๐Ÿ“ž +255 742 119 753 โœ‰๏ธ tours@resilienceexpedition.com
KPAP Certified โ˜… 5.0 Rating
PLAN EXPEDITION
GET A FREE QUOTE
  1. Home
  2. Privacy Policy
Your privacy matters to us

Privacy Policy

This policy explains how Resilience Expedition collects, uses, stores, and protects your personal information when you use our website, enquire about safaris or climbs, or travel with us in Tanzania.

Effective date1 January 2024
Last updated24 April 2026
Governing lawTanzania & GDPR compliant
Data controllerResilience Expedition, Moshi TZ
Plain English Summary

What this policy means in plain language

We only collect data needed to arrange your safari or Kilimanjaro climb
We never sell your data to third parties
You can request deletion of your data at any time
We share only what is necessary with parks, guides, and lodges to deliver your trip
We use cookies to improve site experience โ€” you can opt out
Marketing emails are opt-in only โ€” unsubscribe instantly any time

Resilience Expedition is a Tanzania-registered tour operator and travel agency based in Moshi, Kilimanjaro Region, Tanzania. We arrange Kilimanjaro climbs, Northern Circuit safaris, Ngorongoro crater packages, Zanzibar beach holidays, and combined expedition itineraries throughout Tanzania.

For the purposes of data protection law โ€” including the Tanzania Personal Data Protection Act (PDPA) and, where applicable, the European Union General Data Protection Regulation (GDPR) โ€” Resilience Expedition is the data controller responsible for your personal information.

Our registered details

Resilience Expedition ยท Moshi, Kilimanjaro Region, Tanzania ยท Email: tours@resilienceexpedition.com ยท Phone: +255 742 119 753 ยท Website: www.resilienceexpedition.com

By using our website, submitting an enquiry form, booking a trip, or communicating with us by any means, you acknowledge that you have read this Privacy Policy and agree to the collection and use of your information as described herein.

Personal identification data

  • Full name (first name and last name)
  • Email address
  • Phone number and/or WhatsApp number
  • Nationality and country of residence
  • Passport number and expiry date (required for park permit applications)
  • Date of birth (required for Kilimanjaro KINAPA permits)

Trip and booking data

  • Safari or climb package selected, dates, and duration
  • Group size and composition (adults, children, ages)
  • Accommodation tier preference (budget, mid-range, luxury)
  • Flight arrival/departure details and airline information
  • Emergency contact name and phone number
  • Travel insurance provider and policy number

Health and special requirements

  • Dietary requirements and food allergies (to inform lodge and camp kitchens)
  • Medical conditions relevant to high-altitude trekking (voluntarily disclosed for safety)
  • Accessibility requirements or mobility considerations
  • Medication declarations relevant to altitude (voluntary, for guide awareness)

Payment data

  • We do not store payment card numbers, CVV codes, or banking credentials on our servers
  • Payments are processed through secure third-party payment gateways (Stripe, bank transfer)
  • We retain records of amounts paid, payment dates, and transaction references for accounting purposes

Technical and usage data

  • IP address, browser type and version, operating system
  • Pages visited, time spent on pages, referral source
  • Device type (desktop, mobile, tablet)
  • Cookie data (see Section 9 for full details)
โš ๏ธ
Special category data

Health information you voluntarily provide (such as medical conditions for altitude safety) is classified as "special category" data under GDPR. We collect this only with your explicit consent and use it solely to keep you safe during your trip. It is deleted after your trip concludes unless you request otherwise.

We collect your personal data through the following channels:

Channel Data collected Purpose
Website enquiry forms Name, email, phone, trip details, dates Respond to your safari or climb enquiry
Booking confirmation forms Full booking data, passport details, emergency contacts Arrange all trip components
Email correspondence Any information you share in emails Trip planning and support
WhatsApp / phone calls Contact and trip details discussed Customer service and booking management
Google Analytics / cookies Anonymous usage data, IP, device Website improvement and analytics
Payment processors Transaction confirmation (not card data) Financial record-keeping
Review platforms Reviews you post publicly (TripAdvisor, Google) Service improvement (we do not store these)

We do not purchase, rent, or obtain personal data lists from third parties. All data we hold has been provided directly by you or generated by your use of our website.

