Privacy policy
Last updated: 4 October 2026
Riad Roca takes the protection of your personal data seriously. This policy explains what data we collect, why, and what your rights are.
1. Data controller
ROCAMYA SARL (Riad Roca), Derb Jamaa 12, Kennaria, Marrakech 40000, Morocco. Contact: info@rocamarrakech.com, +212 7 03 19 80 33.
2. The data we collect
When you book a stay: first and last name, email address, phone number, country of residence, dates of stay, number of travellers, flight number (if you request a transfer), preferences and special requests, and the information needed for invoicing.
When you contact us: the content of your messages (email, form, Instagram, Facebook or WhatsApp messaging) and your contact details.
When you browse our website: browsing data (pages viewed, date and time, length of visit), IP address, device and browser type, how you arrived on the site. This data is collected through cookies and similar technologies (see section 5).
Payments: we never store your card details. They are processed directly by our secure payment provider.
3. Why we use this data
- Managing your booking and your stay: performance of the contract
- Sending you practical information before arrival: performance of the contract
- Answering your questions: legitimate interest
- Organising your airport transfers: performance of the contract
- Processing payments and meeting our accounting obligations: legal obligation
- Measuring website audience and improving our services: legitimate interest
- Showing you our offers online (advertising): legitimate interest
- Sending you our offers by email: consent
4. Who has access to your data
We never sell your data. We share it only with the providers needed to run the riad:
- Cloudbeds: booking management software
- Payzone: secure payment processing
- Zoho and Brevo: sending our emails
- Meta (Facebook, Instagram): measuring and delivering our advertising
- Google Analytics: website audience measurement
- Booking.com, Expedia: when you book through these platforms, under their own terms
Some of these providers are located outside the European Union. These transfers are covered by the safeguards provided for by the GDPR (standard contractual clauses or adequacy decision).
Your data may also be passed on to the Moroccan authorities where the law requires it (guest registration).
5. Cookies and trackers
Our website uses:
- Necessary cookies: essential for the website and the booking engine to work.
- Audience measurement cookies (Google Analytics 4): to understand how our website is used.
- Advertising cookies (Meta pixel): to measure the effectiveness of our advertising and show you relevant content on Facebook and Instagram.
These cookies are set as soon as you arrive on the website. You can set your browser at any time to block or delete them, or manage your Meta advertising preferences from your Facebook or Instagram account settings.
6. How long we keep your data
- Booking data: 3 years after your stay (10 years for accounting documents, in line with our legal obligations)
- Email or message exchanges: 3 years after the last contact
- Browsing data and cookies: 13 months maximum
- Advertising data: 180 days maximum
7. Your rights
Under the GDPR and Moroccan law 09-08, you have the following rights: access to your data, rectification, erasure, restriction of processing, portability, objection to processing, and withdrawal of your consent at any time.
To exercise them, write to us at info@rocamarrakech.com. We will reply within one month.
If you believe your rights are not being respected, you can lodge a complaint with the data protection authority of your country of residence (in France, the CNIL, www.cnil.fr; in Belgium, the APD, www.autoriteprotectiondonnees.be).
8. Security
We implement technical and organisational measures to protect your data: encrypted connections (HTTPS), access restricted to authorised persons, providers selected for their level of security.
9. Changes
This policy may be updated. The date of the last update appears at the top of this page.
