Your information
Privacy Policy
This policy explains how Magical Exploits Safaris Ltd handles information collected through this website and travel enquiries. It also explains our current technical services, retention approach and how to contact us about your information.
1. Who we are
Magical Exploits Safaris Ltd is a Kenya-based safari and travel operator with offices in Nairobi. We use the information described here to respond to enquiries and support the travel arrangements you ask us to help with.
For privacy questions or requests, email info@magical-exploits.co.ke.
2. Information you provide
Depending on your request, the enquiry form may collect:
- Your name, email address, residence, and optional phone number or contact preference.
- Travel dates or flexibility, number of travellers, children's ages and room requirements.
- Your chosen destination, journey or travel style, interests, budget and display currency.
- Arrival details and optional practical requirements relevant to the arrangements you are considering.
The current enquiry form does not request children's names or dates of birth. Please provide only the information needed to explain your request.
3. Information for particular travel services
Additional questions depend on the service you select:
| Service | Relevant enquiry details |
|---|---|
| Airport or transfer arrangements | Airport, flight, arrival, transfer route and luggage details |
| Travel document assistance | Nationality, destination, application stage and the help you need |
| Long-term car hire | Dates, vehicle requirements and driving preference |
| Accommodation reservations | Dates, rooms and accommodation priorities |
| Private guiding | Destination, preferred language and interests |
You do not need a customer account to enquire. Sending an enquiry does not automatically create an account, order, booking or payment. The website currently supports enquiries and quotations; online checkout and payment are not available.
4. Optional practical or sensitive information
You may choose to tell us about dietary needs, accessibility requirements or a health-related practical consideration that affects your travel arrangements. Share only what is useful for planning the assistance you need.
We do not routinely ask for medical records. The current enquiry system does not request passport scans, file uploads, card details or other payment details. Please do not include unnecessary sensitive documents or information in your message.
The enquiry consent covers the optional practical information you choose to provide. These details remain optional; you can contact us first to discuss what information is needed.
5. Enquiry consent and use of information
The enquiry form requires your consent before submission. We record the consent accepted with your enquiry, including the version of the consent statement.
We use enquiry information to understand your request, respond to you, prepare or refine travel proposals and quotations, and communicate about the services you have requested. If an enquiry develops into a booking, relevant information becomes part of arranging and supporting that booking. Technical information also helps protect the form and manage duplicate submissions.
An enquiry is not a marketing subscription. Accepting enquiry processing does not automatically subscribe you to marketing messages. If necessary information is missing, we may need to ask for it before we can respond fully or prepare a quotation.
6. How enquiry records are stored
Enquiries are held in private website records with administrator-restricted access. A record can contain the validated request details, enquiry reference, timestamps, consent version and acceptance, and delivery status.
The system may also hold technical mappings that help recognise duplicate or replayed requests. These are separate from the travel details used to prepare your proposal.
7. Communication and email
Enquiries are delivered to our authorised team through business email. Hostinger provides the authenticated email delivery service. Operational messages and replies can contain the details needed to handle your request.
An acknowledgement or enquiry reference confirms receipt of a request; it does not confirm a booking. Please use the contact details in our correspondence if you need to correct information or add relevant travel details.
8. Bot and abuse protection
We use Cloudflare Turnstile to help protect the enquiry form from automated abuse. The form sends a challenge token to Cloudflare for verification. Cloudflare may process browser and network signals under its Turnstile privacy policy.
Our form protection also uses pseudonymised, expiring technical keys and aggregate rejection counts to manage request limits and duplicate submissions. Pseudonymised information is not the same as anonymous information. Hosting and infrastructure services may maintain separate technical or security logs.
9. Cookies and browser storage
The current enquiry system uses short-lived session and receipt cookies. A separate browser local-storage entry remembers your display-currency preference.
The website does not currently run analytics or advertising tracking on its visitor pages. Our Cookie Policy identifies the enquiry cookies and currency storage, their purposes and configured persistence.
10. Technical providers and external services
Technical services involved in the current enquiry process include Hostinger email delivery and Cloudflare Turnstile. Their processing is also described in the Hostinger privacy policy and Cloudflare policy linked above.
Travel arrangements may require further information beyond an initial enquiry. What is needed for the particular service can be discussed during quotation or booking; please do not send extra identity or sensitive documents before they are requested and the appropriate process is explained.
11. International technical processing
Our technical providers may process information through infrastructure outside Kenya. The location and handling of their processing depend on the provider and service involved. Their privacy information provides further details about their own practices.
12. How long information is retained
| Record type | Retention approach |
|---|---|
| Ordinary enquiry records | Retained for 24 months after the last meaningful interaction, then deleted unless they form part of an active or confirmed booking, dispute, legal matter, or required accounting, tax or business record |
| Operational enquiry emails | The same 24-month period after the last meaningful interaction, with the same exceptions |
| Duplicate or replay-protection mappings | Kept only as long as technically necessary; approximately 30 days is the target where technically practical |
| Confirmed booking and travel records | Retained according to applicable accounting, tax, contractual and legal recordkeeping requirements; there is no single deletion period for all such records |
The approximate target for duplicate-protection mappings allows reasonable technical variation. It is not a fixed legal deletion deadline.
Deletion from active systems may not immediately remove information from rotating backups, infrastructure logs or security records. These have separate technical retention arrangements; we do not state a fixed retention period for them here.
13. Privacy requests
Contact info@magical-exploits.co.ke if you want to ask about information we hold, request a correction or deletion, or raise a privacy concern. Include enough information for us to locate the relevant enquiry or correspondence, such as your enquiry reference if available.
We may need to verify your identity before responding to a request involving personal information. Please do not send identity documents with your first message unless we have explained why they are needed and how to provide them. We will consider the request alongside any applicable recordkeeping requirements and explain where these affect what can be done.
14. Security
Measures in the current enquiry system include administrator-restricted records, protected session cookies, server-side challenge verification, request limits and periodic cleanup of technical protection data.
No website or email system can guarantee absolute security. Keep unnecessary sensitive information out of public enquiry messages and tell us if you believe information has reached the wrong recipient.
15. External links and WhatsApp
Links to other websites take you to services with their own privacy practices. This includes a WhatsApp contact link, which opens only when you choose to follow it and does not automatically send a message.
The current website does not embed maps, videos or live chat, and its fonts are served locally. Privacy information shown by an external service applies to your use of that service.
16. Changes to this policy
We may update this policy when our information handling or website services change. The version identifier at the end of this page identifies the text you are reading. Please check the current policy when providing new information.
17. Contact
Magical Exploits Safaris Ltd
Email: info@magical-exploits.co.ke
Telephone / WhatsApp: +254 722 255 755
Main office: 5D Residence, B1, Waiyaki Way, Nairobi, Kenya.
Second office: 7th Floor, Uniafric House, Loita Street, Nairobi, Kenya.
Use Contact for a general question or Plan My Safari for a travel enquiry. Send privacy requests to the email address above.
Version: ME-PRIVACY-2026-09-v1
