Privacy Policy
Last reviewed: 2026-09-30.
This page explains what personal data Tahiti Dream Excursion collects when you browse this site or book a tour, why we collect it, who else sees it, how long we keep it, and how to ask us to erase it.
What we collect and why
When you book a tour we collect your name, email address, phone number, country of residence, the tour dates and times you choose, the number of guests, any special requests, and any dietary requirements you tell us about. We also collect an emergency contact name and phone number — this is another person’s personal data, which you supply to us on their behalf — and, in the health and safety declaration you complete before submitting your booking, any medical conditions you choose to disclose. We collect all of this because we cannot run a boat excursion without knowing who is coming, when, whether anyone has a dietary requirement Keanu needs to plan around, and who to contact and what to tell emergency services if something goes wrong on the water. Country of residence is recorded as part of the booking record. This is the contract basis: we process it because you asked us to arrange a tour and we need the information to do that. Medical conditions are special-category data under Article 9 of the GDPR. You provide them voluntarily, entirely at your own choice, so the crew can respond appropriately if a medical situation arises during the excursion, and we use them for nothing else. Dietary requirements are handled differently: you provide them voluntarily too, but we use them to plan meals and share them with the crew through the calendar entry for your excursion (see "Who else sees your data" below) — and because a dietary requirement can itself reveal a health condition, we treat it as special-category data under the same Article 9 as well.
If you accept our cookie banner, we also collect advertising-measurement data through Meta (Facebook) so we can tell which ads actually bring visitors to this site, and so Meta can show our tours again to people who have already visited (retargeting), and site-usage data through Google Analytics so we can see which pages and tours visitors look at and where they come from. This is the consent basis: nothing in this category is collected unless you accept, and you can withdraw that consent at any time (see "Your choices" below).
Your payment card details are typed directly into PayZen/OSB’s own payment page and never reach our servers. We do receive your email address, first name, last name and the booking reference so the payment can be matched back to your booking, and the amount and currency charged. We keep the resulting financial record for 7 years because French tax and accounting law requires it — this is the legal-obligation basis, and it is why a request to erase your data cannot remove the underlying financial record (see "How long we keep your data").
Who else sees your data — our processors
We do not sell your data. A small number of companies process it on our behalf so the booking, the payment and the tour itself can actually happen: Supabase, Resend, Google Calendar, PayZen, Meta, Google Analytics, Google Maps and Vercel.
Supabase is our database. It holds everything above: your name, email, phone number, country of residence, booking dates, amounts paid, special requests, dietary requirements, your emergency contact’s name and phone number, and any medical conditions you disclosed. It is ours to control, and we can erase your identifying details from it on request while the financial row itself is kept for the 7-year period the law requires.
Resend sends every booking-related email we send you: the request-received email when you submit a booking, the hold-lifecycle emails while your payment is pending (a hold-expiring reminder, a payment-chase reminder, a final unpaid notice, and a notice if your held date expires unpaid), your booking confirmation, 48-hour and 24-hour reminders before your tour, a post-tour follow-up, and a cancellation email if the booking is cancelled. It also sends us an internal alert — not to you — when a refund needs manual action, which can include your name and booking reference. Each customer-facing email contains your name, booking reference, tour date and time, guest count and meeting point. Resend retains this email data for 30 days across all plans (with flexible retention for Enterprise), per Resend’s own published retention policy: https://resend.com/docs/dashboard/webhooks/how-to-store-webhooks-data
Google Calendar holds an entry for your tour so Keanu can see his schedule. The event carries the tour name, your name, guest count, phone number, any special requests, any dietary requirements you gave us, your booking reference, and the meeting-point location. This calendar is ours, not a shared one, and if you ask us to erase your data we delete the matching calendar event as part of that request.
7-year financial record we keep ourselves.
Meta (Facebook/Instagram) receives advertising-measurement data only if you accept our cookie banner, for two purposes: measuring which ads bring visitors to this site, and showing our tours again to people who have already visited (retargeting). It is switched off entirely on your confirmation and payment pages, so the private link to your own booking is never shared with Meta. Different events send different information: a page view sends no parameters at all; starting the booking form sends no parameters at all; submitting a booking request sends only an amount and a currency; and viewing a tour page sends the tour name, a content type, an amount and a currency. There is no event that tells Meta a booking was completed or paid for — we do not send that information to Meta at all. Loading Meta’s own measurement script also lets Meta collect your IP address and device information as a normal side effect of the script running, separate from the four events above.