Primary purposes

  • To respond to your safari, Kilimanjaro, or Zanzibar enquiry and provide a customised quote
  • To arrange and confirm your booking โ€” including lodges, park permits, vehicle, guide, and transfers
  • To apply for national park permits with TANAPA, NCAA, and KINAPA on your behalf (requires passport data)
  • To communicate trip logistics, itinerary changes, safety briefings, and pre-departure information
  • To provide emergency contact and medical information to guides for safety during your trip
  • To process payments and maintain accurate financial records
  • To issue invoices, receipts, and booking confirmations

Secondary purposes

  • To send post-trip review requests (one email only, opt-out available)
  • To send seasonal safari newsletters and offers โ€” only if you have subscribed or opted in
  • To analyse website usage and improve content, navigation, and booking conversion (anonymised data)
  • To comply with Tanzania tourism, tax, and record-keeping regulations
  • To defend against legal claims or disputes where necessary

What we will never do

  • Sell, rent, or trade your personal data to any third party for commercial gain
  • Send you unsolicited marketing emails without your explicit consent
  • Use your data for automated decision-making or profiling that produces legal effects
  • Share your health or medical data with any party other than your assigned guide and lodge (for safety)
  • Retain your data beyond the periods specified in Section 8

We share your personal data only where it is strictly necessary to deliver your trip or comply with legal obligations. The parties we may share data with are:

Recipient Data shared Reason
Tanzania National Parks (TANAPA) Name, nationality, passport number Park entry permit applications
Ngorongoro Conservation Area Authority (NCAA) Name, nationality, passport number Crater descent permit applications
KINAPA (Kilimanjaro National Park Authority) Name, DOB, nationality, passport number Kilimanjaro climb permit registration
Accredited lodges and tented camps Name, arrival/departure dates, dietary needs, group size Accommodation booking and meal preparation
Assigned TANAPA-licensed guides Name, group details, emergency contacts, health disclosures Safety and trip delivery
Airport and hotel transfer partners Name, flight details, arrival time Arranging ground transfers
Stripe / payment processor Payment amount and reference (not card data) Secure payment processing
Google (Analytics, Gmail) Anonymised usage data, email correspondence Analytics and communication
Legal authorities Any data required by law Compliance with legal obligations or court orders only

We require all third parties who process data on our behalf to protect it using standards equivalent to our own. We do not permit our service partners to use your personal data for their own marketing purposes.

Resilience Expedition is based in Tanzania. If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction with data transfer restrictions, please be aware that your personal data will be transferred to and processed in Tanzania, which may not have data protection laws equivalent to your home country.

We transfer your data internationally only where:

  • The transfer is necessary to perform your safari or climb booking contract โ€” for example, submitting your passport details to TANAPA, NCAA, or KINAPA for permit registration
  • The transfer is to tools that provide adequate safeguards โ€” Google Workspace (Google LLC), which maintains Standard Contractual Clauses (SCCs) approved by the European Commission
  • You have provided explicit consent to the transfer after being informed of the risks

For EEA/UK customers, we rely on the necessity of contract performance (Article 46(2)(c) GDPR) and SCCs as the primary safeguards for international transfers. A copy of the applicable transfer mechanism is available on request by emailing tours@resilienceexpedition.com.

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Our retention periods are:

Data type Retention period Reason
Enquiry data (no booking made) 12 months from last contact Follow-up and business planning
Booking and trip records 7 years from trip completion date Tanzania tax and accounting law (TRA requirements)
Passport and permit data Deleted 6 months after trip completion No longer required once permits used
Emergency contact and health data Deleted immediately after trip completion Special category data โ€” minimal retention
Payment transaction records 7 years from transaction date Tanzania Revenue Authority (TRA) legal requirements
Marketing list (subscribed) Until you unsubscribe + 30 days suppression Consent withdrawal compliance
Website analytics data 26 months (Google Analytics default) Statistical anonymised data โ€” no personal identifiers

After retention periods expire, data is permanently deleted from our systems and from all cloud services we use. If you wish to request earlier deletion, please contact us at tours@resilienceexpedition.com (see Section 10 โ€” Your Rights).

Our website uses cookies โ€” small text files placed on your device โ€” to improve your browsing experience, understand how visitors use our site, and occasionally to show relevant content. Here is a breakdown of the types of cookies we use:

Managing your cookie preferences

You can control and/or delete cookies as you wish. You can delete all cookies that are already on your computer, and you can set most browsers to prevent them from being placed. However, if you do this, you may have to manually adjust some preferences every time you visit our site.

  • Browser settings: All major browsers allow you to control cookies through their settings/preferences. Search your browser's help documentation for "cookies"
  • Google Analytics opt-out: Install the Google Analytics Opt-out Browser Add-on at tools.google.com/dlpage/gaoptout
  • Cookie banner: When you first visit our site, our cookie consent banner allows you to accept or decline optional cookies

Under applicable data protection law, you have the following rights regarding your personal data. To exercise any of these rights, email tours@resilienceexpedition.com. We will respond within 30 calendar days (or within the statutory timeframe required by applicable law).

Right of Access

Request a copy of all personal data we hold about you (a Subject Access Request / SAR).

Right to Rectification

Request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure

Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.

Right to Restrict Processing

Request that we pause processing your data in certain circumstances โ€” for example, while accuracy is disputed.

Right to Data Portability

Receive your personal data in a structured, machine-readable format, and transfer it to another service.

Right to Object

Object to processing based on legitimate interests (e.g. analytics) or to direct marketing at any time.

Right to Withdraw Consent

Withdraw consent at any time where processing is consent-based โ€” including unsubscribing from marketing.

