Dyafna · Legal
Privacy Policy
Last updated 31 August 2026
This policy explains what personal data Dyafna (“Dyafna”, “we”, “us”) collects when you use our website, guest storefronts and apps (the “Platform”), how we use and protect it, and the rights you have. Dyafna is the controller of the data processed to run the Platform. The establishment you book with (your “Host”) is a separate, independent controller for its own relationship with you, including the guest registration the law requires it to keep.
1. The data we collect
Information you give us:
- Account & profile: your name, email, phone number, country or nationality, and preferred language.
- Bookings & orders: the items you book, dates, guest counts, and any notes or requests you add.
- Check-in: the guest details required for registration and, where local law requires it, a photo of an identity document and your signature.
- Messages & reviews: what you send to Hosts and to partner sellers through the Dyafna inbox, and any reviews you leave.
Information created when you use Dyafna: order and payment records (status, amount and a payment reference, not your card number), your sign-in activity, and technical data such as your IP address, device and the pages you view, collected through essential cookies.
Information from others: your Host (for bookings made with them), our payment provider (confirmation that a payment succeeded), and, if you arrived through a referral or affiliate link, that referral source.
2. How we use your data
- to provide the Platform and process your bookings and payments;
- to support the guest registration and tourist-tax steps the law requires for your stay;
- to send you the messages you need (sign-in codes, booking confirmations, receipts and service updates) and, only if you opt in, other updates;
- to keep accounts secure and to prevent fraud and abuse;
- to check messages for the specific patterns described in section 8, so that bookings stay covered by our payment and dispute process;
- to support you, improve the Platform, and meet our legal, tax and accounting obligations.
3. Legal bases (guests in the EU/EEA and UK)
If data-protection law applies to you, we rely on:
- Performance of a contract: to take and fulfil your bookings and run your account;
- Legal obligation: for guest registration, tax and accounting records;
- Legitimate interests: to keep the Platform secure, prevent fraud, improve our service, and enforce the terms our hosts and partners agree to (see section 8) — each balanced against your rights;
- Consent: where you opt in to something optional, such as marketing emails. You can withdraw it at any time from your notification settings, or by replying to ask us to stop.
4. Payments
We do not collect or store your full card details. Payments are processed by PayPal, which acts as an independent controller of the information you provide to it; its handling of that data is governed by PayPal’s privacy statement. We keep only what we need to manage your order and any refund: a payment reference, the amount and the status.
5. Identity documents and check-in data
Local law requires your Host to register the guests who stay with them, so at check-in we ask for your name, nationality, date of birth and identity document number. You type these details in. We do not take or store a photograph or scan of your identity document.
We do keep the signature you draw when you sign the rental agreement, as part of that agreement, because it is what makes the document valid. You can ask us to delete your check-in data at any time.
6. Who we share data with
- Your Host: the establishment you book with, so it can prepare for and register your stay;
- Service providers acting on our instructions under contract, for example hosting, email delivery and fraud prevention;
- Our payment provider (PayPal) to take payment and process refunds;
- Authorities where the law requires it, or to protect the rights and safety of guests, Hosts or the public.
We do not sell your personal data, and we do not use third-party advertising trackers.
7. International transfers
Dyafna operates from Morocco. If you are in the EU/EEA or the UK, your data is transferred to and processed in Morocco. We rely on appropriate safeguards for these transfers, such as standard contractual clauses and the fact that processing is necessary to perform the booking you asked for.
8. Keeping the platform honest
We check messages between guests, hosts and partner sellers for a small number of specific patterns: attempts to move a booking off the platform, payment details for methods we cannot see, contact details being exchanged (a phone number, an email address, or a move to another messaging app), and links to other sites. Messages to our own support team are not checked. We do this to protect guests, to prevent fraud, and to enforce the terms hosts and partners agree to when they list with us.
Nothing is blocked, hidden or edited, and no decision about you is ever made automatically. A match simply raises a note for a member of our team to read. The note records which pattern matched and a short, partly hidden extract — we do not keep a second copy of your phone number or email address in it.
