Legal
Privacy Policy
Last updated: 7 August 2026
1. What we collect
- Account data: email address and password (stored as a salted hash).
- Agent data: company name, licence number, licence document, phone, and bank details needed for payouts.
- Booking data: names of travellers, party size, selected dates and add-ons, and payment records (card data is handled by the licensed payment provider — GoRaajje never stores full card numbers).
- Communication data: messages sent through the platform and reviews you post.
- Technical data: session cookies, and anonymised search queries used only in aggregate to improve the service.
2. How we use it
- To operate the service: bookings, payments, notifications, payouts and messaging.
- To verify agents before they publish packages (licence checks).
- To keep the platform safe: fraud prevention, moderation of reviews and messages.
- To improve the product, using aggregate and anonymised data only.
We rely on: performance of our contract with you (providing the service), legitimate interests (fraud prevention, platform security), and consent where we ask for it (e.g. optional marketing).
3. Who we share it with
- Agents, to fulfil your booking: the agent you booked with sees your contact details, party size and booking history for their packages.
- Payment providers, to process charges and refunds.
- Service providers (hosting, email delivery) bound by confidentiality.
- Authorities, only when legally required.
We never sell personal data, and messages between a customer and an agent are visible only to those two parties and GoRaajje support.
4. Retention
Account data is kept while your account is active. Financial records (payments, payouts, fee entries) are kept as audit trails as required by law and good accounting practice. Anonymised search statistics are kept indefinitely in aggregate.
5. Your rights and choices
- Access and correction: view and update your account details at any time.
- Export: request a copy of your personal data.
- Deletion: request deletion of your account and data, subject to legal retention of financial records.
- Messaging and reviews: you control what you post; abusive content can be reported and hidden by moderation.
- Marketing: we do not send marketing email; booking notifications can be managed in settings.
These rights are honoured by GoRaajje as commitments; the specific procedures of a future Maldivian data protection law, once enacted, will apply.
6. Security
Data is transmitted over encrypted connections, passwords are stored hashed, and access to personal data is restricted to staff who need it. We commit to notifying affected users and the relevant authorities of any significant breach.
7. Cookies and local storage
We use a small number of technical cookies and browser storage: a session cookie for login, a CSRF cookie for form security, and a local-storage preference for your theme choice. We do not use advertising or cross-site tracking cookies.
8. Children
The service is not directed at children under 18, and accounts cannot be created by anyone under 18.
9. Contact
Privacy questions or requests: hello@goraajje.com. Complaints may also be raised with the Consumer Ombudsman's Office under the Consumer Protection Act (Law No. 12/2020).