Right to Lodge a Complaint

Complain to a supervisory authority โ€” in Tanzania, the TCRA; in the EU, your local Data Protection Authority.

How to make a request

Email tours@resilienceexpedition.com with the subject line "DATA REQUEST โ€” [Your Full Name]". Include your name and the email address you used when enquiring or booking. We may request proof of identity before processing your request. There is no fee for standard requests.

Our website is not directed at children under the age of 16, and we do not knowingly collect personal data from children under 16 without verifiable parental or guardian consent.

When a child under 16 travels with us as part of a family group, their personal data (name, nationality, passport details, age) is collected for the sole purpose of national park permit applications (all visitors must be registered, regardless of age). This data is:

  • Provided by the parent or legal guardian โ€” not collected directly from the child
  • Used only for permit applications to TANAPA, NCAA, or KINAPA
  • Deleted 6 months after trip completion in line with our retention schedule
  • Never used for marketing or any purpose other than the booking and trip delivery

If you believe we have inadvertently collected data relating to a child under 16 without appropriate consent, please contact us immediately at tours@resilienceexpedition.com and we will delete it promptly.

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, destruction, or alteration.

Technical safeguards

  • Our website is served over HTTPS with TLS encryption on all pages
  • Enquiry and booking forms transmit data over encrypted connections
  • Email communications are handled through Google Workspace, which provides encryption at rest and in transit
  • Payment processing is handled exclusively by PCI-DSS compliant payment processors (Stripe). We never see or store your card details
  • Access to customer data within our team is restricted on a need-to-know basis
  • Team accounts use two-factor authentication (2FA) where available

Organisational safeguards

  • Staff are trained on data protection principles and confidentiality obligations
  • Third-party service partners are contractually required to maintain equivalent security standards
  • We conduct periodic reviews of our data handling practices
  • Physical documents containing personal data (printed booking forms) are stored securely and shredded after use
โš ๏ธ
Data breach notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by applicable law.

While we implement these measures, no internet transmission is 100% secure. We cannot guarantee absolute security of data transmitted to our site, but we will notify you promptly in the event of a breach affecting your data.

Our website may contain links to external websites operated by third parties โ€” such as national park authority websites, hotel booking platforms, review sites (TripAdvisor, Google), social media platforms (Facebook, Instagram), and payment processors.

This Privacy Policy applies only to the Resilience Expedition website and the data we process. When you click a link to an external site, you leave our jurisdiction and the third party's own privacy policy applies. We:

  • Are not responsible for the privacy practices or content of any third-party websites
  • Do not endorse, monitor, or control third-party privacy policies
  • Recommend you read the privacy policy of any external website before submitting personal data to it

Third-party services embedded in or used alongside our website include:

  • Google Analytics โ€” usage analytics. Privacy policy: policies.google.com/privacy
  • Google Maps โ€” embedded maps. Privacy policy: policies.google.com/privacy
  • Stripe โ€” payment processing. Privacy policy: stripe.com/privacy
  • WhatsApp (Meta) โ€” customer messaging. Privacy policy: whatsapp.com/legal/privacy-policy
  • Unsplash โ€” photography sourcing. Privacy policy: unsplash.com/privacy

We reserve the right to update this Privacy Policy at any time to reflect changes in our data practices, legal requirements, or business operations. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page and in the hero section
  • Where the change materially affects how we process your data, notify active customers by email
  • Maintain the previous version of this policy, available on request from tours@resilienceexpedition.com

We encourage you to review this Privacy Policy periodically. Your continued use of our website or services after any changes constitutes acceptance of the updated policy.

Version history

Version Date Key changes
v1.0 โ€” Initial 1 January 2024 First published policy
v1.1 15 March 2025 Added children's data section; updated retention periods
v1.2 1 January 2026 Added Tanzania PDPA references; updated cookie types
v1.3 โ€” Current 24 April 2026 Added international transfer safeguards; expanded rights grid; updated third-party list

If you have any questions, concerns, or complaints about this Privacy Policy or the way we handle your personal data, please contact us using the details below. We are committed to resolving any data protection concerns fairly and promptly.

Data Controller contact details

Resilience Expedition
Moshi, Kilimanjaro Region, Tanzania
Email: tours@resilienceexpedition.com
Phone: +255 742 119 753
WhatsApp: +255 742 119 753
Website: www.resilienceexpedition.com

If you are not satisfied with our response

If you have raised a concern with us and are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection supervisory authority:

  • Tanzania: Tanzania Communications Regulatory Authority (TCRA) โ€” tcra.go.tz โ€” which oversees the Tanzania Personal Data Protection Act
  • EU/EEA residents: Your local national Data Protection Authority (DPA). A full list is available at edpb.europa.eu
  • UK residents: Information Commissioner's Office (ICO) โ€” ico.org.uk โ€” helpline: 0303 123 1113

We always prefer the opportunity to address your concern directly before you escalate to a supervisory authority. Please contact us first โ€” we aim to resolve all data protection concerns within 30 calendar days.