Notes are deleted after 90 days unless we acted on one, in which case we keep it with the record of what we did. The messages themselves follow the periods in section 9. If we send you a warning, it tells you what we saw, and you can reply to us at support@dyafna.com. We may also freeze a conversation, which both people can see, or in serious cases remove it.
9. How long we keep it
- Account data: while your account is open. You can close your account yourself from the privacy page in the app. We then wait 30 days — nothing is deleted in that time and you can cancel — and after that we remove your name, email address, phone number, photo and sign-in. What we cannot remove is listed in section 10;
- Booking, payment and tax records: for as long as the law requires us to keep them (typically several years);
- Identity details: we do not store a photo or scan of your passport or ID card. The document type and number you type at check-in are kept on the registration record, for as long as the law requires the property to hold it;
- Messages about a booking: kept for as long as the law requires us to keep business records, currently ten years. A conversation counts here if you ordered anything from that host, or checked in at any of their properties — not only if the conversation is formally attached to an order. Cancelled and abandoned orders do not count;
- Messages where nothing was ever booked: 24 months after the last activity in the conversation, then deleted. We keep a conversation past that if we froze it or acted on something in it, because we also have to keep the record of what we did;
- Message-check notes (section 8): 90 days, unless we acted on one, in which case it is kept with the record of what we did.
- Our internal records of what we did: we log administrative actions on the Platform, with who did them, when, and their IP address. Records of a decision that affected money, someone else’s access, or a legal document are kept for ten years, so we can answer for them if you ever question one. Everything else — for example a note that a member of our team opened a page — is kept for two years.
When we no longer need data, we delete it or anonymise it so it can no longer identify you.
10. Your rights
Closing your account. Guests can close their account from the privacy page in the app, without asking us. If you host or sell on Dyafna, write to us instead: your account carries listings, bookings and agreements other people depend on, so we close it by hand once those are settled.
Closing removes your name, email address, phone number, photo and sign-in. Three things stay, and only because someone is legally obliged to hold them: your bookings and payments (Moroccan commercial and tax law), the arrival form the property completed for you (a register the property must keep, not ours to delete), and messages about a booking. None of them stays linked to an account anyone can sign in to, and each is deleted on the schedule in section 9. This is the exception the law allows where a record must be kept; everything outside it goes.
Subject to the law that applies to you, you can ask us to: access a copy of your data; correct it; delete it; restrict or object to how we use it; receive it in a portable format; and withdraw any consent you gave. To exercise any of these, email support@dyafna.com. You also have the right to complain to a data-protection authority, in Morocco the CNDP, or, in the EU/EEA or UK, your local supervisory authority.
11. Cookies
We use cookies that are essential to make Dyafna work: keeping you signed in and protecting against fraud. We also store your language, currency, theme, and — if you host with us — which property you were last looking at, so the app looks the way you left it. We don’t use advertising cookies and we don’t track you across other websites. You can clear or block cookies in your browser, but the essential ones are needed to sign in and check out.
There is one cookie that isn’t essential. If you reach Dyafna through a partner or referral link (a web address containing ?ref=), we store that referral code for 180 days so the partner who sent you gets credited if you later sign up. It holds only the code and the date, it is read only by us, and it is never set if you arrive any other way. Clearing your cookies removes it.
Two other companies can store something in your browser, and only at themoment you use them: PayPal, when you choose to pay by PayPal at checkout, and Cloudflare Turnstile, the anti-fraud check that confirms you are a real person when you sign in or check in.
12. Security
We protect your data with measures including encryption in transit, restricted access, short-lived sign-in codes, and email sending locked to known servers. No system is ever perfectly secure, but we work to keep your data safe and to respond quickly if something goes wrong.
13. Children
Dyafna is not intended for people under 18. A parent or guardian should make any booking that includes a minor.
14. Changes to this policy
We may update this policy as Dyafna grows or the law changes. We’ll post the new version here with an updated date, and give reasonable notice of significant changes.
15. Contact us
One address reaches us, for privacy requests and for everything else: support@dyafna.com. Put “privacy” in the subject line and it goes to the person handling data requests.
Dyafna, Marrakech, Morocco.