Privacy Policy
Last updated: 2026-08-18
Version 2026-08-18 · Effective 2026-08-18
Who we are and what this policy covers
Afrahi is an online marketplace for event services in Morocco. It connects customers planning an event with independent service providers such as venues, caterers, photographers, decorators and entertainers. This policy explains what personal data the operator of Afrahi collects, why it is processed, who it is shared with, and the choices you have.
It applies to everyone who uses the platform: visitors browsing without an account, customers, service providers, field agents, bloggers, support users and administrators. It covers the website, the account areas, and the emails and notifications we send you as part of the service.
The operator of Afrahi decides why and how your personal data is processed and is therefore responsible for it under Moroccan Law 09-08 on the protection of individuals with regard to the processing of personal data. Identification details of the operating entity are published on the platform and can be obtained from the contact address below.
Data we collect
We collect only what the service needs. Depending on how you use Afrahi, this may include:
- Account data: full name, email address, phone number, city, preferred language, profile picture, role (customer, provider, agent, blogger, administrator), account identifier, sign-in method (password or Google), and whether the account is active.
- Service provider business data: business name and public handle, descriptions and service lists in one or more languages, categories, cities served, starting prices, availability, years of experience, photos, cover image, logo, promotional video link, social links, address, map coordinates, WhatsApp number, business email and phone.
- Provider status data: verification status, plan and premium expiry, sponsored-placement periods, founding-member status, profile completeness score, rating, review count and ranking signals.
- Booking and Package requests: event date and type, guest count, the budget you state, event location, your notes, status history, the provider’s reply and invoice references. When you ask for a specific Package, we also keep that Package as it stood at the moment you asked — its name, the language that name was shown in, and the price information displayed — so that a later edit to the listing cannot rewrite what you actually requested.
- Product orders: the product ordered, the quantity, your note, the provider’s reply and the status history, together with the product as it stood at the moment of ordering — its title, the language that title was shown in, and the unit price displayed where the listing showed one. Payment for a product order is arranged directly between you and the provider; Afrahi does not collect it.
- Messages and notifications: conversations between customers and providers, message contents, any images sent, read status and timestamps, and the notifications we send you — whose title and text may name the Package request or Product order they concern, so that they can be understood.
- Reviews: ratings, comments, any review images, and whether the review came from a booking or an invitation.
- Favorites and requests: the providers you save to your favorites, which stay private to you, and requests for a provider to be added in a city or category.
- Reports and moderation: the report you submit, its reason, our investigation status, the decision taken, the administrator who took it and when.
- Support: support tickets, replies and live-chat messages.
- Editorial content: blog posts and provider features written by authorized authors.
- Field-agent onboarding: provider cards created by an agent, the handover (claim) link status, and the attribution of the card to the agent who created it.
- Provider subscriptions: package length, amount in dirhams, the amount charged in US dollars where PayPal is used, payment method, payment status, payment gateway order and capture references, invoice number and payment date.
- Technical data: security and error diagnostics, IP address processed for security and rate limiting, browser and device information, and authentication cookies.
- Legal acceptance records: which version of the Terms and of this policy you accepted, when you first accepted, when you last confirmed, how many times, in which language and in which context (registration, sign-in, or a required re-acceptance).
Customer-side records — a booking or Package request, a Product order, a favorite — arise whenever you use Afrahi as a customer, whatever kind of account you hold. A provider, an agent, a blogger or an administrator who books or orders from another provider produces the same records, and this policy treats them the same way.
Public provider pages also record anonymous activity events — a page view, and clicks on the WhatsApp, phone and chat buttons. These events store only the provider concerned, the type of event and the time. They are not linked to a named visitor and are used to produce aggregate audience statistics for the provider and for the platform.
We never ask for and never store your card number, CVV or bank credentials. Online payments are entered on PayPal’s own interface.
Where the data comes from
Most data comes from you. Some reaches us from other sources:
- Directly from you when you create an account, complete a profile, book, message, review, report or contact support.
- From other participants: a customer’s booking or message reaches the provider concerned, and a provider’s reply reaches the customer.
- From Google when you choose to sign in with Google — we receive your name, email address and profile picture, not your Google password.
- From a field agent or an administrator who prepares a provider card on a business’s behalf before handing it over to its owner.
- From your use of the platform: activity events, security logs and diagnostics.
- From our payment provider: the status and references of a subscription payment.
- From your communications with support.
