporarily for display during the current interaction, including a one-use handoff from generation to the editor. We do not archive full Google responses, photo references or image files, or copy provider descriptions or photos into proposal/PDF snapshots. You can unlink an entry, pause live fetching, or explicitly create a draft without Google. In the standalone lookup, unticking the feature agreement clears the displayed results and stops further requests until you opt in again.
5. Travel documents
Documents uploaded to a trip room vault are stored outside the public web root, are downloadable only by authorized room members (and the operator only if you choose "share with operator"), and carry an integrity checksum. They are never used for anything except the trip they belong to, and deleting a document deletes the stored file.
6. Proposal & site analytics
When an operator shares a proposal link with you, the Platform records engagement events — that the proposal was opened, which sections were viewed, approximate location (country level, from IP), and device type — and shows this to the operator so they know when to follow up. These events are tied to the proposal, not to an advertising profile, and are not shared with anyone except that operator.
7. How long we keep it
Account data lives as long as your account does. Booking, invoice, and payment records are kept for the statutory accounting period after the trip. Inquiries that never become bookings are pruned after 24 months. Trip room documents are deleted when you delete them, when the room is deleted, or at the latest 12 months after the trip ends. Reviews stay published (they are the marketplace's memory), but on account deletion they are de-linked from your identity and shown under a neutral traveler label.
8. How it is protected
All traffic is TLS-encrypted. Passwords are hashed, never stored. Access to production systems is key-based and limited. Tenant data is isolated per operator at the application layer, documents live outside the web root, and traveler-facing write endpoints are rate-limited. Backups are taken regularly and access-restricted. No system is perfectly secure — if we ever discover a breach affecting you, we will notify you and the relevant authority as the law requires.
9. Your rights
Depending on where you live (including under Kenya's Data Protection Act, the GDPR if you are in the EU/UK, and similar laws), you can ask us to: access a copy of your data, correct it, delete it, restrict or object to certain processing, or export it in a portable format. Write to hello@safarisuite.africa — we respond within 30 days. You can also complain to your data protection authority.
10. Contact
Data controller: Safari Suite, safarisuite.africa. Privacy contact: hello@safarisuite.africa.
Related: Terms of Use · Privacy Policy · Cookies · Operator Agreement