Legal
Privacy Policy
What we collect, why, how we store it, and the rights you have over it.
Effective 22 July 2026.
1. Who is responsible for your data
Tishmac Safaris ("we", "us") is the data controller for personal information collected through this website, our email and messaging channels, and our booking and payment pages. We are based in Nairobi, Kenya, and we handle personal data in line with the Kenyan Data Protection Act, 2019 — and, where it applies to you, the data protection law of your home country (such as the EU/UK GDPR).
2. What we collect
- Identity and contact details — your name, email address, phone or WhatsApp number, nationality, and preferred language.
- Booking details — travel dates, party size (including children's ages when relevant to pricing), pickup locations, itinerary, and any health, mobility, or dietary information you choose to share so we can plan your trip safely.
- Payment information — the amount, currency, date, and status of payments, and the receipt we issue. Your full card number never reaches us: card details are entered directly with our certified payment provider and are never stored on our servers.
- Correspondence — the messages you exchange with us by email, website form, or messaging apps, so we have an accurate record of what was agreed.
- Technical basics — standard web server logs (IP address, browser type, pages requested) used for security and troubleshooting, and the essential cookies described in Section 8.
3. Where your data comes from
- Directly from you — through this website, email, or messages.
- From the travel agent you booked through, when your booking reaches us via an agent: they pass us the details needed to operate your tour (your name, party, dates, pickup, language, and a contact address for messages).
4. Why we use it
- To prepare quotes, confirm bookings, and operate your trip — the contract between us.
- To send you the practical messages a trip needs: confirmations, pickup details, your personal trip page, payment requests you initiate, and receipts.
- To respond when you write to us, and to keep a record of what was agreed.
- To meet legal obligations — accounting, tax, and lawful requests from authorities.
- We do not send marketing emails without your consent, and we never sell your data.
5. How we store and protect it
- Your data is stored in our managed booking systems on secured servers, protected by encryption in transit (HTTPS everywhere), firewalls, and access controls.
- Access is limited to the staff who need it to plan or operate your trip, each with individual credentials.
- Because we operate as part of a group, your booking is also processed in our group's central reservations system, under the same protections and this same policy. It is used only to operate your trip — the brand you booked with is the brand you hear from.
- Payment card data is handled entirely by our payment provider under their PCI-DSS certification.
6. Who we share it with
- Service providers who make the trip work — lodges and hotels (your name and party for the reservation), park and ticketing authorities where required, our payment provider (to process payments you make), and our email and messaging providers (to deliver the messages we send you).
- The agent you booked through, when your booking came via one — they receive booking status and the replies we send you through their platform.
- Authorities, where the law requires it.
- Each provider receives only what it needs for its role. We never sell or rent personal data to anyone.
7. How long we keep it
- Booking and payment records: kept for as long as required for accounting and legal purposes under Kenyan law (generally up to seven years), then deleted or anonymized.
- Enquiries that never become a booking: kept long enough to answer you and follow up, then removed from active systems.
- Health, mobility, or dietary notes: kept only for the trip they concern.
8. Cookies
This website uses essential cookies only — the session and security cookies the site needs to function (for example, protecting forms against forgery). We set no advertising or cross-site tracking cookies. The full list is in our Cookie Policy.
9. Your rights
You can, at any time:
- Ask what personal data we hold about you, and receive a copy.
- Have inaccurate data corrected.
- Ask us to delete data we no longer need to keep by law.
- Object to or restrict a use of your data, and withdraw any consent you gave.
- Complain to a supervisory authority — in Kenya, the Office of the Data Protection Commissioner — if you believe we have mishandled your data.
To exercise any of these, contact us via the contact page. We respond within 30 days.
10. Changes to this policy
If we change this policy, the new version appears on this page with a new effective date. Meaningful changes affecting an active booking will be communicated to you directly.