Effective Date: April 28, 2026
Nomad Surf Camp ("we," "our," or "us") respects your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use and store it, who we share it with, and the rights you have under the EU/UK General Data Protection Regulation (GDPR) and Moroccan Law 09-08.
By using nomad.surf or booking with us, you agree to the practices described below. If you do not agree, please do not use the site.
The data controller responsible for your personal data is:
We collect personal data only when you choose to provide it (e.g. booking a stay, contacting us, signing up for our newsletter), and limited technical data automatically when you visit the site.
Under GDPR Art. 6, every use of your data has a defined legal basis:
| Purpose | Legal basis |
|---|---|
| Manage your booking, take payment, prepare your arrival | Contract (Art. 6(1)(b)) |
| Reply to your enquiries, contact form, WhatsApp messages | Contract / legitimate interest (Art. 6(1)(b)/(f)) |
| Send you a confirmation, reminder, or arrival instructions | Contract (Art. 6(1)(b)) |
| Send marketing emails, promotions, newsletters | Consent (Art. 6(1)(a)) — opt-in only |
| Site analytics & session recordings (Microsoft Clarity, Google Analytics) | Consent (Art. 6(1)(a)) |
| Advertising performance & remarketing (Google Ads) | Consent (Art. 6(1)(a)) |
| Security, fraud prevention, server logs | Legitimate interest (Art. 6(1)(f)) |
| Comply with tax, accounting, and legal obligations | Legal obligation (Art. 6(1)(c)) |
We never sell or rent your personal data. We share it only with the following categories of recipients, and only to the extent necessary:
Each provider acts under a written Data Processing Agreement and is bound to use your data only for the purposes we instruct.
Our servers are located in Morocco. Some processors (Google, Microsoft, PayPal) may transfer data to the United States or other countries. These transfers rely on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework, ensuring an adequate level of protection.
We use cookies and similar technologies (localStorage, sessionStorage) for the purposes described below. You can accept, reject, or customise non-essential cookies at any time using our cookie banner or by clicking .
| Name | Provider | Purpose | Retention |
|---|---|---|---|
PHPSESSID | nomad.surf | Maintains your session (login, basket, CSRF protection) | Session |
nomad_cookie_consent_v2 (localStorage) | nomad.surf | Remembers your cookie preferences | 6 months |
csrf_token (server session) | nomad.surf | Prevents Cross-Site Request Forgery on forms | Session |
| Name | Provider | Purpose | Retention |
|---|---|---|---|
_clck, _clsk, CLID, ANONCHK, MUID | Microsoft Clarity | Session recording, heatmaps, anonymous user behaviour analysis | Up to 1 year |
_ga, _ga_*, _gid, _gat | Google Analytics 4 | Aggregated traffic statistics, visitor counts, page popularity | Up to 2 years |
| Name | Provider | Purpose | Retention |
|---|---|---|---|
_gcl_au, _gcl_aw, _gac_* | Google Ads | Conversion tracking, attribution, campaign measurement | Up to 90 days |
NID, IDE, DSID | Google (DoubleClick) | Remarketing & ad personalisation | Up to 13 months |
We use Google Consent Mode v2 — until you grant marketing consent, Google's tags do not set advertising cookies and only receive aggregated, cookieless signals.
If you are in the EU, EEA, UK, or Switzerland, you have the following rights regarding your personal data:
To exercise any of these rights, email contact@nomad.surf. We will respond within 30 days. We may ask you to confirm your identity before acting on the request.
We use HTTPS for all traffic, hashed passwords, parameterised database queries, server-side input validation, a Content Security Policy, and access controls on our admin panel. Despite these measures, no internet transmission is 100% secure; we cannot guarantee absolute security but commit to notifying affected users and the relevant authority within 72 hours of any breach affecting personal data, as required by GDPR Art. 33–34.
Our services are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you.
We may update this Privacy Policy to reflect changes in our practices or legal obligations. The "Effective Date" at the top will indicate the latest revision. For material changes affecting your rights, we will notify you by email or by a prominent notice on the website.
For any privacy question, request, or complaint:
Nomad Surf Camp · Hay Tissaliouine, Tamraght, Agadir 80020, Morocco