Legal
Privacy Policy
What we collect when you plan a trip with us, why we need it, and what we will never do with it.
Version 1.0 · Last updated 12 August 2026.
Contents
1. Who we are
Maguca Tours & Safaris, of Arusha, Tanzania is the data controller for the personal information described here. That means we decide what is collected and why, and we are answerable for it.
For anything to do with your personal information — a question, a correction, a request to see or delete what we hold — write to info@magucasafaris.com, or call +255 754 835 283. Please mark data requests clearly so they reach the right person quickly.
This policy is written to meet Tanzania's Personal Data Protection Act, 2022, and the UK and EU GDPR for travellers who contact us from Europe.
2. What we collect
We collect only what a trip actually requires. In practice that is:
When you enquire
- your name, email address and phone number;
- what you are planning: approximate dates, number of nights, how many adults and children are travelling and the ages of any children, an indication of budget, and whatever you write in the message box;
- the page you enquired from, and the IP address the enquiry came from, which we use to stop spam and abuse of the form.
When you book
- traveller names, email addresses, phone numbers and country of residence;
- the record of your acceptance: the name you typed, the date and time, the IP address, and the version of the booking terms you accepted;
- your itinerary and any operational notes needed to run it — dietary requirements, and health, fitness or accessibility information you choose to give us so we can tell you whether a trip is suitable and keep you safe on it;
- your travel insurance details, including the policy and emergency assistance numbers, which are a condition of booking for Kilimanjaro and Meru climbs.
When you pay
- the amount, date, method and reference of each payment, and the invoices and receipts issued for it;
- never your card number.Card and mobile money payments are taken on our payment provider's own secure page. Card details are entered there, not on our website, and they are never sent to or stored on our systems.
When we email you
- a log of the documents and messages we have sent to you, and when.
3. Children's information
Where children are travelling we ask for their ages, because park fees, seat and tent arrangements and some activities depend on them. We do not ask children for information directly and this website is not aimed at them — details of a child under 18 should be given to us by a parent or guardian, who by giving them confirms they have the authority to do so.
We collect nothing more about a child than the trip requires.
4. Why we use it, and our legal basis
- To answer your enquiry and prepare a quote — because you asked us to, as steps taken at your request before entering a contract.
- To run your trip, including booking lodges, camps, flights and park entries in your name — to perform our contract with you.
- To take payment and issue invoices, receipts and refunds — to perform our contract, and to meet our tax and accounting obligations.
- To keep you safe, using health, fitness and insurance information you give us. Health information is sensitive, so we rely on your explicit consent for it, and you can withdraw that consent — though we may then be unable to run a trip safely.
- To protect the site from spam and fraud, using IP addresses and a bot check on our forms — our legitimate interest in keeping the service usable.
- To keep records after you travel — to meet legal record-keeping duties and to defend or bring a claim.
5. What we do not do
We think this is as important as the list above, so it is stated plainly. We do not:
- sell, rent or trade your information to anyone;
- add you to a mailing list because you enquired. There is no newsletter sign-up on this site. If we ever start one, it will be something you opt into, never something you are opted out of;
- run advertising trackers, analytics profiling or third-party marketing pixels on this site;
- make any decision about you by automated means alone. A person reads your enquiry.
8. Where your information goes
We are based in Tanzania and your information is processed here. Some of the services above operate from other countries, so running the platform necessarily involves transfers outside Tanzania — and, for European travellers, outside the EEA.
Where that happens we rely on the safeguards permitted by the Personal Data Protection Act and, for European travellers, on the standard contractual clauses or an equivalent protection in our contract with that provider. You can ask us which safeguard applies to a particular service.
9. How long we keep it
We keep personal information only as long as there is a reason to, then delete it. Our standard periods are:
- Enquiries that do not become bookings — 24 months from our last contact with you. So we can pick up a conversation you may return to, and see where enquiries come from.
- Bookings, quotes, invoices, receipts and payment records — 7 years from the end of your trip. Tax and accounting law requires us to keep financial records, and this is also the period in which a claim could be brought.
- Your acceptance record (name, date, IP address, terms version) — Kept with the booking it belongs to. It is the evidence of the contract between us. Deleting it would leave neither side able to show what was agreed.
- Record of emails we sent you — 24 months. To show what was sent, and when, if a document is disputed or goes astray.
- IP addresses captured with an enquiry — 12 months. To investigate spam and abuse of the enquiry form.
Backups are kept on a rolling cycle and are overwritten in turn, so information deleted from the live system disappears from backups as that cycle completes.
10. How we protect it
- The whole site is served over HTTPS, and payment pages are hosted by our provider.
- Access to booking records is limited to the staff who need it, each with their own account, and the administration system is not linked from the public site.
- Public forms are rate-limited and protected by a bot check; document links use unguessable tokens rather than sequential numbers.
- Databases and media are backed up daily, with a tested restore procedure.
No system is perfectly secure. If a breach ever affects your information and is likely to put your rights at risk, we will notify you and the Personal Data Protection Commission without undue delay.
11. Your rights
You can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything that is wrong or incomplete;
- delete what we hold — though we may have to keep booking and financial records for the periods in clause 9;
- stop or restrict a particular use, including any use for direct marketing;
- provide your information in a portable form, or send it to someone else;
- withdraw a consent you gave us, at any time, without affecting what came before.
Write to info@magucasafaris.com. We will reply within 30 days, and we will not charge you for a reasonable request. We may need to confirm who you are first, so that we do not disclose your information to someone else.
If you are not satisfied with our answer, you may complain to the Personal Data Protection Commission in Tanzania. Travellers in the UK or EU may also complain to their own supervisory authority.
12. Changes to this policy
When this policy changes we update the version and date at the top of the page. If a change materially affects how we use information you have already given us, we will tell you directly rather than rely on you noticing.
This policy covers this website and our booking service. It does not cover sites we link to, which have policies of their own. Your booking is also governed by our Booking Terms & Conditions.