- From business or public information you submit for verification.
- From administrators recording a moderation decision.
Why we process your data
- Creating your account, authenticating you and keeping your session secure.
- Operating the marketplace, provider profiles, search and rankings.
- Enabling booking and Package requests, Product orders, messaging, reviews and favorites.
- Verifying providers and moderating content and behaviour.
- Answering support requests and sending transactional messages about your account, bookings and payments.
- Selling and activating provider subscriptions and sponsored placements.
- Issuing invoices and keeping accounting records.
- Preventing fraud and abuse, applying rate limits, protecting the platform and establishing or defending legal claims.
- Measuring how the service is used, in aggregate, to improve it.
- Complying with our legal obligations and responding to lawful requests from competent authorities.
- Enforcing the Terms of Service.
- Preserving evidence relating to reports, disputes and enforcement decisions.
We do not sell your personal data, and we do not use it for third-party advertising.
What is public, what is shared, what stays internal
Different parts of your data have very different visibility. In short:
- Public: a published provider profile — business name, handle, description, services, categories, cities, starting price, photos, logo, video, rating, reviews, and the business contact details the provider chooses to publish (WhatsApp number, phone, business email, address, map location, social links).
- Public: reviews, together with the display name of their author and the date.
- Shared with the other party: when you book, request a Package, order a Product or message a provider, that provider sees your name and the content of your request; their replies reach you. Contact details you write inside a message are visible to the recipient.
- Private to you: your favorites. A provider is never shown who saved them; where a provider sees a favorites figure it is an aggregate count that identifies nobody.
- Internal: reports, moderation decisions, support tickets, payment and invoice records, security logs and legal acceptance records — visible only to the account holder where the platform shows them, and otherwise to authorized staff.
- Private to one provider: the lead records a provider keeps to manage their enquiries — the stage of a discussion, their own notes, follow-up dates, a lost reason, an estimated value they typed themselves, and the name, phone number and event details of a contact they added manually after being reached outside the platform. Customers never see any of it, and no other provider can reach it. Afrahi does not verify amounts written there and does not confirm that any deposit or payment was made.
- Never displayed publicly: your password (which we never see in readable form), authentication data, and the private notes of a booking beyond the parties concerned.
A provider decides which business contact details to publish. Anything published on a provider profile is visible to every visitor and may be indexed by search engines. Do not publish a personal phone number or address you do not want to be public.
Service providers and third parties
We use a small number of specialised suppliers to run the service. Each processes data on our instructions or, where they act for themselves, under their own privacy terms:
- Supabase — authentication, database, file storage and realtime features.
- Vercel — hosting and execution of the application.
- Resend, and any SMTP infrastructure configured by the operator — transactional email such as verification, notifications and receipts.
- Google — only if you choose to sign in with Google.
- PayPal — online payment of provider subscriptions and sponsored placements, including card payments processed on PayPal’s side.
- Sentry — error monitoring, when monitoring is enabled by the operator.
- OpenStreetMap — map tiles and address search used by the location picker.
- Banks, WhatsApp or a field agent — only when a provider chooses a manual payment channel for a subscription.
- Professional advisers, courts, regulators and competent public authorities — where we are legally required to disclose data or need to establish or defend a legal claim.
These services have their own privacy practices, which apply to what they collect on their own account. Some environment settings exist in the codebase for channels that are not in use (for example SMS or mobile push); no data is sent to them while they remain inactive.
Payment information
Payments made to Afrahi are payments for provider subscriptions and sponsored placements. Marketplace transactions are different: booking and Package requests and Product orders are agreed and settled directly between a customer and a provider, and Afrahi neither collects nor processes money for them.
For each such payment we store the provider concerned, the package and its duration, the amount in dirhams, the amount charged in US dollars where PayPal is used, the payment method, the status, the payment gateway order and capture references, the invoice number and the payment date.
Card details are entered on PayPal’s interface and are processed by PayPal. Afrahi does not receive or store card numbers, expiry dates, security codes or bank credentials.
Where a provider arranges payment with our team instead of paying online — currently over WhatsApp or through the Help Center — we record the resulting order and invoice so the subscription can be activated and accounted for. Orders recorded under arrangements we no longer offer stay in our accounting records as they were.
Hosting and transfers outside Morocco
Some of the suppliers listed above operate infrastructure outside Morocco, which means personal data may be hosted or processed abroad.
