Safari Studio privacy policy
Effective date: [date of publication]
1. Who we are
Safari Studio is a customer relationship and operations system for safari and tour operators. It is made and run by [Strandwolf Desert Tours CC, trading as Safari Studio], [registration number], 22 Hendrik Witbooi Street, Swakopmund, Erongo, Namibia ("Safari Studio", "we", "us"). Questions about this policy and requests about your data go to privacy@safari-studio.com.
This policy covers the website safari-studio.com, the application at app.safari-studio.com, and the same application where we run it for one customer under their own address. It covers the people who use the application (our customers and their staff) and the people whose details a customer keeps in it (their clients, travellers and suppliers).
2. Two roles
For some data we decide why and how it is processed; for other data our customer decides and we act on their instructions.
- Our customer's data about their own clients, travellers, suppliers and emails ("Customer Data"): the customer is the responsible party (the controller) and we are their operator (processor). We process it only to provide the service as the customer configures it, under the data processing terms in our Terms of Service. If you are a traveller or a client of a safari operator who uses Safari Studio, that operator is responsible for your data and is the one to ask about it; we will help them answer you.
- Account, billing and website data: data about our customers' staff as users, their subscriptions and payments, and visitors to our website. Here we are the responsible party.
3. What we collect and why
Users of the application. Name, email address, Google account identifier, role, sign-in times, the organisation you belong to, your settings and what you do in the application (an audit log of changes). We use these to sign you in, to show you the right data, to keep a record of who changed what, and to support you. The legal basis is the contract with your organisation and our legitimate interest in running a secure service.
Customer Data, processed on our customer's instructions. Contacts and companies; deals, notes, tasks and meetings; costings, quotes, invoices and payments; travellers' details entered by the client or the operator, which can include dates of birth, nationality, dietary needs, medical conditions, insurance details and emergency contacts; suppliers, rates and holds; proposals; files; email threads from mailboxes the customer connects; vehicle assignments. Dates of birth, medical details, insurance details and payment references are encrypted at rest with a key the application holds separately from the database.
Email and calendar. When a customer connects a Google Workspace mailbox, an IMAP mailbox or a forwarding address, we read, store and send email for that mailbox so that it shows next to the right client or supplier and replies can be sent from the application. When a member connects their Google Calendar, we create meetings in it and read changes to them. See section 5 for the Google rules we follow.
Marketing features (Max plan). When a customer connects Google Ads, Google Analytics, Search Console, a Facebook Page or an Instagram account, we store the account identifiers and access tokens (encrypted), create and manage the campaigns, posts and emails the customer approves, and read back their results. See sections 5 and 6.
Billing. Plan, seats, invoices and payment status. Card and bank details are entered on Stripe's pages and held by Stripe; we never see or store card numbers.
Website visitors. Server logs (IP address, pages requested, browser type, time) kept for 30 days for security. [The website uses Google Analytics 4 to count visits; no advertising cookies.]
Support. What you write to us at support@safari-studio.com and the records needed to answer.
4. How the application uses artificial intelligence
Some features send text to Anthropic's API (the Claude models) to write a draft: a reply, a summary, ad copy, a social media post or a marketing email. We send what the draft needs: your instructions, your brand voice settings, itinerary and supplier descriptions, and the email or notes being answered. We do not send travellers' dates of birth, medical details, insurance details or payment references to generate marketing content. Under Anthropic's commercial terms, data sent through its API is not used to train its models. Every draft is shown to you to edit before it is sent or published; nothing goes out on the AI's say-so.
5. Google user data
Safari Studio's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we access, and only for the purpose named:
- Sign-in: your Google account's email address, name and picture, to sign you in and show who you are.
- Gmail (for mailboxes a customer's administrator connects): we read messages and their attachments, store them in the customer's account, label and archive them, and send messages the user writes, so that email sits next to the right client, supplier and booking and can be answered from the application. Workspace customers grant this through domain-wide delegation to their own mailboxes.
- Google Calendar (for members who connect it): we create, update and cancel meetings and read changes to them.
- Google Ads, Google Analytics and Search Console (Max plan, when connected): we create and change campaigns, ad groups, ads, keywords, conversion actions, Analytics properties and Search Console sites, and read their reports, as the customer directs in the application.
