
Privacy Policy
Your privacy matters to us
Privacy at a glance
The short version. The numbered sections below are the full policy and take precedence if the two ever differ.
- Collected & linked to you
Contact and trip details
Name, email, phone, travel dates, party size, and whatever you write to us or type into the booking form's notes box.
§02 - Collected, not linked to you
Anti-abuse check
When you book or send a message, a one-way hash of your IP address, so the forms cannot be used to flood us. It is not readable back into an address.
§05 - Never collected
Payment, location, ad profile
No card details are entered on this site. No GPS location, no advertising identifiers, no purchase history, no biometrics, no contacts or photos.
§02 - No tracking
No ad or cross-site cookies
Local storage holds only your language and theme choice. We do not follow you across other websites and show no third-party ads.
§05 - Never sold
Not sold, rented or traded
Shared only with the providers who run the site and the local partners who deliver a trip you actually book.
§04 - Kept for
24 months, or 7 years
Inquiries: up to 24 months after last contact. Booking and financial records: up to 7 years, for tax law.
§07 - Processed in
Yemen, Canada and the US
We operate from Socotra. Enquiries are also handled from Canada. The booking database, the website host and the email service are in the United States.
§06 - Your control
Access, correct or delete
Email socotraquest@gmail.com and we act within the time the law allows. Marketing consent can be withdrawn any time.
§08
Who we are
This website is operated by The Socotra Quest, a small tour operator based on Socotra Island, Yemen, reachable at socotraquest@gmail.com or +1 514 434 4207 ("we", "us"). We are the party responsible for the personal information described below.
The telephone number above is a Canadian line. Enquiries and calls are handled for us from Canada by a family member acting on our behalf, which means your name, your message and your booking details may be read there as well as in Yemen. She is not a separate company and does not decide what happens to your information; we do.
Information we collect
When you use our website or contact us, we may collect:
- Full name, email address and phone number
- Travel preferences, party size and dates you share
- Any additional information you include in your inquiry or correspondence
- Limited technical data automatically generated when you visit (e.g. browser type and pages viewed), recorded in our host's server logs
When you reserve dates on our booking page, we store the trip you chose, your arrival and departure dates, the number of travellers, your name, email and phone number, anything you write in the notes box, and a booking reference. This is kept in our booking database, and it is the record we work from.
We also store a one-way hash of your IP address at the moment you book or send us a message, and nothing else about your connection. It exists so neither form can be used to submit unlimited bookings or messages, it cannot be turned back into an address, and it is deleted within 24 hours.
We do not ask for special-category data such as health information, and the booking form does not require it. If you choose to put medical, dietary or accessibility details in the notes box, we use them only to plan your trip safely and share them only with the guides and providers who need them. You are welcome to leave the box blank and tell us those things directly instead.
We never collect payment details. There is no card form anywhere on this website.
How we use it & our legal basis
We use your information to:
- Respond to inquiries and plan, confirm and run your trip (to perform our agreement)
- Communicate itinerary changes and travel updates (legitimate interest / contract)
- Hold the dates you reserved, and keep the record of your booking (to perform our agreement, and to take steps at your request before it)
- Keep the website secure and working, including limiting how many bookings one connection can submit (legitimate interest)
- Keep booking and financial records for as long as tax and accounting law requires (legal obligation)
- Send marketing only where you have given consent, which you may withdraw at any time
Service providers we share data with
We do not sell, trade or rent your personal information. We share it only as needed with:
- Supabase: hosts the booking database, where your booking is stored (United States, us-east-1)
- Resend: sends your booking confirmation and our copy of it, and delivers messages from the enquiry form to our inbox (United States)
- Cloudflare Turnstile: checks that a booking or a message is being sent by a person rather than a bot, on the booking and enquiry pages only (United States)
- Google (Gmail): receives and stores our correspondence (United States)
- Netlify: website hosting, CDN and server logs (United States)
- Our Canadian point of contact, a family member who answers enquiries and calls on our behalf and who is bound to keep what she sees confidential (Canada)
- Local accommodation, transport and guide partners, and visa-processing authorities, strictly as required to deliver a trip you book
Cookies, local storage & analytics
We use a small amount of browser local storage to remember your language and theme preferences and whether you have seen the intro. These are strictly necessary for the site to function and do not track you across other websites. On the staff-only booking dashboard, the same mechanism holds a sign-in session; that page is not part of the public site and nothing on it is set for visitors.
The one-way hash of your IP address described in §02 is not stored in your browser and is not a cookie. It lives on our side for up to 24 hours and is used for nothing but rate limiting.
We use no analytics, no advertising or cross-site tracking cookies, no session recording, and no third-party error or performance monitoring.
The one exception is on the booking and enquiry pages, which load Cloudflare Turnstile to stop automated spam. It runs in its own frame and looks at signals from your browser to decide whether you are a person, usually without asking you to do anything. Cloudflare receives that information to perform the check. We use it for nothing else, and it is not used to track you across this site or others. No other page loads it.
International data transfers
We operate from Yemen, enquiries are also handled on our behalf from Canada, and the providers above are in the United States, where your booking record is stored in a database in the us-east-1 region. Your information may therefore be processed and stored in any of those three places, and outside your own province and country, including outside Québec, the rest of Canada, and the EEA. We share only what is necessary and rely on those providers' own contractual and security safeguards.
How long we keep it
We keep inquiry correspondence for up to 24 months after our last contact, and booking-related and financial records for up to 7 years to meet tax and accounting obligations. A reservation that is cancelled or never goes ahead is removed from the booking database once it is no longer needed, and the anti-abuse hashes described in §02 are deleted within 24 hours. After that we delete or anonymize the information.
Your rights
Depending on where you live (including under Canada's PIPEDA and Québec Law 25, and California's CCPA/CPRA), you may have the right to access, correct, delete, port or restrict your personal information, to withdraw consent, and to complain to a regulator. We do not sell or "share" your personal information as those terms are defined under California law. To exercise any right, email socotraquest@gmail.com and we will respond within the time required by applicable law.
Children
Our website and services are intended for adults. We do not knowingly collect personal information from children under 16. If you believe a child has provided us data, contact us and we will delete it.
Security & breach
We take reasonable measures to protect your information, though no method of transmission is completely secure. If a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by law (including Québec Law 25 and applicable US/Canadian breach-notification rules).
AI and your information
We use AI writing tools to help draft and edit the wording on this website (see our Terms). We do not put your inquiry, your correspondence or any other personal information into those tools, we do not use it to train any AI model, and nothing you send us is profiled or scored. A person reads and answers every message you send us.
One step is automatic, and it is fair to say so plainly: when we are running instant bookings, the website records your reservation and sends your reference without waiting for one of us to look at it. That step applies a fixed rule to the dates you picked. It does not evaluate you, and it is not the point at which a trip is agreed — a person reviews every booking before it becomes a confirmed trip, as set out in our Terms. When we are running bookings by approval instead, nothing is confirmed until one of us has read it. You can always ask us to review a decision, and reach a person by replying to any email we send you.
Privacy contact & changes
The person responsible for personal-information protection is the owner of The Socotra Quest, reachable at socotraquest@gmail.com. We may update this policy; material changes will be posted here with a new date below.
Last updated: September 2026