Privacy and personal information
Privacy policy
Version 1.4 · Last updated: 26 September 2026.
This policy explains how information is handled on the site and in our services. Browsing alone is not consent to advertising or measurement. Consent for uses that require it is requested separately, as appropriate.
1. Who we are and how to contact us
The data controller is Yossi Bezalel, exempt business no. 302446067, trading as Yossi Tourism and Travel under the Morocco Travel Center brand, operator of moroc.co.il. Business address: 2 Biluya Street, Tel Aviv-Yafo.
Privacy enquiries: info@moroc.co.il or 050-9114161. We will handle requests within the periods prescribed by law.
2. Notice at the time of collection (section 11 of the Law)
Providing information to us is voluntary; you have no legal obligation to provide it to us. Required fields are needed to handle the particular request. Without contact details we cannot reply, and without application details and documents we cannot submit a visa application. You may also contact us by phone or email.
Forms explain the collection and link to this policy. You may request access to and correction of information as provided by law. Do not send card details or an identity document scan through a general enquiry form. The cancellation form does not require a phone number or a reason for cancelling.
3. What information is collected and why
| Information | When and for what purpose |
|---|---|
| Name, phone, email and enquiry content | Enquiry forms: replying, clarifying the request and offering the requested service. Cancellations: identifying the transaction, recording the notice and handling your rights. |
| Dates, travel party, cities and preferences | Questionnaire and planner: creating and saving a plan. Answers may include religious and accessibility preferences and details about children. Provide only what is needed for planning, not medical diagnoses. |
| Name, passport details, birth date, photo, passport scan, minor’s documents and travel documents | Visa process: saving a draft, checking documents and submitting the application to Morocco’s official portal. Documents may contain particularly sensitive information. We do not use them for advertising measurement. |
| Transaction and payment details | Charging, receipts, customer service, refunds and accounting records. The card number is entered with the payment provider and is not stored by us. |
| IP address, browser data and request logs | Site operation, security and abuse prevention. Measurement and advertising are activated only according to the choice described in section 9. |
4. Who the information is passed to
Information is shared according to the service and purpose. We do not sell passport documents or enquiry details. Consent-based advertising measurement is described separately in section 9.
- To the Moroccan government’s official visa portal: application details and documents required for the submission you requested. Moroccan authorities handle the information under the law applicable to them.
- To tourism suppliers in Morocco: request details needed for a quote; contact details to the selected supplier according to the booking process. Do not put identifying or medical information in free-text fields that do not ask for it. Visa documents are not part of a tourism quote request.
- To infrastructure and operational providers: Vercel for the site, Supabase for databases and storage, Grow for payments and Make for transmitting payment requests, Resend for email and Cloudflare for infrastructure and protection, including Turnstile where enabled on forms. Operational notifications to staff and suppliers may use ElevenLabs and Meta on WhatsApp. A cancellation notification contains only an identifier and receipt time; cancellation details remain in the enquiry system.
- To Google Analytics and advertising tools configured on the site, only according to your section 9 choice. Measurement data may identify a browser or enable matching by the provider; it should not be regarded as anonymous.
- To authorities and competent bodies when disclosure is required by law.
- Some processing takes place outside Israel, including through international providers and in Morocco. Storage in Europe does not mean all processing takes place there. Contact us for information about transfers related to your request.
5. Questionnaire and trip planner
The current planner builds a route from your answers, the site’s planning rules and its catalogue. It is not an AI conversation with a language-model provider. Do not submit a passport, payment details or medical information there.
Questionnaire answers may be stored in your browser to restore a draft. Creating a plan saves the answers and result on the server, even before you provide contact details. If you leave a phone number for follow-up, it is saved with the request details.
A plan with a sharing link is accessible to anyone holding that link, including the answers saved with it. The link is not a password-protected personal account. Share it only with people you want to see the plan and preferences; you may ask us to delete it.
6. How long we keep information
Information is retained for the purpose for which it was collected and to meet our obligations. Retention periods differ by information type:
| Information | Retention and deletion |
|---|---|
| Documents for a visa application delivered to the customer | The deletion mechanism is designed to delete files 30 days after visa delivery. Deletion may be delayed by a fault or a documented hold to handle a dispute or legal obligation. Application and payment records are not deleted with the files. |
| Uncompleted visa drafts | A cleanup mechanism targets drafts inactive for 30 days, subject to payment checks and deletion holds. A paid or submitted application is not automatically treated as an abandoned draft. |
| Shared plans and questionnaire answers saved with them | The plan link remains available until 30 days after the trip ends. If no end date can be calculated, it is available for 90 days from creation. Access is then blocked and the plan and saved answers are scheduled for deletion in the daily cleanup. A fault may delay deletion. Any PDF you already downloaded remains with you. |
| Enquiries and request details other than files | There is currently no single automatic deletion deadline for all these records. Continued retention and deletion requests are assessed according to purpose and law. Enquiry details sent to staff, including a copy of planning details, are not deleted with the shared plan. |
| Receipts and accounting records | For the period required by bookkeeping law. This obligation does not authorize keeping passport scans or all visa fields for the same period. |
| Backups and security logs | Deleting an active record does not guarantee immediate deletion from every backup or provider system. Retention depends on the record, provider and operational or legal need. Contact us about specific information. |
7. Your rights
You may request access to information about you and correction of information that is inaccurate, incomplete, unclear or outdated, subject to the Privacy Protection Law. You may also request deletion; the request will be assessed under the law, retention purpose and applicable retention duties.