We never use Google user data to serve advertising, never sell it, and never share it with data brokers. No person at Safari Studio reads a customer's email except with that customer's explicit permission to resolve a support request, or where needed to investigate abuse or security, or where the law requires it. Google data is stored only as long as the customer keeps the connection and the account; disconnecting a mailbox or calendar in Settings stops access at once and deletes the tokens, and the customer can delete the stored messages.
6. Facebook and Instagram data
When a customer connects a Facebook Page and the Instagram professional account linked to it, we store the Page and account identifiers and an access token (encrypted), publish the posts the customer has approved, and read each post's reach and engagement to show in the application. We do not read the customer's private messages or their followers' personal data. Disconnecting in Settings deletes the token at once. To have all data from a connected Meta account deleted, disconnect it and write to privacy@safari-studio.com; we confirm within 30 days.
7. Who we share data with
We use these providers to run the service. Each one processes data only for us and under a contract.
| Provider | What for | Where |
|---|---|---|
| DigitalOcean | Servers and database | United States (New York) |
| Cloudflare | File storage (R2) and, later, DNS | Global network |
| Sign-in, Gmail, Calendar, Ads, Analytics, Search Console | United States and global | |
| Meta | Facebook and Instagram publishing and insights | United States |
| Anthropic | AI drafts | United States |
| Resend | Transactional and, for Max customers, marketing email | United States |
| Stripe | Subscriptions and payments | United States and Ireland |
| Mapbox | Route maps on proposals (receives only the page's origin and the map area) | United States |
| Sentry | Error reports (no email bodies, tokens or personal details) | United States |
| ExchangeRate-API | Daily exchange rates (no personal data) | United States |
We do not sell personal data. We disclose it to authorities only when the law requires it, and we tell the customer when we may.
8. Where data is stored and international transfers
Our servers are in the United States. Customers are in Namibia, South Africa and elsewhere, and their clients travel from Europe, the United Kingdom, the United States and other countries. Where the GDPR or the UK GDPR applies to Customer Data, the transfer to us and to our providers rests on standard contractual clauses in our Terms of Service and in each provider's terms; where POPIA applies, on the customer's authorisation and the safeguards in this policy.
9. How long we keep data
- Customer Data: for as long as the customer's account is active and as the customer configures it. After a trial lapses or a subscription ends the account goes read-only with export open, and the data is deleted 90 days later unless the customer asks sooner.
- A customer's own retention rule can anonymise lost enquiries after three years.
- Deleted records stay recoverable for 30 days, then are removed.
- The audit log of changes is kept for the life of the account.
- Backups are encrypted and kept for 30 days.
- Account and billing records: 7 years after the account ends, as tax law requires.
- Website logs: 30 days.
10. How we protect data
Encryption in transit (TLS) everywhere; dates of birth, medical details, insurance details, payment references and access tokens encrypted at rest; every query bound to one organisation with row-level security in the database as a second lock; an audit log of every change; signed-in access only, with Google sign-in limited to each customer's own domains; virus scanning of uploads; encrypted off-site backups restored and tested regularly; two-factor authentication on every provider account we hold. No system is perfectly secure; if a breach affects you we will tell the customer, and where the law requires it the people affected and the regulator, without undue delay.
11. Your rights
Depending on where you are, you may have the right to see the data we hold about you, to correct it, to have it deleted, to receive a copy, to object to or restrict its processing, and to complain to a data protection authority. If your data is Customer Data, the safari operator who holds your booking is the one to ask, and the application gives them an export and a delete-or-anonymise action per person so they can answer you quickly. For account data, write to privacy@safari-studio.com. We answer within 30 days and never charge for a first request.
12. Children
Safari Studio is for businesses and their staff, not for children. Travellers under 18 are entered by the adult booking the trip, who is responsible for that information.
13. Cookies
The application sets one session cookie to keep you signed in and no advertising or tracking cookies. [The website sets Google Analytics cookies only if you accept them.]
14. Changes
We will post changes here with a new effective date and tell customers by email of any change that affects their rights. Continued use after the date means acceptance.
15. Contact
privacy@safari-studio.com · [Strandwolf Desert Tours CC], 22 Hendrik Witbooi Street, Swakopmund, Namibia.