Google Analytics (Google Ireland Ltd), only if you accept cookies. It records a pseudonymous cookie ID, the pages you visit, your device and approximate location, and — when you submit a booking request or a booking is confirmed — the amount and your booking reference. It never receives your name, email or phone number. Data is deleted automatically after 14 months. Withdrawing consent stops collection and removes its cookies. The private link to your own booking is removed from every page address before it is sent, so it is never shared with Google.
Google Maps (Google Ireland Ltd) shows the pickup points on the booking page, only if you accept cookies or tap “Show map”. Until then nothing is loaded from Google Maps. Once it loads, your browser fetches the map from Google, and Google receives your IP address, your browser and device information, and the map area being viewed. We do not send Google your name, contact details or booking. If you tap “Show map” without accepting cookies, we note that choice in your browser’s session storage, so the map stays shown until you close the tab.
Vercel hosts this website and processes request logs, including IP addresses, for all visitors. Separately, a platform-level firewall rule rate-limits the booking endpoint to protect it from abuse. This is covered by Vercel’s own platform policy.
That is the complete list: Supabase, Resend, Google Calendar, PayZen, Meta, Google Analytics, Google Maps and Vercel, and nothing else. We do not use any other analytics tool, and no heatmap or session-recording tool.
Cookies and local storage
We remember your answer to the cookie banner — whether you accept or refuse — in your browser’s local storage under the key tdx_consent, with no expiry, so we do not ask you again, and we note in your browser’s session storage under tdx_banner_shown that the banner was shown. Those two are written either way. The two cookies — tdx_returning and tdx_lastTour, both lasting 30 days — are set only if you accept; refusing sets no cookies at all. Withdrawing your consent later (via the cookie-preferences control in the footer) clears these and also expires Meta’s own tracking cookies and the Google Analytics cookies.
How long we keep your data
Financial and transaction records are kept for 7 years to satisfy French accounting and tax obligations. This is a fixed legal cap, not a marketing choice, and it applies even if you ask us to erase your other data. Everything else — your name, phone number, special requests and dietary requirements on the booking itself — can be erased on request, subject to the disclosures above for Resend (email copies already sent are not removed) and PayZen (retained per its own 15-month transaction-data policy).
Your rights and how to ask for erasure
You can ask us what personal data we hold about you, ask us to correct it, or ask us to erase it. To do any of this, email bookings@tahiti-dream-excursion.com. We commit to responding within 30 days of receiving your request, in line with our data-protection obligations. When we erase your data: on the booking itself, we clear your emergency contact, medical conditions, dietary requirements, special requests and any refund note, and mark any existing cancellation reason as removed; on your customer record, we replace your name and phone number with a fixed marker, set your country to a non-identifying code, turn off marketing consent, and replace your email address with a new one derived from your internal account ID that cannot receive mail, so the real address is freed for you to book again in future; and we delete your newsletter subscription outright and delete the matching Google Calendar event. Two things are deliberately kept even after erasure: the financial record of the booking itself, for the 7-year period described above, because the law requires it, and the date you accepted the liability waiver, because on its own that date does not identify you and it is our only proof the waiver was ever signed.
Because Resend is our email-sending provider, every booking email we send — the request-received email when you submit a booking, the hold-lifecycle emails while your payment is pending (a hold-expiring reminder, a payment-chase reminder, a final unpaid notice, and a notice if your held date expires unpaid), your booking confirmation, 48-hour and 24-hour tour reminders, a post-tour follow-up, and a cancellation email — stays in Resend’s own storage after we send it. An erasure request does not remove emails already sent through Resend — removing our copy would not remove the copy already in your inbox, so the practical benefit is small, and email records also serve as proof of what we told you about a booking. Resend does not offer a way for us to delete an email once it has been sent.
Who is responsible for this data, and your right to complain
Tahiti Dream Excursion is the data controller for the personal data described on this page, reachable at bookings@tahiti-dream-excursion.com for any of the requests above.
If you are unhappy with how we have handled your data, you can also lodge a complaint with the CNIL (Commission Nationale de l’Informatique et des Libertés), the French data-protection supervisory authority, at cnil.fr — you do not need to contact us first.
Your choices
You do not have to accept analytics or advertising cookies to book a tour. Refusing the cookie banner means Google Analytics and Meta’s measurement script never load and none of the tracking cookies above are set. You can change your mind at any time using the cookie-preferences control in the site footer, which clears your previous choice and reloads the page so the new choice takes effect immediately.
Questions
If anything on this page is unclear, email bookings@tahiti-dream-excursion.com and we will answer directly rather than pointing you back at this document.