Email info@moroc.co.il with your name and request. We will ask for proportionate identity verification where needed, without another identity document scan if a suitable alternative exists. Access requests will be handled within 30 days, subject to law; other requests follow their applicable deadlines. You may also contact the Privacy Protection Authority.
You can change your measurement choice in cookie settings. Choosing “Essential only” stops future browser measurement and requests cancellation of future server purchase events linked to that browser’s consent identifier. A server update failure displays a message and allows a retry. The update does not recall information already sent or identify transactions from another browser or after the cookie was deleted. Contact us in those cases or about the use of transaction information.
8. Information security
The site uses HTTPS, separate permissions for content, payment and visa systems, and private storage for visa documents. Access to management systems requires authentication and appropriate permissions.
Security measures reduce risk but do not guarantee immunity. If an incident occurs, we will investigate and act according to applicable reporting and response obligations. Do not email passport documents or submit them through the general enquiry form; use the dedicated upload process.
9. Cookies, browser storage and advertising measurement
Measurement tools are configured by site environment. They do not load before you choose “Accept”. Choosing “Essential only” lets you keep using the services. You can reopen cookie settings in the footer and change your choice.
- Operation: authentication, security and document-upload cookies, accessibility and display preferences, and browser drafts. The cookie choice is saved for up to a year. After measurement consent, a random identifier is also stored in a one-year cookie, linking the choice to orders from that browser and allowing future server measurement of them to be withdrawn. The server stores a hash of the identifier and the consent record; cookie expiry does not delete transaction records. Drafts and preferences in local storage may remain until reset or site-data deletion, including on a shared device.
- Referring-partner attribution: a partner link may store a partner code in a cookie for up to 90 days to attribute an order. Another cookie limits repeat-click counting to an hour. These are separate from Google and Meta tags. Links to external booking sites are also subject to those sites’ policies.
- Google Analytics measures pages and actions after consent. When Google Ads is configured, action data is also used to measure advertising conversions. Google tags on the site are configured without Google Signals or advertising-personalization signals. This does not guarantee that the provider has no information from other sources.
- When the Meta pixel (Facebook and Instagram) is configured, it measures pages and actions after consent. Browser measurement and advertising tags do not load in the visa and payment process, personal trip plans, contact page, administration interface or partner area.
- When a server-side Meta purchase event is configured, the consent linked to the transaction is checked again before sending. No event is sent without valid permission, after expiry or after withdrawal. It may include amount, event identifier, IP address, browser details and attribution identifiers, plus SHA-256-hashed email and phone for matching. Hashing is not encryption and does not anonymize the information. Passport documents and questionnaire answers are not sent in this event.
10. Service messages and mailing lists
An enquiry or booking does not subscribe you to advertising. We will send information needed to handle your request, such as an order update or a missing-document notice. Advertising does not become a service message merely because it is sent to a customer.
If advertising mailings are offered, subscription will be separate from the service and handled according to law, including sender identification and an unsubscribe option.
11. Minors and other people’s information
Services are booked by adults. Provide another person’s information with their permission, and a minor’s information through a parent or guardian, only as needed for the service. Do not upload family members’ documents that are not required for the application.
12. Social networks and external sites
Content you post on Facebook, Instagram, TikTok or YouTube is also subject to that platform’s settings and policy. Information transferred from there to us for an enquiry will be handled according to its purpose and applicable law. Following an external link is subject to that site’s policy.
13. Policy changes
We will publish dated updates. Material changes to collection or use will be brought to your attention, with additional consent requested when required. Publishing a new version does not itself authorize a new use of previously collected information.
14. Contact
Morocco Travel Center · Yossi Tourism and Travel · Yossi Bezalel
info@moroc.co.il · 050-9114161 · 2 Biluya Street, Tel Aviv-Yafo
26.9.2026
Courtesy translation only. The Hebrew version is binding, under Israeli law.
Read the Hebrew version