Where Moroccan law requires it, we will complete the applicable CNDP formalities and put the appropriate legal safeguards in place with each supplier before such a transfer is made, and we will keep contractual confidentiality and security commitments with our processors.
We do not claim that any declaration or authorisation has been granted. When the CNDP references are issued they will be published in this policy.
How long we keep data
We keep personal data for as long as it is needed for the purpose it was collected for, and then delete or anonymise it. How long that is depends on the type of data and on the obligations attached to it.
- Account and profile data: while the account exists. When you delete your account, your sign-in identity is deleted, the account can no longer be used, your personal profile disappears, and the marketplace records that depend on it are removed with it.
- Bookings, Package requests, Product orders, messages and reviews: while they remain useful to the parties and to the operation of the marketplace, and they follow the account they depend on when it is deleted.
- Images and documents: media attached to content that is deleted goes with it. Media that one account uploaded but that belongs to content which remains published — a guide, a category illustration, a provider page prepared on a business’s behalf — stays with that content, because it belongs to the content and not to whoever uploaded it.
- Reports, moderation decisions and enforcement records: kept as evidence for as long as needed to handle disputes, prevent repeat abuse and answer legal claims — including after an account is closed. When the account or the profile concerned is deleted, the record survives with its links to them cleared.
- Support records: kept to follow up on your request and to improve support quality.
- Payment, invoice and accounting records: kept for the period required by accounting and tax rules. These are the subscription payments made to Afrahi, and they are not deleted merely because an account is closed. Such a record may still carry the historical identifier of the profile it belonged to, which no longer corresponds to any usable profile on the platform.
- Legal acceptance records: kept as proof of which version of the Terms and of this policy was accepted, when it was first accepted and when it was last confirmed. After an account is deleted, the record may keep that account’s historical identifier — which no longer points to any usable account — so the proof remains meaningful. We do not keep your profile in order to keep that proof.
- Security and technical logs: kept for a short period for security and troubleshooting purposes. This includes short-lived technical records that let an upload security check finish safely; they are kept only for the operational period that cleanup needs, and they are not part of your account.
- Backups: data may persist in encrypted backups for a limited period after deletion, and is overwritten on the normal backup cycle.
Keeping one of these records does not keep your account. A retained legal-acceptance, accounting or moderation record cannot be signed in to, does not restore a usable Afrahi account and does not put your profile back on the platform. It exists only for the specific purpose stated above.
Precise retention periods are being confirmed with our accountant and legal counsel, and will be stated here once fixed. We do not keep data indefinitely simply because it is convenient.
How we protect your data
- Row-level security in the database, so each request can only reach the records its author is allowed to read or write.
- Restricted administrative access, limited to the staff who need it for their duties.
- Encryption in transit (HTTPS) between your browser and the platform.
- Server-side validation of the data you submit, including re-verification and re-encoding of uploaded images.
- Rate limiting and abuse protection on sensitive endpoints.
- Storage rules restricting what can be uploaded and who can read it.
- Error monitoring, when enabled, to detect and fix failures quickly.
No online service can promise absolute security. We work to protect your data with reasonable technical and organisational measures, and we ask you to protect your own credentials and to tell us promptly if you believe your account has been compromised.
Your rights
- Access: obtain confirmation that we process your data and a copy of it.
- Correction: have inaccurate or incomplete data corrected — most profile data can be edited directly from your account.
- Objection: object, on legitimate grounds, to processing that is not required to provide the service or to meet a legal obligation.
- Deletion: delete your account and the associated data from your account page, subject to the records we must lawfully keep (see “How long we keep data”).
- Contact us at any time about how your data is handled.
To exercise these rights, write to the contact address at the end of this policy. We may ask for information to confirm your identity before acting on a request, so that nobody else can obtain or change your data.
You may also lodge a complaint with the Moroccan national data protection authority, the CNDP.
Age requirement
Afrahi accounts are for adults. You must be at least 18 years old to create an account. We do not knowingly collect data from minors; if we learn that an account belongs to a minor, we will close it and delete the associated data, keeping only what we are legally required to retain.
Changes to this policy and contact
We may update this policy as the service evolves or as the law requires. Each version carries a version number and an effective date, shown at the top of this page.
When a change is material, we will make it visible on the platform, and we may ask you to acknowledge the new version before you continue to use features that involve your data — for example booking, messaging or publishing content.
For any privacy question or request, write to us at contact@afrahi.ma.